Early accessWorkLoop is available to download now. We are finishing partner reviews and polishing small details before the full launch.What's new
Legal

Privacy Policy

How WorkLoop handles your information, plainly stated, with no surprises.

Last updated October 1, 2026Applies to useworkloop.com and the WorkLoop apps

This policy describes what WorkLoop collects, why, who it is shared with, how long we keep it, and the choices you have. It applies to useworkloop.com and the WorkLoop desktop and mobile apps. Questions? Email info@useworkloop.com.

Information we collect

Account information. Name, username, email address, password (stored only as a salted hash), profile photo, and sign-in method (email and password, passkey, or Google, Microsoft or Apple sign-in).

Content you create. Tasks, projects, notes, routines, goals, team chat messages, files and attachments you upload, and call participation in team channels. Voice and video are carried in real time and are not recorded by WorkLoop.

Teams and organizations. Membership, roles, invitations and activity within the workspaces you join.

Billing information. Payments are handled by Stripe. We receive your plan, subscription status and the last four digits and brand of your card, never the full card number.

Device and usage data. Device type, app version, IP address and approximate location derived from it, sign-in and security events, and push notification tokens if you enable notifications.

Data from connected accounts. If you choose to connect Google, Microsoft or Google Drive, we receive the data described below. Connecting is always optional.

We do not sell your personal data and we do not use it for advertising.

Google user data

WorkLoop offers Google sign-in and two optional Google integrations. We request only the access listed here, and only when you start the connection.

Google scopeWhat we accessWhy
openid, email, userinfo.emailYour Google account email address and basic profile identifier.To sign you in, link your Google account to your WorkLoop account, and label which Google account a connection belongs to.
calendar.readonlyThe list of your calendars and the events on the calendars you select (title, time, location and description).To let you view and import events as tasks in WorkLoop. Access is read-only. WorkLoop never creates, edits or deletes anything in your Google Calendar.
drive.metadata.readonlyFile metadata only: file name, type, size, icon and link, for files in your Drive.To let you browse and search your Drive and attach a link to a file on a task, message or team file library. WorkLoop does not read, download or copy the contents of your files. File bytes stay in Google Drive.

How we handle it. Calendar events are fetched when you open or import them and are used to create tasks only when you choose to import. When you link a Drive file we store its name, type, size, icon and link so teammates can see the reference; teammates still need their own Drive access to open it. Google refresh tokens are encrypted at rest. We do not use Google user data to train AI or machine-learning models, and we do not use it for advertising.

Limited Use. WorkLoop's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the user-facing features described above, we do not transfer it to others except as needed to provide those features, comply with law, or as part of a merger or sale with notice to you, and no humans read it unless you give consent for specific items, it is necessary for security or abuse investigation, or the law requires it.

Disconnecting and deleting. You can disconnect a Google Calendar or Google Drive connection at any time in WorkLoop settings. Disconnecting deletes the stored tokens for that account and stops all access. You can also revoke WorkLoop at myaccount.google.com/permissions. Tasks you already imported and file links you already created remain until you delete them. To have anything else removed, email us.

Microsoft and Apple data

If you use Microsoft or Apple sign-in we receive your email address and account identifier (and your name if the provider supplies it). If you connect Outlook Calendar we request read-only calendar access (Calendars.Read, User.Read) to show and import events, under the same limits as Google Calendar above. If you connect OneDrive we access file metadata to let you link files. Disconnecting removes the stored tokens.

How we use your information

We use your data to provide and operate WorkLoop, sync across your devices, deliver messages, notifications and calls, process payments, send service and security notices, detect fraud and abuse, provide support, moderate content that is reported, and meet legal obligations. Aggregated, anonymized analytics help us understand product usage, never to profile you for advertising.

Sharing and service providers

We share data only as needed to run the service. Content you put in a team or organization is visible to its members according to their roles and permissions. We use these categories of providers, who process data on our behalf:

  • Stripe for payment processing.
  • LiveKit for real-time voice and video in team channels.
  • Expo / Apple / Google push services to deliver push notifications.
  • Email delivery for account, security and notification emails.
  • Hosting and storage for our servers, database, file storage and backups.
  • Sign-in and integration providers (Google, Microsoft, Apple) when you choose to use them.

We may disclose information if required by law or to protect the rights, safety and security of users or WorkLoop. If WorkLoop is involved in a merger or acquisition we will tell you before your data becomes subject to a different policy. We never sell personal data or share it for advertising.

Storage, security and retention

Data is stored on servers we control and protected with TLS in transit, encrypted storage of third-party access tokens, hashed passwords, optional multi-factor authentication and passkeys, rate limiting, and access controls on staff tools with audit logging.

We keep account and content data while your account is active. Expired or revoked sign-in tokens, abandoned OAuth and checkout sessions, and payment webhook logs are purged automatically (typically within days to 90 days). Security event logs are kept 90 days. Staff audit logs are kept up to one year. When you delete your account we delete or de-identify your personal data, except what we must keep for legal, tax, fraud-prevention or security reasons, and backups age out on their normal cycle.

Cookies and similar technologies

We use essential cookies and local storage for sign-in and preferences, and optional analytics to understand how the marketing site and app are used. You can control non-essential cookies in your browser settings.

Your rights and deleting data

Depending on your region (including the EEA, UK and California), you may access, correct, export or delete your personal data, restrict or object to certain processing, and withdraw consent. You can edit most data in the app, disconnect integrations in settings, and request account deletion from the app or by email. Contact info@useworkloop.com and we will respond within the timelines required by applicable law. You may also lodge a complaint with your local data protection authority.

Children

WorkLoop is not directed to children under 13 (or the minimum age in your country) and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

Changes to this policy

We will update this page when our practices change and revise the date below. For material changes we will notify you in the app or by email.

Contact us

For privacy requests or questions about this policy, email info@useworkloop.com. We will work with you to resolve concerns promptly.

Last updated: October 1, 2026. See also our Terms of Service and Security overview.