Privacy Policy
Version 1.1 — Last updated: 2026-08-31
Loopika AI Co., Ltd. ("Company", "we", "us", or "our") values your privacy. This Privacy Policy explains how we collect, use, and protect your personal information when you use the Loopika AI platform ("Service").
1. Information We Collect
1.1 Information You Provide Directly
- Name, email address, and account credentials
- Billing and payment details (processed securely via PCI-DSS compliant payment gateways)
- Brand DNA, business configurations, and communication preferences entered on the platform
- Content, files, and assets uploaded to our Service
1.2 Automatically Collected Information
- Usage information (pages viewed, features utilized, access timestamps)
- Device and browser information, IP address, and approximate geolocation
- System log files and operational analytics data
1.3 Information from Third-Party Integrations
- Social media and messaging channels (Facebook, Instagram, LINE, TikTok, Gmail) when you connect your accounts
- Customer conversation records and inquiries received through our Unified Inbox and Chatbot features
2. Purposes of Data Processing
We use your personal data to:
- Deliver the Service — Power our Unified Inbox, customer interaction tools, and AI-assisted reply drafting
- Maintain & Enhance Quality — Analyze system stability and optimize user experience
- Communicate — Send account notifications, system updates, and essential service alerts
- Security & Integrity — Detect unauthorized access, prevent abuse, and safeguard platform security
- Regulatory Compliance — Fulfill applicable statutory and legal requirements
3. Data Sharing and Disclosure
We do not sell your personal data. We disclose data solely to:
3.1 Third-Party Service Providers
- Cloud infrastructure providers (DigitalOcean, Supabase) for secure hosting and database storage
- AI technology providers (Google Gemini API / Vertex AI) under commercial enterprise terms strictly for real-time prompt generation
- Payment processors for subscription handling
- Email delivery providers for operational alerts
All service providers are bound by strict Data Processing Agreements (DPAs) and confidentiality covenants.
3.2 Legal Obligations
We may disclose information where required by court order, subpoena, or lawful request from government authorities.
3.3 Business Transfers
In the event of a merger, acquisition, or asset transfer, user data may be transferred with advance notification.
4. Data Retention Schedule
| Data Category | Retention Duration |
|---|---|
| Active User Accounts | Duration of active subscription |
| Terminated Accounts | 90 days following closure, followed by irreversible deletion |
| System Logs | 12 months |
| Billing & Tax Records | 7 years (in compliance with financial regulations) |
| AI Generated Content | Duration of account lifecycle + 30 days |
5. Security Safeguards
We enforce comprehensive administrative, technical, and physical security measures:
- TLS/HTTPS encryption for all data in transit
- Strong AES encryption for database storage, sensitive credentials, and OAuth tokens
- Role-Based Access Control (RBAC) adhering to the principle of least privilege
- Periodic security reviews and automated daily backup redundancy
6. Your Legal Rights (PDPA & GDPR)
Under applicable data protection laws, you are entitled to:
- Right to Access — Request confirmation of and access to your personal data
- Right to Rectification — Request correction of inaccurate or incomplete records
- Right to Erasure — Request deletion of your personal data
- Right to Data Portability — Request your data in a structured, commonly used machine-readable format
- Right to Restrict/Object — Object to or request restriction of data processing
- Right to Withdraw Consent — Withdraw your processing consent at any time
Inquiries and requests may be submitted to: privacy@loopika.ai. We reply within 30 days.
7. Cookies and Tracking
We use essential cookies necessary for authentication and session integrity, and analytical cookies to gauge feature adoption. You may configure cookie preferences through your web browser.
8. International Data Transfers
Your data may be processed on secure infrastructure located outside Thailand. All cross-border transfers satisfy the standards prescribed by PDPA and GDPR.
9. Google API Services User Data Policy & Limited Use Disclosure
Loopika AI's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
9.1 Purpose of Accessing Gmail Data
Our application requests access to Gmail data via https://www.googleapis.com/auth/gmail.readonly and https://www.googleapis.com/auth/gmail.send exclusively to provide the Unified Inbox functionality:
- Email Ingestion (
gmail.readonly): To retrieve inbound customer email inquiries and display email threads inside your Unified Inbox so you can read and manage customer communication in one place.
- Outbound Email (
gmail.send): To enable you to send reply emails directly to customers from within the Loopika AI interface.
9.2 AI and Machine Learning Restrictions (No Model Training)
- We DO NOT use Google Workspace or Gmail user data (including email body content, headers, attachments, or recipient metadata) to develop, train, fine-tune, or improve generalized or non-personalized Artificial Intelligence (AI) or Machine Learning (ML) models.
- Any AI processing of customer email content (such as generating draft suggestions via the Google Gemini API) is performed strictly on demand in real-time. Interactions are routed through commercial enterprise endpoints with zero data retention for training, ensuring no customer data is retained or used by third-party model providers.
9.3 Additional Protections & User Controls
- We never sell Google user data to third parties.
- We do not utilize Google user data for advertising purposes, including targeted or personalized advertising.
- Human review of your email data is strictly prohibited, except where you have provided explicit consent for a specific support request, where required for security investigations (such as abuse prevention), or where mandated by applicable law.
- You can revoke Loopika AI's access to your Gmail account at any time via the platform's Social Connection settings or directly through your Google Account Security Permissions, which immediately halts data access and deletes stored OAuth tokens.
10. Modifications to this Policy
We reserve the right to revise this Privacy Policy. Material amendments will be communicated via email or prominent platform notification at least 30 days prior to taking effect.
11. Contact Information & Data Protection Officer
Data Protection Officer (DPO)
Email: privacy@loopika.ai
Address: Loopika AI Co., Ltd., Bangkok, Thailand
This policy complies with the Personal Data Protection Act B.E. 2562 (PDPA) and Google API Services User Data Policy.