Looply

Privacy Policy

Effective Date: July 26, 2026

Company: Linkks LLC FZ

Address: Meydan Hotel, Dubai, UAE

Contact: hello@joinlooply.com

1. Introduction

Your privacy is critically important to us. This Privacy Policy explains how Linkks (also known as Looply) collects, uses, stores, and protects your personal information when you use our outreach automation and blog publishing services. This policy applies to all users of our web application, mobile applications, and related services.

2. Data We Collect

We collect the following categories of data:

  • Account Information: Email address, username, display name, and profile picture
  • Outreach Content: Campaign settings, sequencing preferences, and contact workflow data
  • Blog Content: Articles, pages, images, and publishing configurations
  • Analytics Data: Page views, clicks, anonymous visitor identifiers, session identifiers, user agents, referral sources, geographic country/city, and salted IP hashes for public page analytics. Page owners may also store normalized IP addresses they choose to exclude from future analytics tracking.
  • Technical Data: Session identifiers, device information, browser type, and IP addresses. For authenticated accounts, we may store your IP address and IP-derived country/currency to localize pricing and protect the service.
  • Third-Party Integration Data: Data from connected services like Google, Notion, Vercel, Webflow, WordPress, and Shopify

3. Google User Data

Looply uses Google Sign-In for authentication and offers an optional Gmail connection for campaign delivery, inbox synchronization, and replies. This section describes the complete Google Workspace data flow, the narrow purposes for which that data is used, and the controls that apply to it.

3.1 Google Data We Access

Depending on the Google feature you choose, Looply accesses:

  • Google Sign-In data: Your name, email address, stable Google account identifier, and profile picture
  • Gmail read-only data (gmail.readonly): Message content, headers, participants, timestamps, labels, thread identifiers, and attachment metadata needed to synchronize and display the connected mailbox
  • Gmail send permission (gmail.send): Used for campaign email only after the account owner confirms every current recipient affirmatively consented to receive email from the selected Google Workspace sender, and for user-authored replies from the connected Gmail account

Looply does not request Google Contacts or Other Contacts scopes and does not access Google Contacts data.

3.2 How We Use Google Data

We use Google user data exclusively to:

  • Authenticate your account and display your chosen profile information
  • Synchronize the connected Gmail mailbox into Looply's unified inbox
  • Display email conversations to the account owner and keep thread and unread state current
  • Send campaign email only to recipients covered by a current affirmative-consent attestation, and send user-authored replies from the connected Gmail account
  • Generate optional, user-visible reply-draft suggestions as described in Section 3.4

Connected Gmail OAuth accounts can be selected for campaign delivery only after the account owner confirms that every current recipient affirmatively consented to receive email from the selected Google Workspace sender. Looply records the confirmation against a fingerprint of the campaign's current recipient set. Adding, removing, reassigning, or changing a recipient invalidates the confirmation and blocks Gmail sending until the owner confirms it again. Looply prohibits spam and unsolicited commercial email through Google Workspace APIs. Other campaign transports have their own provider and legal requirements.

3.3 Google Data Storage

OAuth tokens, synchronized mailbox records, and reply metadata are stored in our production database on Supabase infrastructure with encryption in transit and at rest, access controls, and tenant-level Row Level Security. Tokens are available only to the backend services that perform the requested Gmail operation. We retain synchronized Gmail data while the mailbox or Looply account remains active and as otherwise described in Section 10. Account deletion removes associated active data within 30 days and backup copies are purged within 90 days.

3.4 AI Processing and Third-Party Service Providers

Looply does not use Google Workspace data to create, train, or improve any generalized, non-personalized, or foundational artificial intelligence or machine-learning model. We do not permit any third party to use Google Workspace data for that purpose.

  • OpenAI API Platform (paid commercial API): When the email reply-draft feature is available for a conversation, the relevant thread content and sender/recipient context may be sent to OpenAI solely to return user-visible draft suggestions. OpenAI states that API Platform business data is not used to train its models by default, and Looply does not opt in to model-training data sharing.
  • Anthropic commercial API (paid API): Used for separate Looply coworker features. Technical boundaries prevent Gmail and other Google Workspace mailbox content or snippets from entering Anthropic prompts.
  • Google Gemini Developer API (paid service): Used for separate content and image features. Gmail and other Google Workspace mailbox data is not sent to Gemini.
  • Supabase and Trigger.dev: Infrastructure processors used to securely store mailbox data and run campaign delivery, inbox synchronization, and reply workflows. They may process only the data necessary to provide those user-facing functions under our instructions.

We do not sell, rent, transfer, or disclose Google user data for advertising, data-broker, credit, surveillance, or third-party marketing purposes. Other disclosure occurs only when required by law or necessary to protect users and the service.

3.5 Google API Services User Data Policy and Limited Use

Looply's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3.6 Revoking Access and Deleting Google Data

You can disconnect Gmail in Looply to stop future mailbox access, revoke Looply's grant at any time from your Google Account Permissions page, and request deletion of synchronized Google data by contacting hello@joinlooply.com. Revoking a Gmail grant stops future access but does not itself delete your Looply account. Deleting the Looply account follows the deletion periods stated above.

4. Webflow User Data

Our application integrates with Webflow to enable publishing blog articles directly to your Webflow CMS. This section specifically describes how we access, use, store, and handle Webflow user data.

4.1 Webflow Data We Access

When you connect your Webflow account via OAuth, we request access to the following:

  • Sites (sites:read): View your Webflow sites to let you select which site to publish to
  • CMS Collections (cms:read): Read your CMS collection schemas to map article fields correctly
  • CMS Items (cms:write): Create and publish article items in your Webflow CMS
  • Assets (assets:write): Upload article images (featured images and inline images) to your Webflow Assets CDN

4.2 How We Use Webflow Data

We use Webflow user data exclusively for the following purposes:

  • Site Selection: Display your available Webflow sites so you can choose where to publish
  • Collection Mapping: Read your CMS collection structure to correctly map article content to your fields
  • Article Publishing: Create new CMS items containing your AI-generated or manually created articles
  • Image Uploads: Upload featured images and inline article images to your Webflow Assets

We do NOT modify or delete existing content in your Webflow CMS without your explicit action. All publishing actions are initiated only when you click "Publish" or enable auto-publish.

4.3 Webflow Data Storage

Webflow OAuth tokens are stored securely on our authentication server (Fly.io) with encryption at rest. Your Webflow site selection and CMS field mappings are stored in our database (Supabase). We do not store copies of your Webflow content - we only interact with it during publishing operations.

4.4 Webflow Data Sharing

We do not share your Webflow data with any third parties except Webflow's own API (to perform the publishing actions you request). Your Webflow credentials and content are never shared with advertisers, data brokers, or other external services.

4.5 Revoking Webflow Access

You can disconnect Webflow at any time from Looply's Blog Integration settings. You can also revoke access from Webflow's Settings → Apps & Integrations page. Revoking access will immediately stop all future publishing operations but will not delete articles already published to your Webflow site.

5. How We Use Your Data

We use the data we collect for the following purposes:

  • To provide, maintain, and improve our services
  • To authenticate your identity and manage your account
  • To display your campaign and blog content to authorized users and visitors
  • To provide analytics about your page performance
  • To communicate with you about your account and our services
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations

6. Data Storage and Security

Your data is stored on secure servers provided by Supabase (hosted on AWS infrastructure). We implement industry-standard security measures including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Row Level Security (RLS) policies to ensure data isolation between users
  • Regular security audits and vulnerability assessments
  • Secure authentication using OAuth 2.0 protocols
  • Limited employee access to production data on a need-to-know basis

7. Data Sharing and Third Parties

We may share your data with the following categories of third parties:

  • Service Providers: Cloud hosting and workflow processing (Supabase/AWS and Trigger.dev), payment processing (Stripe), email delivery, AI APIs as specifically limited in Section 3.4, and analytics services
  • Integration Partners: When you connect third-party services like Notion, Vercel, Webflow, WordPress, or Shopify, we share necessary data to enable those integrations
  • Legal Requirements: When required by law, subpoena, or other legal process
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

We do not sell your personal data to third parties for advertising or marketing purposes.

8. Third-Party Integrations

Our service integrates with various third-party platforms. When you connect these services, you are subject to their respective privacy policies:

  • Google: For authentication and the optional Gmail connection for campaign delivery, inbox synchronization, and replies described in Section 3
  • OpenAI: Paid commercial API for optional, user-visible email reply drafts and other product AI features
  • Anthropic: Paid commercial API for coworker features that do not receive Google Workspace mailbox data
  • Google Gemini: Paid API for content and image features that do not receive Google Workspace mailbox data
  • Apple: For Sign in with Apple authentication
  • Notion: For importing and syncing content from Notion workspaces
  • Vercel: For custom domain hosting and deployment
  • Webflow: For publishing articles to Webflow CMS
  • WordPress: For publishing articles to WordPress sites
  • Shopify: For publishing articles to Shopify blogs
  • Stripe: For payment processing and subscription management

9. Your Rights and Choices

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your account and associated data
  • Portability: Request your data in a machine-readable format
  • Objection: Object to certain processing of your data
  • Withdrawal: Withdraw consent for data processing where applicable

To exercise these rights, please contact us at hello@joinlooply.com.

10. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you services. When you delete your account:

  • Account data is permanently deleted within 30 days
  • Backup copies are purged within 90 days
  • Anonymized analytics data may be retained indefinitely
  • Legal records may be retained as required by law

11. Cookies and Tracking

We use cookies and similar technologies for authentication, preferences, and analytics. You can control cookie settings through your browser preferences. Essential cookies required for the service to function cannot be disabled.

12. Children's Privacy

Our services are not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

13. International Data Transfers

Your data may be transferred to and processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses and compliance with applicable data protection laws.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Effective Date" above. Your continued use of the service after changes constitutes acceptance of the updated policy.

15. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices:

Email: hello@joinlooply.com

Website: joinlooply.com

Address: Linkks LLC FZ, Meydan Hotel, Dubai, UAE

© 2026 Linkks LLC FZ. All rights reserved.