The AI task manager that can't read your inbox.
Not “won't.” Can't. LoopVantage holds no inbox permissions to misuse — the only email we ever see is the email you choose to forward. This page walks through exactly how that works, for people who read privacy pages skeptically. Which should be everyone.
No inbox scopes · Raw email purged after extraction · Never trains on your data
The architecture
Privacy by structure, not policy
A policy is a promise. An architecture is a constraint. We built the constraint.
Most AI email tools open with the same request: full read access to your mailbox. Every message you've ever received — offer letters, medical bills, the thread where you vented about your board — synced to their servers, protected by a paragraph in a privacy policy that says trust us. The policy can change. The access already happened.
LoopVantage inverts the model. There is no inbox OAuth scope anywhere in the product. Sign-in with Google or Microsoft requests your identity — name and email address — and nothing else. The consent screen you see at signup is the complete list of what we can touch, and your mailbox is not on it. We could not sync your inbox if we wanted to, and no future policy revision, acquisition, or breach can change that, because the permission simply does not exist.
Instead, you forward or BCC the specific emails that contain real commitments to a private capture address that only accepts mail from you. You decide, message by message, what the AI ever sees. The default is nothing — which is what a default should be.
The usual model
“Grant read access to your entire mailbox”
Every email synced. Relevance decided by their software, after the fact. Your exposure is your whole inbox, forever.
The LoopVantage model
“Sign in” — identity only, then you forward
Relevance decided by you, before we see anything. Your exposure is exactly the emails you chose to send us — briefly, as you'll see below.
Follow the data
The life of a forwarded email
Five steps, from your Sent folder to a tracked commitment — and what exists at the end.
It arrives at your private capture address
You forward or BCC an email from Gmail, Outlook, or your phone. The message lands on an inbound webhook that verifies the mail provider's signature before processing a single byte — unauthenticated traffic is rejected at the door.
The verified-sender gate drops everything that isn't you
Only mail from your own confirmed addresses is accepted. A stranger, a spammer, or a malicious actor who discovers your capture address can shout into it all day — their mail is discarded without processing. Nobody can inject tasks into your list but you.
AI extracts the commitment schema — nothing more
The extractor pulls a structured record: what's owed, by whom, to whom, by when, and how confident it is. Low-confidence guesses are dropped. And nothing becomes a task until you explicitly accept it — the AI proposes, you dispose.
The raw email is purged
After extraction, the original message body is deleted from our systems. What persists: the task title, deadline, counterparty, and a short snippet so you have context. The thread about your salary negotiation does not live on our servers — because we threw it away on purpose.
Deep links point back to your mailbox — not ours
Every task keeps a link that reopens the source thread in your own Gmail or Outlook. We don't need to keep your email to give you one-click context, because you already have a copy. It's called your inbox.
Net result: for any email you forward, our long-term storage holds a commitment record and a snippet — not the email. See how capture feels in practice on the email capture page.
AI data handling
The AI reads your email as evidence, never as orders.
Extraction runs through a commercial AI API under terms that do not train models on your content. Your forwarded emails make your task list smarter — they never make anyone's model smarter.
Prompt injection gets a plain answer too. A forwarded email is untrusted input, and we treat it that way: the extractor handles email text strictly as data to be analyzed, its output is confined to a rigid commitment schema, and nothing it produces can execute an action, send a message, or become a task without your explicit accept. An email that says “ignore previous instructions” gets the same treatment as one that says “send the deck by Friday” — parsed, scored, and put in front of a human.
What the AI is allowed to do
- Read the forwarded message as data, not instructions
- Output one thing: a structured commitment record
- Attach a confidence score — low scores are dropped
- Wait for your Y/N before anything becomes a task
Not on the list: sending email as you, executing anything, or training on your content. The product never requests send scopes either — follow-up bumps go out from your own address, on your say-so.
Security details
The unglamorous parts, done properly
Smaller mechanisms that matter more than a badge wall.
Signed, single-use action links
Radar reminder emails carry one-tap buttons — Sent it, Got reply, Snooze. Each is a signed, single-purpose token, and none acts on a bare click: a confirm step stands between the link and the change. So when your company's mail scanner prefetches every URL in the message, nothing resolves, snoozes, or completes behind your back.
A capture endpoint that checks credentials
The inbound email webhook verifies the mail provider's cryptographic signature before accepting anything. Random POST requests to the endpoint — a favorite of automated scanners — are turned away unprocessed.
Encrypted in transit
Every connection to LoopVantage — browser, webhook, API — runs over TLS. Data moving between you and us is not readable on the wire.
Managed infrastructure
LoopVantage runs on established managed cloud platforms rather than hand-patched servers — infrastructure hardening, at-rest encryption, and physical security are handled by teams whose entire job is exactly that.
On the roadmap
What we haven't built yet — labeled as such
A trust page that only lists strengths isn't a trust page. Here's what's planned, not shipped.
Opt-in ambient inbox sync
For people who want full autopilot, a read-only inbox connection is planned — as a separate, explicit choice with its own consent screen, never a default and never bundled into sign-in. Forward-based capture remains forever for everyone who'd rather not hand over a mailbox. If we ever ship this, this page will document it with the same specificity as everything above.
SOC 2
We do not hold a SOC 2 certification today, and we won't imply otherwise with a suggestive badge. A formal audit is planned as the Team tier approaches — the point where companies, not just individuals, put their workflows on us.
Self-service data deletion
During early access, full account deletion is handled by request and completed promptly — every record and your capture address, gone. A one-click self-service version is planned so you never have to ask a human to be forgotten.
FAQ
The questions a skeptic asks
Can LoopVantage employees read my email?
What exactly do you store about a forwarded email?
What does deleting my data actually mean?
Which AI provider processes my email, and do they train on it?
Someone finds my capture address. What can they do with it?
Why should I believe any of this?
More on what the product does with all this careful plumbing: the Follow-Up Radar, the daily command center, and pricing — free during early access.
Privacy isn't a settings page here — it's the architecture.
Identity-only sign-in. You forward what matters. Raw email purged. Free during early access.