What soloop does
soloop is a workbench for solo founders. You bring an idea, URL, repo, deck, or file. soloop keeps the project thread, proposes the next move, runs approved research, prepares approved Twitter/X work, runs approved coding tasks, and records the signals that come back.
Project memory is the point. Chats, docs, tasks, approvals, signals, and execution records let the agents see the same history you see.
The product is still in beta. Features, integrations, pricing, data flows, and retention rules can change as we tighten the product.
Data we collect
We collect the records that make the workspace work: what you type, what you upload, what soloop creates, what connected services return, and server records for login, security, and debugging.
Do not upload secrets, private keys, production credentials, regulated data, private customer records, health data, financial account data, or sensitive personal data unless you have the right to use it here and have decided soloop is the right place for it.
Email, name, authentication provider, login metadata, billing plan, credit balance, and account timestamps.
Project name, product description, URLs, repo URL, onboarding doc draft, generated app records, and project status.
Uploaded decks, PDFs, ZIPs, source files, filenames, file size, MIME type, hashes, extracted text, storage paths, and vector-search IDs.
Messages, conversation titles, TODO cards, approvals, edits, task status, agent output, acceptance criteria, logs, sandbox IDs, and deployment URLs.
Provider name, external username, external email, scopes, status, token expiry, encrypted refresh-token fields, OAuth state, GitHub installation metadata, and Stripe account metadata.
Twitter/X or other approved-source URLs, comments, author handles, public feedback, LLM analysis, qualified-user records, and notifications.
How our agents use data
Agents use project context for the task in front of them. That context can include recent messages, project docs, approved TODOs, files, account status, signals, and prior results.
Analysis and outside action are separate. A task that can publish, deploy, spend credits, use a connected account, or change code goes through the product flow built for that action.
Plan Agent
Uses the project doc, recent messages, task state, signals, and connected-account status to suggest one next move.
It does not post, deploy, send messages, refresh tokens, or write to external services.
Analyst
Runs approved desk research against public sources, then writes findings, reports, and signals back to the workspace.
It uses private connected accounts only when the feature clearly asks for that access.
Social Agent
The active publishing flow is Twitter/X: drafts, posts, replies, media handling, quota checks, and comment monitoring.
No post or reply goes out without a connected account and the visible product flow.
Coding Agent
Works from the approved brief, project files, repo context, sandbox logs, test output, and deployment status.
Review code, logs, deployment changes, and data manifests before shipping them to users.
AI training
soloop does not use workspace content, uploaded files, connected-account content, generated code, or signals to train a general soloop model.
When a task uses an AI model, we send the prompt plus relevant context to model or routing providers such as OpenAI-compatible providers, TokenRouter, Anthropic, or other providers used by the product.
Those providers return output and keep the abuse, safety, debug, or billing records their own policies, contracts, and retention settings allow.
AI output can be wrong, incomplete, outdated, duplicated, insecure, or unsuitable for your use. You are responsible for reviewing output before publishing, deploying, sending, or relying on it.
OAuth and connected accounts
If you connect Twitter/X, Reddit, GitHub, Stripe, or another service, we store account metadata to show status and run the feature you chose.
Where refresh tokens are needed, soloop stores them encrypted with AES-256-GCM fields. OAuth state records finish authorization flows and resume the pending task.
GitHub App installation records store installation metadata. Short-lived GitHub installation access tokens are generated on demand and are not persisted.
Stripe Connect account links are temporary and created on demand. soloop stores connected-account metadata such as Stripe account ID, country, currency, charges status, payouts status, requirements, and email when Stripe returns it.
Stripe processes subscription billing, taxes, invoices, payment methods, and customer records on its hosted payment surfaces. We do not receive or store full card numbers or CVC.
You can revoke a connected account in the external service. You can also ask us to disconnect or delete the related soloop records.
Cookies and logs
soloop uses cookies and similar browser storage for login, session refresh, security, and product state.
Servers and providers collect IP address, user agent, request path, timestamps, errors, performance data, and diagnostics to keep the service working, detect abuse, and debug failures.
If we add analytics or marketing cookies later, we will update this policy and expose the controls required by law.
Security
soloop uses account ownership checks, server-side authorization, encrypted refresh-token storage, scoped OAuth flows, short-lived authorization state, sandboxed coding execution, provider access controls, and operational logs.
No internet service is perfectly secure. Do not put production secrets, private keys, customer databases, or regulated data into soloop unless you have decided the risk is acceptable.
If you believe your account, token, repo access, Stripe account, or workspace has been exposed, contact us quickly and revoke the affected external connection where possible.
Retention and deletion
We keep account records while your account exists. We keep project records while the project is active, unless product behavior or law calls for a shorter period.
Project deletion can remove or queue cleanup for project documents, storage objects, conversations, messages, TODOs, measure tasks, coding tasks, signals, notifications, and OpenAI vector-store references tied to that project.
Some records can remain longer for security, fraud prevention, billing, accounting, legal obligations, disputes, abuse review, backups, debugging, or product operation.
Backups and provider records do not always disappear instantly. Deletion can take time to finish across every system.
When we no longer need retained personal data, we delete it or anonymize it so it can no longer reasonably identify you, subject to legal and operational limits.
Your choices and rights
You can choose what to upload, what to connect, what to approve, and what to publish or deploy.
Your location can give you rights to access, correct, export, delete, restrict, or object to some processing of your personal data.
You can revoke external account access through the external service. Related soloop workflows can stop working until you reconnect.
You can ask us for account deletion, project deletion, data export, correction, or privacy review through the contact channel below.
Children
soloop is not for children. You must be at least 18 years old, or the age of majority where you live, to use the product.
If you believe a child provided personal data to soloop, contact us so we can review and delete it where required.
Changes
We update this Privacy Policy when the product, integrations, laws, or data flows change.
If a change materially affects you, we will give notice by posting the updated policy or using an in-product notice.
Contact
For privacy, security, deletion, export, or account-access requests, use the email link below.
Soloop, Inc. is responsible for this policy. Postal address: 6357 Joaquin Murieta Ave, Newark, CA 94560, United States. Email: [email protected].
[email protected]