Our Privacy Promise
Your tasks, notes, and files remain your content. CalmLoop processes your task data only to provide and support the features you choose. CalmLoop does not sell your task data, use it for advertising, or show you ads.
Information CalmLoop Handles
- Account information: your name, email address, bcrypt password hash and other authentication data, and timezone, used for account access, security, verification, and reminders.
- Your content: tasks, dates, priorities, projects, notes, and attachment content and metadata, used for the task-management features you choose.
- Subscription information: plan status and payment records used to manage access. Card details are handled by Razorpay and are not stored by CalmLoop.
- MCP connection information: token name, display prefix, access profile, expiry, last-use, and revocation metadata, used to manage connected clients securely.
- Website usage: basic page-usage and device information handled through Google Analytics to understand and improve the product and website.
How Information Is Used
- Provide and support the task, note, attachment, reminder, search, history, and MCP features you choose.
- Protect account access, verify requests, respond to support questions, and diagnose service problems.
- Manage subscriptions, process payments, and maintain required payment records.
- Measure basic website and application usage to improve CalmLoop.
CalmLoop's Google Analytics integration does not deliberately send task titles, task descriptions, notes, or attachment contents to Google Analytics. CalmLoop does not use your task data for advertising.
Service Providers and Connected Clients
- Google Analytics handles basic website and application usage and device information under Google's privacy practices.
- Razorpay handles payment and card processing.
- Email delivery: the configured email-delivery provider receives recipient details and the message content needed for account, reminder, and subscription emails. Task reminders may include task titles and due-date details.
- File storage: the configured file-storage provider stores attachments you choose to upload.
- MCP and AI clients: a client you choose receives the CalmLoop data returned by actions allowed by that token's access profile. The client and its provider handle that data under their own privacy practices.
Revoking a CalmLoop MCP token blocks future CalmLoop access for that token, but it cannot retract data that a client or provider already received.
Security and MCP Access
CalmLoop uses HTTPS to protect data in transit. Passwords are one-way hashed with bcrypt. Protected data requests require authentication and per-user authorization and ownership checks. Attachment downloads require authorization and use short-lived signed links.
For MCP access, you create a named token with read, write, or full access and choose an expiry of 30, 90, or 365 days. You can revoke a token at any time. CalmLoop shows the raw MCP token once and stores an HMAC-SHA-256 verification digest instead of the raw MCP token secret server-side. Keep every copied token confidential and store it only in a trusted client environment or secret store.
Data Requests and Retention
To request an export, access, correction, or deletion of your CalmLoop data, email info@algozasolutions.com. CalmLoop verifies account ownership before acting on a request. Some payment, security, or legal records may be retained where required or reasonably necessary.
When a trial or paid period expires, existing data remains viewable and new task or note creation pauses until renewal. If you want your content deleted instead, use the request path above.
Questions
CalmLoop is operated by Algoza Solutions OPC Private Limited. For questions about this policy or CalmLoop's data practices, email info@algozasolutions.com.