Skip to content
LEGAL

Privacy notice

LAST UPDATED 28 JULY 2026

This notice describes what Loupe collects from a developer’s machine, who inside the workspace can access it and how long it is retained.

What we collect

  • Prompt text submitted through supported-agent hooks, after on-device redaction.
  • Repository name, branch, commit SHA and pull-request number at the moment of the prompt.
  • Which agent and model were in use, and how long the turn took.
  • Device hostname, operating system version and which hooks are installed.

What we never touch

  • Keystrokes outside a prompt submission. Prompt collection is invoked by supported-agent hooks.
  • Screen contents. Loupe never captures or transmits a screenshot.
  • General application activity outside supported-agent hook invocations is not part of prompt collection.
  • Raw secrets. Credentials are matched and replaced on the device before any upload.

Redaction happens before upload

The device agent applies the built-in ruleset — AWS access keys, database connection strings, bearer and JWT tokens, private key blocks, and customer identifiers — plus any regular expressions your workspace adds. Matches are replaced with a labelled placeholder such as [redacted · database url]. The uploaded payload contains the placeholder instead of the matched value.

Who can see what

Individual prompt text is subject to server-enforced workspace roles. Admins can read it; security access is limited to sessions with detected patterns; billing cannot read prompt data.

Retention

Your workspace chooses the window — 1, 7, 30 or 90 days. Scheduled retention removes prompt text after that window; derived aggregates remain without it.

Your rights

Write to privacy@loupe.dev to access, export or erase your data. We answer inside 30 days. Our data processing agreement is available at /dpa.