Privacy Policy
LAST UPDATED · 10 JULY 2026
1. Who We Are
Loopsfinity is a software development automation platform that helps engineering teams plan, prototype, and execute their product roadmap. Our website is loopsfinity.com. For any privacy-related questions, you can reach us at hello@try.loopsfinity.com.
2. What This Policy Covers
This Privacy Policy explains how Loopsfinity collects, uses, stores, and shares information when you visit our website, request a demo, or use the Loopsfinity platform as a customer.
The Service is a B2B product. The people who interact with us are primarily business professionals acting in their professional capacity, engineers, founders, and product leads at companies evaluating or using Loopsfinity. Where we refer to "personal data" in this policy, we mean information that relates to an identified or identifiable individual, such as a name or work email address, not a company as a whole.
This policy does not govern the personal data that you or your organisation store within your own codebase or systems and may incidentally transmit to us when you connect your repositories. You are responsible for any such data and for ensuring that connecting your repositories to Loopsfinity complies with your own obligations to the individuals whose data it may contain.
3. Data We Collect
We collect the following categories of information:
Demo and contact data
When you complete the demo request form on our website, we collect: your name, work email address, company or product name, approximate codebase size, the issue tracker your team uses, and a description of the next milestone you want to ship. We use this information to prepare for and schedule your demo, and to assess whether Loopsfinity is a good fit for your team.
Account data
When you become a customer, we collect: your name, work email address, and your organisation's name and billing details. We use this to create and manage your account, send invoices and subscription-related communications, and provide customer support.
Repository access
When you connect your GitHub or GitLab account, Loopsfinity accesses the specific repositories you authorise via OAuth. The data we access includes: source code files, directory structure, commit history, branch information, pull request metadata, and issue or ticket data in your connected issue tracker. We access this information to deliver the Service, specifically, to map your codebase, generate plans, write tests and code, and open pull requests on your behalf.
Usage data
We collect logs of agent runs, feature usage events, API call counts, and error reports. This data does not include the content of your code but does include metadata such as which features you used, how long runs took, and whether errors occurred. We use this to operate, monitor, debug, and improve the Service.
Communications
We retain emails and other messages you send us, including support requests and replies to automated communications from us, to manage our relationship with you and to respond to your enquiries.
Website analytics
We use Google Analytics 4 (GA4) to understand how visitors use our website. GA4 collects anonymised data including which pages were visited, time spent on each page, browser type, device type, and approximate geographic location (at the country or city level). This data does not identify you personally. See Section 8 for more about Google Analytics and how to opt out.
4. What We Do Not Do
We want to be explicit about certain things we do not do:
- We do not sell your data. We do not sell, rent, or trade your personal data or your codebase to any third party for any purpose.
- We do not use your code to train AI models. Your codebase, design system, and any materials from your repositories are not used to train, fine-tune, or improve any artificial intelligence or machine learning model, by Loopsfinity or by any third party at our direction.
- We do not share your confidential business information with competitors. We treat your code, architecture, and product plans as confidential and do not share them with other Loopsfinity customers or with competitors.
- We do not store your code beyond active task requirements. We do not maintain persistent copies of your codebase on our infrastructure. Code is accessed and processed in memory during the execution of tasks you request. We do not build or maintain a secondary copy of your repositories outside of your own version-control system.
- We do not push to your main branch or deploy on your behalf. Loopsfinity creates branches and opens pull requests only. Nothing enters your main or production branch without your team's explicit approval.
5. How We Use Your Data
We use the data we collect for the following purposes:
- Providing the Service. To connect to your repositories, map your codebase, generate PRDs and ticket breakdowns, create prototypes, execute code generation tasks, and open pull requests as you direct.
- Scheduling and conducting demos. To prepare for your demo, understand your use case, and follow up after the call.
- Account and subscription management. To create your account, process payments, send invoices, notify you about subscription changes, and handle renewals and cancellations.
- Customer support. To respond to your questions, investigate issues, and resolve problems with the Service.
- Service improvement. To analyse usage patterns, identify bugs, and inform decisions about new features and performance improvements. We use aggregated and anonymised data for this purpose wherever possible.
- Legal compliance. To meet our obligations under applicable law, including accounting regulations and any lawful requests from regulators or courts.
- Security. To detect, investigate, and prevent fraudulent, abusive, or unlawful use of the Service.
6. Third-Party AI Processing
Delivering the core Service requires sending portions of your data to third-party AI model providers. When Loopsfinity executes a development task, such as mapping your codebase, generating a PRD, writing tests, or writing implementation code, it sends relevant context to the APIs of one or more of the following providers:
- Anthropic (Claude models), anthropic.com
The context sent to these providers may include: code files and snippets from your authorised repositories, file and directory structures, commit messages, task descriptions and milestone briefs, acceptance criteria, and design system information. This transmission is technically necessary to generate the outputs the Service produces; the Service cannot function without it.
Each provider processes submitted data under its own API terms and privacy policies. Per their published API policies at the time of writing, these providers do not use data submitted via their APIs to train their models. However, Loopsfinity cannot guarantee or control what these providers do beyond their published commitments. We recommend reviewing the current API policies of each provider if you have specific data-handling requirements.
By using the Service, you consent to this transmission and confirm you have the rights and authority to authorise it.
7. GitHub and GitLab Integration
Loopsfinity accesses your version-control repositories exclusively through the OAuth integration you authorise. This integration:
- Accesses only the repositories you explicitly select and authorise, not your entire GitHub or GitLab account;
- Uses access tokens that are stored securely and used only to perform tasks you request;
- Can be revoked at any time through your GitHub or GitLab account settings, under the "Authorised OAuth Apps" or equivalent section;
- Upon revocation, immediately ceases all Loopsfinity access to your repositories, we cannot read, write to, or create branches or pull requests in any repository once access is revoked.
Loopsfinity creates branches within your repositories for each ticket it executes and opens pull requests for your team's review. It does not push commits directly to your main or default branch, and it does not trigger deployments. Branches and pull requests created before you revoke access remain in your repository under your control; revoking access does not delete them.
8. Google Analytics
We use Google Analytics to understand how visitors use the Loopsfinity website. Google Analytics sets cookies in your browser to collect anonymised behavioural data, including: which pages you visit, in what order, how long you spend on each page, your approximate geographic location, your device type, and your browser. This information is processed by Google and transmitted to us in aggregated, anonymised form.
We use this data to improve our website content and understand which pages are most useful to visitors. We do not use Google Analytics data to identify individual visitors or to build advertising profiles.
9. Data Retention
We retain different categories of data for different periods, based on the purpose for which it was collected and applicable legal requirements:
- Demo request data: Retained until you ask us to delete it, or until 24 months after your last interaction with us if you do not become a customer.
- Customer account data: Retained for the duration of your subscription plus 90 days following termination or expiry, after which it is deleted or anonymised. Where legal obligations require longer retention (for example, financial records), those obligations take precedence.
- Repository access and code context: Not retained. Code is processed in memory during task execution and is not persistently stored by Loopsfinity outside your own repositories.
- Usage logs and operational data: Retained on a rolling 90-day basis.
- Invoicing and billing records: Retained for the period required by applicable accounting and tax law, typically 7 years.
- Support communications: Retained for 3 years from the date of the last communication in the thread, after which they are deleted.
10. Security
Protecting your data is a core responsibility, not an afterthought. We maintain a range of technical and organisational measures designed to guard against unauthorised access, disclosure, or loss. These include:
- Isolated workspace environments for each task, separated from other workloads by dedicated security controls;
- Encryption of all data in transit using TLS/SSL across every connection;
- Secure authentication mechanisms and access controls, with permissions granted on a least-privilege basis;
- Regular security reviews and ongoing monitoring to identify and respond to potential threats;
- Restricted access to personal data within our organisation, limited to team members who need it to deliver or support the Service.
No security measure is infallible. If you become aware of a potential vulnerability or security concern involving Loopsfinity, please contact us at hello@try.loopsfinity.com. We treat security reports as a priority and support responsible disclosure.
11. Your Rights
Depending on the laws applicable in your jurisdiction, you may have one or more of the following rights regarding your personal data:
- Right of access: The right to request a copy of the personal data we hold about you.
- Right to correction: The right to request that we correct inaccurate or incomplete personal data.
- Right to deletion: The right to request that we delete your personal data, subject to certain legal exceptions (for example, where we are required to retain billing records).
- Right to portability: The right to receive your personal data in a structured, machine-readable format and to transmit it to another controller.
- Right to object or restrict processing: The right to object to or request restriction of certain processing activities.
- Right to withdraw consent: Where processing is based on consent, the right to withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at hello@try.loopsfinity.com. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request. We will not discriminate against you for exercising any privacy rights.
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction.
12. International Data Transfers
Loopsfinity is a global service and may process or store data in countries other than the country in which you are located. In particular:
- Our infrastructure and service providers may be located in the United States or other countries;
- The third-party AI model providers described in Section 6 may process data in the United States or other regions in which they operate.
Where we transfer personal data across national borders, we ensure that appropriate safeguards are in place in accordance with applicable data protection law, such as standard contractual clauses or other lawful transfer mechanisms. If you have questions about the specific safeguards applicable to transfers of your data, please contact us at hello@try.loopsfinity.com.
13. Children
The Service is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe that a minor has provided personal data to us, please contact us at hello@try.loopsfinity.com and we will take steps to delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, in the Service, or in applicable law. If we make material changes, we will notify current customers by email to the address associated with their account at least 14 days before the updated policy takes effect. The updated policy will also be published at loopsfinity.com/privacy.html with an updated "Last updated" date.
For minor or non-material changes (such as updates to contact details or clarifications that do not alter the substance of the policy), we may update this page without advance notice.
15. Contact
For any questions, concerns, or requests relating to this Privacy Policy or to how we handle your personal data, please contact us at hello@try.loopsfinity.com. We aim to acknowledge all enquiries within 2 business days and to provide a substantive response within 30 days.