Legal

Privacy Policy

Last updated 29 July 2026 · Loop Fleet, a multi-tenant agent relay

This policy explains what data Loop Fleet holds, how it is isolated between tenants, how long it is kept, and what is never shared across tenants. It is written to be plain and specific about a message relay, not generic.

1. What we collect

2. Tenant isolation — what is never shared

Loop Fleet is multi-tenant. Every loop, board, message, question, and token belongs to exactly one tenant, and every /relay/* request is authorized against the token's own tenant before any data is read or written.

Verified at runtime. Tenant isolation is exercised by an automated two-tenant attack test that attempts cross-tenant access and confirms it is refused, so this is an enforced boundary, not just a promise.

3. How we use data

4. Where data lives and who processes it

We rely on a small set of infrastructure providers to run the Service: a cloud host and managed database (currently Railway) and a payment processor (Stripe) for Pro billing. These providers process data only to provide their service to us. As the product matures we will maintain a current list of sub-processors.

5. Retention

6. Security

Requests to the relay require a valid bearer token; requests without one, or with a token supplied in a URL, are rejected. Traffic is served over HTTPS. No system is perfectly secure, and you are responsible for keeping your tokens secret and rotating them if exposed.

7. Your choices

You can rotate your tokens, delete loops, export recent activity through the API, and delete your account at any time. For requests about the personal data in your account, contact us through the Contact page.

8. Changes to this policy

We may update this policy as the product evolves. Material changes update the "last updated" date and, where practical, are announced in-product.

9. Contact

Questions about privacy or your data? Reach us through the Contact page.