Catalpas Atelier Privacy Policy

Version: 1.1

Effective Date: 2026-07-14

Operator: Heliopolis Creative and Culture Limited (Hong Kong)

Contact: privacy@catalpasatelier.com

This Privacy Policy explains how Heliopolis Creative and Culture Limited, trading as Catalpas Atelier ("Catalpas Atelier", "we", "us", or "our"), handles personal information when you use our international website, account and subscription services, support services, and desktop software.

Our current desktop products covered by this Policy are Catalpas Atelier Scribe and Catalpas Atelier Scroll (together, the "Covered Software"). The Writing Suite (Scroll + Scribe) is a commercial plan that may provide entitlements to both products; it does not change how local project content is handled.

This Policy is a privacy notice, not a request for blanket consent. Where we rely on consent for a particular activity, such as optional analytics or marketing technologies, we ask for that consent separately and allow you to withdraw it.

Our Terms of Use and EULA govern your use of the website, account, subscriptions, and Covered Software. Our separate Cookie and Tracking Notice explains optional technologies used on catalpasatelier.com. The Catalpas Atelier Docs and Blog properties provide their own property-specific cookie notices and consent controls.

1. Who we are and when this Policy applies

Catalpas Atelier is operated for the international region by:

This Policy applies to:

  • catalpasatelier.com and its account, checkout, billing, download, and support surfaces;
  • a Catalpas Atelier account and the entitlements associated with it;
  • the online services used by the Covered Software for sign-in, entitlement verification, billing links, downloads, and updates; and
  • information you voluntarily provide when requesting support.

The Catalpas Atelier Docs and Blog properties may display supplemental privacy or cookie notices describing processing specific to those properties. A supplemental notice controls for that property if it provides more specific information. The international and mainland China regions use different operators, infrastructure, account systems, and legal documents; this Policy does not govern services expressly offered by the mainland China operator.

2. Personal information we collect

We collect only information reasonably needed to provide, secure, support, and improve the relevant service.

2.1 Account and profile information

When you create or manage an account, we may process:

  • email address, display name, and optional profile information;
  • a cryptographic password hash, never your plaintext password;
  • account region, language, preferences, and email-verification status;
  • session, access, and refresh tokens and related security records;
  • product, plan, tier, entitlement, renewal, cancellation, and expiry status; and
  • marketing communication choices and the time at which you changed them.

If you use Sign in with Google, Google authenticates you and, after you complete Google's consent screen, provides the identifiers and profile fields needed to create or connect your Catalpas Atelier account, such as a Google account identifier, email address, name, and profile image. We do not receive your Google password.

2.2 Subscription, order, and billing information

Stripe processes international card and payment-method information. We may receive and store:

  • Stripe customer, checkout-session, subscription, invoice, payment, refund, and dispute identifiers;
  • the product or Writing Suite, tier, billing interval, amount, currency, tax, and order status;
  • renewal, cancellation, payment-failure, refund, and entitlement status;
  • transaction dates and limited billing/contact details made available by Stripe; and
  • records needed for accounting, fraud prevention, support, and legal compliance.

We do not receive or store full payment-card numbers, card security codes, or online-banking credentials. The Covered Software does not collect payment-card details; it opens the relevant Catalpas Atelier account or billing page.

2.3 Website and network information

When you visit our website or connect to an online service, our servers, hosting providers, content-delivery providers, and security systems may receive:

  • IP address, request time, requested URL, referring URL, response status, and network/security signals;
  • browser type and version, operating system, device category, language, and approximate region derived from network information;
  • account/session identifiers when you are signed in; and
  • records of suspicious, failed, or abusive requests.

With your separate consent, analytics or marketing providers may also process page views, campaign/referrer information, browser/device information, approximate location, cookie or pixel identifiers, and the events described in our Cookie and Tracking Notice.

Campaign links. If you follow a Catalpas Atelier campaign redirect such as /r/<slug>, we record a first-party campaign visit before redirecting you. The record may contain the campaign identifier, a single-visit pseudonymous request identifier, landing page, request time, referrer, browser/user-agent information, IP address, and approximate country. We use it to route the request, apply an offer you requested, prevent abuse, troubleshoot links, and perform limited campaign measurement based on our legitimate interests. This first-party visit record is separate from optional analytics and advertising pixels.

We do not store a persistent campaign visitor cookie or link a campaign visit to a later registration or purchase unless you have granted marketing consent. If you grant that consent, we may store the host-only cas_visitor pseudonymous identifier for up to 30 days and use it to attribute a later registration or purchase to the campaign. Withdrawing marketing consent removes or disables that browser identifier for future attribution; it does not erase a campaign visit already recorded or information already received by a provider.

2.4 Desktop online-service information

When Scribe or Scroll signs in, refreshes a session, verifies an entitlement, checks for an update, retrieves release information, or opens an account service, the request may include information such as:

  • product name, application version, build, distribution channel, and service region;
  • operating-system name and version and basic compatibility information included by the request;
  • account/session identifiers, entitlement request and response, and relevant timestamps;
  • update channel, current version, target platform and architecture, and update status; and
  • IP address and ordinary server/security logs generated when the request reaches our service.

We do not currently use the Covered Software to perform advertising tracking, third-party product analytics, hardware fingerprinting, MAC-address collection, device binding, or automatic third-party crash reporting. The Covered Software may create diagnostic logs on your device. Those local logs, screenshots, project samples, or crash details are sent to us only if you choose to provide them to support.

If we plan to add telemetry, crash reporting, device binding, or another materially different collection practice, we will update the applicable notice before enabling it and request consent where required.

2.5 Support and communications

When you contact us, we process your message, contact details, account and order references, and any screenshots, files, logs, or project excerpts you choose to provide. Please send only the material needed to resolve your request and remove personal or confidential content that is not relevant.

3. Local-first project content

Scribe and Scroll are local-first desktop applications. By default, project content is stored in locations you control on your device or storage provider.

For Scribe, local project content may include manuscripts, notes, outlines, images, PDFs, typography and layout settings, project assets, and exports.

For Scroll, local project content may include documents, Story and planning data, cards, custom properties and relationships, reference cards and links, timelines, maps, tasks, metadata, delivery profiles, manifests, and other project files.

We do not, by default, upload, host, publish, sell, analyse, or use this local project content to train AI models. Scribe and Scroll do not currently provide Catalpas-hosted project sync or AI analysis of local project content. Creating a local export, reference link, bibliography projection, or delivery manifest does not by itself upload that content to Catalpas Atelier.

You may choose to move or share files through your own storage, email, collaboration, publishing, or other third-party services. Those services process the files under their own terms and privacy notices. If we later offer Catalpas-hosted sync, collaboration, AI assistance, backup, or remote publishing, we will provide updated information before those features process project content.

4. How and why we use personal information

We use personal information to:

  • create, authenticate, protect, and administer accounts;
  • provide Free and paid product entitlements and verify access to plan features;
  • process checkout, renewal, cancellation, refund, tax, accounting, and support requests;
  • deliver downloads, release information, updates, security fixes, and service messages;
  • diagnose errors, maintain compatibility, prevent fraud and abuse, and protect our services;
  • respond to support, privacy, legal, and business enquiries;
  • send marketing communications when you have opted in, and record opt-outs;
  • measure and improve our INTL web properties when you permit optional analytics;
  • measure advertising and persistent campaign attribution when you permit optional marketing technologies;
  • route campaign links, preserve an offer you requested, prevent link abuse, and perform limited first-party campaign measurement; and
  • comply with law, enforce agreements, establish or defend legal claims, and protect users and the public.

Where the GDPR, UK GDPR, or a similar law applies, our legal bases generally include:

  • contract, when processing is necessary to create or administer your account, provide an entitlement, deliver software services, process an order, or provide requested support;
  • legitimate interests, such as securing accounts and services, preventing fraud, maintaining compatibility, operating campaign redirects, performing limited first-party campaign measurement, understanding service reliability, and defending legal rights, balanced against your rights and expectations;
  • consent, for optional analytics, marketing trackers, persistent campaign attribution, and marketing communications where consent is required; and
  • legal obligation, for tax, accounting, consumer-protection, sanctions, regulatory, and lawful-request requirements.

Where we ask for consent, you may withdraw it at any time. Withdrawal does not affect processing already lawfully carried out before withdrawal.

5. Cookies, analytics, and advertising measurement

catalpasatelier.com uses strictly necessary storage for functions such as language selection, authentication, security, preserving an offer you requested, and remembering your privacy choices. Optional analytics and marketing technologies are off unless you choose the relevant category.

Our consent design provides that:

  • Google Analytics 4 is not loaded and receives no data before you grant analytics consent;
  • Meta Pixel and Reddit Pixel are not loaded and receive no events before you grant marketing consent;
  • a persistent first-party campaign attribution identifier is not stored or linked to your account before you grant marketing consent; and
  • analytics and marketing choices can be granted, rejected, or withdrawn independently.

A first-party campaign redirect and its limited server-side visit record may operate without marketing consent as described in Section 2.3. That record does not enable Meta Pixel, Reddit Pixel, Google Analytics, or persistent cross-session attribution.

Our Official website, Docs, and Blog properties each store their own consent choice. A choice on one property does not automatically apply on another. We use separate Google Analytics properties for those sites and may use shared Meta and Reddit pixels for suite-level campaign measurement. The use of a shared pixel does not override the requirement for separate consent on each property.

See our Cookie and Tracking Notice and the "Cookie preferences" control on the relevant site for details and choices.

6. When we disclose personal information

We disclose only information reasonably needed for the relevant service or legal purpose. Categories of recipients may include:

  • Stripe, for checkout, payment processing, invoicing, subscriptions, tax-related payment data, fraud prevention, refunds, and disputes;
  • Google, for Sign in with Google and, after the relevant site consent, Google Analytics 4;
  • Meta, after marketing consent, for Meta Pixel advertising attribution and measurement;
  • Reddit, after marketing consent, for Reddit Pixel advertising attribution and measurement;
  • hosting, database, storage, network, content-delivery, and security providers, including infrastructure in Tencent Cloud's Tokyo region for parts of our backend;
  • email and customer-support providers, for transactional messages and support communications;
  • professional advisers, auditors, insurers, regulators, courts, and public authorities, when reasonably necessary or legally required; and
  • a successor or transaction counterparty, in connection with a proposed or completed merger, financing, restructuring, sale, or transfer, subject to appropriate confidentiality and legal safeguards.

Some providers act as our processors or service providers; others may act as independent controllers for parts of their service. Their own notices explain their processing. We require appropriate contractual and security protections where applicable.

We do not sell personal information for money. We do not disclose local Scribe or Scroll project content to advertising providers. Optional Meta and Reddit measurement may be treated as "sharing", targeted advertising, or a similar regulated activity under some US state laws; it remains disabled unless you grant marketing consent, and you may withdraw that consent.

7. International transfers

We operate from Hong Kong and use providers that may process information in Hong Kong, Japan, the United States, the European Economic Area, the United Kingdom, or other locations. Those locations may have different privacy laws from your home jurisdiction.

Where required, we use an applicable legal transfer mechanism, such as an adequacy decision, contractual safeguards, or a data processing agreement, and apply supplementary safeguards appropriate to the processing. Contact us if you would like more information about the safeguards relevant to your information.

8. Retention

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security, support, and dispute requirements. Retention depends on the record:

  • account and entitlement records are generally kept while the account is active and for a limited period after closure where needed for restoration, security, disputes, or legal obligations;
  • authentication and security records are retained for periods appropriate to token validity, incident investigation, fraud prevention, and audit needs;
  • orders, invoices, refunds, and accounting records are retained for the period required by applicable tax, accounting, and consumer laws;
  • support records are retained for as long as needed to resolve and document the issue and related claims;
  • web server, campaign-visit, and security records are retained for limited operational, measurement, fraud-prevention, and dispute periods;
  • the Official site's consent record is designed to expire after 12 months, after which we may ask again;
  • a consented first-party campaign visitor cookie is designed to expire after 30 days, while associated attribution records are retained only for documented campaign measurement, accounting, fraud-prevention, and dispute purposes; and
  • provider analytics and advertising data follow our configured settings and the relevant provider's retention rules.

We may retain information longer where necessary to comply with law, preserve evidence, resolve a dispute, or enforce an agreement. We may retain aggregated or de-identified information that no longer identifies an individual.

9. Security

We use reasonable technical and organisational safeguards appropriate to the nature of the information, including access controls, password hashing, encryption in transit where appropriate, least-privilege access, logging, backup controls, and service-provider review. No service or transmission method is completely secure. You are responsible for protecting your credentials, devices, local project files, and backups.

10. Your privacy rights and choices

Depending on your location, you may have rights to:

  • access or receive a copy of personal information;
  • correct inaccurate or incomplete information;
  • request deletion, restriction, or portability;
  • object to processing based on legitimate interests;
  • withdraw consent;
  • opt out of targeted advertising, sale, or sharing as those terms are defined by applicable law;
  • appeal a refusal where applicable; and
  • complain to a competent privacy or data-protection authority.

You can change optional website tracking choices through the site's Cookie preferences control and unsubscribe from marketing email using the link in the message. Where applicable law requires us to recognise a valid browser-based opt-out preference signal, we will treat it as an opt-out for the browser and property from which it is received.

To exercise another right, email privacy@catalpasatelier.com. Tell us which account, site, and right your request concerns. We may need to verify your identity and may retain a limited record of the request. We will not discriminate against you for exercising a privacy right.

If you are in the EEA or United Kingdom, you may complain to the supervisory authority in the country where you live or work or where the alleged infringement occurred. If applicable law requires us to appoint an EU or UK representative, we will publish that representative's contact details here before the appointment becomes required.

11. Children

Our services are not directed to children under 13. You must also meet any higher minimum age that applies where you live, or use the services only with valid consent from a parent or guardian where the law permits. We do not knowingly collect personal information from a child in violation of applicable law. Contact us if you believe this has occurred.

12. Changes to this Policy

We may update this Policy to reflect changes in law, providers, products, or processing. The version and effective date identify the current text. If a change is material, we will provide notice appropriate to the change, such as a website, account, email, or in-product notice. Where a new activity requires consent, we will request it rather than relying only on continued use.

13. Contact

For privacy questions, requests, or complaints, contact: