Privacy Policy

Last updated: August 2026

LoopTask is operated by Jobr LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA, which is the data controller for the information described in this policy. Contact us at [email protected].

1. What we collect

We collect information you give us when you sign up: your name, email address, and password (stored as a one-way hash). When you hire an agent, we store the brief you provide (your product, ICP, tone preferences, etc.) so the agent can do its job.

We also collect standard usage data — pages visited, actions taken, timestamps — to improve the product and debug issues.

2. How we use it

  • To operate the service and run your AI agents
  • To send transactional emails (receipts, agent updates, alerts)
  • To process payments via Stripe (we never see your card details)
  • To improve the product based on aggregate usage patterns

We do not sell your data. We do not use your brief data to train shared models.

3. Third-party services

We use the following sub-processors, all located in the United States:

  • Railway Corporation — application hosting, database and job queue
  • Cloudflare, Inc. — object storage for post media, DNS and CDN
  • OpenAI, L.L.C. — AI inference (your brief, and the message or comment an agent is replying to, are sent for generation only; they are not used to train models)
  • Stripe, Inc. — payment processing
  • Slack Technologies — agent notifications, where you connect Slack

4. Google user data (YouTube)

When you connect a YouTube channel, LoopTask uses the Google API Services described below. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What we access. With your permission we request two scopes: youtube.readonly, which lets us read your channel's name, ID, and the status of videos published through LoopTask; and youtube.upload, which lets us upload videos to your channel. We do not read your subscriptions, comments, watch history, or any video you did not publish through LoopTask.

How we use it. Solely to provide the feature you asked for: publishing the videos you or your agent schedule, and showing you their status inside the app. We do not use Google user data for advertising, and we do not use it to develop, improve, or train AI/ML models.

What we share. Nothing. Google user data is never sold, and never transferred to third parties — including data brokers, advertisers, or AI model providers — except where strictly required to operate the feature at your direction, or where the law requires it.

How we protect it. Google OAuth access and refresh tokens are encrypted at rest with AES-256 and are never written to logs. All traffic to and from Google APIs runs over TLS. Access is limited to the systems that publish your posts.

Retention and deletion. We keep your Google tokens only while the channel is connected. Disconnecting the channel on the Integrations page revokes the token with Google and deletes it from our database immediately. Deleting your LoopTask account removes all remaining Google user data within 30 days. You can also revoke LoopTask's access at any time from your Google Account permissions page.

5. Meta Platform Data (Facebook, Instagram, Threads)

When you connect a Facebook Page, Instagram business account, or Threads profile, LoopTask acts on that account on your behalf. We handle the data Meta makes available to us in line with Meta's Platform Terms and Developer Policies.

What we access. The list of Pages and Instagram accounts you administer, so you can choose which to connect; the posts published through LoopTask; comments, mentions and direct messages received on those accounts; and post and account metrics such as views and reach. We do not read your personal Facebook profile, your friends, or content on accounts you have not connected.

How we use it. Solely to provide the features you asked for: publishing the posts you or your agent approve, showing comments and messages in your inbox so you can reply, and displaying performance metrics. We do not use Meta Platform Data for advertising, and we do not use it to train AI models.

What we share. Nothing is sold or shared with data brokers or advertisers. The only third parties involved are the sub-processors listed in section 3, acting under contract on our instructions.

How we keep customers separate. Every connected account, post, comment and message is stored against the organisation that connected it, and every query is scoped to that organisation. One customer's data is never visible to another.

How we protect it. Access tokens are encrypted at rest with AES-256-GCM and are never written to logs. All traffic to and from Meta's APIs runs over TLS.

Retention and deletion. We keep tokens only while the account is connected. Disconnecting on the Integrations page revokes the token with Meta and deletes it from our database immediately. Deleting a comment or message from your LoopTask inbox removes our stored copy only — it does not delete anything on Facebook or Instagram. Deleting your LoopTask account removes all associated Meta Platform Data within 30 days. You can also remove LoopTask at any time from your Facebook apps and websites settings, or request deletion by emailing [email protected] with the connected account name; we confirm completion by email within 30 days.

6. Data retention

We keep your data while your account is active. If you cancel, we delete your account data within 30 days on request. Agent message logs are retained for 90 days.

7. Security

Passwords are hashed with bcrypt. OAuth tokens are encrypted at rest. All data is transmitted over TLS. We do not log passwords or raw credentials.

8. Government and law enforcement requests

We do not give any government or public authority access to your data except where we are legally required to. When we receive such a request:

  • We review whether the request is lawful and properly issued before responding, and reject requests that are not.
  • We disclose only the minimum information the request actually requires — never a whole account or database because it was easier.
  • We keep a written record of each request, what we disclosed, the legal basis, and who decided.

Where the law allows it, we will tell the affected customer before disclosing anything.

9. Your rights

You can request a copy of your data, ask us to delete it, or update it at any time. Email us at [email protected].

10. Changes

We may update this policy. Material changes will be emailed to active users at least 14 days before they take effect.

11. Contact

Questions? [email protected]