Privacy Policy
What Loftline collects, who processes it on our behalf, how long we keep it, and how to get it back or have it deleted.
- Effective
- August 26, 2026
- Version
- 1.0
- Contact
- support@loftline.dev
Who controls your data
Loftline is operated by Ankan Hazra, an individual operating as a sole proprietor based in India, who is the data controller for everything described here. For any question about your data, or to exercise any of the rights below, write to support@loftline.dev.
What we collect
- Account details. Your name, email address, and avatar image if you set one. If you sign in with Google or GitHub, we store the tokens that provider issues us so the connection keeps working. If you use a password, we store it hashed and never in a readable form.
- Session and security data. For each active session we record the IP address and browser user agent it was created from, so you can recognise a session that is not yours.
- Your work. Projects and their names and descriptions, the contents of your canvases, generated specifications, and the messages you exchange with the AI — including everything you type into it.
- Collaboration records. The email addresses you invite to a project, which may belong to people who do not have a Loftline account.
- Usage counters. How many AI tokens your account has used this month, how much canvas storage your projects occupy, and — for each MCP token — how many requests it has made and when it was last used.
- Billing records. Which plan and features you hold, and the identifiers our payment provider uses for your subscription. We never see or store your card details — those go to Polar and stay there.
We use all of it for one purpose: running the product you signed up for, billing it correctly, keeping it secure, and answering you when you write to us. We do not sell it, and we do not share it for anyone else's advertising.
What we do not collect
Loftline runs no analytics and no third-party tracking. There is no Google Analytics, no product analytics SDK, no session replay, no advertising pixel and no cross-site tracker anywhere in the application. We do not build a profile of you, and we cannot tell you which pages you visited, because nothing records it.
There is one exception, and this page said we would name it before it processed anything. When the application crashes, a crash report goes to Sentry, our error-monitoring provider, so that we find out something is broken without waiting for you to tell us. A report contains the error, the code path that produced it, the page you were on, and your browser and operating system version.
If you were signed in it also carries your account identifier — not your email address, so that we can see a crash affected three different people rather than happening three times. We have configured it not to record your IP address and not to send the contents of your requests, and it does not watch what you do: nothing is sent unless something has already gone wrong.
What the AI sees
When you ask Loftline to generate or extend a diagram, or to produce a specification, we send your prompt together with the relevant contents of that canvas to our model provider so it can produce the result.
Your content is not used to train models — not by us, and not by the provider, whose API terms exclude training on submitted content. Your conversations with the AI are stored so you can come back to them, and are deleted automatically as described under how long we keep things.
Collaboration and invitations
Real-time collaboration is powered by a third-party service that has to know who is in the room in order to draw them there. When you open a project, we send it your name, email address and avatar for that session, along with your cursor position and the contents of the canvas you are editing.
If you have not set an avatar, we generate a placeholder from an external service, which means your display name appears in a request to that service. Setting an avatar avoids this.
Inviting someone stores the email address you typed, so that the invitation can be matched when they accept. If you were invited to a project and want that record removed, write to support@loftline.dev — you do not need an account to ask.
Who processes data for us
Loftline is built on infrastructure we do not own. Each of these processes some of your data on our behalf, and only for the purpose named:
- Polar — payments, as merchant of record. Receives your email and payment details; we never receive the card.
- Neon — the PostgreSQL database holding accounts, projects and billing records.
- Vercel — hosting, and the object storage holding canvas snapshots and generated specifications.
- Liveblocks — real-time collaboration. Receives your name, email, avatar, cursor position and canvas contents.
- OpenAI — diagram and specification generation. Receives your prompts and canvas context.
- Trigger.dev — runs generation jobs in the background, and therefore handles the same content while a job is in flight.
- ImageKit — stores and serves avatar images.
- DiceBear — generates placeholder avatars from a display name.
- Sentry — error monitoring. Receives crash reports: the error, the page it happened on, your browser version, and — if you are signed in — your account identifier, but not your email address and not your IP address. Processed in the EU.
- Our email provider — delivers verification codes, invitations and account notices. Receives your email address and the contents of those messages.
Google and GitHub are involved only if you choose to sign in with them, in which case they tell us your name, email and avatar.
How long we keep things
- AI conversations are deleted automatically after seven days of inactivity, by a job that runs daily.
- MCP tokens expire after 90 days by default, and you can revoke one at any time.
- Projects, canvases and specifications are kept until you delete them or delete your account.
- Account and billing records are kept while the account exists. Some billing records are retained afterwards by our payment provider where tax law requires it.
Deleting your account
You can delete your account yourself, from the danger zone in Settings. Doing so immediately removes your account record, your projects and their canvases, the canvas snapshots and generated specification files held in our object storage, your collaborator memberships in other people's projects, invitations you sent and invitations addressed to you, your AI conversations, your API tokens, your usage records and your avatar, and cancels any active subscription.
If you collaborate on a project someone else owns, deleting your account removes your membership and your own activity, but leaves their project and its contents intact.
Deletion is not reversible, and we cannot restore an account afterwards.
Your rights
Whatever data protection law applies to you, you can ask us to show you the data we hold about you, correct it, delete it, or give you a copy you can take elsewhere. You can also object to how we use it.
Write to support@loftline.dev and we will respond within thirty days. There is no charge. If you are not satisfied with our answer, you can complain to the data protection authority where you live.
Security, and who can see your account
Traffic is encrypted in transit. Passwords are hashed, and API tokens are stored hashed so that even we cannot read one back — a token is shown once, at the moment you create it, and never again. No system is perfectly secure, and we do not claim otherwise.
You should also know that Loftline has an administrator function which can sign in as an accountin order to investigate a problem, and can adjust an account's plan, trial or usage balances. Every such session is recorded as an impersonation. This exists for support, it is used sparingly, and we would rather you learned about it here than discovered it later.
Where your data goes
We operate from India, and the providers listed above operate in other countries, principally the United States and the European Union. Using Loftline therefore involves transferring your data across borders. We rely on the contractual protections each provider offers for those transfers.
Children
Loftline is a tool for professional software work and is not intended for children. We do not knowingly collect data from anyone under sixteen. If you believe a child has created an account, tell us and we will remove it.
Changes to this policy
When this policy changes, the effective date and version at the top of the page change with it. For a change that materially affects how we handle your data — a new category of collection, or a new processor — we will email account holders before it takes effect.
Something here unclear, or not matching what you see in the product? Write to support@loftline.dev and we will fix the document or the product, whichever is wrong.