The AI task manager that can't read your inbox.

Not “won't.” Can't. LoopVantage holds no inbox permissions to misuse — the only email we ever see is the email you choose to forward. This page walks through exactly how that works, for people who read privacy pages skeptically. Which should be everyone.

No inbox scopes · Raw email purged after extraction · Never trains on your data

The architecture

Privacy by structure, not policy

A policy is a promise. An architecture is a constraint. We built the constraint.

Most AI email tools open with the same request: full read access to your mailbox. Every message you've ever received — offer letters, medical bills, the thread where you vented about your board — synced to their servers, protected by a paragraph in a privacy policy that says trust us. The policy can change. The access already happened.

LoopVantage inverts the model. There is no inbox OAuth scope anywhere in the product. Sign-in with Google or Microsoft requests your identity — name and email address — and nothing else. The consent screen you see at signup is the complete list of what we can touch, and your mailbox is not on it. We could not sync your inbox if we wanted to, and no future policy revision, acquisition, or breach can change that, because the permission simply does not exist.

Instead, you forward or BCC the specific emails that contain real commitments to a private capture address that only accepts mail from you. You decide, message by message, what the AI ever sees. The default is nothing — which is what a default should be.

The usual model

“Grant read access to your entire mailbox”

Every email synced. Relevance decided by their software, after the fact. Your exposure is your whole inbox, forever.

The LoopVantage model

“Sign in” — identity only, then you forward

Relevance decided by you, before we see anything. Your exposure is exactly the emails you chose to send us — briefly, as you'll see below.

Follow the data

The life of a forwarded email

Five steps, from your Sent folder to a tracked commitment — and what exists at the end.

1

It arrives at your private capture address

You forward or BCC an email from Gmail, Outlook, or your phone. The message lands on an inbound webhook that verifies the mail provider's signature before processing a single byte — unauthenticated traffic is rejected at the door.

2

The verified-sender gate drops everything that isn't you

Only mail from your own confirmed addresses is accepted. A stranger, a spammer, or a malicious actor who discovers your capture address can shout into it all day — their mail is discarded without processing. Nobody can inject tasks into your list but you.

3

AI extracts the commitment schema — nothing more

The extractor pulls a structured record: what's owed, by whom, to whom, by when, and how confident it is. Low-confidence guesses are dropped. And nothing becomes a task until you explicitly accept it — the AI proposes, you dispose.

4

The raw email is purged

After extraction, the original message body is deleted from our systems. What persists: the task title, deadline, counterparty, and a short snippet so you have context. The thread about your salary negotiation does not live on our servers — because we threw it away on purpose.

5

Deep links point back to your mailbox — not ours

Every task keeps a link that reopens the source thread in your own Gmail or Outlook. We don't need to keep your email to give you one-click context, because you already have a copy. It's called your inbox.

Net result: for any email you forward, our long-term storage holds a commitment record and a snippet — not the email. See how capture feels in practice on the email capture page.

AI data handling

The AI reads your email as evidence, never as orders.

Extraction runs through a commercial AI API under terms that do not train models on your content. Your forwarded emails make your task list smarter — they never make anyone's model smarter.

Prompt injection gets a plain answer too. A forwarded email is untrusted input, and we treat it that way: the extractor handles email text strictly as data to be analyzed, its output is confined to a rigid commitment schema, and nothing it produces can execute an action, send a message, or become a task without your explicit accept. An email that says “ignore previous instructions” gets the same treatment as one that says “send the deck by Friday” — parsed, scored, and put in front of a human.

What the AI is allowed to do

  • Read the forwarded message as data, not instructions
  • Output one thing: a structured commitment record
  • Attach a confidence score — low scores are dropped
  • Wait for your Y/N before anything becomes a task

Not on the list: sending email as you, executing anything, or training on your content. The product never requests send scopes either — follow-up bumps go out from your own address, on your say-so.

Security details

The unglamorous parts, done properly

Smaller mechanisms that matter more than a badge wall.

Signed, single-use action links

Radar reminder emails carry one-tap buttons — Sent it, Got reply, Snooze. Each is a signed, single-purpose token, and none acts on a bare click: a confirm step stands between the link and the change. So when your company's mail scanner prefetches every URL in the message, nothing resolves, snoozes, or completes behind your back.

A capture endpoint that checks credentials

The inbound email webhook verifies the mail provider's cryptographic signature before accepting anything. Random POST requests to the endpoint — a favorite of automated scanners — are turned away unprocessed.

Encrypted in transit

Every connection to LoopVantage — browser, webhook, API — runs over TLS. Data moving between you and us is not readable on the wire.

Managed infrastructure

LoopVantage runs on established managed cloud platforms rather than hand-patched servers — infrastructure hardening, at-rest encryption, and physical security are handled by teams whose entire job is exactly that.

On the roadmap

What we haven't built yet — labeled as such

A trust page that only lists strengths isn't a trust page. Here's what's planned, not shipped.

Planned

Opt-in ambient inbox sync

For people who want full autopilot, a read-only inbox connection is planned — as a separate, explicit choice with its own consent screen, never a default and never bundled into sign-in. Forward-based capture remains forever for everyone who'd rather not hand over a mailbox. If we ever ship this, this page will document it with the same specificity as everything above.

Planned

SOC 2

We do not hold a SOC 2 certification today, and we won't imply otherwise with a suggestive badge. A formal audit is planned as the Team tier approaches — the point where companies, not just individuals, put their workflows on us.

Planned

Self-service data deletion

During early access, full account deletion is handled by request and completed promptly — every record and your capture address, gone. A one-click self-service version is planned so you never have to ask a human to be forgotten.

FAQ

The questions a skeptic asks

Can LoopVantage employees read my email?

There is no inbox to read — you never connect one. What exists on our side is the email you forwarded, for the short window between arrival and purge, and after that only the extracted record and snippet. There is no employee tool for browsing message content, and the deep link on every task points into yourmailbox, not a copy of ours — because we don't keep one.

What exactly do you store about a forwarded email?

The extracted commitment — title, type, deadline, counterparty — plus the subject line, a short snippet for context, and a deep link back to the thread in your own Gmail or Outlook. The raw message body is purged after extraction. Attachments follow the same rule: we are a commitment tracker, not a file archive.

What does deleting my data actually mean?

Deleting a task removes its extraction and snippet. Deleting your account removes everything — tasks, radar items, snippets, your capture address — so mail sent to that address afterward goes nowhere. During early access, account deletion is by request; one-click self-service is planned. Note the head start: the most sensitive material, raw email, was already purged in normal operation before you asked.

Which AI provider processes my email, and do they train on it?

Extraction runs on Anthropic's Claude models via their commercial API, which does not train on API data. Neither do we. Your forwarded emails improve your task list and nothing else — no model, ours or anyone's, learns from your content.

Someone finds my capture address. What can they do with it?

Waste their own time. The capture address only accepts mail from your verified sender addresses; anything else is discarded before processing. And even a spoofed message that somehow produced a candidate task would still hit the human gate — nothing enters your list without your explicit accept.

Why should I believe any of this?

Fair. Two things are checkable today: the OAuth consent screen at sign-in shows identity-only scopes — Google and Microsoft render that screen, not us — and the product visibly has no “connect your inbox” step to grant more. The rest is architecture we've described specifically enough to be held to. Try it with one forwarded email and see what shows up: a commitment, a snippet, and a link back to your own mailbox.

More on what the product does with all this careful plumbing: the Follow-Up Radar, the daily command center, and pricing — free during early access.

Privacy isn't a settings page here — it's the architecture.

Identity-only sign-in. You forward what matters. Raw email purged. Free during early access.