Legal
Privacy Policy
How Loopyback collects, uses and protects your data.
Last updated: July 2026
Introduction
This Privacy Policy explains how Loopyback (“Loopyback,” “we,” “us,” or “our”) collects, uses, and safeguards information when you use our browser extension, web application, and related services (collectively, the “Service”). We built Loopyback to help teams capture workflows into clear, step-by-step guides, and we take the responsibility of handling your data seriously.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our practices, please do not use the Service.
Information we collect
We collect several categories of information to provide and improve the Service:
- Account information — such as your name, email address, organization, and authentication credentials when you register.
- Content you capture — the screenshots, steps, and annotations you record when creating a guide.
- Usage data — information about how you interact with the Service, including features used, pages viewed, and session duration.
- Device and log data — IP address, browser type, operating system, and diagnostic information collected automatically.
How we use your information
We use the information we collect to deliver, maintain, and improve the Service, to authenticate users and secure accounts, to provide customer support, and to communicate with you about updates, security notices, and product news. We also use aggregated, de-identified data to understand usage patterns and guide product decisions.
We do not sell your personal information, and we do not use the content of your guides to train third-party advertising models.
Screenshots & captured content
The core of Loopyback is capturing your workflow as a series of screenshots and steps. This captured content is stored on your behalf so that you can edit, share, and export it as a guide. You retain ownership of all content you create.
Captured content is only visible to you and the members of your workspace, unless you explicitly choose to share a guide via a public link or export. You are responsible for reviewing captured content before sharing it externally.
Automatic PII redaction
To reduce the risk of accidentally exposing sensitive information, Loopyback automatically scans captured screenshots for common categories of personally identifiable information (PII) — such as email addresses, phone numbers, credit card numbers, and access tokens — and blurs them before the content is saved.
Automatic redaction is provided as a safeguard and not a guarantee. We encourage you to review every guide before sharing it, and you can manually redact additional regions at any time.
Legal bases (GDPR)
We process personal data on the following legal bases: performance of our contract with you (providing the Service you signed up for), our legitimate interests (securing and improving the Service, preventing abuse), your consent (where required, for example for non-essential cookies or marketing emails), and compliance with legal obligations (such as tax and accounting rules).
Cookies
We use cookies and similar technologies that are strictly necessary to operate the Service, such as keeping you signed in and remembering your preferences. Details about what we set and how long it lasts are in our Cookie Policy.
Data sharing & third parties
We share information only in limited circumstances: with service providers who process data on our behalf (such as cloud hosting, analytics, and payment processing) under contractual confidentiality obligations; when required to comply with a legal obligation or valid legal process; and in connection with a merger, acquisition, or sale of assets, subject to this policy.
All third-party processors are vetted for appropriate security and privacy practices and are permitted to use your data only to provide services to us.
Data retention
We retain personal information for as long as your account is active or as needed to provide the Service. When you delete a guide or close your account, we remove the associated content from active systems within a reasonable period, and from backups in the normal course of backup rotation.
We may retain certain information where required to comply with legal obligations, resolve disputes, or enforce our agreements.
Your rights (GDPR/CCPA)
Depending on where you live, you may have rights over your personal information, including the right to access, correct, delete, or export your data, and the right to object to or restrict certain processing.
- Under the GDPR, you may request access, rectification, erasure, portability, and restriction of processing.
- Under the CCPA, you may request disclosure of the categories of data we collect and request deletion of your personal information.
- You may withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us using the details below. We will not discriminate against you for exercising your privacy rights.
International transfers
Loopyback is based in the European Union and stores customer content with EU-hosted infrastructure where possible. Where a service provider processes data outside the European Economic Area, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision (for example, the EU–US Data Privacy Framework).
Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it promptly.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will provide reasonable notice, for example by posting the updated policy and revising the date above, and where appropriate by notifying you directly.
Contact
If you have questions about this Privacy Policy or how we handle your data, contact our privacy team at privacy@loopyback.com. We aim to respond to all legitimate requests within 30 days.