PRIVACY ARCHITECTURE

Store less.
Protect more.

LoopBar is designed so its own database never needs your password, card number, bank details, identity documents, prompts, or AI answers.

What LoopBar stores

  • A random extension device identifier.
  • Verified ad-impression amounts, first-click timestamps, and the 50/50 revenue ledger.
  • Pseudonymous payout-provider and transfer identifiers.
  • Account identity as a secret-keyed one-way fingerprint—not a readable login email address.
  • A hashed, short-lived website session token. Raw session tokens remain in secure HttpOnly cookies.
  • A PayPal email address or Venmo U.S. mobile number encrypted with AES-256-GCM only when you choose that payout method. LoopBar also stores a masked display hint and a secret-keyed fingerprint to prevent duplicate reward accounts.
  • Approved loading-banner and right-rail campaign artwork in isolated object storage, plus the destination and placement needed to deliver the campaign. Campaign artwork must not contain personal data.
  • Short-lived pairing-code hashes. Raw codes expire after ten minutes and can be used once.

What stays elsewhere

Supabase Auth stores your login email, authentication record, and password verifier; LoopBar never receives or stores your password. Cloudflare Turnstile may process network and browser signals when enabled on account-access forms to distinguish people from abusive automated traffic. LoopBar briefly relays the single-use challenge token to Supabase Auth for verification but does not retain it. Zoho processes messages sent to LoopBar’s public support and advertising inboxes. Stripe-hosted pages handle payout identity, bank, card, and Stripe Connect details. PayPal processes PayPal and Venmo payouts and may require recipient verification. LoopBar receives only the identifiers and status needed to operate the account ledger and detect duplicate payout identities.

Cookies and public-site analytics

LoopBar currently uses only strictly necessary, secure cookies for signed-in account and operator sessions. The public website does not install advertising cookies, cross-site trackers, or a third-party audience-analytics script, so it does not show a consent banner that would imply optional tracking exists. If optional analytics or marketing cookies are introduced, LoopBar will update this notice and add consent controls before they load where required.

AI and advertising data

The extension detects brief loading-state labels locally. It does not send prompts or answers to LoopBar. Ad requests contain a random device identifier and placement information, not conversation content. LoopBar records whether a sponsored banner received its first click, but does not build or sell browsing histories. Users choose Loading banner, Right Sponsor Rail, or Both in their account, and the persistent placement is removable and limited to active chat pages.

PlayaYield test integration

LoopBar 1.6.28 bundles the PlayaYield SDK for a test-only 320×50 advertisement inside the extension popup and requests test-only 320×50 loading and 300×250 right-rail units using PlayaYield’s required content-script placement. Page inventory remains fail-closed unless PlayaYield approves that extension placement; LoopBar shows a clearly labeled $0 test fallback after denial, timeout, invalid output, or creative failure. It runs only when sponsored banners are enabled. PlayaYield may receive the extension identifier, requested placement and size, IP address, browser or device details, and availability, impression, click, or other test-ad interaction data needed to deliver and validate that unit. The publishable test key creates no payable advertising revenue or LoopBar Wallet credit. LoopBar requests access only to www.playayield.com for this test-ad delivery and tracking. See PlayaYield’s Privacy Policy.

Retention, deletion, and control

Expired pairing and website-session records can be removed automatically. Financial records are retained only as needed for reconciliation, fraud prevention, accounting, tax, refunds, disputes, security, and legal obligations. Sign in and choose Request account deletion, or email support@loopbar.co from the account address. LoopBar will delete or de-identify data that is not required to be retained and will include the Supabase authentication record in the process.

Your choices

You may disable all sponsor banners from the extension, select Loading banner, Right Sponsor Rail, or Both in your account, dismiss an individual banner, unlink browsers, request access or correction, and request account deletion. LoopBar does not use prompts, answers, or browsing histories for personalized or retargeted advertising.

This page describes the implemented architecture. Final commercial launch still requires jurisdiction-specific legal review and published retention periods.