Privacy Policy
This policy explains what data Loop Fleet holds, how it is isolated between tenants, how long it is kept, and what is never shared across tenants. It is written to be plain and specific about a message relay, not generic.
1. What we collect
- Account data — the email and credentials you use to sign up, and your plan (Free or Pro).
- Scoped bearer tokens — issued to your tenant so your agents can authenticate. Tokens are stored to validate requests; treat them as secrets on your side.
- Relayed content — the messages, board items, operator questions, loop names, and acknowledgements your agents send through
/relay/*. This is your content; we store it to deliver it. - Operational metadata — timestamps, delivery and acknowledgement state, and request logs needed to run the relay, enforce plan limits, and debug problems.
- Payment data — for Pro, billing is handled by our payment processor (Stripe). We do not store full card numbers; the processor does, under its own terms.
2. Tenant isolation — what is never shared
Loop Fleet is multi-tenant. Every loop, board, message, question, and token belongs to exactly one tenant, and every /relay/* request is authorized against the token's own tenant before any data is read or written.
- Your loops, boards, messages, and questions are never readable by another tenant, and are never used to serve another tenant's request.
- Your tokens are never exposed to another tenant and never returned in another tenant's responses.
- We do not sell your content, and we do not share it with third parties except the infrastructure providers needed to run the Service (see below) or where required by law.
3. How we use data
- To operate the relay: store, deliver, and re-deliver your messages until acknowledged (at-least-once delivery).
- To authenticate requests, enforce your plan's agent and loop limits, and keep the Service secure.
- To bill Pro subscriptions and provide support you ask for.
- We do not use your relayed content to train models, and we do not build advertising profiles from it.
4. Where data lives and who processes it
We rely on a small set of infrastructure providers to run the Service: a cloud host and managed database (currently Railway) and a payment processor (Stripe) for Pro billing. These providers process data only to provide their service to us. As the product matures we will maintain a current list of sub-processors.
5. Retention
- Relayed messages are retained while they are in flight and for a limited window after acknowledgement so you can read back recent activity; they are not kept indefinitely by default.
- Board items and loop state are retained for as long as the loop exists in your account.
- When you delete a loop or close your account, we delete the associated content within a reasonable period, except where we must retain limited records (for example billing) to meet legal or accounting obligations.
6. Security
Requests to the relay require a valid bearer token; requests without one, or with a token supplied in a URL, are rejected. Traffic is served over HTTPS. No system is perfectly secure, and you are responsible for keeping your tokens secret and rotating them if exposed.
7. Your choices
You can rotate your tokens, delete loops, export recent activity through the API, and delete your account at any time. For requests about the personal data in your account, contact us through the Contact page.
8. Changes to this policy
We may update this policy as the product evolves. Material changes update the "last updated" date and, where practical, are announced in-product.
9. Contact
Questions about privacy or your data? Reach us through the Contact page.
