Privacy, written to be read.
You are handing Manyloom real work: projects, clients, invoices, and the keys to your other apps. So this page is honest and plain, a real policy you can act on. If a line matters to you, it’s written so you can actually understand it.
01 · What this is, and who we are
Manyloom is a calm AI project workspace. You drop your work in, and an AI operator we call Loomy sorts it into tasks and plans, builds small tools for you, connects your other apps, runs an invoicing layer, and can act on your behalf when you ask it to.
Manyloom is made by BUTENKO ART STUDIO, a studio based in Burnaby, British Columbia, Canada. Here, “we”, “us”, and “Manyloom” mean the same thing. “You” means the person or business using the product.
This policy explains what data we hold, why, who else touches it, and the control you have over it.
02 · What we collect
We collect only what the product needs to work for you.
Account data
- Your name, email, and password (stored hashed, never in plain text).
- Your plan and billing status. Card details go straight to Stripe, and we never see or store them.
The work you put in
- Projects, tasks, notes, and plans you create or that Loomy drafts for you.
- Personal information inside that work, like client names, contacts, invoice figures, and anything else you include.
Content from connected apps
- When you connect Google or Gmail, Notion, Obsidian, or a social account, we read the content you allow so Loomy can work with it.
- We request the narrowest access a feature needs. We do not scrape your whole account.
Usage data
- Basic, privacy-first analytics: which features are used and where errors happen, so we can fix and improve them.
- No ad-tracking, no third-party trackers, no advertising cookies.
If you try the demo
- When you open the demo we store the email you enter, plus which parts of the demo you viewed and for how long, so we can improve it and occasionally email you about Manyloom.
- Every email has a one-click unsubscribe, and you can have your demo record deleted anytime by writing to privacy@manyloom.com.
03 · How we use it
We use your data to run Manyloom and to let Loomy do the work you ask of it:
- To sort your work into tasks and plans, build tools, and connect your apps.
- To let Loomy draft, organise, and propose actions on your behalf.
- To run the invoicing and money layer you set up.
- To bill your subscription, support you, and keep the service secure and reliable.
We do not sell your data. We do not use it for advertising. We don’t share it except with the sub-processors named below, all of whom act only to run the service for you.
04 · AI and your data
Loomy is powered by AI, and this is the part people worry about, so we keep it plain.
- We do not train AI models on your data, and we never permit a provider to. Your work is not used to teach any model, ours or anyone else’s.
- We keep your content inside Manyloom’s own infrastructure wherever we can, and we minimise any exposure to outside AI providers. Where a feature relies on a third-party AI provider, that provider acts only as a processor bound by contract, is not permitted to train on your content, and is named in the sub-processors list below.
- You stay in control of what AI touches: mark any item Private so it is handled by a local model only, or Sealed so no AI reads it at all.
- Your work is used only to produce the result you asked for, and it is never carried into anyone else’s account.
05 · Connected apps and permissions
- Connections use OAuth, the standard way to link apps without sharing your password.
- We ask for least-privilege scopes: the smallest permission a feature needs, and no more.
- You can see every connection you’ve granted from your settings, and revoke any of them in one click, and Loomy loses access immediately.
- Your access tokens are held in an encrypted secrets vault, never in plain text.
06 · Who else touches your data
To run Manyloom we rely on a short list of trusted sub-processors. Each handles a specific job and nothing more.
- Stripe for payments. Your card data goes directly to Stripe, and we never store or see it.
- Our hosting, the servers that run Manyloom, operated by us on infrastructure we control.
If we add a provider, including any AI provider used by a feature, it appears here first. If this list changes in a way that affects you, we’ll update this page.
07 · Where your data lives
Manyloom is hosted on our own servers in the United States. Your primary data is stored there, encrypted in transit and at rest.
How AI handles your content, and the Private and Sealed controls you have over it, is covered above in “AI and your data”.
08 · Your data is yours
Under Canadian privacy law (PIPEDA) and the GDPR, you have clear rights over your data. We build them in rather than making you ask.
Export
You can export your work at any time, in open formats. No lock-in. Your data leaves in a form you can read and reuse.
Retention while active
While your account is active we keep your data so the product can work. Finished work isn’t quietly cleared. It moves into your Archive and is kept whole. Retention runs on a rolling 12 months from your last payment; every payment resets the clock.
Export-then-delete
When work is removed, either on your request or 12 months after your last payment, we first package a complete copy and email it to the account owner. Only then is the work removed, and it sits in a 30-day recoverable trash before the permanent purge. This is also how we honour a right-to-erasure request under the GDPR and PIPEDA.
When a subscription ends
Your work stays put when you stop paying. Your account becomes read-only while the retention window runs. You can still see and export everything. Resubscribing resets the 12-month clock and your data continues uninterrupted.
Deletion
You can delete your account whenever you want. We keep a 30-day grace window, and after that deletion is permanent and revokes all OAuth tokens to your connected apps. To request deletion, write to privacy@manyloom.com.
09 · Cookies and analytics
- Manyloom is privacy-first and cookieless for analytics. No advertising cookies, no third-party trackers.
- Our analytics count usage in aggregate; they don’t follow you across the web.
- We use only the essential cookies needed to keep you signed in and secure.
10 · Children, international users, and changes
Children
Manyloom is for adults and businesses. You must be 16 or older to use it, and we don’t knowingly collect data from anyone under 16.
International users
You can use Manyloom from anywhere. Wherever you are, the rights above apply. Your primary data is stored on our own servers in the United States. If you’re in the EU or UK, the GDPR rights described here are honoured.
If a breach happens
If a security breach ever affects your data, we’ll tell you and notify the relevant authority as the law requires. We won’t hide it.
Changes to this policy
If we change this policy in a way that matters, we’ll update the date above and let you know. We won’t quietly weaken your protections.