Legal
Privacy Policy
Last updated September 30, 2026
How Ellis Labs collects, uses, shares, and protects personal information in Attune Projects, its client portal.
1.What this policy covers
This policy explains how Ellis Labs (“we”, “us”) handles personal information in Attune Projects, the client portal at projects.attunehub.ai (the “Portal”). It applies to Ellis Labs staff and to the people our clients invite to their workspace. It also covers visitors to the Portal’s public homepage at projects.attunehub.ai, who have no account (see “What we don’t do” for the measurement that applies to them). Our company website, ellislabs.ai, is covered separately.
We operate the Portal. When we handle your organization’s business information to deliver an engagement, your Engagement Agreement also governs how that information is used and kept confidential.
2.Information we collect
- Account information. Your name, email address, a password (stored only as a one-way hash), an optional profile picture, your role, the organization and projects you belong to, and your notification preferences.
- Content you contribute. Messages, comments, proposed tasks, approvals and change requests, meeting notes, and the files you upload — along with the earlier versions of those files.
- Activity records. An activity log of actions taken on each project (for example, who approved a deliverable and when), read markers, and reactions. This keeps a reviewable trail and powers notifications.
- Assistant conversations. When you use the AI assistant, your conversation is stored and is visible only to you. We also record usage details for each request — the feature used, the model, token counts, and estimated cost — for reliability and cost control.
- Connected-app authorizations. When you connect a third-party app, we store the access token and the permission level you granted, so you can review and revoke it.
- Technical information. Standard server logs and security records: IP address, browser and device details, timestamps, and the pages requested. We use these for security (such as rate limiting and sign-in lockouts), troubleshooting, and abuse prevention.
- Email. When you reply to a notification email, we receive the reply and its attachments and post them into the matching conversation, removing the quoted thread. Our email provider records delivery events for the messages we send.
- Analytics you connect. If a project connects a Google Analytics property, we read that property’s traffic data to produce reports. We don’t send Portal information to Google to do this.
3.How we use it
We use this information:
- To run the Portal and deliver your engagement — showing you your projects, files, and conversations.
- To sign you in and keep your account secure.
- To send the notifications you’ve chosen, along with invitations and sign-in links.
- To power the AI assistant and any connected apps you use, within your permissions.
- To keep an accurate record of project activity.
- To monitor reliability, fix errors, and prevent abuse.
- To meet legal obligations and enforce our Terms of Use.
4.What we don’t do
We don’t sell personal information and we don’t use the Portal to serve advertising.
We do measure how the Portal itself is used, including its public homepage, through Google Tag Manager and Google Analytics, so we can see which parts of it help and which get in the way. What we send is the page you opened (with project and record identifiers removed from the address), whether you are Ellis Labs staff or a client team member, and which organization and project the page belongs to.
We also record that certain actions happened — a deliverable approved or sent back, a file uploaded or downloaded, a reply posted, a task moved, the assistant opened, a hosted site opened, an invitation accepted — together with plain facts about them such as how many files were attached or which status a task moved to. We do not send your name, your email address, the text of anything you write, the names of files you upload, or what you ask the assistant.
For the notification emails we send you, our email provider tells us whether each one was delivered, bounced, or marked as spam, and we keep that against the notification so we can tell when a message never reached you. We may also count those outcomes in Google Analytics by type of email; when we do, you are identified only by a one-way code derived from your address, never the address itself.
5.The AI assistant and your information
To answer a question or take an action, the assistant sends the relevant Portal information you ask about — such as a task, a deliverable and its feedback, or a conversation — to our AI model provider, Anthropic, to generate a response. It only ever has access to what your own account can see. We use Anthropic’s commercial API, under terms that don’t allow our data to be used to train its models.
Any assistant action that would reach other people — sending a status update, posting a message — requires your explicit confirmation before it happens.
8.How we protect it
Every connection to the Portal is encrypted, and our providers encrypt stored data. Access to information is enforced at the data layer, so each person can reach only the projects and material they’re allowed to see. Passwords are stored as one-way hashes. Sign-in links are single-use and short-lived, and accounts lock temporarily after repeated failed attempts.
Our error-monitoring pipeline strips names, email addresses, message bodies, and secrets from reports before anything leaves the Portal.
No system is perfectly secure. If we learn of a breach affecting your information, we’ll notify the affected people and organizations as the law requires.
9.How long we keep it
We keep Portal information for as long as your organization’s engagement is active and for a reasonable period afterward, so the record of a project stays available to both sides. Files keep their version history, and archived files are hidden rather than destroyed, by design.
Assistant conversations are kept until you delete them or your account is removed. Technical logs are kept for a limited period for security and troubleshooting.
You can ask us to delete your account or specific information (see “Your choices and rights”). We may keep some records where we need them to meet legal obligations, resolve disputes, or enforce our agreements.
10.Your choices and rights
From Account & notifications you can update your name, picture, and notification preferences, review and sign out of your sessions, and revoke connected apps. Every notification email includes a one-click unsubscribe.
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to complain to a data-protection authority. To exercise these rights, email hello@ellislabs.ai from the address on your account. We’ll verify the request and respond within the time the law requires.
If your organization invited you to the Portal, some requests — such as removing you from a project — may need to go through your organization’s client lead, and we may refer them there.
11.International users
Ellis Labs is based in the United States and operates the Portal from there. If you use it from elsewhere, your information will be transferred to and processed in the United States, where privacy laws may differ from those where you live. Where the law requires it, we rely on appropriate safeguards for those transfers.
12.Children
The Portal is a business tool and isn’t directed at children under 18. We don’t knowingly collect information from children. If you believe a child has provided us information, contact us and we’ll remove it.
13.Changes to this policy
We may update this policy from time to time. The “last updated” date at the top shows the current version, and we’ll let you know in the Portal or by email if a change is material.
14.Contact
Privacy questions or requests: hello@ellislabs.ai.