Attune Projects

Legal

Privacy Policy

Last updated September 30, 2026

How Ellis Labs collects, uses, shares, and protects personal information in Attune Projects, its client portal.

1.What this policy covers

This policy explains how Ellis Labs (“we”, “us”) handles personal information in Attune Projects, the client portal at projects.attunehub.ai (the “Portal”). It applies to Ellis Labs staff and to the people our clients invite to their workspace. It also covers visitors to the Portal’s public homepage at projects.attunehub.ai, who have no account (see “What we don’t do” for the measurement that applies to them). Our company website, ellislabs.ai, is covered separately.

We operate the Portal. When we handle your organization’s business information to deliver an engagement, your Engagement Agreement also governs how that information is used and kept confidential.

2.Information we collect

  • Account information. Your name, email address, a password (stored only as a one-way hash), an optional profile picture, your role, the organization and projects you belong to, and your notification preferences.
  • Content you contribute. Messages, comments, proposed tasks, approvals and change requests, meeting notes, and the files you upload — along with the earlier versions of those files.
  • Activity records. An activity log of actions taken on each project (for example, who approved a deliverable and when), read markers, and reactions. This keeps a reviewable trail and powers notifications.
  • Assistant conversations. When you use the AI assistant, your conversation is stored and is visible only to you. We also record usage details for each request — the feature used, the model, token counts, and estimated cost — for reliability and cost control.
  • Connected-app authorizations. When you connect a third-party app, we store the access token and the permission level you granted, so you can review and revoke it.
  • Technical information. Standard server logs and security records: IP address, browser and device details, timestamps, and the pages requested. We use these for security (such as rate limiting and sign-in lockouts), troubleshooting, and abuse prevention.
  • Email. When you reply to a notification email, we receive the reply and its attachments and post them into the matching conversation, removing the quoted thread. Our email provider records delivery events for the messages we send.
  • Analytics you connect. If a project connects a Google Analytics property, we read that property’s traffic data to produce reports. We don’t send Portal information to Google to do this.

3.How we use it

We use this information:

  • To run the Portal and deliver your engagement — showing you your projects, files, and conversations.
  • To sign you in and keep your account secure.
  • To send the notifications you’ve chosen, along with invitations and sign-in links.
  • To power the AI assistant and any connected apps you use, within your permissions.
  • To keep an accurate record of project activity.
  • To monitor reliability, fix errors, and prevent abuse.
  • To meet legal obligations and enforce our Terms of Use.

4.What we don’t do

We don’t sell personal information and we don’t use the Portal to serve advertising.

We do measure how the Portal itself is used, including its public homepage, through Google Tag Manager and Google Analytics, so we can see which parts of it help and which get in the way. What we send is the page you opened (with project and record identifiers removed from the address), whether you are Ellis Labs staff or a client team member, and which organization and project the page belongs to.

We also record that certain actions happened — a deliverable approved or sent back, a file uploaded or downloaded, a reply posted, a task moved, the assistant opened, a hosted site opened, an invitation accepted — together with plain facts about them such as how many files were attached or which status a task moved to. We do not send your name, your email address, the text of anything you write, the names of files you upload, or what you ask the assistant.

For the notification emails we send you, our email provider tells us whether each one was delivered, bounced, or marked as spam, and we keep that against the notification so we can tell when a message never reached you. We may also count those outcomes in Google Analytics by type of email; when we do, you are identified only by a one-way code derived from your address, never the address itself.

5.The AI assistant and your information

To answer a question or take an action, the assistant sends the relevant Portal information you ask about — such as a task, a deliverable and its feedback, or a conversation — to our AI model provider, Anthropic, to generate a response. It only ever has access to what your own account can see. We use Anthropic’s commercial API, under terms that don’t allow our data to be used to train its models.

Any assistant action that would reach other people — sending a status update, posting a message — requires your explicit confirmation before it happens.

6.Who we share it with

  • Your team and Ellis Labs. Within the Portal, information is shared according to its visibility setting. Client-visible material is shown to your organization’s team on that project, and the Ellis Labs staff working on your engagement can see the project. Material marked internal is visible only to Ellis Labs staff.
  • Service providers. We rely on a small number of providers to run the Portal, each acting on our instructions: Vercel (application hosting and file storage), Neon (database), Resend (sending and receiving email), Anthropic (the default model for the AI assistant and AI teammates; if we configure another model provider, such as OpenAI or Google, that provider processes the same content on our instructions), Sentry (error monitoring, when enabled), and Google (reading connected analytics properties, and measuring use of the Portal itself). These providers are based in the United States, and your information may be stored or processed there.
  • Embedded content. Deliverables may embed designs, videos, or reports from Figma, Loom, or Looker Studio. When you view an embed, that provider may collect information under its own privacy policy.
  • E-signature services. For contracts, we store only a reference to the DocuSign envelope and the unsigned proposal document — never the signed document containing personal details.
  • Connected apps you authorize. If you connect a third-party AI app, it can access your Portal information at the level you approved, until you revoke it.
  • Legal and safety. We may disclose information if required by law, to protect the rights and safety of people or of Ellis Labs, or as part of a merger, acquisition, or sale of the business — in which case this policy continues to apply to it.

7.Cookies and local storage

The Portal uses a session cookie to keep you signed in. It’s an essential cookie: it isn’t used for advertising.

Google Analytics also sets cookies to recognise a returning browser and group a visit into one session. They are used to measure how the Portal is used, never for advertising, and we don’t combine them with anything you do outside it. You can block them with your browser’s settings or an extension without losing access to any part of the Portal.

We keep a few interface preferences — such as whether the sidebar is collapsed and how you like a list sorted — in your browser’s local storage. They stay on your device and aren’t sent to us.

8.How we protect it

Every connection to the Portal is encrypted, and our providers encrypt stored data. Access to information is enforced at the data layer, so each person can reach only the projects and material they’re allowed to see. Passwords are stored as one-way hashes. Sign-in links are single-use and short-lived, and accounts lock temporarily after repeated failed attempts.

Our error-monitoring pipeline strips names, email addresses, message bodies, and secrets from reports before anything leaves the Portal.

No system is perfectly secure. If we learn of a breach affecting your information, we’ll notify the affected people and organizations as the law requires.

9.How long we keep it

We keep Portal information for as long as your organization’s engagement is active and for a reasonable period afterward, so the record of a project stays available to both sides. Files keep their version history, and archived files are hidden rather than destroyed, by design.

Assistant conversations are kept until you delete them or your account is removed. Technical logs are kept for a limited period for security and troubleshooting.

You can ask us to delete your account or specific information (see “Your choices and rights”). We may keep some records where we need them to meet legal obligations, resolve disputes, or enforce our agreements.

10.Your choices and rights

From Account & notifications you can update your name, picture, and notification preferences, review and sign out of your sessions, and revoke connected apps. Every notification email includes a one-click unsubscribe.

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to complain to a data-protection authority. To exercise these rights, email hello@ellislabs.ai from the address on your account. We’ll verify the request and respond within the time the law requires.

If your organization invited you to the Portal, some requests — such as removing you from a project — may need to go through your organization’s client lead, and we may refer them there.

11.International users

Ellis Labs is based in the United States and operates the Portal from there. If you use it from elsewhere, your information will be transferred to and processed in the United States, where privacy laws may differ from those where you live. Where the law requires it, we rely on appropriate safeguards for those transfers.

12.Children

The Portal is a business tool and isn’t directed at children under 18. We don’t knowingly collect information from children. If you believe a child has provided us information, contact us and we’ll remove it.

13.Changes to this policy

We may update this policy from time to time. The “last updated” date at the top shows the current version, and we’ll let you know in the Portal or by email if a change is material.

14.Contact

Privacy questions or requests: hello@ellislabs.ai.