Talomis
Menu

Privacy

Plain language. You should not need a lawyer to understand what a directory does with your name.

Version 2.0. Last updated 28 August 2026

Read the site and we hold nothing about you. Send a request and we hold what the artist needs to answer you.

  • No analytics product, no advertising pixel, no tracking cookie, no third party script on any page you read.
  • No payment rail. We never see a card number because we never ask for one.
  • The nearest to you feature does its arithmetic in your own browser. Your coordinates are not sent anywhere.
  • We do not sell your details, and we do not hand them to anybody except the artist you picked and the providers that run the service.
  • Ask and we tell you what we hold, correct it, or delete it.
  • If you are listed here and would rather not be, say so and your page comes down. No reason needed.

This summary is here to be read. The sections underneath it are the ones that count.

The controller of everything on this page, which is the legal word for whoever is answerable for it, is Talomis, run by Tony Krohn. Talomis is a directory of tattoo artists that connects a client to an artist for a consultation and then gets out of the way.

Write to bookings@neotradatlas.com about anything on this page. A person reads it.

One row for each kind of thing we hold, what it is for, and the legal ground it sits on. If a category is not listed here, we do not hold it.

  1. Reading the site

    Nothing you type, because there is nothing to type. No account, no sign in, no advertising tracker, no cross site profile, no cookie set by us on any page. Our host and our database see your IP address the way every web server does, in ordinary server logs.

    Why To serve you the page, and to keep the site standing up.

    Ground Our legitimate interest in running a website, Article 6(1)(f).

  2. A request

    Your first name and last name, your email address, your phone number if you give one, what you write about the idea, where it goes on your body, the styles, the size and the timing, and whether you want colour. We record that you confirmed you are 18 or older and that you accepted the Talomis terms, the two boxes on the form, and we record the tag on the link you arrived from.

    Why The artist needs all of it to decide whether they are the right person for your tattoo and to reach you about it. It is the reason you filled the form in.

    Ground Steps taken at your request before a contract, Article 6(1)(b), and our legitimate interest in passing it to the artist you picked, Article 6(1)(f).

  3. Photographs you upload

    Up to three reference images and one placement photograph, held in a private store. The image files keep whatever information your camera wrote into them, which on a phone can include the place the photograph was taken. We do not strip it and we do not read it.

    Why So the artist can see what you mean and where it goes.

    Ground Steps taken at your request before a contract, Article 6(1)(b).

  4. A consultation time

    The time you picked, and a short lived hold on it. The consultation goes on the artist's calendar with your name, your email, your phone number and your description written into the event, and you are invited to it, so Google sends you the invitation.

    Why It is what booking a time means.

    Ground Steps taken at your request before a contract, Article 6(1)(b).

  5. An artist account

    The email address on the account, and a password if you set one rather than using a sign in link. Your handle, name, city, state, shop name, shop address, styles, bio, booking link, follower number if you enter one, your photographs, your links, your conventions and guest spots, your store rows, and your booking settings. We log the date you claimed the page and the email address you claimed it with, and the date you accepted the booking terms.

    Why It is your page. All of it is what you chose to publish or how you chose to run it.

    Ground Performing our agreement with you, Article 6(1)(b), which is these terms and the covenant.

  6. A Google Calendar connection

    An access token and a refresh token, encrypted before they are stored, plus which provider it is and whether the connection is live. The tokens are never sent to a browser.

    Why To offer real consultation times and to put a confirmed one on your calendar.

    Ground Your consent, given on Google's own screen, Article 6(1)(a). You can take it back at any time.

  7. A page nobody has claimed

    The artist's public handle, their name, their city and country, coordinates worked out from that city, their styles, up to three of their published work images with a written description of each, and, where the artist published one publicly, a contact email address.

    Why A directory of working artists is only useful if the working artists are in it, and a client who finds you needs a way to reach you. There is a section below on this, and an unconditional way out of it.

    Ground Our legitimate interest in publishing a professional directory, Article 6(1)(f).

  8. Counting

    Two kinds of row. One when an artist's page is opened, carrying the artist's id and the tag on the link. One when somebody starts an intake or opens live times, carrying the artist's id, the kind of event and the same tag. Neither row carries a name, an account, a device id, a fingerprint or the page you came from. Two visits by the same person are two rows that cannot be joined, by us or by anybody holding the database.

    Why So an artist can see their own numbers, and so we can tell whether this is working.

    Ground Our legitimate interest in measuring our own service, Article 6(1)(f).

  9. Stopping abuse

    When you send a request or upload a photograph, Cloudflare's bot check sees your IP address and some ordinary details about your browser. Our own rate limiter keeps a shortened one way hash of your IP address, and of an email address on some paths, for a few days. A shortened hash of an IP address is a pseudonym rather than an anonymisation, and we call it that rather than calling it anonymous.

    Why A form with no brake on it becomes a spam machine pointed at working artists.

    Ground Our legitimate interest in keeping the service usable, Article 6(1)(f).

  10. Writing to us

    Your name, your email address, the subject and your message. The contact form stores nothing at all: the message is delivered as email and there is no copy of it in the database.

    Why To answer you.

    Ground Our legitimate interest in answering our own mail, Article 6(1)(f).

Two things we do that you would want told plainly. When you send a request to an artist who has not joined Talomis yet, we relay it to the contact email they have published, and a copy comes to our own desk mailbox so a person can tell whether it landed. And when you pick a consultation time, your name, your email, your phone number and your description are written into the calendar event on the artist's calendar, and you are added as a guest, which is why the invitation arrives from Google rather than from us.

We do not sell your details. We do not share them for advertising. We do not build a profile of you across sites, and there is nothing here that could.

Your location never leaves your browser. When you tap nearest to you on the coastline, your browser hands the coordinates to the page and the page does the arithmetic in your own browser. There is no request, no geocoding service and no map tiles. The only place a coordinate is written is your own device, under the key talomis.near, and it dies with the tab. Talomis does not see it. The site is a set of static files, so this is a thing you can check by reading the source.

The other things kept on your device, all of them small, none of them sent to us:

  • atlasRef and atlasSrc, the tag on the link you arrived from, so a request sent three screens later still names the link that brought you. Session only.
  • talomisViewed, the artists already counted this visit, so one visit is one count. Session only.
  • talomisSelf, set when an artist opens their own page, so they do not inflate their own numbers. Session only.
  • talomis:sound, whether you turned the sound on. It stays off until you ask for it, and no audio is even started before you do.
  • If you are an artist and you make a signing key, the private half is generated in your browser and stored there, in a form this code cannot read back out. It is never transmitted to us or to anybody.

No page you read loads anything from another company's server. The fonts, the images and the scripts are served from this site, so reading it does not announce you to anybody. There is one exception and it is deliberate: when you start filling in the booking form, Cloudflare's bot check loads from Cloudflare, and it sees your IP address. It loads on engagement rather than on page load, so a visitor who reads a page and leaves makes no request to Cloudflare at all.

There is no payment rail on this site. Talomis does not process payments, hold funds, take deposits or act as a payment agent for anybody. We hold no card number, no bank detail and no payment token, because nothing here asks you for one. There is no payment processor in the list below, and its absence is the point rather than a gap.

Whatever you and your artist agree is paid directly to them, under their own policy. Nobody from Talomis will ask you for money.

One honest note, because Talomis and the older atlas sites share a database. Some artists took a paid subscription on those older sites, billed by Stripe, before Talomis existed. If that is you, Stripe holds that billing relationship. Nothing on Talomis is for sale to artists and no new payment starts here.

This section only applies to artists who choose to connect a calendar. Nothing here touches a client's Google account, and no client is asked to connect anything.

When an artist connects Google Calendar, Talomis asks for exactly two permissions and nothing else.

  • See when you are busy (calendar.freebusy). This is the only reading permission and it returns time ranges only. It does not return event titles, descriptions, guests or locations. We use it to work out which consultation times to offer, and for nothing else. We cannot see what your appointments are.
  • Create and delete events (calendar.events). This is a writing permission. We use it to put a confirmed consultation on your calendar with the client invited, to add a Google Meet link when you offer video consultations, to mirror the conventions and guest spots you enter in your studio, and to remove those events when a consultation is cancelled or declined.

Reading is busy times only. We do not list your events, search them, or read the contents of any event we did not create. The one exception is that we look up an event we put there ourselves, by the id we stored when we created it, and we read three fields from it: the start, the end, and whether it is still there. That is how a consultation you move or delete in your own calendar gets picked up on your page. We never read the title, the description, the guests or the location, of that event or of any other.

Being straight about the permission itself: the second permission is broader than the use we make of it, because Google does not offer a narrower one that can create an event. Google will not let the connection complete unless both permissions are granted. The limits above are limits we hold ourselves to in code, and this policy is where we are held to them.

What we write into your calendar. A consultation event we create carries the client's name, their email address, their phone number if they gave one, and what they wrote about the tattoo, and the client is added as a guest so Google sends them the invitation. That is the point of booking a consultation, and it means Google holds that information as part of your calendar.

We do not use Google user data for advertising, and we do not use it to train any AI model. We do not sell it, and we do not share it with third parties except Google itself and the providers listed below that are required to operate the service.

How the tokens are held. The access token and the refresh token are encrypted before they are written down, with AES 256 GCM under a key derived with HKDF SHA 256 from a secret that lives in the server's own secret store and is not in any code repository. A fresh random value is used for each encryption. The ciphertext sits in one column that no browser can read: the database grants a browser the connection status and nothing else. You can disconnect at any time from your studio, or revoke access directly at your Google account permissions page. When you disconnect, the stored tokens are deleted and automated booking stops.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Where the connection is made today: the calendar is still connected in the older atlas studio, because Google sends the consent screen back to that address, and that step moves to this site at launch. The two permissions above, and the limits on them, are the same either way.

Each one handles data only to do its own part of the job, under a contract, and none of them is allowed to use it for anything of their own.

  • Supabase. The database, the sign in, and the private store your photographs live in. Everything above passes through here. Their policy
  • Cloudflare. Hosting and delivery of the site, so Cloudflare sees the ordinary request details every host sees, including your IP address. Their policy
  • Cloudflare Turnstile. The bot check on the request form. It loads from Cloudflare when you start filling the form in, not when you read a page, and your IP address is sent with the check. Their policy
  • Resend. The email that carries a request to an artist, a copy back to a client, a reminder before a consultation and a cancellation notice. Their policy
  • Google. Only when an artist has connected a calendar, and only for the two permissions set out above. Their policy
  • OpenStreetMap Nominatim. Used once when a page was built, to turn a city and state name into map coordinates. No visitor data goes near it. Their policy

There is no payment processor on that list, because there is no payment on this site. There is no analytics company on it either.

We will also hand over data when the law requires it, and we will tell you when we are allowed to tell you. If Talomis is one day passed to somebody else, this policy and the covenant go with it, and you will be told before anything moves.

Talomis is run from the United States and the providers above are mostly United States companies, so data reaches the United States. Nearly half the artists listed here work in the United Kingdom or the European Union, so this matters and it is not buried.

Where information about somebody in the UK or the EU is transferred to the United States, we rely on the standard contractual clauses in our agreements with those providers, and on the UK addendum where it applies. Some of them are also certified under the EU and UK data privacy frameworks. You can ask us which mechanism covers which provider and we will tell you.

Where there is an automatic timer, it is named. Where there is not, that is said rather than dressed up, because a retention promise nothing enforces is worse than no promise at all.

  1. Requests, and the photographs with them

    Kept while the artist's page is open, because the request is that artist's record of their own client. There is no automatic timer on it today and we would rather say that than print a number nothing enforces. Ask us and we delete the record and the photographs within thirty days. If an artist's page comes down, the requests attached to it come down with it and we delete the photographs in the same pass. If the bot check rejects a request, the record and the photographs are deleted straight away and nothing is sent to anybody.

  2. An artist account and page

    Kept while the page exists. Ask us to remove the page and it goes, along with the requests, the links, the conventions, the store rows and the counting rows attached to it. Your account itself is deleted on request.

  3. Google Calendar tokens

    Deleted the moment you disconnect, from your studio or from your Google account. Nothing survives the disconnection and automated booking stops with it.

  4. Counting rows

    Kept as counts. They carry no identifier for you and there is no timer on them. They go when the artist's page goes.

  5. Abuse limits

    The hashed keys are deleted automatically within a few days of being written. Nothing else is kept about the attempt.

  6. Email

    Mail you send us stays in the mailbox until it is cleared out. The contact form itself keeps no copy in the database.

  7. Backups

    Ordinary backups age out on their own schedule, so a deletion clears the live system first and works its way out of the backups after that. It is not instant and we will not pretend it is.

Wherever you live, you can ask us to show you what we hold about you, to correct it, or to delete it. Email bookings@neotradatlas.com, say what you want, and we answer within thirty days. There is no fee and no form.

We will ask you enough to be sure it is you, which usually means writing from the address the record is under. We ask for the least we can get away with and we do not keep what you send to prove it.

Artists can do most of it without asking. Edit or remove anything on the page from the studio, disconnect the calendar, turn automated booking off, or press the export button, which is promise 005 of the covenant and hands you your page, your work, your captions and your requests in one plain open file. To have the whole page taken down, email us and it comes down.

Clients can cancel a consultation with the link in the confirmation email, and can ask us to delete a request they sent. If the artist has already received it by email, we will tell you that, because we cannot reach into somebody else's mailbox and we will not pretend otherwise.

The UK GDPR and the EU GDPR give you these rights, and we honour them for anybody who asks, wherever they are:

  • Access. A copy of what we hold about you.
  • Rectification. Correct anything wrong.
  • Erasure. Have it deleted.
  • Restriction. Have us stop using it while something is being sorted out.
  • Portability. Get it in a machine readable file. For artists that is the export button, and it works now.
  • Objection. Object to anything we do on the ground of legitimate interests, including a listing you did not ask for. If you object to a listing, we do not weigh it against anything. We take the page down.
  • Withdraw consent. Where consent is the ground, which here means the calendar connection, take it back at any time. That does not undo what was done before you took it back.
  • No automated decisions. Nothing here decides anything about you automatically, and there is no profiling.

You can also complain to your own data protection authority. In the UK that is the Information Commissioner's Office. In the EU it is the supervisory authority where you live, and the list is on the European Data Protection Board site. We would rather you told us first, but you do not have to.

One gap, named rather than hidden. Article 27 expects a controller outside the UK and the EU to appoint a representative there. Talomis is one person in the United States and has not appointed one. That is a shortfall on our side, not on yours: it takes nothing away from the rights above, and it does not stop you complaining to your own authority. Write to the address on this page and it reaches a person directly.

Under California law you can ask what personal information we have collected about you and where it came from, ask us to delete it, ask us to correct it, and ask what we disclosed and to whom. Use the same address as everybody else and we will not treat you any differently for asking.

We do not sell personal information and we do not share it for cross context behavioural advertising. We have not done either in the last twelve months, and there is nothing on this site that could: no advertising network, no data broker, no tracking pixel. So there is no opt out link, because there is nothing to opt out of.

The categories we collect are the ones listed above: identifiers such as a name, an email address and a phone number, commercial information such as the request you sent, internet activity such as a page count and an IP address seen by our host, and geolocation only in the sense that a photograph you upload may carry it. We collect them for the purposes given in the same list, from you directly, and from an artist's own public posts in the case of a listing. You can name an authorised agent to ask on your behalf.

Most of the artists on this site never asked to be here. Their page was built from their own public work, without them being asked first. That is the most sensitive thing this site does, so here is the whole of it.

What was taken and from where. Public content published by the artist under their own professional handle: the profile photograph, up to three post images, the bio text, and the city or shop they publicly tagged. The city was turned into map coordinates so the page appears in the right place. Where the artist published a business contact email publicly, that address was recorded, and it is what a client request gets relayed to. Copies of the images are held on our own servers so the page does not depend on links that expire, and each image carries a written description produced by an automated pass so it can be read by a screen reader and found by a search engine.

Why we think we are allowed to. The information is professional rather than private, it was published by the artist to be seen, it is used for the purpose it was published for, which is being found and hired, and the page carries no cut, no fee and no advertisement. That is a legitimate interests judgement under Article 6(1)(f), and a legitimate interests judgement is exactly the kind that a person is entitled to argue with.

So the way out is unconditional. Email us and your page comes down. You do not have to give a reason, claim the page first, prove who you are beyond writing from an address that makes sense, or talk to anybody about staying. We do not weigh your objection against our interest, we do not counter offer, and we do not ask again later. We aim to have it down within seven days and we confirm when it is done.

What removal actually removes. The page, the stored copies of the images, the descriptions written for them, the coordinates and the contact address, and the entry from the sitemaps and the plain text files that assistants read. What it cannot remove is anything a search engine, an assistant, an archive or another person already copied. We ask the search engines to drop the page and they usually do, on their own schedule. We say this plainly because a removal promise that pretends to reach the whole internet is a lie.

The same route works for one photograph rather than the whole page, or for correcting a shop name, a city or a style that is wrong.

Every page on this site except an artist's own signed in studio is deliberately open to search engines and AI assistants. Nothing is blocked in robots.txt except that studio, and /llms.txt is written so an assistant can read the site properly and send a person to the artist. Being read and cited is how anybody finds an artist here.

What that means for you, said before rather than after: anything on a public page can be indexed, cached, quoted, summarised by an assistant, and archived by people we have nothing to do with. Once that has happened we cannot take it back. Treat anything you publish on your page as published to the internet, because it is.

What is not public: your account email, a client's request, the photographs a client uploads, your calendar tokens, and anything else in the studio. Client photographs sit in a private store that no anonymous visitor can read or even list, reachable only by the artist the request was sent to, through a link that stops working after an hour, and by one operator account for support and moderation.

You must be 18 or older to send a request, hold an account or upload anything here, and sending a request requires you to confirm it. This site is not built for children and we do not knowingly collect anything from anybody under 18.

If you believe we hold something belonging to somebody under 18, write to us and we delete it. A parent or guardian does not need to explain themselves to us.

What is actually in place: everything travels over an encrypted connection. The database enforces row level security, so an artist can read their own rows and nobody else's, and the browser key that every visitor carries grants nothing a stranger could not already ask for. Client photographs sit in a private store with anonymous reading and listing switched off. Google tokens are encrypted before storage under a key held in a server secret store. The powerful database key is never in a browser, never in a build and never in the code repository. Uploads are checked by reading the actual bytes rather than trusting the file name. Forms are rate limited and behind a bot check. Artists can turn on a second step at sign in.

What we will not claim: that any of this makes the site unbreakable. No system is perfectly secure and anybody who tells you theirs is has something to sell. We are a small operation and we would rather you knew the size of us than believed a slogan.

If you find a hole, write to us before you write about it anywhere else and we will fix it and thank you properly.

If a breach puts your information at risk, we tell you. We say what happened, what was reached, what we have done and what you should do, and we say it as soon as we understand it rather than waiting until the story is tidy. If we do not know something yet, we say that instead of guessing.

Where the law sets a clock we work to it, which in the UK and the EU means telling the supervisory authority within seventy two hours of finding out, and telling you without undue delay where the risk to you is high. Under United States state laws we notify as those laws require.

Covenant promise 006: what is written here does not change quietly. A change is listed below with the date on it, the old words stay readable, and artists are asked to accept again where the change affects them. If a change means we would use something we already hold for a new purpose, we tell you before we do it, not after.

The record

  1. Version 2.0, 28 August 2026

    Rewritten against a full read of the code on the day 1.0 was written. Added: the legal basis for every category, that our host and our bot check see IP addresses, that every artist page view is counted and not only pages with live times, that the bot check loads from Cloudflare when you engage the form, that a booked consultation writes your details into the artist's calendar event and invites you, that a request to an artist who has not joined is copied to our own desk mailbox, that uploaded photographs keep their camera information, the honest position on retention, UK and EU rights with the representative gap named, California rights, the security posture, breach notification, and the unconditional removal right for an unclaimed page.

  2. Version 1.0, 28 August 2026

    First version on this site, ported from the atlas policy dated 19 August 2026.

One mailbox, read by a person. Use it to see what we hold, correct it, delete it, take a page down, or argue with any of the above. Talomis mail moves onto this domain at launch and this address changes with it.

Email us about your data

bookings@neotradatlas.com

The terms