Privacy Policy

How AgentLoom collects, uses, protects, and shares information — including data accessed from connected Google, GitHub, and cloud accounts.
Last updated: July 14, 2026

Overview

AgentLoom (“AgentLoom,” “we,” “us”) provides an orchestration platform that runs AI coding agents against software repositories you connect. This Privacy Policy explains what information we collect when you use the AgentLoom website, dashboard, and API, how we use it, the limited circumstances in which we share it, and the choices you have.
It applies to agent-loom.com and the authenticated AgentLoom application. It does not cover third-party services you connect (such as GitHub, Google Cloud, or Anthropic), which are governed by their own privacy policies.

Information we collect

We collect only what we need to operate the service:
Account information: your name and email address, obtained when you sign up or sign in with email, GitHub, or Google.
Workspace and repository data: the organizations, repositories, issues, and pull requests you connect, and the run configuration and outputs AgentLoom produces on your behalf.
Connected-cloud data: read-only diagnostic data from a cloud account you explicitly connect (Google Cloud or Microsoft Azure; see the connected-cloud sections below).
Billing information: plan selection and subscription status. Payment card details are handled by our payment processor and are never stored on AgentLoom servers.
Technical and usage data: log entries, IP address, device and browser information, and product interactions used to operate, secure, and improve the service.

How we use information

We use the information above to:
Provide, maintain, and operate the AgentLoom service, including running agents against your connected repositories.
Surface diagnostics, run status, and logs so you can supervise and steer agent work.
Authenticate you, secure your account, and prevent abuse.
Process subscriptions and provide support.
Improve reliability and product quality, and comply with legal obligations.

Google user data and Limited Use

If you connect a Google Cloud account to AgentLoom for cloud diagnostics, you grant the read-only scope https://www.googleapis.com/auth/cloud-platform.read-only. AgentLoom uses this scope solely to read diagnostic information — such as Cloud Logging entries and Cloud Run service metadata — so we can surface the status and failure details of your runs back to you. The effective ceiling on what AgentLoom can read is your own IAM permissions on the connected account.
We do not use this access to create, modify, or delete any resource, and we do not use Google user data for advertising or to train generalized AI models. Access tokens and refresh tokens for connected accounts are stored encrypted using envelope encryption backed by a cloud key-management service, and you can disconnect the account at any time to revoke access.
AgentLoom's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft Entra ID and Azure data

If you connect a Microsoft Azure account to AgentLoom for cloud diagnostics, you sign in with Microsoft Entra ID and grant delegated access to Azure Resource Manager (https://management.azure.com/user_impersonation) and Azure Monitor Log Analytics (https://api.loganalytics.io/Data.Read). AgentLoom uses this access solely to read diagnostic information — resource and service metadata and log-query results — so we can surface the status and failure details of your runs back to you. The effective ceiling on what AgentLoom can read is your own Azure role-based access control (RBAC).
As with other connected accounts, we do not use this access to create, modify, or delete any resource, and we do not use the data for advertising or to train generalized AI models. Access tokens and refresh tokens for connected accounts are stored encrypted using envelope encryption backed by a cloud key-management service, and you can disconnect the account at any time to revoke access.

How we share information

We do not sell your personal information. We share information only as needed to run the service, and only with providers bound to protect it:
Infrastructure: Google Cloud Platform, where the service and your data are hosted.
Payments: our payment processor (Stripe), which handles subscription billing.
AI model provider: the model provider you configure under your own key (for example, Anthropic). Under bring-your-own-key billing, that provider bills you directly and processes prompts and outputs under its own terms.
Legal and safety: when required by law, or to protect the rights, safety, and security of AgentLoom, our users, or the public.
Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.

Data retention and deletion

We retain information for as long as your account is active or as needed to provide the service, then delete or de-identify it within a reasonable period unless a longer retention is required by law. Run artifacts and logs are retained on a rolling window and expire automatically. You can request deletion of your account and associated data by contacting us.

Data security

We apply industry-standard safeguards: encryption in transit, encryption at rest for stored secrets and connector tokens via a cloud key-management service, scoped access to connected systems, isolated execution environments for agent runs, and audit logging. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address issues that arise.

Your rights and choices

Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can disconnect any connected account at any time from the dashboard, which revokes AgentLoom's ongoing access. To exercise other rights, contact us using the details below.

International data transfers

AgentLoom operates on cloud infrastructure that may process data in regions other than your own. Where we transfer personal information across borders, we rely on appropriate safeguards consistent with applicable law.

Children's privacy

AgentLoom is a tool for software teams and is not directed to children under 16. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice.

Contact us

Questions about this policy or your data can be sent to privacy@agent-loom.com, or through the contact form at agent-loom.com/contact.