Privacy Policy

Last updated: June 21, 2026

Version: 1.0 Effective Date: 2026-05-01 Last Updated: 2026-06-21


A Brief Note on This Policy

We believe you should understand exactly what happens to your data. This policy explains what we collect, why we collect it, who has access to it, and what you can do about it—in plain language. Where legal language is unavoidable, we've tried to keep it simple. If something is unclear, email us at privacy@inloop.work.


1. Who We Are & What This Policy Covers

inloop ("we," "us," "our," or "the Company"), provided and operated by DENDEN Technology Ltd, a company incorporated and registered in the Republic of Rwanda, operates the inloop platform, a cloud-based solution for collaborative field reporting, project management, and construction workflow automation.

This Privacy Policy applies to:

  • The inloop web application (frontend & API)
  • All related services and features
  • Mobile applications (iOS and Android)

This policy does NOT apply to:

  • Third-party services linked from inloop (their privacy policies govern)
  • Content you share with third parties through our integrations (e.g., Slack, Gmail, Jira)

Data Controller: DENDEN Technology Ltd (Republic of Rwanda) Registered Address: Norrsken House KN 78, Kigali, Rwanda Privacy Contact: privacy@inloop.work DPO/Privacy Officer: Not currently designated

If you are an EU/EEA resident, you may exercise your data rights directly by contacting privacy@inloop.work. DENDEN Technology Ltd is established in Rwanda (outside the EU/EEA). Where applicable, all EU/EEA personal data transfers are safeguarded by Standard Contractual Clauses (SCCs) as described in Section 6.


2. What Data We Collect

We collect data in a few ways: data you give us directly, data we collect automatically, and data from third parties.

2.1 Data You Provide Directly

Account Registration

When you sign up for inloop, we ask for:

  • Email address – used for login, password recovery, and account verification
  • Full name – used to personalize your account
  • Password – securely hashed before storage (we never store or see your plain-text password)

Profile & Account Settings

You can optionally add:

  • Phone number
  • Profile picture or avatar
  • Bio or description
  • Location (city/country level, not precise geolocation)
  • Social media links
  • Website

Content You Create

inloop's core feature is collaborative reporting. We store:

  • Report titles, descriptions, and full text content
  • Attached files (documents, images, etc.)
  • Comments, tags, and labels you add
  • Metadata about reports (status, priority, urgency, AI-suggested tags)

All this content remains yours; we store it to provide the service.

Invitations & Team Setup

When you invite team members:

  • Email addresses of invitees (used to send invitations)
  • Team member roles and permissions
  • Member tags and assignments within reports

Emails & Communications

We store logs of:

  • Password reset requests
  • Team invitation emails
  • Transactional notifications (the fact that we sent them, not the full email content)

2.2 Data We Collect Automatically

Login & Session Data

When you log in, we collect:

  • Your IP address (for security and to detect unusual access patterns)
  • Device info: browser type, operating system, device type
  • Timestamp of login and activity

We use this to:

  • Keep you securely logged in across sessions
  • Prevent fraudulent access
  • Help you manage multiple devices
  • Show you active sessions you can revoke

Sessions are stored in a cache (Redis) and automatically expire after 8 days of inactivity.

Usage Analytics & Product Telemetry

We use Amplitude and Sentry to monitor application performance, identify crashes, and improve usability:

  • Feature interactions, screen navigation, and button clicks
  • Session duration and diagnostic metrics
  • Session Replay (Diagnostics): Visual reproductions of user interactions during application crashes or sampled sessions to diagnose rendering bugs. Privacy Safeguards: All text inputs are automatically masked (maskAllText: true, maskLevel: 'medium'), sensitive authorization tokens/cookies are stripped before transmission, and media content is blocked.
  • File upload metrics and system latency

We use this data to understand platform health, fix crashes, and improve product workflows under Legitimate Interest.

Error Tracking

When errors occur, Sentry captures:

  • Error messages and stack traces
  • The page/action that triggered the error
  • Your user ID (if authenticated) and system diagnostics (browser, OS, device model)
  • Network errors and authorization headers are automatically sanitized

2.3 Data from Third-Party Integrations

OAuth Login & Linked Accounts

If you sign up or log in via Google, Apple, LinkedIn, or Microsoft:

  • We receive your email and name from the provider
  • We create a link between your inloop account and that provider
  • We store an encrypted OAuth token so you can access integrated tools (Gmail, Slack, etc.)

External Tool Integrations

If you connect external tools to inloop (Gmail, Slack, Jira, GitHub, Google Docs):

  • We receive and securely store OAuth access tokens
  • These tokens allow us to send/create content on your behalf
  • When you export a report to one of these tools, we send the content to that tool's API

We do NOT store passwords for external tools; only OAuth tokens (encrypted).

2.4 Sensitive Data

What We Don't Collect

We do NOT knowingly collect:

  • Health or medical information
  • Biometric data (fingerprints, facial recognition)
  • Precise geolocation (GPS coordinates)
  • Children's data (under 13 in the US; see Section 9)

What You May Choose to Store

Because inloop stores user-generated content (reports), you may choose to include sensitive information in reports (health data, financial details, etc.). We store this data only to provide the service and will protect it according to our security practices (see Section 10). However, responsibility for what you upload is yours.

Important: If you use AI features (summaries, classifications), note that report content may be sent to our AI provider to generate suggestions (see Section 3 for details).


3. Why We Use Your Data

For each type of data, here's what we do with it and why.

3.1 Providing the Service (Contract)

Legal Basis: Service delivery is necessary to fulfill our agreement with you.

  • Authentication & account management: We use your email, password hash, and session tokens to let you log in securely
  • Report storage & collaboration: We store your reports and team data so you can access and share them
  • Team management: We track who is on your team and what permissions they have
  • File storage: We keep your uploaded attachments in AWS S3

Your Choice: You can request deletion of your account and all associated personal data at any time (see Section 7).

3.2 Improving & Operating the Service (Legitimate Interest)

Legal Basis: Understanding how users interact with inloop helps us deliver a better product.

  • Usage analytics: We track which features are used most, where users get stuck, and what devices they use
  • Error tracking: We monitor application errors to identify and fix bugs
  • Performance monitoring: We track system performance to keep the service fast and reliable
  • A/B testing: We may test different versions of features (minimal PII exposure)

Your Choice: We don't currently offer analytics opt-out, but we can add one if requested. Email privacy@inloop.work.

3.3 Security & Fraud Prevention (Legitimate Interest + Legal Obligation)

Legal Basis: Protecting accounts and data is both a legal obligation and in everyone's interest.

  • Login IP tracking: We track IPs to detect unusual access (e.g., logins from multiple countries in a few hours)
  • Session monitoring: We flag suspicious session activity
  • Rate limiting: We limit failed login attempts to prevent brute-force attacks
  • Payment verification (when implemented): We use fraud detection to verify transactions

Your Choice: If you believe your account is compromised, revoke all sessions from your account settings.

3.4 Communicating with You (Contract + Legal Obligation)

Legal Basis: Sending necessary communications is part of the service agreement and sometimes a legal requirement.

We send:

  • Password reset emails (you requested)
  • Invitation and team notifications (part of collaboration)
  • Billing & subscription emails (when payment features are live)
  • Security alerts (if we detect suspicious activity)
  • Legal notices (if required by law)

We do NOT currently send marketing or promotional emails, but if we do in the future, we will ask for your consent first.

Your Choice: Transactional emails (password resets, invitations) are necessary to use inloop. You cannot opt out of these without deleting your account.

3.5 AI-Assisted Features (Contract)

Legal Basis: Using AI features is optional; by using them, you consent to processing.

When you use AI features (report summaries, classifications, suggestions), your report content is sent to our AI provider to:

  • Generate summaries and classifications
  • Suggest tags and structure
  • Extract insights

Important: The AI provider may see your report content. However:

  • We do NOT send personally identifiable information separately
  • The provider is contractually bound to keep data confidential
  • You control when AI features are used

Your Choice: Don't use AI features if you're uncomfortable with content being sent to the provider. All AI processing is optional and triggered only when you explicitly request it.

3.6 Legal Compliance & Record-Keeping (Legal Obligation)

Legal Basis: Laws require us to keep certain records.

  • Consent records: We store records of your acceptance of this policy and our Terms of Service (with timestamp and IP address) for at least 3 years to prove compliance
  • Financial records: We keep transaction records for 7 years (tax law)
  • Data retention: We log when data is deleted to prove we comply with your rights

Your Choice: You cannot object to legal obligations, but you can exercise your GDPR/CCPA rights (Section 7).


4. Who We Share Your Data With

The short answer: We don't sell your data to advertisers. We share data with service providers only as needed to run the service.

4.1 Service Providers & Sub-Processors

We use the following companies to operate inloop. They are contractually bound to protect your data and use it only for the purposes we specify:

Service ProviderPurposeData CategoryPrivacy Policy
Amazon Web Services (AWS)Cloud infrastructure, hosting, secure storage & content deliveryUploaded files, database records, media assetshttps://aws.amazon.com/privacy
Oracle (Oracle Cloud Infrastructure)Cloud infrastructure, compute & database hostingApplication services, database records, telemetryhttps://www.oracle.com/legal/privacy/
GoogleUser authentication (OAuth) & email/document exportsEmail, profile name, OAuth tokenshttps://policies.google.com/privacy
SentryApplication stability & error diagnosticsError logs, diagnostic stack traces, masked replayshttps://sentry.io/privacy
AmplitudeProduct analytics & usage telemetryAggregated usage events, masked interaction telemetryhttps://amplitude.com/privacy
Transactional Email ProviderTransactional & security notification deliveryEmail address, recipient name[To be configured]
Apple, Microsoft, LinkedInOptional identity & login providersEmail, name, OAuth tokens (if used)See respective providers
Slack, Jira, GitHubOptional third-party tool integrationsExported report content (when user-initiated)See respective providers

4.2 Business Transfers

If inloop is acquired, merged, or assets are sold:

  • Your data may be transferred as part of the transaction
  • You will be notified (email or prominent website notice)
  • You will have the right to object or delete your account before the transfer

4.3 Legal Requests & Law Enforcement

We may disclose your data if:

  • Required by law or court order (subpoena, warrant)
  • Necessary to protect safety or prevent fraud
  • To enforce this Privacy Policy or Terms of Service

We will:

  • Notify you of legal requests when legally permitted
  • Provide only the minimum data required
  • Preserve your rights under privacy laws

4.4 Aggregated & Anonymized Data

We may share aggregated, anonymized statistics with partners (e.g., "inloop had 10,000 reports created last month"). This data cannot identify individuals.

4.5 Data NOT Sold or Shared for Marketing

We do NOT sell your personal information to advertisers or data brokers. We do not share your email, name, or behavior with third parties for targeted advertising.


5. How We Protect Your Data

5.1 Encryption

  • In Transit: All data traveling between your device and inloop is encrypted with HTTPS/TLS 1.2+
  • At Rest: Sensitive data (OAuth tokens, refresh tokens) is encrypted in our database using Fernet encryption (AES-128-CBC + HMAC-SHA256)
  • Passwords: Your password is hashed with bcrypt before storage; we never store or see your plain password

5.2 Access Control

  • Least Privilege: Only employees and automated systems that need access to data can access it
  • Role-Based Permissions: Team members have granular permission levels and contextual authorization enforced across projects and organizations
  • Authentication: inloop enforces secure authentication with automated step-up multi-factor / One-Time Password (OTP) verification challenges for sensitive actions, elevated permissions, or high-risk access patterns

5.3 Audit Logging & Security Telemetry

  • Session & Auth Logs: We log when sessions are created, used, step-up verified, and revoked
  • Security & Error Logs: We track application errors, rate limit events, and authorization failures for fraud detection, platform security, and debugging
  • Log Retention Pipeline: Live operational logs and monitoring metrics in Grafana/Loki are retained for 14 days; security audit logs and event archives in secure Amazon S3 storage are retained for 180 days before automated deletion

5.4 Security Measures

  • Rate Limiting: We limit login and step-up verification attempts to prevent brute-force attacks
  • Step-Up Verification (MFA/OTP): High-risk actions and administrative operations trigger immediate one-time passcode verification to the user's verified email address
  • Session Monitoring: We flag unusual activity (login from multiple locations, suspicious IP deviations)
  • Vulnerability Management: We conduct regular security reviews and fix vulnerabilities promptly

5.5 What We Don't Guarantee

While we implement strong security measures, no system is 100% secure. We cannot guarantee:

  • Protection against zero-day exploits
  • Protection against sophisticated attacks
  • Absolute prevention of unauthorized access

Your Responsibility: Keep your password secure, don't share your login, and report suspicious activity immediately.

5.6 Breach Notification

If we discover a security breach that exposes your personal data:

  • GDPR (EU residents): We will notify affected individuals and supervisory authorities within 72 hours (unless risk is low)
  • CCPA (California residents): We will notify without unreasonable delay
  • Other jurisdictions: We will notify as required by local law

6. Where Your Data is Stored

Your data is securely hosted and processed within enterprise cloud infrastructure (primarily Amazon Web Services and Oracle Cloud Infrastructure). All data is stored in encrypted databases and object storage facilities, and content is delivered over secure, TLS-encrypted connections.

Data Location: We store and process data in enterprise data centers within our designated hosting regions. If you are an EU/EEA resident and data is transferred outside the European Economic Area, we utilize Standard Contractual Clauses (SCCs) to safeguard the transfer under GDPR.

International Data Transfers (GDPR)

If you are in the EU/EEA and your data is transferred to the US or other countries:

  • We use Standard Contractual Clauses (SCCs) as approved by the EU Commission
  • We conduct Transfer Impact Assessments (TIAs) to evaluate risks post-Schrems II
  • Sub-processors (AWS, Oracle, Google, Sentry, Amplitude) have their own SCCs and transfer mechanisms in place

You have the right to request our TIA or object to specific transfers; email privacy@inloop.work.


7. Your Rights & How to Exercise Them

The rights below apply to all users; some are specific to certain jurisdictions. Where your jurisdiction gives you additional rights, those apply too.

7.1 Universal Rights (All Users)

Right to Access (Know)

You can request a copy of all personal data we hold about you.

  • How to request: Email privacy@inloop.work with subject "Data Access Request"
  • What you'll get: A JSON or CSV file with all your data
  • Response time: 30 days (GDPR) or 45 days (CCPA)
  • Cost: Free

Right to Correct (Rectification)

You can update inaccurate or incomplete information.

  • How to correct: Log in and update your profile, or email privacy@inloop.work
  • Response time: 30 days

Right to Delete (Erasure / Right to Be Forgotten)

You have the right to request the deletion of your account and all associated personal identifiers at any time. inloop provides an accessible, in-app mechanism to initiate this process.

How to Request Account Deletion:

  1. Open the inloop mobile app and navigate to your account settings.
  2. Tap the "Delete My Account" option. This will redirect you to our verified, secure web form at https://inloop.work/contact?email=your@email.com&purge=true, pre-filled with your registered email address.
  3. Review and submit the deletion request form.
  4. You will receive an email confirmation acknowledging receipt of your request.

You may also submit a deletion request by emailing privacy@inloop.work with the subject line "Account Deletion Request" and including the email address associated with your inloop account.

Data Deletion Timeline:

Upon submission of a verified deletion request, the following process is executed:

StageActionTimeline
1. Immediate DeactivationYour account profile is deactivated. Access to the inloop platform, all field reporting data, workspaces, and team features is suspended. You will no longer be able to log in.Immediate upon form submission
2. Production Data PurgeAll personal data, including your profile information, reports, comments, uploaded files, team associations, and project memberships, is permanently extracted and wiped from our active production databases.Within 90 calendar days of request submission
3. Backup OverwriteAny residual copies of your data in our secure, encrypted archival backups are completely cycled and overwritten.Within 120 calendar days of the initial request

What Gets Permanently Deleted:

  • Your account profile (name, email, phone, avatar, bio)
  • All reports, drafts and auto-saved content, comments, tags, labels, and file attachments you created
  • Team memberships, project associations, and role assignments
  • Session data, device information, and login history
  • OAuth tokens and linked third-party account connections

Regulatory Retention Exceptions:

Certain data elements may be legally exempt from immediate destruction if required by applicable local, state, or international law. These include:

  • Financial transaction records — retained for up to 7 years per tax law requirements
  • Regulatory compliance and audit logs — anonymized and retained as required by law
  • Consent records — proof of your acceptance of this Privacy Policy and Terms of Service, retained for a minimum of 3 years
  • Active anti-fraud tracking data — retained where necessary to protect the integrity of the platform and comply with legal obligations
  • Data subject to active legal proceedings, court orders, or government investigations

Any retained data will be limited to the minimum necessary to satisfy the applicable legal obligation and will be permanently deleted once the obligation expires.

Confirmation: You will receive a final confirmation email once your personal data has been permanently purged from our production systems.

Right to Data Portability (Export)

You can export your data in a machine-readable format (JSON or CSV).

  • How to export: Log in → Settings → Export My Data
  • What you'll get: All reports, comments, profile info in structured format
  • Format: JSON or CSV
  • Response time: Within 30 days (may be longer for large exports)

Right to Withdraw Consent

For any processing based on your consent (AI features, email preferences):

  • How to withdraw: Log in → Settings → Preferences
  • Effect: We stop the specific processing (e.g., AI suggestions), but won't affect past processing
  • Note: Withdrawing consent won't affect service delivery if the service is based on contract

Right to Object

You can object to processing for legitimate interest reasons (analytics, marketing, etc.).

  • How to object: Email privacy@inloop.work
  • What happens: We stop the processing (or justify why we continue)

7.2 GDPR-Specific Rights (EU/EEA Residents)

Restriction of Processing

You can ask us to limit how we use your data (e.g., "store but don't analyze").

  • How to request: Email privacy@inloop.work with "Restriction of Processing"
  • Response time: 30 days
  • Note: We may continue processing for legal, safety, or service reasons

Lodge a Complaint with a Supervisory Authority

If you believe we're violating GDPR, you can file a complaint with your local data protection authority:

CountryAuthorityWebsite
AustriaAustrian DPAhttps://www.dsb.gv.at
BelgiumBelgian DPAhttps://www.autoriteprotectiondonnees.be
BulgariaBulgarian DPAhttps://www.cpdp.bg
CroatiaCroatian DPAhttps://www.azop.hr
CyprusCypriot DPAhttps://www.dataprotection.gov.cy
Czech RepublicCzech DPAhttps://uoou.gov.cz
DenmarkDanish DPAhttps://www.datatilsynet.dk
EstoniaEstonian DPAhttps://www.aki.ee
FinlandFinnish DPAhttps://tietosuoja.fi
FranceCNILhttps://www.cnil.fr
GermanyGerman DPA (BfDI)https://www.bfdi.bund.de
GreeceGreek DPAhttps://www.dpa.gr
HungaryHungarian DPAhttps://www.naih.hu
IrelandIrish DPChttps://www.dataprotection.ie
ItalyItalian DPAhttps://www.gpdp.it
LatviaLatvian DPAhttps://www.dvi.gov.lv
LithuaniaLithuanian DPAhttps://www.ada.lt
LuxembourgLuxembourg DPAhttps://cnpd.public.lu
MaltaMaltese DPAhttps://idpc.org.mt
NetherlandsDutch DPA (AP)https://www.autoriteit-persoonsgegevens.nl
PolandPolish DPAhttps://www.uodo.gov.pl
PortugalPortuguese DPAhttps://www.cnpd.pt
RomaniaRomanian DPAhttps://www.dataprotection.ro
SlovakiaSlovak DPAhttps://www.office.gov.sk
SloveniaSlovenian DPAhttps://www.ip-rs.si
SpainSpanish DPAhttps://www.aepd.es
SwedenSwedish DPAhttps://www.datainspektionen.se
UKICOhttps://ico.org.uk

7.3 CCPA/CPRA Rights (California Residents)

Right to Know

You have the right to know what personal information we collect, use, and share.

  • How to request: Email privacy@inloop.work
  • Response time: 45 days (with possible 45-day extension)
  • Cost: Free

Right to Delete

You can request the deletion of your personal information at any time.

  • How to request: Use the in-app account deletion workflow (which redirects to our secure web form at inloop.work/contact?purge=true), or email privacy@inloop.work with subject "Account Deletion Request"
  • What happens: Your account is immediately deactivated. Personal data is permanently purged from production databases within 90 calendar days. Encrypted backups are fully overwritten within 120 calendar days of the initial request.
  • Exceptions: We may retain specific data elements for legal compliance (tax records, regulatory logs), fraud prevention, or active legal proceedings as required by applicable law
  • Response time: Acknowledgment within 45 days (extendable by 45 days for complex requests). Actual data deletion completes within the timeline above.

Right to Correct

You can correct inaccurate personal information.

  • How to correct: Update your profile, or email us
  • Response time: 45 days

Right to Opt-Out of Sale or Sharing

We do not sell or share your personal information with third parties for targeted advertising. Therefore, this right does not apply.

Shine the Light (California Civil Code § 1798.83)

California residents can request what personal information we share with third parties for their direct marketing.

  • Answer: We do NOT share personal information with third parties for marketing purposes.

Non-Discrimination

You will NOT be discriminated against for exercising CCPA rights:

  • Price/service unchanged: Exercising your rights won't affect pricing or service quality
  • No retaliation: We won't deny, charge more, or lower quality service

Contact Info for CCPA Requests

  • Web form: https://inloop.app/ccpa-request
  • Email: privacy@inloop.work

7.4 How to Exercise Your Rights

Email: privacy@inloop.work Subject: [Right] Request (e.g., "Data Access Request," "Deletion Request") Include:

  • Your full name
  • Email address associated with your account
  • Which right you're exercising
  • Proof of identity (for verification)

Response Time:

  • GDPR (EU): 30 days (extendable by 60 days for complex requests)
  • CCPA (CA): 45 days (extendable by 45 days)
  • Other jurisdictions: As required by law, typically 30 days

Fee: Most requests are free. We may charge a reasonable fee if requests are manifestly unfounded or excessive.


8. Cookies & Tracking Technologies

8.1 Current Cookie Usage

JWT Access Tokens (NOT Technically a Cookie)

Currently, we store your login token in localStorage (browser storage), not cookies. This means:

  • Security Risk: localStorage is vulnerable to XSS attacks
  • Planned Fix: We will migrate to httpOnly cookies in a future update
  • What happens: Your login session will be more secure and inaccessible to JavaScript

Other Technologies:

  • Session IDs (Redis): Server-side session data is stored in Redis, not cookies
  • No Third-Party Tracking Cookies: We do NOT use Google Analytics, Mixpanel, or other analytics pixels

8.2 Cookies We Plan to Use (Future)

Once we implement cookie consent:

CookiePurposeTypeDuration
inloop_access_tokenAuthentication (httpOnly)Strictly Necessary8 days
inloop_refresh_tokenRefresh login (httpOnly)Strictly Necessary8 days
inloop_preferencesUser settings (theme, language)Functional1 year

Strictly Necessary: These cookies are required for the service to work; no consent needed. Functional: These enhance user experience; we will ask for consent via banner.

8.3 Third-Party Cookies

We do NOT currently embed third-party tracking (Google Analytics, Facebook Pixel, etc.). If we add analytics in the future, we will:

  • Update this policy
  • Ask for your consent via cookie banner
  • Allow opt-out

9. Children's Privacy

inloop is not intended for children under 13 (US) or under 16 (EU).

Policy

  • We do not knowingly collect data from children under 13 (US) or under 16 (EU)
  • If you are under these ages: Do NOT use inloop without parental consent
  • If we discover we have data from a child: We will delete it promptly

Parental Responsibility

Parents/guardians:

  • Monitor your child's online activities
  • Use parental controls on devices
  • Do not provide your payment information to a child

Reporting

If you believe we're processing a child's data, email privacy@inloop.work with details, and we will investigate and delete the data within 30 days.


10. Data Retention

We keep your data for as long as necessary to provide the service. Here's the breakdown:

Data CategoryRetention PeriodWhyWhat Happens
Active account dataUntil you request account deletionService functionalityHard delete
Deactivated account dataUp to 90 calendar daysProcessing deletion requestPermanently purged from production databases
Backup copiesUp to 120 calendar daysEncrypted archival / disaster recoveryFully cycled and overwritten
Session data8 daysAutomatic session expiryAuto-deleted
OAuth tokensUntil revoked or 6 monthsService integrationHard delete on revocation
Consent records3+ yearsLegal hold (proof of consent)Retained for audit purposes
Financial records7 yearsTax law requirementsHard delete after 7 years
Live application & telemetry logsUp to 14 daysSystem health monitoring & real-time diagnosticsAuto-purged
Security & access audit logsUp to 180 daysSecurity auditing, compliance & fraud preventionAutomated lifecycle purge
Diagnostic error logs (Sentry)Per standard retention (~90 days)Bug tracking & crash resolutionSentry auto-purges

Deletion Method:

  • Immediate deactivation: Account access is suspended; data remains in production systems pending purge
  • Production purge: Personal data is permanently extracted and wiped from active databases within 90 calendar days
  • Backup overwrite: Residual archival copies in encrypted backups are fully cycled and overwritten within 120 calendar days of the initial request

Account deletion is permanent and irreversible. Once your personal data has been purged from production systems and backups have been overwritten, we cannot recover your account or any associated data.


11. Policy Updates

We may update this Privacy Policy to reflect changes in law, technology, or our practices.

How We Notify You

  • Email: We will send a notification to your registered email
  • Website Banner: A notice will appear when you log in
  • In-app Alert: A notification will appear in your account

What Changes Require New Consent

Material changes (e.g., we start selling data, expand data sharing, change purposes) require your affirmative consent. You can accept or delete your account.

Non-material changes (typos, clarifications, minor updates) don't require re-consent.

Version History

VersionEffective DateKey Changes
1.02026-05-01Initial policy
1.12026-06-21Updated account deletion process (in-app workflow, data deletion timelines), revised data retention schedule, Apple/Google app store compliance

12. Contact Information

Privacy Inquiries: Email: privacy@inloop.work Mailing Address: Norrsken House KN 78, Kigali, Rwanda

Data Subject Access Requests (DSAR): Email: privacy@inloop.work Subject: "Data Access Request"

Complaints or Concerns: You can lodge complaints with your local data protection authority (see Section 7.2).


Acknowledgments

We take privacy seriously. This policy is grounded in actual practices found in our codebase, GDPR requirements, CCPA/CPRA requirements, and privacy best practices. Before using inloop, please read both this Privacy Policy and our Terms of Service.