Loopcut

Legal

Privacy Policy

Loopcut collects as little as it can. This page says exactly what that is, what happens to your requests on hosted plans, and how to get your data out.

Last updated 19 September 2026.

01The short version

Loopcut is an open-source application that runs inside Blender on your computer. If you use it with your own API key or a local model, nothing is sent to us and this policy has almost nothing to cover.

If you create a Loopcut account and use our hosted models, we hold the minimum needed to sign you in, meter your usage and bill you. We relay your model requests to the provider and do not store their content.

02Who we are

Loopcut operates the website at loopcut.org and the hosted model service behind it (the “Service”). You can reach us at hello@loopcut.org.

03What we collect when you use the app without an account

Nothing. The application does not contact our servers unless you sign in. With your own API key, requests go directly from your computer to the provider you configured, under that provider’s terms. With a local model, requests never leave your machine.

The application does not include analytics or crash reporting that reports to us.

04What we collect when you create an account

  • Your email address, and if you sign in with Google, the name and profile picture Google shares with us. We use these to identify your account and send sign-in links.
  • A session cookie so you stay signed in on this website.
  • When you connect the application, the device name it reports (for example your computer’s name) and a hashed access token. We store the hash, not the token itself, so we cannot read it back. You can revoke any device from your account page.
  • Billing records: a Stripe customer identifier, your plan and its status, and the current billing period. Card details are entered on Stripe’s pages and never reach our servers.

05What happens to your requests on hosted plans

When the application sends a request through our gateway, we forward it to a third-party model provider and stream the reply back. Requests can include your message, the parts of your scene the application chose to describe, and viewport images you attached.

We record, per request: a request identifier, the model used, input and output token counts, the resulting cost, whether it succeeded, and how long it took. We use this to enforce your plan’s allowance and show your usage. We do not store the content of your messages, your scene data, images or the model’s reply.

The model provider receives the request content in order to answer it. Their handling of that content is governed by their own terms and privacy policy.

06Who we share data with

  • Supabase, which hosts our database and handles authentication, including the email sign-in links.
  • Stripe, which processes payments and hosts the billing portal.
  • Vercel, which hosts this website and the gateway.
  • Google, only if you choose to sign in with Google.
  • The model providers behind Fast and Pro, who receive request content as described above.

We do not sell personal data, and we do not share it with advertisers.

07How long we keep it

Account and billing records are kept while your account exists and for as long as we are required to keep financial records afterwards. Usage records are kept to operate the allowance windows and for accounting, then aggregated or deleted. Revoked device tokens are kept only as revoked hashes so they cannot be reused.

08Your choices and rights

  • You can use Loopcut without an account at all, with your own key or a local model.
  • You can revoke any connected device from your account page at any time.
  • You can cancel a paid plan from the billing portal linked on your account page.
  • You can ask us to export or delete your account data by emailing hello@loopcut.org from the address on the account. We will confirm and complete the request within 30 days.

Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA, including the right to complain to a supervisory authority. We will honour them.

09Cookies

This website uses only the cookies needed to keep you signed in. There are no advertising or cross-site tracking cookies.

10Security

Access tokens are stored hashed, database access is restricted per user, secrets are kept out of the codebase, and traffic is encrypted in transit. The code that does all of this is open source, so you can check it rather than take our word for it.

11Children

The Service is not directed at children under 16 and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.

12Changes

If this policy changes in a way that matters, we will update the date at the top and note the change in the project’s repository. Continued use of the Service after a change means you accept the updated policy.

Questions about this page: email hello@loopcut.org. See also the Terms of Service and Privacy Policy.