Privacy Policy
Version: 1.0 Effective Date: 2026-05-01 Last Updated: 2026-06-21
A Brief Note on This Policy
We believe you should understand exactly what happens to your data. This policy explains what we collect, why we collect it, who has access to it, and what you can do about it—in plain language. Where legal language is unavoidable, we've tried to keep it simple. If something is unclear, email us at privacy@inloop.work.
1. Who We Are & What This Policy Covers
inloop ("we," "us," "our," or "the Company"), provided and operated by DENDEN Technology Ltd, a company incorporated and registered in the Republic of Rwanda, operates the inloop platform, a cloud-based solution for collaborative field reporting, project management, and construction workflow automation.
This Privacy Policy applies to:
- The inloop web application (frontend & API)
- All related services and features
- Mobile applications (iOS and Android)
This policy does NOT apply to:
- Third-party services linked from inloop (their privacy policies govern)
- Content you share with third parties through our integrations (e.g., Slack, Gmail, Jira)
Data Controller: DENDEN Technology Ltd (Republic of Rwanda) Registered Address: Norrsken House KN 78, Kigali, Rwanda Privacy Contact: privacy@inloop.work DPO/Privacy Officer: Not currently designated
If you are an EU/EEA resident, you may exercise your data rights directly by contacting privacy@inloop.work. DENDEN Technology Ltd is established in Rwanda (outside the EU/EEA). Where applicable, all EU/EEA personal data transfers are safeguarded by Standard Contractual Clauses (SCCs) as described in Section 6.
2. What Data We Collect
We collect data in a few ways: data you give us directly, data we collect automatically, and data from third parties.
2.1 Data You Provide Directly
Account Registration
When you sign up for inloop, we ask for:
- Email address – used for login, password recovery, and account verification
- Full name – used to personalize your account
- Password – securely hashed before storage (we never store or see your plain-text password)
Profile & Account Settings
You can optionally add:
- Phone number
- Profile picture or avatar
- Bio or description
- Location (city/country level, not precise geolocation)
- Social media links
- Website
Content You Create
inloop's core feature is collaborative reporting. We store:
- Report titles, descriptions, and full text content
- Attached files (documents, images, etc.)
- Comments, tags, and labels you add
- Metadata about reports (status, priority, urgency, AI-suggested tags)
All this content remains yours; we store it to provide the service.
Invitations & Team Setup
When you invite team members:
- Email addresses of invitees (used to send invitations)
- Team member roles and permissions
- Member tags and assignments within reports
Emails & Communications
We store logs of:
- Password reset requests
- Team invitation emails
- Transactional notifications (the fact that we sent them, not the full email content)
2.2 Data We Collect Automatically
Login & Session Data
When you log in, we collect:
- Your IP address (for security and to detect unusual access patterns)
- Device info: browser type, operating system, device type
- Timestamp of login and activity
We use this to:
- Keep you securely logged in across sessions
- Prevent fraudulent access
- Help you manage multiple devices
- Show you active sessions you can revoke
Sessions are stored in a cache (Redis) and automatically expire after 8 days of inactivity.
Usage Analytics & Product Telemetry
We use Amplitude and Sentry to monitor application performance, identify crashes, and improve usability:
- Feature interactions, screen navigation, and button clicks
- Session duration and diagnostic metrics
- Session Replay (Diagnostics): Visual reproductions of user interactions during application crashes or sampled sessions to diagnose rendering bugs. Privacy Safeguards: All text inputs are automatically masked (
maskAllText: true,maskLevel: 'medium'), sensitive authorization tokens/cookies are stripped before transmission, and media content is blocked. - File upload metrics and system latency
We use this data to understand platform health, fix crashes, and improve product workflows under Legitimate Interest.
Error Tracking
When errors occur, Sentry captures:
- Error messages and stack traces
- The page/action that triggered the error
- Your user ID (if authenticated) and system diagnostics (browser, OS, device model)
- Network errors and authorization headers are automatically sanitized
2.3 Data from Third-Party Integrations
OAuth Login & Linked Accounts
If you sign up or log in via Google, Apple, LinkedIn, or Microsoft:
- We receive your email and name from the provider
- We create a link between your inloop account and that provider
- We store an encrypted OAuth token so you can access integrated tools (Gmail, Slack, etc.)
External Tool Integrations
If you connect external tools to inloop (Gmail, Slack, Jira, GitHub, Google Docs):
- We receive and securely store OAuth access tokens
- These tokens allow us to send/create content on your behalf
- When you export a report to one of these tools, we send the content to that tool's API
We do NOT store passwords for external tools; only OAuth tokens (encrypted).
2.4 Sensitive Data
What We Don't Collect
We do NOT knowingly collect:
- Health or medical information
- Biometric data (fingerprints, facial recognition)
- Precise geolocation (GPS coordinates)
- Children's data (under 13 in the US; see Section 9)
What You May Choose to Store
Because inloop stores user-generated content (reports), you may choose to include sensitive information in reports (health data, financial details, etc.). We store this data only to provide the service and will protect it according to our security practices (see Section 10). However, responsibility for what you upload is yours.
Important: If you use AI features (summaries, classifications), note that report content may be sent to our AI provider to generate suggestions (see Section 3 for details).
3. Why We Use Your Data
For each type of data, here's what we do with it and why.
3.1 Providing the Service (Contract)
Legal Basis: Service delivery is necessary to fulfill our agreement with you.
- Authentication & account management: We use your email, password hash, and session tokens to let you log in securely
- Report storage & collaboration: We store your reports and team data so you can access and share them
- Team management: We track who is on your team and what permissions they have
- File storage: We keep your uploaded attachments in AWS S3
Your Choice: You can request deletion of your account and all associated personal data at any time (see Section 7).
3.2 Improving & Operating the Service (Legitimate Interest)
Legal Basis: Understanding how users interact with inloop helps us deliver a better product.
- Usage analytics: We track which features are used most, where users get stuck, and what devices they use
- Error tracking: We monitor application errors to identify and fix bugs
- Performance monitoring: We track system performance to keep the service fast and reliable
- A/B testing: We may test different versions of features (minimal PII exposure)
Your Choice: We don't currently offer analytics opt-out, but we can add one if requested. Email privacy@inloop.work.
3.3 Security & Fraud Prevention (Legitimate Interest + Legal Obligation)
Legal Basis: Protecting accounts and data is both a legal obligation and in everyone's interest.
- Login IP tracking: We track IPs to detect unusual access (e.g., logins from multiple countries in a few hours)
- Session monitoring: We flag suspicious session activity
- Rate limiting: We limit failed login attempts to prevent brute-force attacks
- Payment verification (when implemented): We use fraud detection to verify transactions
Your Choice: If you believe your account is compromised, revoke all sessions from your account settings.
3.4 Communicating with You (Contract + Legal Obligation)
Legal Basis: Sending necessary communications is part of the service agreement and sometimes a legal requirement.
We send:
- Password reset emails (you requested)
- Invitation and team notifications (part of collaboration)
- Billing & subscription emails (when payment features are live)
- Security alerts (if we detect suspicious activity)
- Legal notices (if required by law)
We do NOT currently send marketing or promotional emails, but if we do in the future, we will ask for your consent first.
Your Choice: Transactional emails (password resets, invitations) are necessary to use inloop. You cannot opt out of these without deleting your account.
3.5 AI-Assisted Features (Contract)
Legal Basis: Using AI features is optional; by using them, you consent to processing.
When you use AI features (report summaries, classifications, suggestions), your report content is sent to our AI provider to:
- Generate summaries and classifications
- Suggest tags and structure
- Extract insights
Important: The AI provider may see your report content. However:
- We do NOT send personally identifiable information separately
- The provider is contractually bound to keep data confidential
- You control when AI features are used
Your Choice: Don't use AI features if you're uncomfortable with content being sent to the provider. All AI processing is optional and triggered only when you explicitly request it.
3.6 Legal Compliance & Record-Keeping (Legal Obligation)
Legal Basis: Laws require us to keep certain records.
- Consent records: We store records of your acceptance of this policy and our Terms of Service (with timestamp and IP address) for at least 3 years to prove compliance
- Financial records: We keep transaction records for 7 years (tax law)
- Data retention: We log when data is deleted to prove we comply with your rights
Your Choice: You cannot object to legal obligations, but you can exercise your GDPR/CCPA rights (Section 7).
4. Who We Share Your Data With
The short answer: We don't sell your data to advertisers. We share data with service providers only as needed to run the service.
4.1 Service Providers & Sub-Processors
We use the following companies to operate inloop. They are contractually bound to protect your data and use it only for the purposes we specify:
| Service Provider | Purpose | Data Category | Privacy Policy |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, hosting, secure storage & content delivery | Uploaded files, database records, media assets | https://aws.amazon.com/privacy |
| Oracle (Oracle Cloud Infrastructure) | Cloud infrastructure, compute & database hosting | Application services, database records, telemetry | https://www.oracle.com/legal/privacy/ |
| User authentication (OAuth) & email/document exports | Email, profile name, OAuth tokens | https://policies.google.com/privacy | |
| Sentry | Application stability & error diagnostics | Error logs, diagnostic stack traces, masked replays | https://sentry.io/privacy |
| Amplitude | Product analytics & usage telemetry | Aggregated usage events, masked interaction telemetry | https://amplitude.com/privacy |
| Transactional Email Provider | Transactional & security notification delivery | Email address, recipient name | [To be configured] |
| Apple, Microsoft, LinkedIn | Optional identity & login providers | Email, name, OAuth tokens (if used) | See respective providers |
| Slack, Jira, GitHub | Optional third-party tool integrations | Exported report content (when user-initiated) | See respective providers |
4.2 Business Transfers
If inloop is acquired, merged, or assets are sold:
- Your data may be transferred as part of the transaction
- You will be notified (email or prominent website notice)
- You will have the right to object or delete your account before the transfer
4.3 Legal Requests & Law Enforcement
We may disclose your data if:
- Required by law or court order (subpoena, warrant)
- Necessary to protect safety or prevent fraud
- To enforce this Privacy Policy or Terms of Service
We will:
- Notify you of legal requests when legally permitted
- Provide only the minimum data required
- Preserve your rights under privacy laws
4.4 Aggregated & Anonymized Data
We may share aggregated, anonymized statistics with partners (e.g., "inloop had 10,000 reports created last month"). This data cannot identify individuals.
4.5 Data NOT Sold or Shared for Marketing
We do NOT sell your personal information to advertisers or data brokers. We do not share your email, name, or behavior with third parties for targeted advertising.
5. How We Protect Your Data
5.1 Encryption
- In Transit: All data traveling between your device and inloop is encrypted with HTTPS/TLS 1.2+
- At Rest: Sensitive data (OAuth tokens, refresh tokens) is encrypted in our database using Fernet encryption (AES-128-CBC + HMAC-SHA256)
- Passwords: Your password is hashed with bcrypt before storage; we never store or see your plain password
5.2 Access Control
- Least Privilege: Only employees and automated systems that need access to data can access it
- Role-Based Permissions: Team members have granular permission levels and contextual authorization enforced across projects and organizations
- Authentication: inloop enforces secure authentication with automated step-up multi-factor / One-Time Password (OTP) verification challenges for sensitive actions, elevated permissions, or high-risk access patterns
5.3 Audit Logging & Security Telemetry
- Session & Auth Logs: We log when sessions are created, used, step-up verified, and revoked
- Security & Error Logs: We track application errors, rate limit events, and authorization failures for fraud detection, platform security, and debugging
- Log Retention Pipeline: Live operational logs and monitoring metrics in Grafana/Loki are retained for 14 days; security audit logs and event archives in secure Amazon S3 storage are retained for 180 days before automated deletion
5.4 Security Measures
- Rate Limiting: We limit login and step-up verification attempts to prevent brute-force attacks
- Step-Up Verification (MFA/OTP): High-risk actions and administrative operations trigger immediate one-time passcode verification to the user's verified email address
- Session Monitoring: We flag unusual activity (login from multiple locations, suspicious IP deviations)
- Vulnerability Management: We conduct regular security reviews and fix vulnerabilities promptly
5.5 What We Don't Guarantee
While we implement strong security measures, no system is 100% secure. We cannot guarantee:
- Protection against zero-day exploits
- Protection against sophisticated attacks
- Absolute prevention of unauthorized access
Your Responsibility: Keep your password secure, don't share your login, and report suspicious activity immediately.
5.6 Breach Notification
If we discover a security breach that exposes your personal data:
- GDPR (EU residents): We will notify affected individuals and supervisory authorities within 72 hours (unless risk is low)
- CCPA (California residents): We will notify without unreasonable delay
- Other jurisdictions: We will notify as required by local law
6. Where Your Data is Stored
Your data is securely hosted and processed within enterprise cloud infrastructure (primarily Amazon Web Services and Oracle Cloud Infrastructure). All data is stored in encrypted databases and object storage facilities, and content is delivered over secure, TLS-encrypted connections.
Data Location: We store and process data in enterprise data centers within our designated hosting regions. If you are an EU/EEA resident and data is transferred outside the European Economic Area, we utilize Standard Contractual Clauses (SCCs) to safeguard the transfer under GDPR.
International Data Transfers (GDPR)
If you are in the EU/EEA and your data is transferred to the US or other countries:
- We use Standard Contractual Clauses (SCCs) as approved by the EU Commission
- We conduct Transfer Impact Assessments (TIAs) to evaluate risks post-Schrems II
- Sub-processors (AWS, Oracle, Google, Sentry, Amplitude) have their own SCCs and transfer mechanisms in place
You have the right to request our TIA or object to specific transfers; email privacy@inloop.work.
7. Your Rights & How to Exercise Them
The rights below apply to all users; some are specific to certain jurisdictions. Where your jurisdiction gives you additional rights, those apply too.
7.1 Universal Rights (All Users)
Right to Access (Know)
You can request a copy of all personal data we hold about you.
- How to request: Email privacy@inloop.work with subject "Data Access Request"
- What you'll get: A JSON or CSV file with all your data
- Response time: 30 days (GDPR) or 45 days (CCPA)
- Cost: Free
Right to Correct (Rectification)
You can update inaccurate or incomplete information.
- How to correct: Log in and update your profile, or email privacy@inloop.work
- Response time: 30 days
Right to Delete (Erasure / Right to Be Forgotten)
You have the right to request the deletion of your account and all associated personal identifiers at any time. inloop provides an accessible, in-app mechanism to initiate this process.
How to Request Account Deletion:
- Open the inloop mobile app and navigate to your account settings.
- Tap the "Delete My Account" option. This will redirect you to our verified, secure web form at
https://inloop.work/contact?email=your@email.com&purge=true, pre-filled with your registered email address. - Review and submit the deletion request form.
- You will receive an email confirmation acknowledging receipt of your request.
You may also submit a deletion request by emailing privacy@inloop.work with the subject line "Account Deletion Request" and including the email address associated with your inloop account.
Data Deletion Timeline:
Upon submission of a verified deletion request, the following process is executed:
| Stage | Action | Timeline |
|---|---|---|
| 1. Immediate Deactivation | Your account profile is deactivated. Access to the inloop platform, all field reporting data, workspaces, and team features is suspended. You will no longer be able to log in. | Immediate upon form submission |
| 2. Production Data Purge | All personal data, including your profile information, reports, comments, uploaded files, team associations, and project memberships, is permanently extracted and wiped from our active production databases. | Within 90 calendar days of request submission |
| 3. Backup Overwrite | Any residual copies of your data in our secure, encrypted archival backups are completely cycled and overwritten. | Within 120 calendar days of the initial request |
What Gets Permanently Deleted:
- Your account profile (name, email, phone, avatar, bio)
- All reports, drafts and auto-saved content, comments, tags, labels, and file attachments you created
- Team memberships, project associations, and role assignments
- Session data, device information, and login history
- OAuth tokens and linked third-party account connections
Regulatory Retention Exceptions:
Certain data elements may be legally exempt from immediate destruction if required by applicable local, state, or international law. These include:
- Financial transaction records — retained for up to 7 years per tax law requirements
- Regulatory compliance and audit logs — anonymized and retained as required by law
- Consent records — proof of your acceptance of this Privacy Policy and Terms of Service, retained for a minimum of 3 years
- Active anti-fraud tracking data — retained where necessary to protect the integrity of the platform and comply with legal obligations
- Data subject to active legal proceedings, court orders, or government investigations
Any retained data will be limited to the minimum necessary to satisfy the applicable legal obligation and will be permanently deleted once the obligation expires.
Confirmation: You will receive a final confirmation email once your personal data has been permanently purged from our production systems.
Right to Data Portability (Export)
You can export your data in a machine-readable format (JSON or CSV).
- How to export: Log in → Settings → Export My Data
- What you'll get: All reports, comments, profile info in structured format
- Format: JSON or CSV
- Response time: Within 30 days (may be longer for large exports)
Right to Withdraw Consent
For any processing based on your consent (AI features, email preferences):
- How to withdraw: Log in → Settings → Preferences
- Effect: We stop the specific processing (e.g., AI suggestions), but won't affect past processing
- Note: Withdrawing consent won't affect service delivery if the service is based on contract
Right to Object
You can object to processing for legitimate interest reasons (analytics, marketing, etc.).
- How to object: Email privacy@inloop.work
- What happens: We stop the processing (or justify why we continue)
7.2 GDPR-Specific Rights (EU/EEA Residents)
Restriction of Processing
You can ask us to limit how we use your data (e.g., "store but don't analyze").
- How to request: Email privacy@inloop.work with "Restriction of Processing"
- Response time: 30 days
- Note: We may continue processing for legal, safety, or service reasons
Lodge a Complaint with a Supervisory Authority
If you believe we're violating GDPR, you can file a complaint with your local data protection authority:
| Country | Authority | Website |
|---|---|---|
| Austria | Austrian DPA | https://www.dsb.gv.at |
| Belgium | Belgian DPA | https://www.autoriteprotectiondonnees.be |
| Bulgaria | Bulgarian DPA | https://www.cpdp.bg |
| Croatia | Croatian DPA | https://www.azop.hr |
| Cyprus | Cypriot DPA | https://www.dataprotection.gov.cy |
| Czech Republic | Czech DPA | https://uoou.gov.cz |
| Denmark | Danish DPA | https://www.datatilsynet.dk |
| Estonia | Estonian DPA | https://www.aki.ee |
| Finland | Finnish DPA | https://tietosuoja.fi |
| France | CNIL | https://www.cnil.fr |
| Germany | German DPA (BfDI) | https://www.bfdi.bund.de |
| Greece | Greek DPA | https://www.dpa.gr |
| Hungary | Hungarian DPA | https://www.naih.hu |
| Ireland | Irish DPC | https://www.dataprotection.ie |
| Italy | Italian DPA | https://www.gpdp.it |
| Latvia | Latvian DPA | https://www.dvi.gov.lv |
| Lithuania | Lithuanian DPA | https://www.ada.lt |
| Luxembourg | Luxembourg DPA | https://cnpd.public.lu |
| Malta | Maltese DPA | https://idpc.org.mt |
| Netherlands | Dutch DPA (AP) | https://www.autoriteit-persoonsgegevens.nl |
| Poland | Polish DPA | https://www.uodo.gov.pl |
| Portugal | Portuguese DPA | https://www.cnpd.pt |
| Romania | Romanian DPA | https://www.dataprotection.ro |
| Slovakia | Slovak DPA | https://www.office.gov.sk |
| Slovenia | Slovenian DPA | https://www.ip-rs.si |
| Spain | Spanish DPA | https://www.aepd.es |
| Sweden | Swedish DPA | https://www.datainspektionen.se |
| UK | ICO | https://ico.org.uk |
7.3 CCPA/CPRA Rights (California Residents)
Right to Know
You have the right to know what personal information we collect, use, and share.
- How to request: Email privacy@inloop.work
- Response time: 45 days (with possible 45-day extension)
- Cost: Free
Right to Delete
You can request the deletion of your personal information at any time.
- How to request: Use the in-app account deletion workflow (which redirects to our secure web form at
inloop.work/contact?purge=true), or email privacy@inloop.work with subject "Account Deletion Request" - What happens: Your account is immediately deactivated. Personal data is permanently purged from production databases within 90 calendar days. Encrypted backups are fully overwritten within 120 calendar days of the initial request.
- Exceptions: We may retain specific data elements for legal compliance (tax records, regulatory logs), fraud prevention, or active legal proceedings as required by applicable law
- Response time: Acknowledgment within 45 days (extendable by 45 days for complex requests). Actual data deletion completes within the timeline above.
Right to Correct
You can correct inaccurate personal information.
- How to correct: Update your profile, or email us
- Response time: 45 days
Right to Opt-Out of Sale or Sharing
We do not sell or share your personal information with third parties for targeted advertising. Therefore, this right does not apply.
Shine the Light (California Civil Code § 1798.83)
California residents can request what personal information we share with third parties for their direct marketing.
- Answer: We do NOT share personal information with third parties for marketing purposes.
Non-Discrimination
You will NOT be discriminated against for exercising CCPA rights:
- Price/service unchanged: Exercising your rights won't affect pricing or service quality
- No retaliation: We won't deny, charge more, or lower quality service
Contact Info for CCPA Requests
- Web form: https://inloop.app/ccpa-request
- Email: privacy@inloop.work
7.4 How to Exercise Your Rights
Email: privacy@inloop.work Subject: [Right] Request (e.g., "Data Access Request," "Deletion Request") Include:
- Your full name
- Email address associated with your account
- Which right you're exercising
- Proof of identity (for verification)
Response Time:
- GDPR (EU): 30 days (extendable by 60 days for complex requests)
- CCPA (CA): 45 days (extendable by 45 days)
- Other jurisdictions: As required by law, typically 30 days
Fee: Most requests are free. We may charge a reasonable fee if requests are manifestly unfounded or excessive.
8. Cookies & Tracking Technologies
8.1 Current Cookie Usage
JWT Access Tokens (NOT Technically a Cookie)
Currently, we store your login token in localStorage (browser storage), not cookies. This means:
- Security Risk: localStorage is vulnerable to XSS attacks
- Planned Fix: We will migrate to httpOnly cookies in a future update
- What happens: Your login session will be more secure and inaccessible to JavaScript
Other Technologies:
- Session IDs (Redis): Server-side session data is stored in Redis, not cookies
- No Third-Party Tracking Cookies: We do NOT use Google Analytics, Mixpanel, or other analytics pixels
8.2 Cookies We Plan to Use (Future)
Once we implement cookie consent:
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
inloop_access_token | Authentication (httpOnly) | Strictly Necessary | 8 days |
inloop_refresh_token | Refresh login (httpOnly) | Strictly Necessary | 8 days |
inloop_preferences | User settings (theme, language) | Functional | 1 year |
Strictly Necessary: These cookies are required for the service to work; no consent needed. Functional: These enhance user experience; we will ask for consent via banner.
8.3 Third-Party Cookies
We do NOT currently embed third-party tracking (Google Analytics, Facebook Pixel, etc.). If we add analytics in the future, we will:
- Update this policy
- Ask for your consent via cookie banner
- Allow opt-out
9. Children's Privacy
inloop is not intended for children under 13 (US) or under 16 (EU).
Policy
- We do not knowingly collect data from children under 13 (US) or under 16 (EU)
- If you are under these ages: Do NOT use inloop without parental consent
- If we discover we have data from a child: We will delete it promptly
Parental Responsibility
Parents/guardians:
- Monitor your child's online activities
- Use parental controls on devices
- Do not provide your payment information to a child
Reporting
If you believe we're processing a child's data, email privacy@inloop.work with details, and we will investigate and delete the data within 30 days.
10. Data Retention
We keep your data for as long as necessary to provide the service. Here's the breakdown:
| Data Category | Retention Period | Why | What Happens |
|---|---|---|---|
| Active account data | Until you request account deletion | Service functionality | Hard delete |
| Deactivated account data | Up to 90 calendar days | Processing deletion request | Permanently purged from production databases |
| Backup copies | Up to 120 calendar days | Encrypted archival / disaster recovery | Fully cycled and overwritten |
| Session data | 8 days | Automatic session expiry | Auto-deleted |
| OAuth tokens | Until revoked or 6 months | Service integration | Hard delete on revocation |
| Consent records | 3+ years | Legal hold (proof of consent) | Retained for audit purposes |
| Financial records | 7 years | Tax law requirements | Hard delete after 7 years |
| Live application & telemetry logs | Up to 14 days | System health monitoring & real-time diagnostics | Auto-purged |
| Security & access audit logs | Up to 180 days | Security auditing, compliance & fraud prevention | Automated lifecycle purge |
| Diagnostic error logs (Sentry) | Per standard retention (~90 days) | Bug tracking & crash resolution | Sentry auto-purges |
Deletion Method:
- Immediate deactivation: Account access is suspended; data remains in production systems pending purge
- Production purge: Personal data is permanently extracted and wiped from active databases within 90 calendar days
- Backup overwrite: Residual archival copies in encrypted backups are fully cycled and overwritten within 120 calendar days of the initial request
Account deletion is permanent and irreversible. Once your personal data has been purged from production systems and backups have been overwritten, we cannot recover your account or any associated data.
11. Policy Updates
We may update this Privacy Policy to reflect changes in law, technology, or our practices.
How We Notify You
- Email: We will send a notification to your registered email
- Website Banner: A notice will appear when you log in
- In-app Alert: A notification will appear in your account
What Changes Require New Consent
Material changes (e.g., we start selling data, expand data sharing, change purposes) require your affirmative consent. You can accept or delete your account.
Non-material changes (typos, clarifications, minor updates) don't require re-consent.
Version History
| Version | Effective Date | Key Changes |
|---|---|---|
| 1.0 | 2026-05-01 | Initial policy |
| 1.1 | 2026-06-21 | Updated account deletion process (in-app workflow, data deletion timelines), revised data retention schedule, Apple/Google app store compliance |
12. Contact Information
Privacy Inquiries: Email: privacy@inloop.work Mailing Address: Norrsken House KN 78, Kigali, Rwanda
Data Subject Access Requests (DSAR): Email: privacy@inloop.work Subject: "Data Access Request"
Complaints or Concerns: You can lodge complaints with your local data protection authority (see Section 7.2).
Acknowledgments
We take privacy seriously. This policy is grounded in actual practices found in our codebase, GDPR requirements, CCPA/CPRA requirements, and privacy best practices. Before using inloop, please read both this Privacy Policy and our Terms of Service.