Attaché

Privacy policy

Last updated: 6 August 2026

This is a translation provided for convenience. The French version is the legally binding one.

Who we are

Attaché is a service published by ATM HOLDING, a French SAS with a share capital of €5,186,850, registered office at 57 montée de Saint-Menet, 13011 Marseille, France (SIREN 902 606 789), acting as data controller under the GDPR. It publishes the attache.studio website and the Attaché service, a secure access layer between advertising and analytics platforms (Google Analytics 4, Google Ads, Google Search Console, Meta Ads) and MCP-compatible AI assistants.

Data processed on this website

  • Contact and early-access forms: name, email, company and message — used only to reply to you and to open your access, sent through our email sub-processor (Resend). Kept for 12 months at most.
  • Analytics: we use Plausible Analytics, a cookieless solution that collects no personal data, plus Google Analytics 4 — the latter only if you accept it through the consent banner. Declining does not affect browsing, and your choice is remembered.

Data processed by the Attaché service

  • OAuth tokens: issued by Google and Meta when a user connects their accounts. Encrypted at rest with AES-256-GCM, never shared, revocable at any time.
  • Shared resource list: the identifiers and display names of the properties and accounts the user explicitly ticked. Identifiers and labels only.
  • Platform data: not stored. Requests are proxied in real time between the AI assistant and the platform APIs, and the responses are never written to disk.
  • Access logs: which platform was queried, when, and with which query parameters (date range, metrics requested) — for auditability and transparency towards the end client. Platform responses are never logged: we keep the question, never the result.

Google user data — Limited Use

Attaché's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely:

  • we use Google user data only to provide and improve the features the user explicitly requested;
  • we do not transfer Google user data to third parties, except as necessary to provide the service, for security purposes, or to comply with applicable law;
  • we do not use Google user data for advertising, and we do not sell it;
  • we do not allow humans to read Google user data, unless we have the user's explicit consent for a specific case, it is necessary for security or to comply with applicable law, or the data has been aggregated and anonymised;
  • we do not use Google user data to develop, improve or train generalised or non-personalised AI or machine-learning models.

Google Ads is the only one of our four sources without a read-only OAuth scope. We therefore request the narrowest scope available (adwords) and restrict it at the application level: any GAQL query that is not a SELECT is rejected server-side before reaching the API, with no bypass path.

Hosting and transfers

The application infrastructure (server, database, cache) is hosted by Railway Corp. in its US East region. That choice does not expose your analytics or advertising data: no business data from your accounts is stored — only encrypted OAuth tokens are.

Current sub-processors:

  • Railway Corp. (United States) — hosting of the application, database and cache.
  • Cloudflare, Inc. (United States) — DNS, CDN, network protection and routing of mail sent to @attache.studio addresses.
  • Resend (Plus Five Five, Inc.) (United States) — transactional email delivery.
  • Plausible Insights OÜ (Estonia) — cookieless analytics.
  • Google Ireland Ltd. — Google Analytics 4, loaded only after your consent, and Google Workspace, the mailbox used to correspond with you.

Transfers outside the European Union rely on the European Commission's standard contractual clauses, together with encryption of data at rest and in transit.

Revocation and deletion

A user can revoke access at any time from their own space. Revocation calls Google's and Meta's own token revocation endpoints, not only our database, so the grant also disappears from the user's Google account permissions page. On account closure, tokens are revoked and deleted and account data is erased within thirty days, subject to statutory retention obligations such as invoicing.

Your rights

Under the GDPR you have rights of access, rectification, erasure, restriction and objection. To exercise them: [email protected]. You may also lodge a complaint with the CNIL, the French data protection authority.