Skip to main content
Privacy
DocumentsPricingAboutBlogSupport
Open workspace

Privacy Policy

Privacy for soloop workspaces.

What we store, when agents touch it, when third-party tools see it, and how to delete it.

Last updatedLast updated: July 19, 2026

Product stateLive beta workspace for solo founders.

Core boundaryPlanning uses context. External action needs approval.

  • soloop reads the workspace context you put there: chats, project docs, files, tasks, approvals, and market signals.
  • Agents can plan, research, draft social work, or run coding tasks. Posting, repo access, deployment, and account actions stay behind product controls.
  • Twitter/X and Reddit refresh tokens are stored encrypted. GitHub installation tokens are generated only when needed.
  • We do not sell personal data. We do not use workspace content to train a general soloop model.

Sections

What soloop doesData we collectHow our agents use dataAI trainingOAuth and connected accountsWhen we share dataCookies and logsSecurityRetention and deletionYour choices and rightsChildrenChangesContact

What soloop does

soloop is a workbench for solo founders. You bring an idea, URL, repo, deck, or file. soloop keeps the project thread, proposes the next move, runs approved research, prepares approved Twitter/X work, runs approved coding tasks, and records the signals that come back.

Project memory is the point. Chats, docs, tasks, approvals, signals, and execution records let the agents see the same history you see.

The product is still in beta. Features, integrations, pricing, data flows, and retention rules can change as we tighten the product.

Data we collect

We collect the records that make the workspace work: what you type, what you upload, what soloop creates, what connected services return, and server records for login, security, and debugging.

Do not upload secrets, private keys, production credentials, regulated data, private customer records, health data, financial account data, or sensitive personal data unless you have the right to use it here and have decided soloop is the right place for it.

Account

Email, name, authentication provider, login metadata, billing plan, credit balance, and account timestamps.

Project

Project name, product description, URLs, repo URL, onboarding doc draft, generated app records, and project status.

Files

Uploaded decks, PDFs, ZIPs, source files, filenames, file size, MIME type, hashes, extracted text, storage paths, and vector-search IDs.

Chats and tasks

Messages, conversation titles, TODO cards, approvals, edits, task status, agent output, acceptance criteria, logs, sandbox IDs, and deployment URLs.

Connected accounts

Provider name, external username, external email, scopes, status, token expiry, encrypted refresh-token fields, OAuth state, GitHub installation metadata, and Stripe account metadata.

Signals

Twitter/X or other approved-source URLs, comments, author handles, public feedback, LLM analysis, qualified-user records, and notifications.

How our agents use data

Agents use project context for the task in front of them. That context can include recent messages, project docs, approved TODOs, files, account status, signals, and prior results.

Analysis and outside action are separate. A task that can publish, deploy, spend credits, use a connected account, or change code goes through the product flow built for that action.

Plan Agent

Uses the project doc, recent messages, task state, signals, and connected-account status to suggest one next move.

It does not post, deploy, send messages, refresh tokens, or write to external services.

Analyst

Runs approved desk research against public sources, then writes findings, reports, and signals back to the workspace.

It uses private connected accounts only when the feature clearly asks for that access.

Social Agent

The active publishing flow is Twitter/X: drafts, posts, replies, media handling, quota checks, and comment monitoring.

No post or reply goes out without a connected account and the visible product flow.

Coding Agent

Works from the approved brief, project files, repo context, sandbox logs, test output, and deployment status.

Review code, logs, deployment changes, and data manifests before shipping them to users.

AI training

soloop does not use workspace content, uploaded files, connected-account content, generated code, or signals to train a general soloop model.

When a task uses an AI model, we send the prompt plus relevant context to model or routing providers such as OpenAI-compatible providers, TokenRouter, Anthropic, or other providers used by the product.

Those providers return output and keep the abuse, safety, debug, or billing records their own policies, contracts, and retention settings allow.

AI output can be wrong, incomplete, outdated, duplicated, insecure, or unsuitable for your use. You are responsible for reviewing output before publishing, deploying, sending, or relying on it.

OAuth and connected accounts

If you connect Twitter/X, Reddit, GitHub, Stripe, or another service, we store account metadata to show status and run the feature you chose.

Where refresh tokens are needed, soloop stores them encrypted with AES-256-GCM fields. OAuth state records finish authorization flows and resume the pending task.

GitHub App installation records store installation metadata. Short-lived GitHub installation access tokens are generated on demand and are not persisted.

Stripe Connect account links are temporary and created on demand. soloop stores connected-account metadata such as Stripe account ID, country, currency, charges status, payouts status, requirements, and email when Stripe returns it.

Stripe processes subscription billing, taxes, invoices, payment methods, and customer records on its hosted payment surfaces. We do not receive or store full card numbers or CVC.

You can revoke a connected account in the external service. You can also ask us to disconnect or delete the related soloop records.

When we share data

We share data with the services that make soloop run: hosting, database, authentication, file storage, AI inference, model routing, sandbox execution, deployment, billing, public research, email, security, and support.

soloop runs on tools such as Supabase, OpenAI-compatible model providers, TokenRouter, Anthropic, Vercel Sandbox, Stripe, X/Twitter, Reddit, GitHub, Apify, hosting providers, and email providers.

When you approve or use a third-party integration, that service's own terms and privacy policy apply to the data sent there.

We can disclose data if law requires it, if we need to protect rights and safety, if we investigate abuse, if we enforce product terms, or if the company is involved in a merger, financing, acquisition, restructuring, or asset sale.

We do not sell personal data. We do not use personal data for third-party interest-based advertising in the product.

Cookies and logs

soloop uses cookies and similar browser storage for login, session refresh, security, and product state.

Servers and providers collect IP address, user agent, request path, timestamps, errors, performance data, and diagnostics to keep the service working, detect abuse, and debug failures.

If we add analytics or marketing cookies later, we will update this policy and expose the controls required by law.

Security

soloop uses account ownership checks, server-side authorization, encrypted refresh-token storage, scoped OAuth flows, short-lived authorization state, sandboxed coding execution, provider access controls, and operational logs.

No internet service is perfectly secure. Do not put production secrets, private keys, customer databases, or regulated data into soloop unless you have decided the risk is acceptable.

If you believe your account, token, repo access, Stripe account, or workspace has been exposed, contact us quickly and revoke the affected external connection where possible.

Retention and deletion

We keep account records while your account exists. We keep project records while the project is active, unless product behavior or law calls for a shorter period.

Project deletion can remove or queue cleanup for project documents, storage objects, conversations, messages, TODOs, measure tasks, coding tasks, signals, notifications, and OpenAI vector-store references tied to that project.

Some records can remain longer for security, fraud prevention, billing, accounting, legal obligations, disputes, abuse review, backups, debugging, or product operation.

Backups and provider records do not always disappear instantly. Deletion can take time to finish across every system.

When we no longer need retained personal data, we delete it or anonymize it so it can no longer reasonably identify you, subject to legal and operational limits.

Your choices and rights

You can choose what to upload, what to connect, what to approve, and what to publish or deploy.

Your location can give you rights to access, correct, export, delete, restrict, or object to some processing of your personal data.

You can revoke external account access through the external service. Related soloop workflows can stop working until you reconnect.

You can ask us for account deletion, project deletion, data export, correction, or privacy review through the contact channel below.

Children

soloop is not for children. You must be at least 18 years old, or the age of majority where you live, to use the product.

If you believe a child provided personal data to soloop, contact us so we can review and delete it where required.

Changes

We update this Privacy Policy when the product, integrations, laws, or data flows change.

If a change materially affects you, we will give notice by posting the updated policy or using an in-product notice.

Contact

For privacy, security, deletion, export, or account-access requests, use the email link below.

Soloop, Inc. is responsible for this policy. Postal address: 6357 Joaquin Murieta Ave, Newark, CA 94560, United States. Email: [email protected].

[email protected]

Product

DocumentsPricing

Resources

CommunityBlog

Company

AboutContact

Support

Support

Legal

TermsPrivacyCookies