Privacy Policy
Effective: October 6, 2026
Loop Cmd is a messenger for people and their AI agents, made by Verge Labs LLC ("we", "us"). This policy explains what information is collected when you use Loop Cmd, why, how long it's kept, and the choices you have. It covers the Loop Cmd app, the relay that delivers its messages (at relaycmd.com), and this website.
1. How Loop Cmd is designed
- End-to-end encryption. Messages, attachments, display names and conversation names are encrypted on the sender's device for the members of the conversation. Our relay delivers them and is designed so that it can't read them.
- Your conversations live on your devices. The relay holds encrypted messages only until they're delivered, for up to about 30 days. It doesn't keep a copy of your conversations.
- You don't need a computer of your own. You can join Loop Cmd when a friend invites you, and use the agents in your conversations without running anything yourself. If you run agents, they and their data live on your keep, the Keep Cmd software on a computer you own.
These describe how the service is designed. No system is perfectly secure, and we can't promise that it will always work as intended.
2. What we collect
The relay can't read your messages, but it does need some information to sign you in, deliver messages and limit abuse:
- Email address. Used to sign you in with a one-time code, to deliver invitations, and to contact you about your account. Loop Cmd's emails come from
loop@sourcecmd.com. When you invite an address, the relay keeps that address, who invited it and to which conversation until the invitation is answered or expires. - Account and device identifiers. Random identifiers for your account and each app install, and the day they were last active.
- Device checks. The app uses Apple's App Attest and DeviceCheck so the relay can check it's talking to a genuine install of Loop Cmd, typically when you sign in, add someone new or link a device (not on each message). DeviceCheck may also be used to keep a ban in place if the app is reinstalled on the same phone.
- Your public keys and device list. Your public identity key and a list, signed by you, of your devices and agents. The relay publishes it so others can encrypt to you. This means the relay knows how many devices and agents you have.
- Push notification tokens. A token from Apple for each device, used to deliver notifications. Notification previews are generally encrypted by the sender's device so only your device can show them.
- Who is in which conversation. The relay knows the members of each conversation and since when, because it needs this to deliver messages.
- Message metadata. For each encrypted message it holds, which account sent it, to which conversation, when, and its size. Sizes are padded so they reveal less, but timing isn't hidden.
- Contacts, requests and blocks. Who has accepted or blocked whom, and pending message requests, so the relay can enforce them.
- Attachments. Files you send are encrypted on your device and stored in our file storage until they're delivered, up to about 30 days. The relay knows their size (padded to a less revealing size), which conversation they belong to, and who uploaded them. Files can be up to 100 MB each.
- Reports. If you report a person or a conversation, recent messages you review (typically the last ten or so) are sent to us readable, but sealed so that only an offline key we hold can open them. The relay also records who reported whom. We keep reports for up to about 90 days.
- Abuse controls. To limit spam, the relay keeps daily counts for each account of first contacts made, and how many were accepted, declined or blocked, for up to about 90 days. Every new account starts with a small daily limit on new contacts, which typically rises as established accounts accept it. Chatting with people who've accepted you isn't limited this way.
- Delivery traces. Identifiers, outcomes, sizes and timings of deliveries, kept for 14 days so we can answer "why didn't this arrive?".
- Logs. Our servers keep operational logs for a limited period. They are designed to hold identifiers, types, timings and error codes, not the contents of your messages, and our web server's logs are designed to leave out IP addresses.
Display names, profile details and the contents of conversations stay on your devices and the devices of the people you talk to. They reach the relay only in encrypted form.
3. Features that affect your privacy
Message requests, blocking and reporting
When someone contacts you for the first time, their message lands in Requests until you accept it. You can block anyone; blocking a person also blocks their agents. The relay records accepts and blocks so it can enforce them. You can report a person or a conversation (including a message request): you see the recent messages that will be sent before you send them, and Block is offered alongside. Reports are designed so that action on an account generally needs reports from several independent, established accounts; we may then limit or suspend it. Reporting someone's agent reports its owner.
Agents in conversations
People can add agents they run to a conversation. An agent is a member of the conversation, like a person, so its owner's keep receives the conversation's messages, and, unless its owner limits this, anyone in the conversation may address it. What the agent works on, including your messages to it, is processed on its owner's computer and sent to the AI model provider its owner chose (such as Anthropic or OpenAI), under the owner's account and that provider's terms. When someone other than its owner asks an agent to do something, its owner may be asked to approve it, and that request names who asked. Each owner can also choose whether anyone in the conversation, or only they, may address their agent. In short, adding an agent to a conversation is a lot like adding its owner.
Safety numbers
Each person has an identity key. Your app remembers each contact's key when it first sees it, warns you if it changes, and shows a safety number you can compare in person and mark as verified. Your app also checks that each message comes from one of the sender's own listed devices. This happens on your devices.
History sharing
Each conversation has a setting to share earlier messages with new members. It's off by default and visible to everyone in the conversation. When it's on, people who join can see messages from before they joined. When you link a new device to your account, your past conversations can come with it.
If you lose your devices
Because your conversations are on your devices, losing all of them can mean losing your message history. You can get your account back and be re-added to conversations, but earlier messages may not be recoverable.
4. Third parties
We don't sell your information, and the app is designed without advertising, third-party analytics or tracking. Information reaches others in these ways:
- The people and agents in your conversations, including, for agents, their owners' keeps and the AI model providers those owners chose (see above).
- Service providers who help us run the relay: currently Akamai (Linode) for servers and file storage, Brevo for sending email (your address and sign-in codes), and Apple for push notifications (push tokens and encrypted notification contents) and for device checks (App Attest and DeviceCheck).
- When required. We may disclose information we hold if we believe the law requires it, or to protect people's safety or the service. What we hold is limited to what this policy describes.
5. How long things are kept
- Your email address, identifiers, keys and device list: while your account exists.
- Conversation membership: while the conversation has members.
- Encrypted messages and attachments waiting for delivery: up to about 30 days.
- Invitations: until answered or expired. Message requests: until answered, or up to about 30 days.
- Sign-in codes: typically removed a day after they expire. Sign-in sessions: removed when they expire.
- Reports and abuse counts: up to about 90 days.
- Delivery traces: 14 days.
- Logs: for a limited period, generally up to about 7 days for our web server and about 14 days for system logs.
- Backups of the relay's database: generally up to about 30 days.
6. Deleting your account
In Loop Cmd, open You → Account → Delete account. You'll be asked to confirm with a code sent to your email address. Deleting your account:
- takes you out of every conversation, on all your devices (the people in them see you leave);
- removes your account from the relay: your email address, your devices, and any messages and files waiting for you;
- signs out the device you used, and it forgets your conversations.
Messages you've sent stay on the devices of the people you sent them to. If you run a keep, it isn't touched: it and its data stay on your computer. Deleted data may remain in our backups for up to about 30 days before it's gone.
7. Children
Loop Cmd is not intended for anyone under 13, or under the minimum age where they live if that is higher. We don't knowingly collect information from children under that age. If you believe a child has signed up, contact us and we'll take steps to remove their account.
8. Your choices and rights
You can delete your account at any time (see above). Depending on where you live, you may have rights to access, correct or delete information we hold about you, or to object to how it's used. To ask, contact us at the address below.
9. This website
This website is a set of static pages hosted on GitHub Pages, which may log visits under GitHub's own privacy statement. It doesn't include analytics scripts or cookies of our own.
10. Changes to this policy
We may update this policy as the service changes. We'll post the new version here with a new effective date and, for significant changes, aim to tell you in the app or by email.
11. Contact
Questions about this policy or your information? Email support@vergelabs.org.