Legal
Privacy Policy
Last updated: September 29, 2026
Loomrail ("we", "us") lets you create named AI agents, give each one a job, and chat with it — with tool use, file attachments, and optional integrations. This policy explains what we collect to make that work, why, where it's kept, and your rights over it. We handle personal data in line with India's Digital Personal Data Protection Act, 2023 and its Rules. Loomrail accounts are for people 13 or older; under 18 needs a parent or guardian's approval.
1. Information we collect
Account information. Name and email when you sign up, or your name, email and photo from Google or Microsoft if you sign in with them — for a Microsoft work account, also your organisation's Microsoft ID, so your company's sign-in rules can apply.
Security settings. If you turn on two-factor sign-in, the key your authenticator app uses (encrypted) and your backup codes (stored only in a one-way scrambled form), plus the devices and places you've signed in from.
Your agents. Each agent's name, goal, description, chosen avatar, and any restrictions ("boundaries") you set for it.
Chat content. Messages you send an agent, any files or pasted text you attach, and the agent's replies — including any tool it ran to answer you.
Rooms. If you group agents into a room, we store the room name, its members, which member (if any) is the chief, and the messages agents exchange when one hands off or escalates a task to another.
Browser sessions. If you ask an agent to browse the web, we run a real browser session on our servers on your behalf and store screenshots of what it saw so you can review its actions. That session is torn down after a period of inactivity.
Routines. If you schedule an agent to run on a cadence, we store that schedule and the resulting conversation each run produces.
AI Memory and Skills. Facts you ask Loomrail to remember, and any instruction presets (Skills) you create, both shared across your agents.
Connected integrations. If you connect a third-party account (Notion, Linear, GitHub, and others) on Settings → Integrations, we store the API key or token that service issues, encrypted at rest, only for as long as the integration stays connected.
Candidates and test-takers. If you use Recruiter or Examiner, you may upload other people's resumes and contact details, and people who take a test you share give their name, email and answers. For that data you decide why it's collected and we process it for you (see Children and people you add, below).
Payments. If you buy a plan or credits, Dodo Payments handles the payment as the merchant of record (it also works out and collects any tax). We keep the plan, amount, date and Dodo's payment reference — never your card or bank details.
Usage and device data. IP address and browser/device type, collected automatically when you use the app, and the date and version of the Terms and Privacy Policy you agreed to.
2. How we use your data
We use your data to operate your account, run your agents' conversations (including inside rooms and scheduled routines), carry out a handoff or escalation between agents you've grouped together, run browser sessions you ask an agent to perform, remember what you ask us to, apply your Skills to chat replies, and let a connected integration act as a tool your agent can use. We do not sell your personal information to third parties.
3. AI processing
Messages you send an agent are sent to an AI model to generate a reply. Which model answers depends on your choice in the composer (or an automatic default), and may include a third-party AI provider (OpenAI, Anthropic, Google, and others). We don't use your chat content to train our own models, and we use providers' business services, which by their terms don't train on it either.
Before text reaches an AI model, secrets such as API keys and passwords are replaced with placeholders. If you use Loomrail through a company, it can also have emails, phone numbers and ID or financial numbers hidden the same way; the real values are put back only where needed, such as the address an email is sent to.
When you ask an agent to search the web, the search words are sent to public search services (see Who processes your data). Images from other websites in a reply load only when you click them.
4. Google user data
If you connect a Google account in Customize → Integrations, Loomrail asks only for the access each feature needs, and uses it only when you ask an agent to do that task:
- Gmail (send only): to send an email you ask an agent to send. Loomrail cannot read your inbox.
- Google Calendar: to show your upcoming events and create or update events you ask for.
- Google Drive: only files you pick with the Google file picker, files you ask Loomrail to save to your Drive, or files Loomrail creates for you — never the rest of your Drive.
- Google Sheets: to read and update spreadsheets you ask an agent to work on.
- Google Docs: to read a document you ask an agent to summarise or use, and to create or edit a document when you ask.
- Google Slides: to create a presentation when you ask, and to read or edit a presentation you name.
- Google Tasks: to list, add, complete or change tasks you ask about.
- Google Contacts (read only): to look up a person's email address or phone number when you name them.
- Google Forms: to create a form when you ask, and to read the responses to a form you name (read only).
- YouTube (read only): to list your own channel's videos.
Google data is fetched when you ask for it and used to answer that request. To write the reply, the relevant part may be sent to the AI model answering you (see AI processing); it is kept in your chat or Space only where the answer includes it. We do not sell Google user data, use it for advertising, or use it to develop, improve or train generalised AI or machine-learning models. People at Loomrail do not read it unless you ask us to (for support), it is needed for security, or the law requires it.
Loomrail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting Google in Customize → Integrations deletes the stored access token. You can also remove Loomrail's access at any time at myaccount.google.com/permissions.
5. Microsoft user data
If you connect Microsoft 365 or Teams & SharePoint, Loomrail uses that access only when you ask an agent to: search and read your Outlook mail, save drafts, and send email or calendar invitations only after you approve the exact message; read your calendar and create events; search, read and save files in OneDrive and SharePoint (including Excel workbooks); manage your Microsoft To Do tasks; and post a Teams channel message only after you approve it. The same rules as for Google data apply: fetched on request, never sold, never used for advertising or to train AI models, and deleted from our systems when you disconnect. You can also remove access at myapps.microsoft.com (work accounts) or account.live.com/consent/Manage (personal accounts).
6. If you use Loomrail through a company
If you join a company on Loomrail (by invitation, automatically because your email address is on the company's verified domain, or because the company's directory added you), that company is responsible for the data in your account as part of its work, and we process it for the company under our Data Processing Agreement.
The company's admins can: see an activity log of your account — sign-ins, apps connected, messages an agent sent, and security and policy changes — but not the content of your chats; choose how long chats are kept; choose which AI models and apps you can use and what is hidden from AI models; require single sign-on or two-factor sign-in; remove you from the company; and delete your account if it's on their verified email domain. The company's activity log is kept for 3 years.
7. Who processes your data, and where
Your account data, chats and files are stored on Google Cloud and Neon (database) servers in Singapore, with short-lived cache and rate-limit data on Upstash in Japan. To run the service, the relevant data is also processed by: AI model providers that answer your messages and make images, video and music you ask for (such as OpenAI, Anthropic and Google, mostly through Vercel's AI Gateway), mostly in the United States; public search services that receive the words of a web search you ask for; our payment provider (currently Dodo Payments); and our email provider for account emails. Each receives only what its job needs, under its own terms, and none may use it for its own purposes. The full list is on the Sub-processors page. We transfer data outside India only to countries the Government of India has not restricted.
8. Children and people you add
You must be 13 or older to create a Loomrail account. We ask for your date of birth when you sign up (or first agree to these terms) and use it only to check your age; we never keep the date itself. If we learn an account belongs to someone under 13, we close it at once and delete it and its data after 30 days, which leaves time to correct a mistyped date through support. To stop repeat attempts, we keep a one-way scrambled form of that email address for 30 days.
If you're 13 to 17, you give us a parent or guardian's email and your account opens once they approve it. Until then we hold only what's needed to ask them: your name, email and sign-in. We keep their email, their name, when they decided, and the date you turn 18 (so teen settings end on time); these are deleted when you turn 18 or the account is deleted. They confirm their own age with a date of birth we don't keep.
Teen accounts get age-appropriate AI replies, no ads, no marketing email, and no tracking or profiling for advertising, and can't make purchases themselves (a parent can buy a plan for them and gets the receipt). A parent can withdraw permission at any time from the link in our email, and can ask to see, correct or delete their teen's data by writing to support@loomrail.com from that email address. An account that isn't approved within 30 days, or stays withdrawn for 30 days, is deleted with its data.
A school, college, employer or recruiter can send someone a test through Examiner, or add a candidate in Recruiter, without that person having an account. The organisation is responsible for having a lawful reason and the person's consent — for a student under 18, a parent or guardian's consent — and Loomrail processes that data on the organisation's instructions. Test-integrity signals (such as leaving the test page) are recorded only for tests an organisation runs, and only to show that organisation.
9. Cookies and tracking
Loomrail doesn't set tracking or advertising cookies. Signing in stores a session token in your browser's local storage — that's the only thing your browser keeps for us.
10. Data retention and deletion
We keep your agents, chats, memories, and skills until you delete them or close your account. Removing a memory, skill, or integration from Settings deletes it immediately; disconnecting an integration deletes the stored key. Closing your account (Settings → Account) deletes your account, its data and the files you uploaded.
We keep a few things longer where the law requires it: payment and invoice records for as long as tax law requires, and security and access logs for at least one year. If you're in a company, its admins may set a shorter period for chats, and its activity log is kept for 3 years.
11. Security
Passwords are stored as salted hashes, never in plain text. Integration keys and tokens are encrypted at rest (AES-256), all traffic is encrypted in transit (HTTPS), and access to your data requires a valid sign-in. You can turn on two-factor sign-in (a code from an authenticator app) in Settings → Security, and sign out of every device from there. Actions by Loomrail staff on accounts are logged.
If a breach affects your personal data, we will tell you and the Data Protection Board of India without delay — what happened, what it means for you, and what we're doing about it.
12. Your rights
Under the DPDP Act you can:
- See your data — download it from Settings → Account → Export, or ask us for a summary of what we hold and who we've shared it with.
- Correct or update it — edit it in the app, or ask us.
- Delete it — delete individual items, or close your account.
- Withdraw consent — disconnect an integration, or close your account. This is as easy as giving consent was; it doesn't affect what was done before.
- Nominate someone to exercise these rights for you if you die or can't act.
- Complain — to us first (below); we reply within 90 days. If you're not satisfied, you can complain to the Data Protection Board of India.
13. Contact and grievance officer
For any question, request or complaint about your personal data, write to our Grievance Officer, Tikeswar Sahoo, at grievance@loomrail.com. We'll confirm we received it and reply within 90 days. For anything else, reach us at support@loomrail.com.
If this policy changes in a way that matters, we'll ask you to agree to the new version the next time you use Loomrail.