Skip to content
Loupine

Privacy Policy

How Loupine handles the data your company puts into its library, and the data this website collects.

Last updated 2026-08-10

Who this covers

Loupine is a private prompt and skill library that companies connect to ChatGPT and Claude through a single MCP connector. This policy covers the product at web.loupine.app — including that connector — and this marketing site at loupine.app.

Loupine is operated from Brazil and can be reached at hello@loupine.app. For the library itself we act as a processor on behalf of the company whose organization holds the data: that company decides what goes in and who may read it. For pilot requests submitted on this site, and for our own operational logs, we act as the controller.

What we collect

Identity and membership
Your name, work email, and the identifiers your company's single sign-on provider gives us, plus your role in the organization and the teams you belong to. You never create a password with us — sign-in happens through your employer's identity provider.
Library content
The prompts and skills your organization saves: name, description, tags, the full instruction text, and every previous version with the account that saved it. This is your company's content, not ours.
Connector usage records
One row per tool call: which tool ran, which user and organization it ran for, which asset it touched, whether it succeeded, and when. This is what lets an admin see whether the library is being used.
Pilot requests from this website
Name, work email, company, an optional WhatsApp number, the page and referrer you came from, any campaign parameters in the link, and the coarse location (country, region, city) your browser request carries. Your IP address is used to rate-limit the form and is not stored.
Operational telemetry
Error reports and server logs, scrubbed of credentials and connection strings, plus cookie-less aggregate page analytics on this site. The product video is embedded from YouTube and only loads once you press play.

What we do not collect

The connector answers tool calls; it cannot read the conversation around them. It has no access to your chat history with ChatGPT or Claude, your memory or saved files in those products, or anything else in your assistant beyond the arguments a tool call sends us.

  • No conversation transcripts, chat history, or assistant memory.
  • No payment card details — the connector performs no transactions.
  • No health data, government identifiers, or credentials.
  • No tracking cookies, no advertising identifiers, no data sold or shared with brokers.

How we use it

  • To serve the library: find, return, and save prompts and skills for the people entitled to see them.
  • To enforce access: every request is scoped to one organization, and to the teams the caller belongs to.
  • To keep version history, so a team can see how an asset changed and who changed it.
  • To operate and debug the service, and to protect it from abuse.
  • To show your own admins how the library is being used inside their organization.
  • To reply to pilot requests submitted on this site.

We do not train models on your library content, and we do not use it to improve any product other than your own organization's service.

What reaches ChatGPT and Claude

This is the disclosure that matters most. When someone in your organization connects the connector to an AI assistant and that assistant calls one of our tools, the result of that call — including the full text of a prompt or skill it loads — is returned into that assistant's conversation. From that point the content is handled by the assistant's provider under that provider's own terms and privacy policy.

Nothing is pushed: content leaves only in response to a tool call the assistant makes on a signed-in user's behalf, and only content that user is already entitled to read.

Who else processes it

WorkOS
Identity, single sign-on, organization membership, and team invitation emails.
Neon
The managed PostgreSQL database that stores the library.
Vercel
Application hosting and cookie-less page analytics.
Sentry
Error monitoring, with secrets and connection strings scrubbed.
Resend
Delivers the internal notification when a pilot request is submitted.
YouTube (Google)
Serves the embedded product video on this site, on play.

These providers process data on our instructions and for no other purpose. We do not sell personal data, and we do not share it for advertising.

How long we keep it

  • Library content and its version history: for as long as your organization is active, and until you delete it.
  • Identity and membership records: for as long as the account is active; removed accounts are marked inactive and cleared when the organization is closed.
  • Connector usage records: up to 12 months, then deleted.
  • Error reports and server logs: up to 90 days.
  • Pilot requests from this site: up to 24 months after our last contact with you, unless you ask us to delete them sooner.

When an organization ends its engagement, we delete or return its library within 30 days of the request, backups included on their own rotation.

Your choices and rights

You can ask for a copy of your data, correct it, or have it deleted. Under Brazil's LGPD and the GDPR you also have the right to object to processing, to restrict it, and to complain to your supervisory authority. Write to hello@loupine.app and we will respond within 30 days.

If your data sits inside a company library, the fastest route is usually your own organization's admin, who can remove assets and memberships directly. Where we act only as a processor, we forward requests to that company and support them in answering you.

Security

  • Sign-in is delegated to your identity provider — we never see or store a password.
  • The connector accepts only OAuth 2.1 access tokens issued for it, and rejects tokens minted for anything else.
  • Every query is scoped to one organization on the server side; the tool surface itself is filtered by role.
  • All traffic is served over HTTPS.

If you believe you have found a vulnerability, write to hello@loupine.app and we will acknowledge it within two business days.

Changes and contact

We update this policy when the product changes; the date at the top is the last substantive edit, and material changes are announced to organization admins by email. Questions, requests, and complaints all go to hello@loupine.app.

Loupine is a business tool sold to companies. It is not directed at children, and we do not knowingly collect data from anyone under 18.