Privacy Policy
Last updated: August 6, 2026
What we collect
Account data:your name, work email, and company details, provided when you sign up or book an audit. If you sign in with Google, Microsoft, or GitHub instead of a password, we receive your email address and that provider's own account identifier for you, and store both so we recognise you next time. We never see your password, we ask for no access to your mail, files, or repositories, and the access token is used once to read your email address and then discarded — we do not keep it. Business data:CSV exports you choose to upload — leads, calls, quotes, jobs, and invoices. These are your business records and can contain your customers' names and contact details; we use them solely to compute your metrics, findings, and reports, and we never contact your customers. Nothing connects to your systems today — we read only the files you upload, and we cannot write to any system you use. See Security for how uploads are protected. Grader data: when you run the free revenue grader, we store the answers you give it — optional company name, industry, team size, monthly ad spend, whether an AI agent books your calls — together with the estimate they produce. It is stored when you press the button, before any email is asked for, and we use it to improve the model and to follow up if you later ask us to. You can ask us to delete it at any time. Booking data: when you book a diagnostic or ask to talk, we store what you enter on that form — your email, and optionally your name, company, phone number, and a free-text note describing your business. We use it only to reply and set up a call, it is emailed to a named person here (not a shared inbox or a sequence), and you can ask us to delete it at any time. It is not tied to a login, so it persists separately from any account until you ask us to remove it. Usage data: on our public pages we count which buttons are pressed, with no cookie, IP address, or identifier attached — that button count holds nothing that could point back to you. We log IP addresses briefly to rate-limit sign-in and form attempts, and discard them within about a day. We run no product analytics today; if we add any that uses cookies, it will load only after you accept analytics cookies, never before.
What we never do
We never sell your data. We never share one client's data with another, and we do not pool client data to build benchmarks or peer comparisons — we measure you against your own numbers, not against anyone else's. We never use advertising cookies or trackers. We never train third-party AI models on your business data.
AI and your data
No AI model sees your data. Every metric, finding, and dollar figure is computed by our own software from your records — the same arithmetic every time, which is what lets us show you the calculation. The explanations around those numbers are written templates filled with the computed figures, not model output. Nothing about your business is sent to a model provider. If we ever add one, we will name it under Subprocessors below before it handles anything of yours.
Legal bases & your rights (GDPR / CCPA)
We process data under contract (providing the service), legitimate interest (service improvement), and consent (analytics cookies). You may request access, correction, export, or deletion of your data at any time — email hello@loupenow.com. We respond within 30 days. You can withdraw cookie consent anytime; essential cookies (login session, security) remain, as the app cannot function without them.
Retention & deletion
Uploaded imports are stored in our database (Cloudflare D1). When you re-upload a record type, the newest file is the one your reports use; earlier uploads are kept until replaced or pruned so your numbers stay explainable. Imports remain until you re-import, ask us to remove them, or delete your account. Deleting your account from account settings takes effect immediately — your own user record is removed straight away, and when the last member of a workspace deletes their account, the workspace and everything in it is purged: imports, invitations, and the activity log. Grader estimates and booking requests are not tied to a login, so deleting an account does not remove them — email us and we delete those on request, immediately and without conditions. You may request deletion of anything we hold, anytime, by email.
Grader submissions are kept separately from account data, because most are from people who never become clients. We keep one while it is still useful — to improve the estimate model, or to reply if you asked us to — and delete it on request, immediately and without conditions. If you become a client and later delete your account, tell us and we will remove any grader submission you made as well.
Subprocessors
Two, and only two: hosting, database, and application delivery (Cloudflare — Workers & D1) and transactional email (Resend). Each is bound by a data-processing agreement. If you sign in with Google, Microsoft, or GitHub, that provider is not a subprocessor — it never receives your business data — but it does know you signed in here. We notify clients 30 days before adding a subprocessor.
International transfers
Data is stored in US regions. For clients in the EU/UK we rely on Standard Contractual Clauses with each subprocessor.
Contact
Loupe · a Grovistra product · hello@loupenow.com