Privacy notice
LAST UPDATED 28 JULY 2026
This notice describes what Loupe collects from a developer’s machine, who inside the workspace can access it and how long it is retained.
What we collect
- Prompt text submitted through supported-agent hooks, after on-device redaction.
- Repository name, branch, commit SHA and pull-request number at the moment of the prompt.
- Which agent and model were in use, and how long the turn took.
- Device hostname, operating system version and which hooks are installed.
What we never touch
- Keystrokes outside a prompt submission. Prompt collection is invoked by supported-agent hooks.
- Screen contents. Loupe never captures or transmits a screenshot.
- General application activity outside supported-agent hook invocations is not part of prompt collection.
- Raw secrets. Credentials are matched and replaced on the device before any upload.
Redaction happens before upload
The device agent applies the built-in ruleset — AWS access keys, database connection strings, bearer and JWT tokens, private key blocks, and customer identifiers — plus any regular expressions your workspace adds. Matches are replaced with a labelled placeholder such as [redacted · database url]. The uploaded payload contains the placeholder instead of the matched value.
Who can see what
Individual prompt text is subject to server-enforced workspace roles. Admins can read it; security access is limited to sessions with detected patterns; billing cannot read prompt data.
Retention
Your workspace chooses the window — 1, 7, 30 or 90 days. Scheduled retention removes prompt text after that window; derived aggregates remain without it.
Your rights
Write to privacy@loupe.dev to access, export or erase your data. We answer inside 30 days. Our data processing agreement is available at /dpa.