← Back to LionLoop

Privacy Policy

Last updated August 27, 2026

Plain-English summary

LionLoop is an AI personal assistant that holds the things in your head — captures, calendar context, and reminders — and helps you act on them. To do that, we store the text you type, the calendar data you choose to connect, and the small amount of account info needed to keep you signed in. We do not sell your data, share it with advertisers, or train any model on your content. Your captures and calendar data are yours; you can export them and delete them at any time.

What we collect

  • Account information. Your email address, collected via Google Sign-In or a magic-link email. If you sign in with Google, we also receive your name and profile photo, used only to display your account inside the app. Used to authenticate you and contact you if needed (rare; we don't send marketing email).
  • Captures. Every note, task, event, and list you save through the capture box. Stored as text in our database, indexed for search and AI classification.
  • Calendar data. When you connect Google Calendar, we sync events (title, time, location, attendees, description) into our database every 15 minutes. This is opt-in; disconnect any time in Settings.
  • OAuth tokens. Encrypted at rest with AES-256-GCM (the encryption key is held outside the database, so a database leak alone wouldn't expose your calendar). Used solely to keep your calendar sync alive.
  • Voice transcripts. When you tap the mic button, audio streams directly from your browser to AssemblyAI for real-time transcription. The audio is not stored. The resulting text is saved as a normal capture.
  • Home and work addresses. Optional. Used to compute drive-time estimates and route planning. Stored as coordinates plus the formatted address you saved.
  • Browser geolocation. Used in three bounded cases: when you tap “Where I am now” in the day planner (the fix is dropped after route calculation); when a capture names your current location as its starting point (that one origin is stored like a typed address); and for the small in-app weather only after you have already granted location access. Weather never asks for permission and never polls while the app is hidden. LionLoop never continuously tracks where you go. See “Location data” below for each contract.
  • Push subscription endpoints. If you opt into push notifications, the browser-generated subscription token is stored so we can send notifications. Tokens are device-specific; revoke any time via your browser's site permissions or by disabling push in Settings.
  • Settings and preferences. Timezone, theme, home and work addresses, any temporary Holiday Mode address and date range you choose, reminder preferences, plan tier, opt-in flags. Stored per user; not shared.
  • Operational logs. We log when LLM and Maps API calls happen (per-user counts, model, timestamp, cost in cents) for budget tracking. These logs do not contain the content of your captures or location coordinates.
  • Classification reliability metadata. When you explicitly change the type of a newly classified capture, we may store the previous and corrected type, timing, and a one-way cryptographic fingerprint scoped to your account and that capture. For explicitly typed captures, we may also store whether a conservative deterministic prediction was eligible, whether it agreed with the production classifier, and the names—not values—of fields that differed. These records never contain your capture text, title, checklist items, entity or place names, addresses, coordinates, prompts, or model output. They are purged daily once they are more than 90 days old. A deleted capture remains recoverable for 30 days; its linked records are removed on the next daily permanent purge after that window. Deleting your account also removes them. During manual reliability review, an allowlisted LionLoop administrator may compare a correction candidate with the current live capture. The capture is read from its existing record for that review and is not copied into the reliability metadata or used to train a model.

How we use your data

  • To run the product: rendering your homepage, classifying captures with AI, generating the morning brief, planning errand routes, sending push reminders.
  • To improve reliability: aggregate counts of API calls and error rates, plus the content-free structural correction and comparison metadata described above. We do not copy individual capture content into these reliability records.
  • To respond if you reach out for support.

We do not sell your data, share it with advertisers, train any AI model on your captures, or use your data to target ads. LionLoop has no ads and no third-party analytics SDKs.

Sub-processors — who else sees your data

Running LionLoop requires a handful of trusted services. Each is named below with the specific data type it sees.

  • Supabase (database, authentication, file storage). Holds your captures, calendar mirror, encrypted OAuth tokens, and account info. US-region.
  • Vercel (web hosting, serverless functions). Runs the LionLoop app code. Processes request data in transit; does not persist captures.
  • Anthropic (Claude AI). Receives the text of individual captures to classify them (extract dates, places, entities), generate your morning brief, propose time slots, and clean voice transcripts. Anthropic's API policy: data is not used for training.
  • Google (Calendar API, Maps Routes API, Places API, OAuth). Calendar data is read only, with your explicit OAuth grant — LionLoop never creates, edits or deletes Google Calendar events. Place names and addresses flow to Places for resolution. Lat/lng pairs flow to Routes for drive-time calculations.
  • AssemblyAI (real-time speech-to-text). Receives streaming audio when you use the mic button. Returns transcribed text. Audio is not stored beyond the streaming session.
  • Open-Meteo (weather conditions and forecast). Receives your date-effective saved base coordinates (your temporary Holiday Mode address while active, otherwise Home) for scheduled and render-time morning-brief forecasts, eligible real-time Event-card context, and the legacy capture-assistance weather path when explicitly invoked. The weather shown in the app (the current greeting-row chip and empty-day forecast line) instead sends your approximate current location — rounded to about a kilometre — when you've already allowed location access, and those saved base coordinates otherwise; see “Location data” below for the full contract. If you explicitly tap Check weather on a planned event, it instead receives the selected event destination's coordinates and the event date (up to seven days ahead). LionLoop does not send your capture text or account identity to Open-Meteo. LionLoop modifies the returned data by rounding temperatures, translating provider weather codes, summarising daily and hourly conditions, and sometimes generating contextual guidance from that weather. Product weather displays are limited to the weather itself rather than adjacent provider credit; generated brief/card text does not yet preserve sentence-level weather provenance. This Privacy Policy is the app-level provider and licence disclosure. Open-Meteo supplies LionLoop's weather conditions and forecasts under CC BY 4.0. The rounding, translation, summarisation, and generated guidance described above are LionLoop's adaptations. Open-Meteo's public-service terms say technical server logs may include an IP address and the requested coordinates and may be kept for up to 90 days; see their terms.
  • Web Push services (FCM for Chrome, APNs for Safari, Mozilla Push for Firefox). Routes push notifications to your device. Sees the notification payload (title + body) but not your account.

Google user data and Limited Use

LionLoop's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: LionLoop reads your Google Calendar to show you your schedule and help you prepare for it. Calendar data may be sent to our AI sub-processor (Anthropic) to produce features such as your morning brief. That is inference only — it generates a result for you, in that moment.

We do not use, transfer or sell raw or derived Google user data to create, train or improve any generalised or foundational artificial-intelligence or machine-learning model, whether our own or anyone else's. Anthropic does not train on data submitted through its API.

No human reads your Google user data except where you explicitly ask us to (for example, to investigate a support issue you raised), where it is necessary for security purposes such as investigating abuse, or where we are required to by law.

Location data — explicit contract

LionLoop treats location data more carefully than the rest because getting this wrong destroys trust. Here is exactly what happens:

  • Location reminders (geofences). If you turn on location reminders in the app, LionLoop registers geofences — the coordinates of places tied to your captures — with your device's operating system, which requires background- location permission. Your device monitors your location and notifies LionLoop only when you arrive at or leave one of those specific saved places. LionLoop never receives or stores your continuous location and never tracks where you go in the background — only the arrival/departure event for a place you saved. Revoke background-location permission any time in your device settings; reminders simply stop firing. (In the browser, with no native geofencing, location is used only when you tap “Where I am now” in the day planner.)
  • No persistence in the planner. When you tap “Where I am now,” your coordinates pass through the route calculation and are then discarded. They are not written to our database, not written to any log, and not retained in any form.
  • Weather at your location. The small weather shown in the app (the greeting-row chip and the empty-day forecast line) uses your device's location only when you have already granted location permission — the weather itself never asks for it. When permission exists, a foreground fix is rounded to roughly a kilometre before it leaves your device and used only for that weather request. Current conditions may refresh about every 30 minutes while the app stays visible and are rechecked when you return after the cache has expired; there is no hidden/background weather polling. LionLoop discards every weather fix and does not store or log it. Open-Meteo may retain provider-side request logs as described above. Without permission (or if a fix fails), the weather quietly falls back to your date-effective saved base address (Holiday Mode while active, otherwise Home).
  • “Leaving from here” captures.When a capture explicitly names your current location as its starting point — you type “from here” or pick “Here” on the capture's origin chip — a single location fix is taken at that moment and stored on that one capture as its journey origin, the same way a typed street address would be. It is one snapshot, not a track: LionLoop never follows your movements. Change or remove it any time via the capture's origin chip or by editing the capture; deleting the capture deletes the coordinates with it. If you set your default starting point to “my current location” in Settings, the same single-fix contract applies to captures for the current day that don’t name a starting point — one snapshot per capture, stored on that capture, never a track. That behaviour is off unless you switch it on, and switching back to “home” stops it immediately.
  • One request out. The coordinates are sent once to Google's Routes API as the origin point for the matrix calculation. Google sees that single request.
  • Permission revocable any time. Use your browser or device settings to revoke geolocation permission for LionLoop. The day-planner falls back gracefully to your date-effective saved base or work address.
  • Saved addresses are different. Your home and work addresses, plus any temporary Holiday Mode address and date range you enter in Settings, are stored as coordinates so they can serve as route origins without repeatedly asking for location permission. Holiday Mode stops affecting behavior after its end date; end or replace it from Settings at any time.

Encryption and security

  • All traffic is HTTPS / TLS. There is no insecure transport path.
  • Calendar OAuth tokens are encrypted at rest with AES-256-GCM using a master key held outside the database. A database leak alone does not expose your calendar access.
  • Row-Level Security on the database limits every read and write to the authenticated user's own data. Service- role bypass is used only for system tasks (cron jobs, scheduled syncs), never for user-initiated requests.
  • Authentication tokens use Supabase's standard JWT- cookie flow. Sign out from Settings to invalidate the current session.

Cookies and local storage

LionLoop uses only the cookies and browser storage it needs to run — to keep you signed in and to secure the account- connection flows. There are no advertising, analytics, or cross-site tracking cookies, which is why you won't see a cookie-consent banner: there is nothing non-essential to opt out of.

  • Session cookies (authentication). Set when you sign in, to keep you signed in. They are HttpOnly and Secure — unreadable by page scripts and only ever sent over HTTPS. Cleared when you sign out from Settings.
  • Connection-security cookie. A short-lived (10-minute) cookie set only while you connect Google or Microsoft Calendar or Gmail, to protect that hand-off against cross-site request forgery. It is deleted the moment the connection completes.
  • Local storage on your device. A few small preferences are kept in your browser and never sent to us — whether you've dismissed the “enable notifications” banner, and a couple of admin-dashboard view toggles. LionLoop also keeps a small, account-scoped capture outbox so a capture can be retried after a connection or response failure. That outbox contains the submitted string fields, including the raw capture text, but never attachments; it is capped at 50 entries and seven days. It is sent to LionLoop only when replaying that capture, and is removed after the capture is accepted, when it expires, when you sign out, when you delete your account, or when invalid stored data is found. Clearing your browser data removes all local storage.
  • Codes saved on your device. When you choose Scan for codes, LionLoop checks the original photo or PDF on your device without an AI call. Verified QR/barcode images and complete no-code results can be saved in your browser, scoped to your account and original files, so reopening does not rescan. This cache holds up to 60 scans and 24 MiB in total, with an 8 MiB limit per scan; older scans are removed to make room. Signing out, deleting your account or clearing browser data removes it. Your browser may also clear it. These saved copies are not uploaded or synchronized to other devices. If storage is unavailable, codes remain available for the current visit.

We use no third-party advertising or analytics cookies — no Google Analytics, no advertising pixels, no cross-site trackers. Our error-monitoring tool (Sentry) is configured to not record session replays and not capture your IP address. If we ever introduce analytics, we will update this page and add a consent control for visitors in regions that require one.

Data retention

We keep your data as long as your account is active. When you delete your account or specific captures:

  • Captures are soft-deleted first, then hard-deleted within 30 days. Anything referencing the capture (entities, push history, plan history) is deleted via cascading foreign keys.
  • Disconnecting Google Calendar revokes the OAuth token with Google and deletes the encrypted token from our database. Synced calendar event mirrors are deleted on the next sync tick.
  • Delete your account any time from Settings (or email privacy@lionloop.ai with subject “Delete my account”). This removes all your data within 7 days, subject only to the rolling 30-day backup retention windows maintained by Supabase and Vercel for disaster recovery. Backup retention is configured at the sub-processor level and is not user-tunable.

Your rights

  • Access. Everything LionLoop knows about you is visible in the app. You can read every capture, every setting, every connected service from Settings.
  • Export. Email us for a JSON export of your captures, settings, and calendar mirror.
  • Correction. Edit any capture in place. Edit settings any time.
  • Deletion. Delete individual captures from the homepage. Delete your entire account from Settings, or by emailing us.
  • Portability. Captures export as JSON; calendar data is already in your Google Calendar (we are a mirror, not the source of truth).

Residents of the EU, UK, California, and other jurisdictions with specific data-protection rights have those rights with respect to LionLoop. Email us to exercise them; we respond within 30 days.

Children

LionLoop is not intended for users under 16 and we do not knowingly collect data from anyone under 16. If you believe a child has provided data to LionLoop, email us and we will delete it.

Changes to this policy

We will update this page when our practices change in material ways (a new sub-processor, a new data category collected, a change in retention). The “Last updated” date at the top reflects the most recent revision. If a change affects how we handle data you have already provided, we will email you before it takes effect.

Contact

For privacy questions, data requests, or account deletion, email privacy@lionloop.ai.

Privacy · LionLoop