InsightLoop

Privacy Policy

Last updated: March 31, 2026

1. Who We Are

ZAACloud LLC (“we”, “our”, “us”) operates InsightLoop, a feedback management platform for product teams. This policy explains what data we collect, why we collect it, and what we do with it.

2. Information We Collect

Account information

When you create an account, we collect your name and email address. If you sign in with Google, we receive your name, email, and profile picture from Google. You can also use InsightLoop anonymously with limited functionality — in that case, we collect no identifying information.

Content you create

Feedback submissions, comments, votes, roadmap items, and project configuration data are stored as part of normal platform use.

File uploads

You can upload files (PNG, JPEG, WebP, and PDF), up to 5 MB per file. Uploaded files are stored on Cloudflare R2.

Session data

When you sign in, we record your IP address, browser user agent, and the session timestamp. This data is used to manage active sessions and is not shared externally.

Submitter email addresses

If feedback arrives through an external channel (such as email or Slack), it may include the submitter's email address so you can follow up with them directly.

3. How We Use Your Information

We use the data we collect to:

  • Operate and maintain the InsightLoop platform
  • Authenticate your identity and manage sessions
  • Send transactional emails: account verification, password resets, and team invitations
  • Deliver Slack notifications when you enable the Slack integration for a project

We do not sell your data. We do not use your content to train machine learning models. We do not send marketing emails.

4. Third-Party Services

We rely on a small set of third-party services to operate InsightLoop:

  • Google OAuth — handles authentication when you sign in with Google. Google receives your authentication request. See Google's Privacy Policy for details.
  • Cloudflare R2 — stores uploaded images and documents. Files are hosted on Cloudflare's infrastructure.
  • Gmail SMTP — delivers transactional emails. Email content passes through Google's mail servers.
  • Slack — receives notification messages when you connect a project to a Slack workspace. Only the content you configure for notifications is sent (feedback titles, status changes, comments).

Each service operates under its own privacy policy. We do not share data with advertising networks, analytics providers, or data brokers.

5. Cookies and Local Storage

InsightLoop uses one essential authentication cookie to maintain your session and one localStorage entry to remember your theme preference. We do not use advertising cookies, analytics cookies, or any third-party tracking.

See our Cookie Policy for the full breakdown.

6. Security

We protect your data with:

  • Encryption in transit — all data is transmitted over TLS/HTTPS.
  • Encryption at rest — your data and uploaded files are stored on encrypted infrastructure.
  • Password hashing — passwords are stored using a one-way cryptographic hash. We never store passwords in plaintext.
  • Project isolation — each project's data is isolated. Members of one project cannot access another project's data unless explicitly invited.

7. Data Retention

  • Sessions expire after 7 days of inactivity.
  • Team invitations expire after 7 days.
  • Feedback, comments, and uploads persist until you delete them or your account.

When you delete your account, your personal data (name, email, sessions, notification preferences) is permanently removed. Feedback and comments you authored remain in the project with the author field cleared, so project context is not lost.

8. Your Rights

Under GDPR and applicable data protection laws, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate information via your account settings
  • Delete your account and associated personal data
  • Portability — request a copy of your data in a machine-readable format
  • Withdraw consent at any time by deleting your account or disconnecting third-party integrations
  • Lodge a complaint with a supervisory authority in your jurisdiction (EEA users)

If you are a California resident, you also have rights under the CCPA, including the right to know what personal information we collect and the right to request deletion.

To exercise any of these rights, email privacy@insightloop.io. We will respond within 30 days.

9. Children

InsightLoop is a business tool and is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

10. Changes to This Policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top. If we make material changes, we will notify you through the platform or by email.

11. Contact Us

Questions about this policy or your data? Email us at privacy@insightloop.io. Also see our Cookie Policy and Terms of Service.