This policy describes what WorkLoop collects, why, who it is shared with, how long we keep it, and the choices you have. It applies to useworkloop.com and the WorkLoop desktop and mobile apps. Questions? Email info@useworkloop.com.
Information we collect
Account information. Name, username, email address, password (stored only as a salted hash), profile photo, and sign-in method (email and password, passkey, or Google, Microsoft or Apple sign-in).
Content you create. Tasks, projects, notes, routines, goals, team chat messages, files and attachments you upload, and call participation in team channels. Voice and video are carried in real time and are not recorded by WorkLoop.
Teams and organizations. Membership, roles, invitations and activity within the workspaces you join.
Billing information. Payments are handled by Stripe. We receive your plan, subscription status and the last four digits and brand of your card, never the full card number.
Device and usage data. Device type, app version, IP address and approximate location derived from it, sign-in and security events, and push notification tokens if you enable notifications.
Data from connected accounts. If you choose to connect Google, Microsoft or Google Drive, we receive the data described below. Connecting is always optional.
We do not sell your personal data and we do not use it for advertising.
Google user data
WorkLoop offers Google sign-in and two optional Google integrations. We request only the access listed here, and only when you start the connection.
| Google scope | What we access | Why |
|---|---|---|
openid, email, userinfo.email | Your Google account email address and basic profile identifier. | To sign you in, link your Google account to your WorkLoop account, and label which Google account a connection belongs to. |
calendar.readonly | The list of your calendars and the events on the calendars you select (title, time, location and description). | To let you view and import events as tasks in WorkLoop. Access is read-only. WorkLoop never creates, edits or deletes anything in your Google Calendar. |
drive.metadata.readonly | File metadata only: file name, type, size, icon and link, for files in your Drive. | To let you browse and search your Drive and attach a link to a file on a task, message or team file library. WorkLoop does not read, download or copy the contents of your files. File bytes stay in Google Drive. |
How we handle it. Calendar events are fetched when you open or import them and are used to create tasks only when you choose to import. When you link a Drive file we store its name, type, size, icon and link so teammates can see the reference; teammates still need their own Drive access to open it. Google refresh tokens are encrypted at rest. We do not use Google user data to train AI or machine-learning models, and we do not use it for advertising.
Limited Use. WorkLoop's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the user-facing features described above, we do not transfer it to others except as needed to provide those features, comply with law, or as part of a merger or sale with notice to you, and no humans read it unless you give consent for specific items, it is necessary for security or abuse investigation, or the law requires it.
Disconnecting and deleting. You can disconnect a Google Calendar or Google Drive connection at any time in WorkLoop settings. Disconnecting deletes the stored tokens for that account and stops all access. You can also revoke WorkLoop at myaccount.google.com/permissions. Tasks you already imported and file links you already created remain until you delete them. To have anything else removed, email us.
Microsoft and Apple data
If you use Microsoft or Apple sign-in we receive your email address and account identifier (and your name if the provider supplies it). If you connect Outlook Calendar we request read-only calendar access (Calendars.Read, User.Read) to show and import events, under the same limits as Google Calendar above. If you connect OneDrive we access file metadata to let you link files. Disconnecting removes the stored tokens.
How we use your information
We use your data to provide and operate WorkLoop, sync across your devices, deliver messages, notifications and calls, process payments, send service and security notices, detect fraud and abuse, provide support, moderate content that is reported, and meet legal obligations. Aggregated, anonymized analytics help us understand product usage, never to profile you for advertising.
Storage, security and retention
Data is stored on servers we control and protected with TLS in transit, encrypted storage of third-party access tokens, hashed passwords, optional multi-factor authentication and passkeys, rate limiting, and access controls on staff tools with audit logging.
We keep account and content data while your account is active. Expired or revoked sign-in tokens, abandoned OAuth and checkout sessions, and payment webhook logs are purged automatically (typically within days to 90 days). Security event logs are kept 90 days. Staff audit logs are kept up to one year. When you delete your account we delete or de-identify your personal data, except what we must keep for legal, tax, fraud-prevention or security reasons, and backups age out on their normal cycle.
Your rights and deleting data
Depending on your region (including the EEA, UK and California), you may access, correct, export or delete your personal data, restrict or object to certain processing, and withdraw consent. You can edit most data in the app, disconnect integrations in settings, and request account deletion from the app or by email. Contact info@useworkloop.com and we will respond within the timelines required by applicable law. You may also lodge a complaint with your local data protection authority.
Children
WorkLoop is not directed to children under 13 (or the minimum age in your country) and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
We will update this page when our practices change and revise the date below. For material changes we will notify you in the app or by email.
Contact us
For privacy requests or questions about this policy, email info@useworkloop.com. We will work with you to resolve concerns promptly.
Last updated: October 1, 2026. See also our Terms of Service and Security overview.