Legal
Privacy policy
Last updated 2026-09-16
looot is operated by AY Automate. Questions about this policy go to walid@ayautomate.com.
What the service is
looot is pay-per-use access to third-party data providers through one key. This page covers the personal data we collect while running that service.
Accounts and tokens
Your account is tied to your email and organization. API tokens are yours to keep private; you are responsible for use under them.
Data we store
- Account email and organization.
- Run records: the inputs you sent, the outputs you received, and their status.
- Your ledger: reservations, settlements, and refunds.
A provider call sends your inputs to that provider, which then holds them under its own terms. We do not sell your data. You can request deletion of your account data at any time.
Cookies
We use session cookies to keep you signed in. We do not use advertising or tracking cookies.
Subprocessors
Services that process data on our behalf, as used in the product today: Supabase (database and authentication), Stripe (payments), Resend (transactional email), Vercel (dashboard hosting), Render (gateway hosting), and Tinybird (usage analytics).
Retention
Run records are kept while your account exists, so you can see your own history and audit log. Delete your account and we delete the data tied to it, on request.
Compliance
We aim to follow GDPR principles: we collect what the service needs, tell you what we store, and delete it on request. We do not hold any formal privacy or security certification today.
Liability
The service is provided as-is. To the extent the law allows, our liability to you is capped at the amount you paid us in the 3 months before the claim.
Changes
We may update this policy as the product changes. We will update the date at the top of this page when we do.
Contact
Reach us at walid@ayautomate.com, or see the contact page.