Privacy Policy

Last updated: August 11, 2026

kumaaa LLC operates loopkeep. This policy explains what we collect and why, across the loopkeep desktop application, the lk command line tool, the loopkeep Console, and this website.

Data stored by the Console and content it excludes

When you use the Console, your device sends us a workflow and trigger catalog used for event delivery and Console listings, and we store it. If your plan includes remote supervision, your device also sends us the latest state of active runs used for Console listings and remote actions, and we store it. We also store run requests and controls made from the Console and their results.

The workflow and trigger catalog and latest active-run state do not include workflow bodies; local file paths or contents; working files; policies; secrets; event or run bodies; prompts; run transcripts; agent sessions; worktrees; or agent-engine information. The transient handling of event bodies that pass through the relay is described under “Relay traffic” below. A technical breakdown of the information sent to us and how it is handled and transmitted is available in our data-handling documentation.

What we collect

  • Account: email address and profile basics, handled by our sign-in provider and used to operate the Console and pair your devices.
  • Device pairing: device identifiers and pairing records, used to route events to your devices.
  • Integration connections: records of the GitHub installations and Slack workspaces you connect. When available, these records include the linked GitHub user login and Slack user ID; they also include the GitHub installation account login and Slack workspace name. For Slack, we store the access token encrypted so the Console can list users and channels and determine channel visibility and membership. When needed, we provide the token to an authenticated paired device, which uses it to fetch requested thread context and to send replies, posts, and notifications. When you disconnect the integration or delete your account, we attempt to revoke the token when possible and appropriate. For GitHub we store no token at all — we mint a short-lived one each time we need it.
  • Workflow and trigger catalog and active-run state: the workflow and trigger catalog used for event delivery and Console listings. If your plan includes remote supervision, we also store the latest state of active runs used for Console listings and remote actions.
  • Console requests and controls: run requests and controls made from the Console and their results.
  • Webhook endpoints: the name of each webhook you create and a hash of the token in its URL. The token itself is shown once when you create it and is not stored by us.
  • Relay traffic: events from integrations you connect pass through our relay — the server that forwards these events to your device — on their way to it. Incoming payloads may include content from those services (such as issue or message text). We process and forward that content solely to deliver it. Every accepted event first enters the queue and is deleted when the device sends a final-processing ACK. After 24 hours from acceptance, an event is never delivered or replayed; its physical cleanup may occur later. The queue is capped at 1,000 events per account, and once it is full the oldest entry is deleted and receives no further delivery. Only the relayed text field is capped at 64 KiB; the cap does not apply to other payload fields. We do not store or use relayed content for any other purpose. These events are never delivered to a device outside your account. For abuse prevention we may keep delivery records (metadata) that do not include the content itself.
  • Operational logs: technical logs and error reports (IP addresses, timestamps, status codes, event identifiers, and the like) for reliability and security. They do not include the content of relayed events.

Cookies

We use only cookies needed for the Service to function and to remember your preferences — such as your sign-in session, language, and theme. Preference cookies may be shared across loopkeep.run and its subdomains so your settings follow you between the site, the docs, and the Console. We do not use advertising or cross-site tracking cookies.

Service providers

We rely on service providers for sign-in, hosting, databases, event relay, error monitoring, and other operations needed to run loopkeep. They process data only on our behalf and under our instructions. Some of them are located outside Japan (for example in the United States); we choose providers with appropriate safeguards and remain responsible for your data. See the current service provider listfor each provider's role and the data it handles.

What we don't do

We do not sell your data. We do not use your content to train models. Relayed content is processed automatically to work out whether it matches your triggers and to deliver it. No person reads it except as required to operate the relay or investigate abuse.

Retention and deletion

Account and device-pairing records are kept while your account exists and deleted when you delete your account. Integration records are deleted when you disconnect the relevant integration or delete your account.

Control-plane workflow catalogs, trigger-routing declarations, and the latest state of active runs replace their previous data. They are deleted when you revoke the device in the Console, when a revoke request from lk logout succeeds, or when you delete your account. The latest state of active runs is also deleted when your plan no longer includes remote supervision. Revocation propagation to the gateway and its routing cache is best effort and may be delayed. Technical cache details are in our data-handling documentation. Records of run requests and controls made from the Console and their results become eligible for deletion 30 days after creation and are deleted on a rolling basis. Content-free duplicate-event and daily delivery/drop records expire or become eligible for cleanup within a few days. To request deletion, contact us at legal@kumaaa.co.jp.

Your rights

You may request access to, correction of, or deletion of your personal data, or ask us to stop using it, by contacting us at legal@kumaaa.co.jp. We will verify your identity and respond as required by applicable law, including Japan's Act on the Protection of Personal Information. Our registered address and representative are available on request.

Security

Data is encrypted in transit. Integration tokens are stored encrypted. Access to production systems is restricted. No system is perfectly secure.

Children

The Service is not directed to children, and we do not knowingly collect personal data from children.

Disclosure

Beyond the service providers above, we disclose data only when required by law or to protect the Service and its users.

Changes

We will announce material changes to this policy (for example on this site, in the app, or by email) and update the date at the top.

Contact

kumaaa LLC — legal@kumaaa.co.jp. This policy is prepared in a Japanese version and an English version; if the two differ, the Japanese version prevails.