DATA AND PRIVACY
Privacy
This notice describes the data processed by the loqy private beta, how it is used, and the controls available today.
Updated · July 16, 2026
Data processed
loqy processes the information required to provide access, operate workspaces, and support the service.
- Account: email, profile, language, and workspace memberships.
- Work: conversations, documents, files, projects, tools, and deliverables created in the product.
- Operations: bounded technical, usage, error, and administration events.
- Access request: email, name, organization, role, team size, use case, constraints, and consent.
Purposes
This data is used to provide the product, enforce access, run requested actions, secure the service, diagnose incidents, and answer requests.
Access request data is used only to qualify the progressive beta opening and contact its author.
Access and sharing
Conversations are private by default. Project and workspace access follows the roles and sharing configured in the product.
Platform administrators access only the surfaces required to operate the service, including the access request inbox and bounded logs.
Providers and models
The service currently relies on Supabase for data, authentication, and storage, Resend for email, OpenPanel for PII-free public events, and server infrastructure served behind Caddy.
Prompts and relevant files may be sent to the model provider selected by the workspace. BYOK keys are resolved for the workspace before an allowed platform fallback.
Retention and deletion
Access requests are intended to be retained for 90 days. Deletion removes the PII row; the requester-free audit event remains append-only.
Work data remains available while the related workspace or resource is retained. Technical periods may vary depending on the type of log or backup.
Cookies and preferences
Authentication cookies are required for private sessions. Language and theme use functional preferences. No targeted advertising is included.
Public events are limited to saas_agents_page_view and saas_agents_public_cta_click.
They include path and surface; clicks may also include href and label.
Tracking is disabled when a browser sends a GPC or DNT signal.
Your choices and contact
If you have an account, ask your workspace administrator to access, correct, or delete your data. Before an invitation, use the access form and reply to its receipt, which is routed to the operating team.
An access request can also be deleted from the Platform inbox by an authorized administrator.