Privacy Policy
How AgentLoom collects, uses, protects, and shares information — including data accessed from connected Google, GitHub, and cloud accounts.
Last updated: July 14, 2026
Overview
AgentLoom (“AgentLoom,” “we,” “us”) provides an orchestration platform that runs AI coding agents against software repositories you connect. This Privacy Policy explains what information we collect when you use the AgentLoom website, dashboard, and API, how we use it, the limited circumstances in which we share it, and the choices you have.
It applies to agent-loom.com and the authenticated AgentLoom application. It does not cover third-party services you connect (such as GitHub, Google Cloud, or Anthropic), which are governed by their own privacy policies.
Information we collect
We collect only what we need to operate the service:
•
Account information: your name and email address, obtained when you sign up or sign in with email, GitHub, or Google.
•
Workspace and repository data: the organizations, repositories, issues, and pull requests you connect, and the run configuration and outputs AgentLoom produces on your behalf.
•
Connected-cloud data: read-only diagnostic data from a cloud account you explicitly connect (Google Cloud or Microsoft Azure; see the connected-cloud sections below).
•
Billing information: plan selection and subscription status. Payment card details are handled by our payment processor and are never stored on AgentLoom servers.
•
Technical and usage data: log entries, IP address, device and browser information, and product interactions used to operate, secure, and improve the service.
How we use information
We use the information above to:
•
Provide, maintain, and operate the AgentLoom service, including running agents against your connected repositories.
•
Surface diagnostics, run status, and logs so you can supervise and steer agent work.
•
Authenticate you, secure your account, and prevent abuse.
•
Process subscriptions and provide support.
•
Improve reliability and product quality, and comply with legal obligations.
Google user data and Limited Use
If you connect a Google Cloud account to AgentLoom for cloud diagnostics, you grant the read-only scope https://www.googleapis.com/auth/cloud-platform.read-only. AgentLoom uses this scope solely to read diagnostic information — such as Cloud Logging entries and Cloud Run service metadata — so we can surface the status and failure details of your runs back to you. The effective ceiling on what AgentLoom can read is your own IAM permissions on the connected account.
We do not use this access to create, modify, or delete any resource, and we do not use Google user data for advertising or to train generalized AI models. Access tokens and refresh tokens for connected accounts are stored encrypted using envelope encryption backed by a cloud key-management service, and you can disconnect the account at any time to revoke access.
AgentLoom's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft Entra ID and Azure data
If you connect a Microsoft Azure account to AgentLoom for cloud diagnostics, you sign in with Microsoft Entra ID and grant delegated access to Azure Resource Manager (https://management.azure.com/user_impersonation) and Azure Monitor Log Analytics (https://api.loganalytics.io/Data.Read). AgentLoom uses this access solely to read diagnostic information — resource and service metadata and log-query results — so we can surface the status and failure details of your runs back to you. The effective ceiling on what AgentLoom can read is your own Azure role-based access control (RBAC).
As with other connected accounts, we do not use this access to create, modify, or delete any resource, and we do not use the data for advertising or to train generalized AI models. Access tokens and refresh tokens for connected accounts are stored encrypted using envelope encryption backed by a cloud key-management service, and you can disconnect the account at any time to revoke access.
Data retention and deletion
We retain information for as long as your account is active or as needed to provide the service, then delete or de-identify it within a reasonable period unless a longer retention is required by law. Run artifacts and logs are retained on a rolling window and expire automatically. You can request deletion of your account and associated data by contacting us.
Data security
We apply industry-standard safeguards: encryption in transit, encryption at rest for stored secrets and connector tokens via a cloud key-management service, scoped access to connected systems, isolated execution environments for agent runs, and audit logging. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address issues that arise.
Your rights and choices
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can disconnect any connected account at any time from the dashboard, which revokes AgentLoom's ongoing access. To exercise other rights, contact us using the details below.
International data transfers
AgentLoom operates on cloud infrastructure that may process data in regions other than your own. Where we transfer personal information across borders, we rely on appropriate safeguards consistent with applicable law.
Children's privacy
AgentLoom is a tool for software teams and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice.
Contact us
Questions about this policy or your data can be sent to privacy@agent-loom.com, or through the contact form at agent-loom.com/contact.