Privacy Policy
Last updated: July 22, 2026
kumaaa LLC operates loopkeep. This policy explains what we collect and why, across the loopkeep desktop application, the lk command line tool, the loopkeep console, and this website.
What stays on your machine
Your workflows, run transcripts, working files, policies, and secrets are stored and processed locally on your device. We do not receive or store them.
What we collect
- Account: email address and profile basics, handled by our sign-in provider (Clerk), used to operate the console and pair your devices.
- Device pairing: device identifiers and pairing records, used to route events to your devices.
- Integration connections: records of the GitHub installations and Slack workspaces you connect, and the access tokens needed to receive their events. Tokens are stored encrypted.
- Relay traffic: events from integrations you connect pass through our relay to reach your device. Incoming payloads may include content from those services (such as issue or message text); we process them transiently into a minimal wake event that references the source without including its content, and retain relay data only as needed for delivery and abuse prevention.
- Operational logs: technical logs and error reports (IP addresses, timestamps, status codes) for reliability and security.
Cookies
We use only cookies needed for the Service to function and to remember your preferences — such as your sign-in session, language, and theme. Preference cookies may be shared across loopkeep.run and its subdomains so your settings follow you between the site, the docs, and the console. We do not use advertising or cross-site tracking cookies.
Service providers
We rely on service providers to run loopkeep — cloud and database hosting, sign-in (Clerk), and error monitoring (Sentry). They process data only on our behalf and under our instructions. Some of them are located outside Japan (for example in the United States); we choose providers with appropriate safeguards and remain responsible for your data.
What we don't do
We do not sell your data. We do not use your content to train models. We do not read your relayed content except as required to operate the relay or investigate abuse.
Retention and deletion
Account, device pairing, and integration records are kept while your account exists, and deleted when you disconnect the integration or delete your account. To request deletion, contact us at legal@kumaaa.co.jp.
Your rights
You may request access to, correction of, or deletion of your personal data, or ask us to stop using it, by contacting us at legal@kumaaa.co.jp. We will verify your identity and respond as required by applicable law, including Japan's Act on the Protection of Personal Information. Our registered address and representative are available on request.
Security
Data is encrypted in transit. Integration tokens are stored encrypted. Access to production systems is restricted. No system is perfectly secure — which is one more reason your content stays on your machine.
Children
The Service is not directed to children, and we do not knowingly collect personal data from children.
Disclosure
Beyond the service providers above, we disclose data only when required by law or to protect the Service and its users.
Changes
We will announce material changes to this policy (for example on this site, in the app, or by email) and update the date at the top.
Contact
kumaaa LLC — legal@kumaaa.co.jp. This policy is prepared in a Japanese version and an English version; if the two differ, the Japanese version prevails.