Privacy Policy · Last updated 2026-07-06
Privacy Policy
Loopi Social (loopi.social) is an AI-native platform that helps small businesses run their online presence — scheduling content to social platforms, hosting a public link page, hosting a brochure website on a custom domain, running email broadcasts and drip sequences, managing a Google Business Profile, and producing short marketing videos — often with the help of AI agents that draft, build, and operate these channels on the owner's behalf. This policy explains what data we collect, why, where it goes, and how to remove it. Loopi Social is operated by an individual developer and is provided "as-is." By using Loopi Social you agree to the practices described here.
This document is organized around your account, the AI agents that can operate on your data, and the channels involved: Content, Mail, Links, Website & Domains, Google Business Profile, and Studio.
1. Account & profile data
When you sign up, we store:
- Account-level: the owner's email address, a salted one-way hash of your password (we never store the plaintext and cannot recover it), an optional Google identifier if you signed in with Google, and account timestamps.
- Profile-level: profile name, optional display name and bio, optional avatar image, and an optional free-form "brand context" describing your brand voice. Brand context is used to guide AI drafts and agents (see §2 and §3).
- Membership: for multi-user accounts, per-member role and per-profile scopes.
- Sessions: short-lived tokens keep you signed in; expired sessions are removed automatically.
- Google sign-in: if you choose Google sign-in, we request only the standard
openid email profilescopes and receive your email address, Google identifier, and (optionally) name and avatar. Signing in does not grant access to Gmail, Drive, or Calendar. Connecting YouTube, a Google Business Profile, or website analytics requests additional Google permissions, described in §2, §6, and §7.
Analytics & cookies: we use Google Analytics for first-party product analytics on our marketing site and the signed-in dashboard, which sets analytics cookies there. We do not load it — or any advertising or behavioral-tracking pixel — on public link-in-bio pages, embeds, or previews. See §10.
2. Content service
When you connect a third-party platform (TikTok, Instagram, LinkedIn, YouTube, Bluesky), we receive an OAuth access token from that platform on your behalf and use it only to publish content you (or an agent acting for you) explicitly schedule.
- Platform OAuth tokens: stored per-profile and per-platform with encryption at rest; refresh tokens (where the platform issues them) are stored alongside. You can disconnect any platform from the Content tab at any time, which deletes the stored tokens.
- Media you upload: stored in cloud object storage under an internal identifier (not your original filename), together with auto-generated thumbnails and transcripts. Media is hard-expired about 12 months (366 days) after upload; you can delete sooner via the Media tab.
- Transcripts: generated in-region using open-source speech-to-text. Your audio is processed on our own infrastructure and is not sent to any third party for transcription. We do extract a single still thumbnail frame from the video and send that one image to our AI provider (Anthropic) for a short visual description that helps with drafting — the audio itself never leaves our infrastructure.
- AI-generated drafts: when you request post drafts from a transcript, we send the transcript text, your profile's brand context, and the target platform to our AI provider. When an AI agent operates your account more broadly, the range of data it may send is described in §3.
- Scheduled posts: the post body, target platform, scheduled time, and any associated media reference. Retained until you delete the post (and, after it fires, retained for analytics until you delete it).
- Platform-side analytics: after a post is published, we may sync the public counts (views, likes, comments, shares) the platform exposes via its API. These arrive pre-aggregated from the platform; we do not collect anything about individual viewers.
YouTube notice: Loopi Social uses YouTube API Services. By connecting a YouTube account, you also agree to the YouTube Terms of Service and acknowledge Google's Privacy Policy. You can revoke Loopi Social's access to your Google account at any time via Google's security settings.
3. AI agents & the data we send to Anthropic
Loopi Social's AI agents operate your channels for you. Our AI provider is Anthropic (the Claude API), and it is the only large-language-model provider we use.
- What is sent: to do their work, agents transmit to Anthropic the data the task requires. This is broader than a single draft — depending on what you ask and what you have connected, it may include your chat messages and instructions, your brand context, post and email drafts and media descriptions, your mail settings and (where a task involves them) subscriber and list details, your website source files, your analytics, and your Google Business Profile listing, reviews, and insights. In short, an agent may send to Anthropic any data it is authorized to read on your behalf in order to carry out what you asked.
- Where agent data lives: an agent's conversation history and its working "memory" (brand facts and prior decisions it retains for you) are stored on Anthropic's infrastructure; on our side we keep only pointers to them. The credential an agent uses to act in your account is held in Anthropic's secure vault.
- Training: Anthropic does not, by default, use data submitted through its API to train its models. Anthropic's own privacy policy governs its handling.
- Usage records: to meter usage, calculate billing, prevent abuse, and improve the service, we record usage metadata for agent activity — including model-usage (token) counts, the model used, session and agent identifiers, timestamps, and, for accounts on a free tier or trial, which gated actions were used. This metadata is tied to your account and profile.
- Public demos: if you use a public demo or preview agent before signing up, the messages you send it are processed by Anthropic in the same way.
- Deletion: deleting your account removes your agents and their stored memory and credentials (see §12).
4. Mail service
Subscribers belong to a list owned by one of your profiles. Sender identity — display name, reply-to address, optional custom sending domain, and footer — is configured once per profile (the brand default) and verified before sending is allowed; lists themselves are pure audiences. Individual emails may carry a per-send override only within those already-verified values.
- Subscriber data: email address, optional first/last name, browser timezone (captured at form submission), any custom fields you provide, status (active/unsubscribed/bounced/complained), the tags you assign, and timeline (subscribed-at, unsubscribed-at).
- Subscription source: when a visitor signs up via a public signup form (e.g., embedded on the account owner's website or link page), we record the subscriber as active immediately — there is no double-opt-in confirmation step. The account owner is responsible for ensuring the embedding page carries the required consent disclosures (see Terms §5).
- Contact-form submissions: an account owner may instead publish a contact form (e.g., a "get in touch" form). When a visitor submits one, we store the submitted field values (including the email address and any message), email a notification to the account owner, and add the visitor to a subscriber list only if they explicitly checked the form's opt-in box. Submissions are retained until the account owner deletes them or the account is removed.
- Sender identity: per profile, the display name and an owner-controlled reply-to address. The reply-to is only used after the account owner verifies it by clicking a signed link sent to that address.
- Email content templates: subject lines, HTML/text bodies, preheader text, and any merge fields you compose for broadcasts and sequences. Retained until you delete them.
- Open and click tracking: when a recipient opens an email, it loads a small tracking image from our servers, and we record the message identifier, the recipient's IP address, the User-Agent, and the timestamp. When a recipient clicks a tracked link, the click passes through a redirect and we record the same fields plus the destination URL before redirecting. These records back the open/click counts shown to the account owner.
- Bounce / complaint handling: our email provider delivers bounce, complaint, and delivery events to us. We store the event type, the provider's reason string (which may contain identifiers about the recipient's mail server), and the timestamp. Hard-bounced and complained addresses are flagged so we will not contact them again.
- Unsubscribe: every email contains a one-click unsubscribe link backed by a per-message token. Clicking it unsubscribes the subscriber without requiring a login.
5. Links service
The Links service hosts your public link-in-bio page at {username}.loopi.social. This page is publicly accessible to anyone who knows the URL — it is intentionally not behind authentication.
- Username & page content: the username you claim (lowercased, globally unique), display name, bio, avatar, theme/color settings, and the link rows you configure (titles, URLs, images, sections, embedded email forms). All of this is published to the public page.
- Link assets (images): images you upload for link tiles or your avatar are stored in cloud object storage and served publicly so the page can render.
- Visitor analytics: when someone visits your public link page or clicks a link on it, we record the event type (view/click/copy/email-submit), the link clicked, the User-Agent header, the Referer header, and any UTM query parameters, and we may record the visitor's IP address. This data renders the analytics you see in
/app/links/analyticsand helps us detect abuse. - Embedded email-capture forms: if you place an email form on your link page, submissions are handled by the Mail service (see §4) and create active subscribers immediately.
For visitors of public link pages: we do not set advertising or third-party analytics cookies on these pages, we do not fingerprint your device beyond the User-Agent your browser already sends, and the request log is used only to give the account owner basic traffic analytics. The account owner is responsible for informing their own audience that this analytics capture exists if their jurisdiction requires such disclosure.
6. Website, domains & website analytics
- Hosted website: if you host a brochure website with us, we store its source files and assets and the built, published site, and we serve the published site publicly. You and the agents you enable author this content; you are responsible for what appears on it, including any forms, embeds, or scripts.
- Custom domains & DNS: we do not register domains for you. If you connect a domain by delegating its nameservers, we operate the authoritative DNS for that zone so we can configure the records your site and mail need. We store your domain name, the DNS records in the zone, and certificate-validation data. When you first delegate a domain, we attempt to mirror your existing public records on a best-effort basis; you remain responsible for verifying your critical records (especially email/MX). See Terms §6 for the risks of delegating a domain you already use.
- Website analytics (Google Analytics): if you enable analytics for a hosted site, we provision a Google Analytics 4 property and your site loads Google's analytics tag. This sends your visitors' data — page views, sessions, approximate geography, device, and events — to Google. The GA4 property is created and managed under Loopi Social's Google Analytics account on your behalf. Google's handling is governed by Google's privacy policy. You are responsible for disclosing this collection to your site visitors and for obtaining any consent (including a cookie-consent banner) your or their jurisdiction requires. This is separate from the first-party link-page analytics in §5.
7. Google Business Profile
If you connect a Google Business Profile, you authorize us (and the agents you enable) to access it through Google using the management permission Google requires. We read your listing details, your customer reviews — including each reviewer's Google display name, profile photo URL, and review text — and your performance insights, and, where you enable it, we can update the listing and post public replies to reviews on your behalf. This review and insight data is passed through live to show it to you; we do not build a separate store of it. The reviewer information is personal data of third parties; when you act on it (for example, replying to a review) you are responsible for that handling. You can revoke access at any time via Google's security settings.
8. Studio
The Studio service renders short marketing videos from media and text overlays you provide. Your uploaded assets, overlay templates, and the rendered videos are stored in our own cloud storage, and rendering is performed on our own infrastructure — no external video-rendering vendor receives your media.
9. Payment processing
Paid plans are billed through Stripe. When you subscribe, your payment details (card number, billing address) are collected and stored directly by Stripe — Loopi Social never sees your card number. We store the Stripe customer and subscription identifiers, your subscription status, and, if you provide one when cancelling, your cancellation reason and any feedback you leave. We use these to grant or revoke access to paid features. Stripe's handling of your payment data is governed by Stripe's privacy policy.
10. Third-party services we send data to
By design, Loopi Social shares data with the following processors:
- Amazon Web Services (United States) — hosts essentially the entire platform: compute, storage, database, outbound email, content delivery, DNS, and certificates. AWS holds the data we store, subject to encryption at rest.
- Anthropic — our AI provider. Receives the data agents need to operate your account (see §3), and stores agent conversation history and memory on its infrastructure. Anthropic does not, by default, train its models on API data.
- Google — if you sign in with Google, we receive your basic profile per the standard sign-in scopes. If you connect YouTube, a Google Business Profile, or website analytics, we exchange the relevant data with Google's APIs (see §2, §6, §7). Our marketing site and dashboard also use Google Analytics (see below).
- Connected social platforms (TikTok, Instagram, LinkedIn, YouTube, Bluesky) — receive your scheduled posts when they fire. Each platform's own privacy policy governs what they do with your content after publication.
- Stripe — receives your payment information directly. We receive only customer and subscription metadata.
- Subscriber inbox providers — when a broadcast sends, the recipient's email provider (Gmail, Outlook, etc.) receives the email; their privacy policies govern handling on their side.
We do not sell or rent your personal data, and we do not run advertising or behavioral-tracking pixels (no Meta Pixel). We use Google Analytics for first-party product analytics on our marketing site and the signed-in dashboard; we do not load it on public link-in-bio pages, embeds, or previews. Where you enable website analytics for a hosted site, that site loads Google Analytics as described in §6.
11. Data retention
- Account & profile rows: retained while the account is active. Deleted on request (see §12).
- Media (videos, images, transcripts, thumbnails): hard-expired about 12 months (366 days) after upload. Earlier deletion via the Media tab.
- Website source & published files: retained while the site exists; removed when you delete the site or the account.
- Domain / DNS configuration: retained while the domain is connected; removed on disconnect or account deletion.
- Agent history & memory: stored on Anthropic's infrastructure and retained until you delete the agent or the account.
- Usage metadata: agent usage records are retained for billing, abuse-prevention, and product-analytics purposes.
- Link-page visitor analytics: retained until the account owner deletes the corresponding link, or until the account is deleted.
- Subscribers: retained until the account owner deletes the list or the individual subscriber. Unsubscribed and bounced subscribers stay on the row with a status flag to prevent re-contact.
- Mail templates, sequences, broadcasts: retained until deleted. Sent broadcasts retain delivery telemetry (open/click and bounce records) until you delete the broadcast.
- Sessions & short-lived security tokens: expire automatically and are removed.
12. Your rights & how to remove data
- Access: the data tied to your account is visible inside
/app. - Deletion: deleting a post, media file, content template, sequence, broadcast, list, subscriber, link, site, or analytics row from the app removes the underlying record. To delete the entire account, email support@loopi.social from the address registered on the account; within 30 days we erase the account, profiles, lists, content, link pages, hosted website source and served files, custom-domain configuration, connected-platform tokens, API keys, usage records, and the AI agents together with their stored memory and credentials. Content already published to social platforms, already delivered to subscriber inboxes, or already served from a domain you control is outside our control and is not deleted.
- Subscriber unsubscribe: every email contains a one-click unsubscribe link. Subscribers can also email the account owner's reply-to address to request removal.
- Disconnect a platform: click "Disconnect" next to any platform connection in the Content tab; the stored OAuth tokens are deleted immediately. For Google connections you can also revoke access in your Google account's security settings.
- EU / UK residents: you have rights of access, rectification, erasure, portability, and objection under GDPR / UK GDPR. For account-level data we act as the data controller. For subscriber data, visitor data, and reviewer data captured or surfaced through the account owner's channels, the account owner is the controller and Loopi Social is the processor — direct erasure or access requests to the account owner first, or to support@loopi.social and we will forward them.
- California residents: you have rights under the CCPA/CPRA to know, delete, and correct the personal information we hold. Loopi Social does not sell personal information and does not share it for cross-context behavioral advertising.
- Washington residents: you have rights under the My Health My Data Act and the Washington Privacy Act where applicable. Loopi Social does not collect consumer health data.
13. Security
All traffic is served over HTTPS. Passwords are stored only as a salted one-way hash; we never store plaintext passwords and have no way to recover one. OAuth tokens for connected platforms, payment identifiers, and stored data benefit from encryption at rest, and session tokens are cryptographically signed. Despite these measures, no online service is perfectly secure — if we become aware of a breach affecting your personal information, we will notify affected users by email without undue delay and as required by applicable law.
14. Children
Loopi Social is intended for adults aged 18 years or older. We do not knowingly collect personal information from anyone under 18. If you are under 18, please do not use this service or submit any information. If you believe a minor has registered, email support@loopi.social and we will remove the account.
15. International transfers
Loopi Social is hosted in the United States. If you access the service from outside the US, your data is transferred to and processed in the US. By using Loopi Social you consent to this transfer. For EU/UK residents we rely on the appropriate transfer mechanisms (Standard Contractual Clauses) where required.
16. Changes to this policy
We may update this policy. The "Last updated" date at the top reflects the most recent change. Material changes will be communicated via an in-app notice and an email to account owners. Continued use of the service after the effective date constitutes acceptance.
17. Contact
Questions about this policy or about your data: support@loopi.social.