Privacy Policy
Last updated: August 21, 2026
1. Who this covers
Loupe is a document and page review service for people working with AI agents, operated at loupe.ac. This policy covers the hosted service at loupe.ac only.
Loupe is free software under the AGPL-3.0-or-later, and anyone may run their own instance. If you are using a Loupe instance that someone else hosts, this policy does not apply to it — whoever operates that instance is the data controller for it, and you should ask them for their policy. We have no access to self-hosted instances and receive no data from them.
For any privacy-related question or request, contact us at [email protected].
2. What we collect and why
Account data
When you create an account we collect your name, email address and a hashed password. This is necessary to give you a secure, personal account (legal basis: performance of a contract).
Connected accounts
If you sign in with Google or GitHub, we store the provider name and the account identifier that provider gives us, along with the email address on it. We do not receive or store your password for those services, and we do not read anything else in those accounts.
Documents, comments and review data
We store the documents your agent submits, every version of them, and the comments, suggestions, decisions and tags created against them — including the quoted passage each comment is anchored to. We store the comments left through the site review widget together with the page URL and the element selector they were placed on. This is the service (legal basis: performance of a contract).
API tokens
MCP and site-review tokens are stored as a one-way hash, never in a form we can read back. A newly minted token is shown once, when you create it; if it is lost, you mint a new one and revoke the old.
Billing data
Payments are handled by Stripe. We never see or store your card details. We keep the Stripe customer and subscription identifiers, your plan, and your trial and renewal dates, so we know what you are entitled to (legal basis: performance of a contract).
Server logs
Our hosting provider automatically records IP addresses, browser type and the paths requested as part of normal server operation. These are kept for a limited period for security and diagnostics (legal basis: legitimate interests).
Cookies
We use only cookies that are strictly necessary for the service to work:
| Cookie | Purpose |
|---|---|
| Session cookie | Keeps you signed in during your visit |
| CSRF token | Protects against cross-site request forgery |
| Remember-me cookie | Keeps you signed in for up to 30 days — only if you tick the box on the sign-in page |
We use no analytics cookies, no advertising cookies and no third-party tracking.
3. What we do not do
We do not sell or rent your personal data. We do not use your documents or comments to train any machine-learning model, our own or anyone else's, and we do not send them to a model provider. See our AI Policy for the full picture, including what happens to a document once your own agent handles it.
4. Who we share data with
We rely on a small number of providers to run the service:
| Service | Purpose | Location |
|---|---|---|
| DigitalOcean | Hosting, database and export storage | Toronto, Canada region (DigitalOcean is a US company) |
| Fastmail | Transactional email (verification, password reset, notifications) | Australia (servers in the United States) |
| Stripe | Payments and subscription billing | United States and Ireland |
Each is bound by its own privacy policy and by applicable data protection law, and processes data only as needed to deliver its service to us.
5. International data transfers
Where a provider processes data outside Canada or the European Economic Area, we rely on appropriate safeguards — including standard contractual clauses where they apply — to protect your information.
6. How long we keep your data
We keep your personal data for as long as your account is active. If you delete your account, your personal data — documents, versions, comments, tokens, connected accounts and billing profile — is deleted within 30 days, except where retention is required by law or for legitimate security purposes such as server logs.
You can export your data at any time from your account settings, without deleting anything.
7. Your rights
Whoever and wherever you are, you have the following rights over your personal data:
- Access — request a copy of what we hold about you
- Rectification — ask us to correct anything inaccurate
- Erasure — ask us to delete your data
- Portability — request your data in a machine-readable format
- Objection — object to certain kinds of processing
- Withdrawal of consent — where processing rests on consent, withdraw it at any time
Write to [email protected] to exercise any of these. We will respond within 30 days.
If you are in Québec you may also complain to the Commission d'accès à l'information du Québec under Law 25. If you are in the European Economic Area you may complain to your local data protection authority under the GDPR.
8. Children
Loupe is a tool for professional and technical work and is not directed at children. You must be at least 16 to hold an account, as set out in our Terms of Use.
9. Changes to this policy
We may update this policy. We will tell you about material changes by email or a notice in the service at least 30 days before they take effect.
10. Contact
Loupe
[email protected]