Privacy
Plain English about the data our live systems collect. Last updated September 5, 2026.
Newsletter subscriptions and inquiries
When you subscribe, we receive your email address, signup source, optional selected interests, and submission time through AgentMail. New signup function logs record delivery status without submitted email addresses, source or interests. Earlier signup logs may contain submitted email addresses and sources. A newsletter signup does not create a product account. To stop updates or request deletion, contact business@loopxxi.com.
Workflow inquiries and local tools
Workflow inquiries send your email, optional team name, system names, workflow outline, source and submission time through AgentMail to the Loop XXI operational inbox. This does not subscribe you to marketing. The contact endpoint logs inquiry category and delivery status, without the form contents. A temporary in-memory request counter uses the request IP for basic abuse limiting. Hosting providers may retain ordinary request logs.
The Follow-up Worklist processes CSV data in browser memory. It makes no analytics, model or upload requests, and does not save your input to browser storage. The input is cleared when you clear the tool or close its page. Downloaded files remain on your device until you delete them.
Account and sign-in data
Loop ID uses Supabase Auth. At sign-up it stores an account ID, email address, sign-in provider and provider identity data, account timestamps, and authentication records. Email-password accounts also have an encrypted password record and confirmation or recovery tokens. Auth sessions record the session, IP address and user agent. Our account record stores email, display name, account status and the data-notice consent timestamp.
Loop Research
We store your submitted research intent, run status and timing, cost, final markdown report, and any error message. We also save a short summary and embedding of each completed run as Loop Memory so later research can use relevant prior context. We store the report content itself. Do not put secrets or sensitive personal information in a research request.
To perform a run, we send the request, relevant saved summaries, generated search queries and research findings to OpenRouter and the selected model providers. Loop Research currently uses OpenAI GPT-4o-mini for planning and writing and Perplexity Sonar Pro for web research.
Loop Gateway
Gateway service logs record the method, path including query string, status, latency, IP address and user agent for each request. Its usage records store the selected model, a hashed payment or credit reference, input and output token counts, cost and timestamp.
The service includes an optional encrypted conversation Vault. When enabled, it stores prompts and responses encrypted at rest. It is not enabled in production today, and we will update this page before enabling it. Gateway forwards the full API request to OpenRouter so the selected upstream model can answer it; that provider still receives the request content needed to process it.
Payments and credits
Stripe-hosted checkout handles card payment details. Our systems receive and retain payment references, amount, payment status, rail, credit association and settlement timestamps. We do not receive card numbers. For Lightning, we retain the invoice payment hash, BOLT11 invoice, amount, purpose, hashed credit association, status and settlement timestamps. Phoenixd keeps the incoming-payment record used to confirm settlement. Our Gateway database does not store an incoming payment preimage.
Site analytics and delivery
The site uses PostHog for page views and explicitly named interaction events, including navigation and download clicks, section views, film starts and completions, inquiry attempts and provider-confirmed receipt. Browser automation signals are estimates; traffic counts are not counts of verified people. These events do not prove a sale. Automatic click capture and session recording are disabled in the shared site script. It uses memory-only anonymous identifiers, removes query strings from PostHog events, and does not create person profiles or capture form fields. We use Sentry for error telemetry. Our public site and Loop ID app are delivered through Vercel; Gateway runs on Railway. These providers receive the technical request data needed to serve and operate the services.
Where data goes
- Supabase hosts authentication, account, credit, run, report and memory data, and runs the product functions.
- Railway runs Gateway, its service logs and connected database services.
- Vercel delivers the public site, Loop ID app and site functions.
- Stripe processes hosted card checkout and sends payment events.
- Resend sends authentication email through Supabase's configured SMTP service.
- OpenRouter and selected upstream model providers process AI requests. For Loop Research, the current providers are OpenAI and Perplexity.
- PostHog and Sentry receive the analytics and error telemetry described above.
- AgentMail receives newsletter subscription details and business inquiries. Legacy preflight or audit-intake functions also forward the submitted email and public endpoint when used.
Retention and choices
The current application code does not set automatic deletion periods for accounts, runs, reports, payment records or service logs. Pending Lightning invoices are marked expired after 24 hours, but are not deleted. Loop Memory supports deletion of individual memories or all memories for an account. To request deletion or ask a privacy question, email business@loopxxi.com. We may keep records where needed for security, fraud prevention, accounting or legal obligations.
Loop XXI LLC is a Wyoming limited liability company. Mailing address: 30 North Gould Street, Sheridan, WY 82801.