manyloomPrivacy & terms
PrivacyTerms← Home
Privacy & terms

Privacy, written to be read.

You are handing Manyloom real work: projects, clients, invoices, and the keys to your other apps. So this page is honest and plain, a real policy you can act on. If a line matters to you, it’s written so you can actually understand it.

Last updated: August 20, 2026Maker: BUTENKO ART STUDIOBased in: Burnaby, BC, CanadaContact: privacy@manyloom.com

01 · What this is, and who we are

Manyloom is a calm AI project workspace. You drop your work in, and an AI operator we call Loomy sorts it into tasks and plans, builds small tools for you, connects your other apps, runs an invoicing layer, and can act on your behalf when you ask it to.

Manyloom is made by BUTENKO ART STUDIO, a studio based in Burnaby, British Columbia, Canada. Here, “we”, “us”, and “Manyloom” mean the same thing. “You” means the person or business using the product.

This policy explains what data we hold, why, who else touches it, and the control you have over it.

02 · What we collect

We collect only what the product needs to work for you.

Account data

  • Your name, email, and password (stored hashed, never in plain text).
  • Your plan and billing status. Card details go straight to Stripe, and we never see or store them.

The work you put in

  • Projects, tasks, notes, and plans you create or that Loomy drafts for you.
  • Personal information inside that work, like client names, contacts, invoice figures, and anything else you include.

Content from connected apps

  • When you connect an app — Google Calendar today, with Gmail, Notion, Obsidian and others on the way — we read only the content you allow so Loomy can work with it.
  • We request the narrowest access a feature needs. We do not scrape your whole account.

Usage data

  • Basic, privacy-first analytics: which features are used and where errors happen, so we can fix and improve them.
  • No ad-tracking, no third-party trackers, no advertising cookies.

If you try the demo

  • When you open the demo we store the email you enter, plus which parts of the demo you viewed and for how long, so we can improve it and occasionally email you about Manyloom.
  • Every marketing email has a one-click unsubscribe, and you can have your demo record deleted anytime by writing to privacy@manyloom.com.

03 · How we use it

We use your data to run Manyloom and to let Loomy do the work you ask of it:

  • To sort your work into tasks and plans, build tools, and connect your apps.
  • To let Loomy draft, organise, and propose actions on your behalf.
  • To run the invoicing and money layer you set up.
  • To bill your subscription, support you, and keep the service secure and reliable.

We do not sell your data. We do not use it for advertising. We don’t share it except with the sub-processors named below, all of whom act only to run the service for you.

Support access to your workspace

We do not access the contents of your workspace unless you grant support access, or where strictly necessary to comply with the law or protect the security of the Service and its users. When you grant support access (in Settings > Security), authorized staff may view your workspace in read-only mode for the window you set. We record who accessed it, which workspace, and when; we email you when each access begins; and staff are bound by confidentiality. We do not use your workspace contents to train models.

Operational and audit records

To run the service, keep it secure, and support you, we keep an internal record of account-level events: subscription and payment changes, support actions we take on your account (like a comped month or a support-access session), and technical errors. These records are tied to your account, are used only to operate, secure, bill, and support the Service, and are never sold or used for advertising. We keep them for as long as needed to run and secure the Service and to meet our legal, tax, and accounting obligations.

04 · AI and your data

Loomy is powered by AI, and this is the part people worry about, so we keep it plain.

  • We do not train AI models on your data, and we never permit a provider to. Your work is not used to teach any model, ours or anyone else’s.
  • We keep your content inside Manyloom’s own infrastructure wherever we can, and we minimise any exposure to outside AI providers. Where a feature relies on a third-party AI provider, that provider acts only as a processor bound by contract, is not permitted to train on your content, and is named in the sub-processors list below.
  • You stay in control of what AI touches: mark any item Private so it stays on Manyloom’s own infrastructure and is never sent to any outside AI provider, or Sealed so no AI reads it at all.
  • Your work is used only to produce the result you asked for, and it is never carried into anyone else’s account.

05 · Connected apps and permissions

  • Connections use OAuth, the standard way to link apps without sharing your password.
  • We ask for least-privilege scopes: the smallest permission a feature needs, and no more.
  • You can see every connection you’ve granted from your settings, and revoke any of them in one click, and Loomy loses access immediately.
  • Your access tokens are held in an encrypted secrets vault, never in plain text.

06 · Who else touches your data

To run Manyloom we rely on a short list of trusted sub-processors. Each handles a specific job and nothing more.

  • Stripe for payments. Your card data goes directly to Stripe, and we never store or see it.
  • Resend for the emails the service sends you — sign-in links and billing notices. It receives your email address and the message content, nothing else.
  • Cloudflare R2 stores our off-box backups. Backups are encrypted before they leave our server, so R2 holds only ciphertext it cannot read.
  • Our hosting provider runs the servers Manyloom lives on. Your data sits on infrastructure we operate.

If we add a provider, including any AI provider used by a feature, it appears here first. If this list changes in a way that affects you, we’ll update this page.

07 · Where your data lives

Manyloom runs on our own servers in the United States (US West). Your data is encrypted in transit. Your password is stored hashed (never in plain text), and your connected-app tokens and our off-box backups are encrypted at rest.

How AI handles your content, and the Private and Sealed controls you have over it, is covered above in “AI and your data”.

08 · Your data is yours

Under Canadian privacy law (PIPEDA) and the GDPR, you have clear rights over your data. We build them in rather than making you ask.

Export

You can export your whole account at any time, yourself, from the Export page — one click, in an open format you can read and reuse. No lock-in, no “premium to leave”.

Retention while active

While your account is active we keep your data so the product can work. Finished work isn’t quietly cleared — it moves into your Archive and is kept whole. We keep your data for at least 12 months from your last payment so you can always come back to it and export it.

When a subscription ends

Your work stays put when you stop paying — nothing is deleted. Active use is paused (you’re taken to a reactivation screen), but you can still export your whole account at any time from there. Resubscribing picks up exactly where you left off, with nothing lost.

Deletion

You can delete your account whenever you want, right from your settings — no need to ask us. Deletion runs on a 30-day grace window: your account keeps working, and you can undo it any time within those 30 days. After the 30 days we permanently delete your account and everything in it from our live systems, and revoke every access token to your connected apps. You can also request deletion by writing to privacy@manyloom.com.

Encrypted backups that were taken before your deletion aren’t edited record-by-record; they age out on a rolling 30-day window,* after which no copy of your data remains anywhere. This is also how we honour a right-to-erasure request under the GDPR and PIPEDA.

* Backups exist only to restore the whole service after data loss. They’re encrypted and are never used to look anyone up individually. Worst case, a copy in a pre-deletion backup is gone within 30 days of the permanent deletion.

09 · Cookies and analytics

  • Manyloom is privacy-first and cookieless for analytics. No advertising cookies, no third-party trackers.
  • Our analytics count usage in aggregate; they don’t follow you across the web.
  • We use essential cookies to keep you signed in and secure, plus a first-party cookie on the public demo to remember your unlock and count demo usage. No advertising cookies, no cross-site tracking.

10 · Children, international users, and changes

Children

Manyloom is for adults and businesses. You must be 16 or older to use it, and we don’t knowingly collect data from anyone under 16.

International users

You can use Manyloom from anywhere, and wherever you are the rights above apply. Your data is stored on our own servers in the United States. If you’re in the EU or UK, your data is transferred to the US under appropriate safeguards (standard contractual clauses), and the GDPR rights described here are honoured.

If a breach happens

If a security breach ever affects your data, we’ll tell you and notify the relevant authority as the law requires. We won’t hide it.

Changes to this policy

If we change this policy in a way that matters, we’ll update the date above and let you know. We won’t quietly weaken your protections.

Made by BUTENKO ART STUDIO · privacy@manyloom.com · Privacy · Terms · manyloom.com