Legal

Privacy policy

Last updated 2026-09-16

For humansFor agents
Draft, under legal review

looot is operated by AY Automate. Questions about this policy go to walid@ayautomate.com.

What the service is

looot is pay-per-use access to third-party data providers through one key. This page covers the personal data we collect while running that service.

Accounts and tokens

Your account is tied to your email and organization. API tokens are yours to keep private; you are responsible for use under them.

Data we store

  • Account email and organization.
  • Run records: the inputs you sent, the outputs you received, and their status.
  • Your ledger: reservations, settlements, and refunds.

A provider call sends your inputs to that provider, which then holds them under its own terms. We do not sell your data. You can request deletion of your account data at any time.

Cookies

We use session cookies to keep you signed in. We do not use advertising or tracking cookies.

Subprocessors

Services that process data on our behalf, as used in the product today: Supabase (database and authentication), Stripe (payments), Resend (transactional email), Vercel (dashboard hosting), Render (gateway hosting), and Tinybird (usage analytics).

Retention

Run records are kept while your account exists, so you can see your own history and audit log. Delete your account and we delete the data tied to it, on request.

Compliance

We aim to follow GDPR principles: we collect what the service needs, tell you what we store, and delete it on request. We do not hold any formal privacy or security certification today.

Liability

The service is provided as-is. To the extent the law allows, our liability to you is capped at the amount you paid us in the 3 months before the claim.

Changes

We may update this policy as the product changes. We will update the date at the top of this page when we do.

Contact

Reach us at walid@ayautomate.com, or see the contact page.