# A small, explicit data boundary.

> How loqy.work handles subscriptions, messages, technical requests, preferences, site analytics, and data-protection rights.

Privacy

The site requires no account. Personal data is handled when you subscribe, contact loqy, make an ordinary web request, or use the site while its self-hosted usage measurement is enabled.

Last updated: August 12, 2026

## Controller and contact

Etienne Debost, a natural person operating under the name loqy in Paris, France, is the controller for personal data handled through this site.

[privacy@loqy.work](mailto:privacy@loqy.work) · [gdpr@loqy.work](mailto:gdpr@loqy.work)

## Data handled and where it comes from

Depending on what you choose to do and the site features you use, the following limited data may be handled:

- subscription data: normalized email address, language, consent version, source, and server-side subscription and update dates;
- consent evidence: the version of the adjacent notice and the UTC time at which you submitted the form;
- unsubscribe data: a one-way digest of a fresh unsubscribe token for each product email campaign; the raw token is not stored;
- messages: your sender address, message, attachments, and routing metadata when you contact a loqy mailbox;
- rights and incident requests: the minimum information needed to verify control of an address, respond, and document the outcome;
- network and site-analytics data: your IP address and request metadata necessarily transit the Scaleway-hosted server and network to deliver the page and protect the service; the self-hosted OpenPanel setup receives page-view, session, referrer, bounded campaign, device, coarse location, outbound-link, scroll, and masked-replay signals; for the separate desktop application stream, country is derived transiently from the request IP on the server; the IP is not retained and no city or coordinates are collected.
- device-only preferences: the selected language and theme are stored in your browser and are not sent to loqy by that storage mechanism.

Subscription and message data comes directly from you. Connection and analytics data comes from ordinary browser requests and bounded interactions on the site. loqy does not buy or enrich subscriber data.

## Purposes and legal bases

**Product updates**

Send release alerts, changelog highlights, and occasional product news on the basis of your consent. You may withdraw it at any time.

**Questions and support**

Read and answer messages on the basis of the request you initiated and loqy’s legitimate interest in communicating about and supporting the project.

**Privacy rights**

Verify and answer data-protection requests in order to comply with legal obligations under the GDPR and French data-protection law.

**Security and delivery**

Deliver and defend the static site, understand aggregate page and interaction use, improve public journeys, inspect outbound and scroll behavior, prevent abuse, and investigate credible incidents on the basis of loqy’s legitimate interest in service and information security. The separate desktop stream supports aggregate reliability and product decisions from launches, bounded activity, first-observed-install observations, aggregate Projects and Tasks counts, and content-free capability and model outcomes.

Every action is optional. An email address is required only if you want updates or an email reply; the language, source, consent version, and timestamps are required to administer and evidence the subscription. Analytics fields are generated by the browser and are not needed to browse or subscribe. If you do not provide the subscription details, that requested service cannot be provided.

Site analytics is used for aggregate usage and diagnostics. It does not decide whether a visitor can access loqy or receive a product response.

## Recipients, processors, and transfers

Google Workspace processes subscriptions in a private Google Sheet through a bound Apps Script endpoint, stores role-mailbox correspondence, and sends product emails from the loqy.work Workspace account.

Scaleway SAS hosts the static site and the self-hosted OpenPanel service used for its site analytics, and necessarily processes network and infrastructure data needed to deliver and protect them. The same self-hosted OpenPanel service hosts the separate macOS application’s opt-in analytics project, which receives only the bounded records described below. The subscription endpoint is operated by Google Workspace, not by this web server.

Access is limited to Etienne acting for loqy, the administrators of the self-hosted OpenPanel service, and the processors needed for hosting and Workspace operations. Analytics data is not sold, rented, shared with advertisers, or exposed through a public API. The separate desktop project is kept apart from the site project.

Google may process data outside the European Economic Area under an applicable adequacy decision or the safeguards in its Workspace Data Processing Amendment, including standard contractual clauses. Current terms and subprocessors are available in Google’s [Workspace Data Processing Amendment](https://workspace.google.com/terms/dpa_terms.html).

GitHub, Discord, LinkedIn, X, Statuspage, and other external destinations linked from the site act under their own terms and privacy notices when you choose to visit them.

## Retention

- Subscription records are kept for at most three years from collection or your latest meaningful interaction, and are deleted earlier when you unsubscribe, withdraw consent, obtain deletion, or the list is retired.
- Ordinary contact and support correspondence is normally kept for up to twelve months after the request closes, unless a longer period is necessary for a security investigation, a legal obligation, or the establishment, exercise, or defence of legal claims.
- Infrastructure and security data, if generated by a provider, follows documented operational retention. OpenPanel analytics records are retained for one year. Session-replay chunks are retained for 90 days. The separate macOS application analytics project retains already received records for 365 days; desktop session replay is disabled. On opt-out, future sends stop and the local analytics file is purged, while already received records remain subject to that server retention. Deletion requests can be sent to privacy@loqy.work. These records are not reused by loqy for advertising.
- Language and theme preferences remain in your browser until you change them, clear site data, or remove them through browser controls.

Deletion from active systems may take additional time to age out of provider recovery copies; those copies are not used for ordinary operations.

## Cookies, local storage, and analytics

loqy.work uses self-hosted OpenPanel for site analytics. It measures page views, session duration, referring sources and bounded UTM values, coarse device and location signals, selected marketing events, outbound-link clicks, scroll behavior, and session replay. It does not receive account identity, email addresses, the value entered in the newsletter signup form, private or visitor-provided prompts or document content, or arbitrary URL query strings or hashes. Replay reconstructs the site's public text and product previews; it masks the value entered in the newsletter signup field and excludes the form's invisible technical response. It uses no advertising cookies, cross-site trackers, marketing pixels, or third-party fonts. Browser Do Not Track and Global Privacy Control signals are honored; requests to stop or delete site analytics can be sent to privacy@loqy.work. The macOS desktop application has a separate analytics stream, enabled only after explicit opt-in in its existing Settings control. It records only launches, bounded activity, and first-observed-install observations (which do not prove that every installation was observed); country derived transiently from the request IP without retaining the IP or collecting city or coordinates; aggregate Projects and Tasks counts; skill and connector types and outcomes without custom names or configuration; and public model/provider identifiers with actual reported token counts, omitting unknown values. It uses no desktop session replay and sends no name, email address, hardware identifier, prompt, response, file, product content, or business identifier.

The browser keys marketing-theme and marketing-language remember only your display preferences on your device. OpenPanel’s browser instrumentation uses only a rotating pseudonymous session identifier needed for these measurements; it does not establish an account or persistent visitor identity. The desktop installation identifier is created only after explicit opt-in, is random and pseudonymous, is stored locally while enabled, is deleted with the local analytics file on opt-out, and a later opt-in creates a new identifier; it contains no name, email address, or hardware identifier and is separate from the website session identifier. Product previews are served from loqy.work and do not create an advertising profile.

## Your rights

Subject to the conditions of the GDPR, you may request access, rectification, erasure, restriction, and portability, object to processing based on legitimate interests, and withdraw consent at any time without affecting earlier lawful processing. A proportionate check that you control the address concerned may be requested; do not send an identity document unless specifically required.

Requests can be sent to privacy@loqy.work or gdpr@loqy.work and will be answered without undue delay, normally within one month. An unsubscribe link or a verified deletion request removes the active subscriber row.

You may also lodge a complaint with the French data-protection authority, the [CNIL](https://www.cnil.fr/fr/plaintes).

## Security and personal-data incidents

The subscriber registry is private, access-controlled through Google Workspace, and operated with a single spreadsheet scope. The public site uses HTTPS and collects no password, payment data, product workspace, prompt, or document through the subscription form.

A suspected personal-data breach is documented and assessed. Where the GDPR threshold is met, loqy will notify the CNIL without undue delay and, where feasible, within 72 hours; people will also be informed without undue delay when the breach is likely to create a high risk to their rights and freedoms.

Report a security issue privately to [security@loqy.work](mailto:security@loqy.work).

## Changes to this notice

Material changes will be dated and published on this page before they apply to new collection. If a new use requires consent, it will not be applied to existing data without a valid new choice.
