Privacy Policy

Updated 4 October 2026.

This Privacy Policy explains how Commonplane, Inc. ("Commonplane," "we," "us") collects, uses, and shares information in connection with the Perfloop website at perfloop.ai (the "Site") and the Perfloop product and services (the "Service"). Perfloop is a product of Commonplane, Inc.

Who we are

For the Site and for personal information about prospective customers and website visitors, Commonplane, Inc. is the data controller. For personal information in customer source code, session records, or telemetry that the Service processes on a customer's behalf, the customer is generally the controller and Commonplane is the processor. That processing is governed by the customer's agreement and, where applicable, a Data Processing Addendum. It is described in detail on our Security & Data Access page.

Information we collect

Information you provide. When you request early access or contact us, we collect your email address, any information you choose to include, and basic technical data about the request. If you create a Perfloop account, we collect identifiers such as your name and email through our authentication provider.

Information collected automatically. When you visit the Site, our hosting infrastructure records standard technical data in server logs: IP address, referring URL, the pages you request, and browser and device type. The Site does not use advertising or cross-site tracking cookies.

Customer data. When a customer connects a repository or telemetry source, the Service accesses and processes that data within the scope the customer grants, as set out on our Security page. Connected telemetry can include metrics and their labels, log aggregates, limited log text, and profiles, which contain function and file names. The Service can keep account records, connection settings, encrypted credentials, repository metadata, query results, session transcripts, proposed changes, proof artifacts, and operational telemetry.

AI clients. You can connect an AI client, such as ChatGPT or Claude, to the Perfloop MCP server. You authorize it by signing in through our authentication provider or, for automation, with a Perfloop API key. Perfloop checks that credential on each request.

The client sends Perfloop its tool calls and their arguments, and basic technical data such as its name and the IP address of the machine that sends the request. Perfloop does not receive or ask for your conversation history. Some tools take text that you or your agent write. No tool asks for a password, API key, or other credential.

The Service keeps text that a tool saves as a record of your workspace, as it does for the same action in the app. Text that a tool takes can also go to the model providers below for the work it starts.

Our traces of these requests record technical details such as identifiers and the tool name. They do not record the text you or your agent write or the result, except that the error message of a failed call can repeat part of what the call sent.

How we use information

We use personal information to:

  • respond to your inquiries and provide access to the Service;
  • operate, maintain, secure, and improve the Site and Service;
  • authenticate users and protect against fraud, abuse, and security incidents;
  • communicate with you about early access and product updates;
  • comply with legal obligations and enforce our terms.

We do not sell your personal information. We do not use customer code or telemetry to train AI models. Selected customer content can be sent to the model providers listed below, and their own retention terms apply. Details are on the Security page.

Legal bases (EEA and UK)

Where the GDPR or UK GDPR applies, we rely on: your consent (for example, marketing emails); our legitimate interests in operating and securing the Site and Service and in responding to you; performance of a contract where you are a customer; and compliance with legal obligations. You may withdraw consent at any time.

How we share information

We share personal information only with service providers that process it on our behalf, under contract and only as needed to run the Site and Service. Each name below links to that provider's privacy policy or privacy terms:

We may also disclose information where required by law or legal process, or to protect rights, safety, and security; and in connection with a merger, acquisition, or sale of assets, subject to this Policy. A current subprocessor list for the Service is available on request.

International transfers

We are based in the United States. We and our providers can process information in the United States and other countries. Where required, we use the transfer safeguards in our provider and customer agreements. These can include the Standard Contractual Clauses.

Data retention

We retain personal information for as long as needed for the purposes described here, to maintain your account or respond to you, and as required by law. Marketing contacts are retained until you unsubscribe or ask us to delete them. Customer-data retention for the Service is specified in the data-access contract on the Security page. This is how long we keep account and product data:

  • Account and workspace records, including records saved through the MCP server, are kept while the customer account is active.
  • An authorized account deletion stops access at once and removes the account's product data after a recovery period of up to 30 days. We keep one summary record of the deletion, without customer content.
  • After an account is deleted, its backups and recovery copies are kept for a limited period and then expire.
  • Operational logs and traces are kept for up to 365 days, also after an account is deleted. Security and audit logs may be kept longer where needed for security, legal or compliance reasons.

Security

We protect information with the technical and organizational measures described on our Security page, including encryption in transit and at rest, least-privilege access, and a contained agent-execution architecture. No method of transmission or storage is completely secure.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to the processing of your personal information, and to withdraw consent.

  • EEA, UK, Switzerland: you may exercise the GDPR rights above and lodge a complaint with your supervisory authority.
  • California, where applicable: you may request to know, access, correct, and delete personal information. We do not sell or "share" personal information for cross-context behavioral advertising, and we will not discriminate against you for exercising your rights.

To exercise any right, email privacy@perfloop.ai. We will verify your request and respond as required by law.

Cookies

The Site does not use advertising or cross-site tracking cookies. The authenticated Service can use cookies that are necessary for sign-in, session security, and related product functions.

Children

The Site and Service are not directed to children under 16, and we do not knowingly collect personal information from them.

Changes

We may update this Policy. We will post the updated version with a new "last updated" date and, where appropriate, provide additional notice.

Contact

Commonplane, Inc.
2093 Philadelphia Pike #9449
Claymont, DE 19703
privacy@perfloop.ai