What soloop does
soloop is a workbench for solo founders. You bring an idea, URL, repo, deck, or file. soloop keeps the project thread, proposes the next move, runs approved research, prepares approved Twitter/X work, runs approved coding tasks, and records the signals that come back.
Project memory is the point. Chats, docs, tasks, approvals, signals, and execution records let the agents see the same history you see.
The product is still in beta. Features, integrations, pricing, data flows, and retention rules can change as we tighten the product.
Data we collect
We collect the records that make the workspace work: what you type, what you upload, what soloop creates, what connected services return, and server records for login, security, and debugging.
Do not upload secrets, private keys, production credentials, regulated data, private customer records, health data, financial account data, or sensitive personal data unless you have the right to use it here and have decided soloop is the right place for it.
With your permission: an anonymous visitor and session ID, public-page paths, active time, explicitly labelled clicks, source attribution, referrer host, consent history, and the account link created after successful authentication.
Email, name, authentication provider, login metadata, billing plan, credit balance, and account timestamps.
Project name, product description, URLs, repo URL, onboarding doc draft, generated app records, and project status.
Uploaded decks, PDFs, ZIPs, source files, filenames, file size, MIME type, hashes, extracted text, storage paths, and vector-search IDs.
Messages, conversation titles, TODO cards, approvals, edits, task status, agent output, acceptance criteria, logs, sandbox IDs, and deployment URLs.
Provider name, external username, external email, scopes, status, token expiry, encrypted refresh-token fields, OAuth state, GitHub installation metadata, and Stripe account metadata.
Twitter/X or other approved-source URLs, comments, author handles, public feedback, LLM analysis, qualified-user records, and notifications.
How our agents use data
Agents use project context for the task in front of them. That context can include recent messages, project docs, approved TODOs, files, account status, signals, and prior results.
Analysis and outside action are separate. A task that can publish, deploy, spend credits, use a connected account, or change code goes through the product flow built for that action.
Soloop
Uses the project doc, recent messages, task state, signals, and connected-account status to suggest one next move.
It does not post, deploy, send messages, refresh tokens, or write to external services.
Research
Runs approved desk research against public sources, then writes findings, reports, and signals back to the workspace.
It uses private connected accounts only when the feature clearly asks for that access.
The active publishing flow is Twitter/X: drafts, posts, replies, media handling, quota checks, and comment monitoring.
No post or reply goes out without a connected account and the visible product flow.
Researches Reddit communities and prepares grounded posts or replies for review.
It does not publish Reddit content without the required approval and verified execution path.
Cold Email
Prepares approved outreach and uses the connected email account for authorized sends.
It does not send email without an approved task and an eligible connected account.
Ads
Builds campaign plans and executes the exact paid-acquisition controls shown for review.
It does not launch or spend without the required campaign and payment approvals.
Build
Works from the approved brief, project files, repo context, sandbox logs, test output, and deployment status.
Review code, logs, deployment changes, and data manifests before shipping them to users.
AI training
soloop does not use workspace content, uploaded files, connected-account content, generated code, or signals to train a general soloop model.
When a task uses an AI model, we send the prompt plus relevant context to model or routing providers such as OpenAI-compatible providers, TokenRouter, Anthropic, or other providers used by the product.
Those providers return output and keep the abuse, safety, debug, or billing records their own policies, contracts, and retention settings allow.
AI output can be wrong, incomplete, outdated, duplicated, insecure, or unsuitable for your use. You are responsible for reviewing output before publishing, deploying, sending, or relying on it.
OAuth and connected accounts
If you connect Twitter/X, Reddit, GitHub, Stripe, or another service, we store account metadata to show status and run the feature you chose.
Where refresh tokens are needed, soloop stores them encrypted with AES-256-GCM fields. OAuth state records finish authorization flows and resume the pending task.
GitHub App installation records store installation metadata. Short-lived GitHub installation access tokens are generated on demand and are not persisted.
Stripe Connect account links are temporary and created on demand. soloop stores connected-account metadata such as Stripe account ID, country, currency, charges status, payouts status, requirements, and email when Stripe returns it.
Stripe processes subscription billing, taxes, invoices, payment methods, and customer records on its hosted payment surfaces. We do not receive or store full card numbers or CVC.
You can revoke a connected account in the external service. You can also ask us to disconnect or delete the related soloop records.
Cookies and logs
soloop uses cookies and similar browser storage for login, session refresh, security, product state, traffic-source attribution, Google Analytics 4 usage measurement, and Google Ads conversion measurement.
Servers and providers collect IP address, user agent, request path, timestamps, errors, performance data, and diagnostics to keep the service working, detect abuse, and debug failures.
Google Analytics and Google Ads may receive pseudonymous identifiers, page and session information, traffic-source data, browser or device information, approximate location, and confirmed-registration conversion events. The Cookie Policy describes current cookie names, purposes, durations, and browser choices.
Security
soloop uses account ownership checks, server-side authorization, encrypted refresh-token storage, scoped OAuth flows, short-lived authorization state, sandboxed coding execution, provider access controls, and operational logs.
No internet service is perfectly secure. Do not put production secrets, private keys, customer databases, or regulated data into soloop unless you have decided the risk is acceptable.
If you believe your account, token, repo access, Stripe account, or workspace has been exposed, contact us quickly and revoke the affected external connection where possible.
Retention and deletion
We keep account records while your account exists. We keep project records while the project is active, unless product behavior or law calls for a shorter period.
Project deletion can remove or queue cleanup for project documents, storage objects, conversations, messages, direct channel tasks, coding tasks, signals, notifications, and OpenAI vector-store references tied to that project.
Some records can remain longer for security, fraud prevention, billing, accounting, legal obligations, disputes, abuse review, backups, debugging, or product operation.
Raw public-page analytics events and source page views are kept for up to 90 days. Analytics consent records and the separate waitlist funnel can be kept for up to 13 months. Aggregated, de-identified reporting may be kept longer when it can no longer reasonably identify a person or browser.
Backups and provider records do not always disappear instantly. Deletion can take time to finish across every system.
When we no longer need retained personal data, we delete it or anonymize it so it can no longer reasonably identify you, subject to legal and operational limits.
Your choices and rights
You can choose what to upload, what to connect, what to approve, and what to publish or deploy.
Your location can give you rights to access, correct, export, delete, restrict, or object to some processing of your personal data.
You can revoke external account access through the external service. Related soloop workflows can stop working until you reconnect.
You can ask us for account deletion, project deletion, data export, correction, or privacy review through the contact channel below.
The Privacy choices control lets you allow, reject, or later withdraw optional analytics and Google Ads conversion measurement. Withdrawing analytics clears the current browser identifier and requests deletion of its raw first-party analytics history.
Children
soloop is not for children. You must be at least 18 years old, or the age of majority where you live, to use the product.
If you believe a child provided personal data to soloop, contact us so we can review and delete it where required.
Changes
We update this Privacy Policy when the product, integrations, laws, or data flows change.
If a change materially affects you, we will give notice by posting the updated policy or using an in-product notice.
Contact
For privacy, security, deletion, export, or account-access requests, use the email link below.
Soloop, Inc. is responsible for this policy. Postal address: 6357 Joaquin Murieta Ave, Newark, CA 94560, United States. Email: [email protected].
admin@soloop.io