Questions about any of this? contact@theloopboard.com
Terms of Use
LAST UPDATED 26 SEPTEMBER 2026 · APPLIES TO LOOPBOARD 1.0.0 AND THELOOPBOARD.COM
Questions about any of this? contact@theloopboard.com
LAST UPDATED 26 SEPTEMBER 2026 · APPLIES TO LOOPBOARD 1.0.0 AND THELOOPBOARD.COM
Questions about any of this? contact@theloopboard.com
LAST UPDATED 26 SEPTEMBER 2026 · APPLIES TO LOOPBOARD 1.0.0 AND THELOOPBOARD.COM
The short version. LoopBoard has no accounts, no analytics, no telemetry and no crash reporting. Your boards, images, videos and recordings never leave your computer. We have no server that receives them and no technical way to see them. The app makes network requests in only five situations, all of them things you triggered directly. Each one is listed below with exactly what it sends and to whom.
What changed on 26 September 2026. This policy now applies to LoopBoard 1.0. Section 3 now explains that LoopBoard only ever edits its own copies of your files, how file cards store the location of files on your computer, how leftover temporary files are cleaned up, and what may remain from an earlier .exe installation after you uninstall a Microsoft Store copy. Section 4(a) now describes the exact YouTube address LoopBoard sends, and section 4 now explains what pasting does. Section 5 now covers copying cards between boards. Nothing changed in what the application collects or sends, which is still nothing.
What changed on 23 September 2026. LoopBoard is now distributed through the Microsoft Store. Section 3 now refers to copies installed with the .exe installer instead of copies installed from this website.
What changed on 19 September 2026. Added what applies if you install LoopBoard from the Microsoft Store: where your files are stored, what happens when you uninstall, the Windows permission prompts, and what Microsoft shares with us (sections 1, 2, 3, 5 and 11). Nothing changed in what the application itself collects or sends, which is still nothing.
LoopBoard is made and distributed by Rayyan Burondkar, an individual trading as LoopBoard, of Dapoli, District Ratnagiri, Maharashtra, India. For the purposes of India’s Digital Personal Data Protection Act, 2023, that individual is the Data Fiduciary for the limited personal data described in this policy. Where the EU or UK General Data Protection Regulation applies, the same individual is the data controller. On the Microsoft Store, LoopBoard is published under the publisher name Artris, which is the same individual.
Contact for any privacy question, request or complaint: privacy@theloopboard.com. That address also reaches the person responsible for answering grievances about how personal data is handled. A postal address will be supplied on request to anyone who needs it for a legal or regulatory purpose.
This policy covers the LoopBoard desktop application and the website at theloopboard.com.
From the application: nothing.
There is no account system, no sign-in, no licence key and no device identifier. LoopBoard contains no analytics SDK, no telemetry, no crash reporter and no usage tracking of any kind. It does not phone home on launch, on a schedule, or ever. It does not check for updates.
This is verifiable rather than a promise: the only outbound network requests the application can make are the five described in section 4, and every one of them is a direct result of an action you took.
From the website and from email: a small amount, described in sections 7 and 8.
If you install LoopBoard from the Microsoft Store: Microsoft, not LoopBoard, handles the download, installation and updates, under Microsoft’s privacy statement. Microsoft gives publishers aggregate reports about their apps, such as install counts, ratings and reviews, and, depending on your Windows diagnostic data settings, crash and hang reports collected by Windows. We see these reports in aggregate form and use them only to fix problems and improve LoopBoard. They do not contain your boards or their contents, and we cannot use them to identify you. The LoopBoard application itself still sends us nothing.
Everything LoopBoard stores, it stores on your own computer. On Windows, in your user data folder:
%APPDATA%\LoopBoard\
├── loopboard.sqlite your boards, items, positions and settings
└── media\<board-id>\
├── originals\ copies of the files you imported, and any trimmed or cropped versions
├── proxies\ compressed copies used for smooth playback
└── thumbnails\ small preview images
%APPDATA% usually resolves to C:\Users\<your name>\AppData\Roaming.
LoopBoard only edits its own copies. When you import a file, LoopBoard copies it into this folder. Trimming, cropping, rotating and flipping work on that copy. The file you imported from is never changed.
If you installed LoopBoard from the Microsoft Store, Windows keeps the same folder inside the app’s own package storage instead, usually %LOCALAPPDATA%\Packages\Artris.LoopBoard_vzw2h08cejcea\LocalCache\Roaming\LoopBoard\. It is still only on your computer. If a %APPDATA%\LoopBoard folder already existed on your computer from the .exe version, Windows may let the Store version keep using and updating the files already in it, including the board database. New media files that the Store version creates are normally kept in the package storage above.
File cards. When you add a file that LoopBoard cannot display, such as a PDF, a PSD or a project file, the board stores that file’s name and its location on your computer so the card can open it. The file itself is not copied into LoopBoard. When you export a board, these locations are removed; the file names are kept, so rename a file first if its name contains something you would rather not share. Opening a file card asks Windows to open the file in its usual app; for some file types that can run programs, LoopBoard asks you to confirm first.
Temporary files. While downloading, recording or pasting, LoopBoard writes to your operating system’s temporary folder in directories named lb-dl-…, loopboard-rec-…, loopboard-clip-… and loopboard-url-…. These are deleted when the operation finishes. If the app is closed during a download or an import, the folder may be left behind; the next time LoopBoard starts, it deletes any lb-dl-…, loopboard-clip-… or loopboard-url-… folder that has been left over for more than an hour. Unfinished screen recordings (loopboard-rec-…) are not deleted by LoopBoard. Windows may clear them, depending on your storage settings, or you can delete them yourself.
Preferences. A few small settings are stored locally by the application: your theme choice, how many videos may play at once, the auto-loop length threshold, and whether you dismissed the click-through warning. No personal data is kept in them.
Deleting everything. If you installed LoopBoard with the .exe installer, uninstalling it does not remove your boards. To delete them completely, uninstall the app and then delete the %APPDATA%\LoopBoard folder. If you installed LoopBoard from the Microsoft Store, uninstalling it normally deletes the boards and media it stored in its package storage, so export any board you want to keep as a .loopboard file first. If you used the .exe version on the same computer before, some data, including boards the Store version saved into the existing database, may remain in %APPDATA%\LoopBoard; delete that folder to remove it. Either way, once it is deleted it is gone. We hold no copy and cannot restore it.
LoopBoard makes outbound network requests in exactly five situations. All are triggered by something you did. None of them sends us anything, and none of them sends your board contents anywhere.
a) Adding a YouTube link card. LoopBoard asks YouTube’s public oEmbed service for that video’s title and thumbnail, by requesting https://www.youtube.com/oembed?url=<the video’s standard YouTube address>. The standard address is rebuilt from the link you added, in the form https://www.youtube.com/watch?v=<video id>, so any extra tracking parameters in your link are not sent. YouTube receives that video address and, as with any web request, your IP address.
b) Adding any other link card. LoopBoard fetches that page once to read its title and preview image from its og: tags. The request identifies itself with a facebookexternalhit user-agent, the common identifier for link-preview fetchers. That website receives the URL you entered and your IP address.
c) Saving a link card’s preview image. If a preview image was found in (a) or (b), LoopBoard downloads it and stores it locally as the card’s thumbnail. This is a request to whichever server hosts that image.
d) Dragging an image from a web page onto a board. When the dragged item is a web URL rather than a local file, LoopBoard fetches that image so it can be saved to your board. It tries twice, first identifying as a normal desktop browser with a referer from the image’s own site, then as a link-preview fetcher, because many sites block one or the other. That site receives the image URL and your IP address.
e) Downloading video or audio from a link. LoopBoard runs yt-dlp, a separate open-source program bundled with it, which contacts the video site directly to fetch the media. That site sees the request the same way it would see any other download client. This traffic goes between yt-dlp and that site; it does not pass through us. LoopBoard sends no credentials, cookies or browser session data with these requests. See the Copyright and acceptable use page.
Opening links. Buttons that open a website (footer links, social links, a link card’s “open” button) hand the URL to your default browser. LoopBoard itself makes no request; from that point your browser and its own settings apply.
Pasting. Pasting a web address into a board creates a link card, which is (a) or (b) above, followed by (c). Pasting an image you copied, or files from your computer, saves them locally and makes no network request.
No request in this list goes to a server we operate. We have no application server. Copying and pasting cards, including between boards, happens entirely on your computer and makes no network request.
These are all local to your machine. Nothing obtained through them is transmitted anywhere.
__loopboard_clip__). Nothing is kept after you close LoopBoard or copy something else.The Settings panel has a “Copy diagnostics” button. It gathers your LoopBoard version, operating system and version, processor architecture, Electron/Chromium/Node versions and a GPU identifier, and copies them to your clipboard. It does not send them anywhere.
They reach us only if you choose to paste them into an email. They contain no personal data and nothing about your boards.
theloopboard.com is hosted on Cloudflare (currently our hosting and content-delivery provider).
As a hosting and content-delivery provider, Cloudflare processes technical connection information for every visitor, including your IP address, user-agent string and the pages requested, in order to route traffic and protect the site from abuse. Cloudflare may set a __cf_bm cookie for bot management. This processing is Cloudflare’s, as our service provider, and is covered by Cloudflare’s privacy policy.
Cloudflare Web Analytics. We use Cloudflare Web Analytics to see how many people visit the site and which pages they look at. It is privacy-first by design: it sets no cookies, does not fingerprint your device, and does not track you across sites or across separate visits. It records the page requested, the referring page, approximate country, and general browser, operating system and device type. We see aggregate totals only. We cannot identify individual visitors, and we cannot follow one person from page to page or from one visit to the next.
We do not run advertising, third-party trackers, or cross-site tracking on this website. We do not sell, rent or share visitor data with anyone, and we do not use it to make any decision about you.
If you email us (a bug report, a question, a source-code request or a copyright concern), we receive your email address, whatever you write, and anything you attach. Our mailbox is currently hosted by Google.
We use it only to reply and to deal with what you raised. We do not add you to a mailing list and we do not use your address for anything else.
Bug reports sent through the app’s “Report a problem” button open your own email client with a pre-filled subject line containing the version number. Nothing is sent until you press send, and you can see and edit everything first.
Where the EU or UK GDPR applies to a particular person’s data, our legal bases are:
| Correspondence you send us | Legitimate interests: answering people who contact us, and keeping a record of what was asked and answered. |
|---|---|
| Website connection logs and abuse prevention | Legitimate interests: serving the site and keeping it available and secure. |
| Aggregate website analytics | Legitimate interests: understanding in aggregate how the site is used. No cookies are set and no individual is identified. |
| Anything required of us by law | Legal obligation. |
Under India’s Digital Personal Data Protection Act, 2023, we process this data for the specified purposes set out above, on the basis of the consent you give by contacting us or, where applicable, for the legitimate uses the Act permits.
| Email correspondence | Up to 24 months after the exchange ends, then deleted, except where we need to keep it longer to deal with a legal claim or to comply with a legal obligation. |
|---|---|
| Source-code requests under the GPL | Kept for as long as the written offer on the licenses page remains open, because the offer is a commitment we may need to evidence. |
| Copyright and rights correspondence | Up to 5 years, because these may need to be produced later. |
| Website connection logs | Retained by Cloudflare on its own schedule, under its policy, not ours. |
| Aggregate analytics | Retained in aggregate form only; no individual record exists to delete. |
We do not sell, rent or trade personal data, and we never will.
The only third parties who touch any of it are the service providers we use to run the site and our mailbox: currently Cloudflare (hosting, content delivery, aggregate analytics) and Google (email). They process it on our behalf, for those purposes only. If you install LoopBoard from the Microsoft Store, Microsoft processes your Store activity as described in section 2, under its own privacy statement.
We may also disclose personal data where we are legally required to, or where it is necessary to establish, exercise or defend a legal claim. If that ever happens we will tell the person concerned unless we are prohibited from doing so.
Because we are in India and these providers operate globally, data handled through them may be processed outside your country. We choose established providers that publish their own safeguards for such transfers.
The application holds your data on your own machine, under your own operating system’s protections. We do not hold it, which removes the single largest risk to it.
For the little we do hold, which is essentially correspondence, we use reputable providers, keep access limited to the developer, and do not copy it anywhere it does not need to be. No system is perfectly secure, and we do not claim otherwise.
If there is a breach affecting personal data we hold, we will notify the people affected and the relevant authority without undue delay and within the periods the applicable law requires.
LoopBoard is not intended for or directed at children under 13, and the application collects no personal data from anyone, of any age.
Indian law treats anyone under 18 as a child for data-protection purposes and requires verifiable parental consent before their personal data is processed. Because the application processes none, this arises only if someone under 18 emails us or visits the site. If you are under 18, please do not email us without a parent or guardian’s involvement, and read the Terms of Use with them.
If we learn we hold personal data of a child without the consent the law requires, we will delete it.
Because the application collects no personal data, there is nothing held about you through it for us to disclose, correct or delete.
For the limited personal data that does exist (correspondence you sent us, and the connection logs our hosting provider keeps), you may ask us to confirm what we hold, to give you a copy, to correct it, to delete it, to restrict or object to how we use it, and, where it applies, to receive it in a portable form. You may also withdraw any consent you gave, without affecting what was done before you withdrew it.
Write to privacy@theloopboard.com. We will acknowledge within 5 working days and respond substantively within 30 days. We do not charge for this.
If you are not satisfied with how we have handled a privacy matter, you may complain to the Data Protection Board of India or, if you are in the EU or UK, to your local supervisory authority. We would rather you came to us first so we can put it right.
The current version is entirely local, and this policy describes exactly that.
We may in future offer optional cloud storage or sync. Such a feature would by definition involve sending your data off your device. If it is built:
We may update this policy. The “last updated” date at the top always reflects the current version, and the current version is the one published at this address. Material changes will be noted on this page.
Privacy questions, requests and complaints: privacy@theloopboard.com
Everything else: contact@theloopboard.com
Questions about any of this? contact@theloopboard.com