Privacy policy
Version of October 4, 2026
This policy explains which personal data we process when you visit this site or use Loopback, why, with whom and for how long.
Who we are
Loopback is operated by Omniselect di Nicola Alessi, Via Pompeo Mariani 6, 20128 Milano, Italy, VAT number IT13233920969 (we). For anything about personal data write to privacy@loopback.dev.
Controller and processor
We are the controller of the data of our customers’ accounts and of the visitors of this site. For the data our customers process with the service, such as their code, their tickets and the emails and reports of their own customers, our customer is the controller and we are the processor: that processing is governed by the data processing agreement.
Data we process
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account | Name, email, password hash, organization, role, language. | Providing the service and securing access to it. | Contract |
| Billing | Billing email, invoices; payment methods are handled by Stripe. | Charging the plan and keeping accounting records. | Contract and legal obligation |
| Security and usage records | IP address, browser, audit log of approvals, merges, tags, emails sent and configuration changes. | Preventing abuse, investigating incidents, proving who approved what. | Legitimate interest |
| This site | Attribution of an invitation or a badge link you followed; requests for sponsored open-source credits. | Crediting the invitation, reviewing requests by hand. | Legitimate interest |
| Data processed for our customers | Tickets and emails, widget reports, error events, repository content. | Diagnoses, replies and fixes, on our customer’s instructions. | As processor, under the data processing agreement |
Processing with AI models
- Before logs and messages enter a prompt, emails, phone numbers, card numbers, IBANs, IP addresses and secrets are masked.
- Customer code and data are not used to train models. We use the zero-retention options of the model providers where they exist.
- When a customer runs the analysis in its own runner or agent, the model provider is chosen and contracted by the customer.
- The shared memory holds only abstract patterns, and only with the explicit consent of the customer; no code, names or personal data.
Sub-processors
These companies process personal data on our behalf. The data processing agreement lists the same companies with the safeguards that apply.
| Company | Service | Data | Location | Used |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, database, object storage and key management. | All the data the service stores. | European Union (Ireland) | Always |
| Anthropic, PBC | Language models for Managed jobs, the onboarding demo and the anonymization of shared patterns. | Ticket content, log excerpts and code sent in prompts, after masking. | United States | Always |
| OpenAI, L.L.C. | Language models for Managed jobs when configured, and text embeddings when configured. | Ticket content, log excerpts and code sent in prompts, after masking. | United States | Only when enabled for Managed |
| OpenRouter, Inc. | Routing of language model requests for Managed jobs. | Ticket content, log excerpts and code sent in prompts, after masking. | United States | Only when enabled for Managed |
| Google Cloud EMEA Limited | Language models through Vertex AI for Managed jobs. | Ticket content, log excerpts and code sent in prompts, after masking. | European Union or United States, by the configured region | Only when enabled for Managed |
| Amazon Web Services EMEA SARL | Language models through Amazon Bedrock for Managed jobs. | Ticket content, log excerpts and code sent in prompts, after masking. | European Union or United States, by the configured region | Only when enabled for Managed |
| Resend, Inc. | Sending and receiving emails. | Emails to and from your customers, team notifications. | United States | Always |
| Stripe Payments Europe, Ltd. | Billing and payments. | Billing contacts, payment methods, invoices. | European Union (Ireland) and United States | Always |
| GitHub, Inc. | Repository integration through the GitHub App, sign-in of GitHub Actions jobs. | Repository metadata, issues, pull requests and comments. | United States | Always |
| Google LLC | Delivery of the font a brand profile sets, on status pages, subscription pages, public changelogs and in the widget. | IP address and browser user agent of the people who open those pages or a page that hosts the widget. | United States | Only when a brand profile sets a font |
A provider marked “Only when enabled for Managed” receives data only after we route Managed requests through it, and we announce that 30 days in advance, like a new sub-processor.
Status pages, subscription pages and public changelogs use fonts served by our own servers; the widget uses the fonts of the page that hosts it. When a brand profile sets a font from Google Fonts, those pages and the widget load it from Google, which receives the IP address and browser user agent of each visitor. Without that font, Google receives nothing.
The code-understanding engine, vexp, is developed by the same company and runs inside our infrastructure or yours: it is an internal component, not a sub-processor.
When you run the analysis in your own runner or agent, you choose and contract the model provider: it is not our sub-processor.
International transfers
Some sub-processors are in the United States. Transfers rely on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the standard contractual clauses of the European Commission.
How long we keep data
| Data | Kept |
|---|---|
| Account data | While the account exists |
| Tickets, messages and reports | As long as the account exists; earlier at the customer’s request |
| Error events | 30 days |
| Screenshots and technical details of widget reports (page, errors, requests, browser) | 30 days after the ticket is closed |
| End-user emails shared through the widget for fix notices | 30 days after they were last shared; longer only while an open ticket still has to notify that user |
| Prompts and outputs of jobs, already masked | 30 days by default, configurable by the customer |
| Clones of repositories | Deleted at the end of each job |
| Code index of a repository (Managed) | Until the repository is disconnected, or 30 days unused |
| Audit log | While the account exists |
| Invoices and accounting records | As long as tax law requires |
| Requests for sponsored open-source credits | 12 months after the request was last updated, or earlier if you ask us |
Your rights
You can ask to access, correct, delete, restrict or receive your data, and object to processing based on legitimate interest, by writing to privacy@loopback.dev. For data we process for one of our customers, we forward your request to that customer. You can also complain to your data protection authority; in Italy, the Garante per la protezione dei dati personali.
Security
The measures that protect data are described on the security page.
Cookies
The cookies of the site and the dashboard are listed in the cookie notice.
Changes
When this policy changes we update the date at the top; for material changes we also tell account owners by email before they apply.