Privacy Policy
This Privacy Policy explains what personal data closedloop.email ("we", "our") collects, how we use it, and your rights under the General Data Protection Regulation (GDPR) and applicable data protection laws.
1. Data We Collect
Account data
- Email address — used for authentication and service communications.
- Password — stored as a bcrypt hash; we never store or transmit your plaintext password.
Infrastructure credentials
- API token — stored encrypted in AWS Secrets Manager while your Loop is being provisioned, then deleted once provisioning succeeds. Re-collected, one-shot, only if you request that your Loop be destroyed.
- Claim token — a one-time token that lets you set your Loop's initial admin password. It is not the password itself, and it is cleared once used. We never hold your Loop's admin password.
- SSH keys — public keys you add for your own access are stored as plain text (public keys are not secret). closedloop.email also embeds its own support SSH key in every Loop by default; it is revocable by you at any time from the Loop's page.
Deployment metadata
- Your Loop's subdomain id, server IP address, status, and timestamps — stored in our database to operate the Service.
Audit logs
- Actions you perform (creating or destroying a Loop) are logged for security and debugging purposes.
Platform access (SSH)
Unless you disable it, closedloop.email retains SSH access to your server for support purposes, via a key pair we control. We do not use this access to read your mail — a Loop's mail flow is entirely local to the server and closedloop.email is not in that path — but the access itself is real for as long as it is enabled, and we are stating that plainly rather than describing the box as beyond our reach. You can revoke it at any time; if you do, and later lose your own admin password, we cannot recover the Loop for you.
Data we do NOT collect
- We do not process the content of the mail inside your Loop — mail delivery is entirely local to your server, and after you claim your Loop we hold no credential capable of authenticating to it.
- We do not use tracking pixels, third-party analytics, or advertising networks.
2. How We Use Your Data
- To authenticate you and maintain your account.
- To provision and destroy Loops you request.
- To send transactional emails (deployment status, security notices).
- To improve and debug the Service.
- To comply with legal obligations.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
3. Data Retention
- Account data is retained as long as your account is active. You may request deletion at any time.
- Your Hetzner Cloud API token is deleted from Secrets Manager as soon as provisioning succeeds; the one-shot destroy token is deleted as soon as destruction succeeds.
- The claim token is deleted once you claim your Loop.
- Audit logs are retained for 12 months.
- Deployment metadata for destroyed Loops is retained in anonymised form for analytics.
4. Data Storage and Security
Our backend infrastructure runs on AWS in the eu-central-1 (Frankfurt, Germany) region. Sensitive credentials are encrypted at rest using AWS KMS. We apply the principle of least privilege to all service components.
5. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your data ("right to be forgotten").
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
To exercise any of these rights, email us at support@closedloop.email. We will respond within 30 days.
6. Cookies
We use only a single session cookie to maintain your authenticated state. We do not use tracking or advertising cookies.
7. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email. Continued use of the Service after changes are posted constitutes acceptance.
8. Contact
closedloop.email is a service operated by cripta.to. For privacy-related questions: support@closedloop.email.