← Back to Loopback
⚠️ DRAFT — starting template only. Have a qualified lawyer / DPO review and complete the [bracketed] placeholders before publishing.

Privacy Policy

Last updated: [DATE] · Data controller: [COMPANY LEGAL NAME], [ADDRESS], [CONTACT].

1. What we collect

2. Tunnelled traffic

Loopback proxies traffic between the internet and your local app. We process this traffic transiently to deliver the Service; the inspector temporarily stores recent requests/responses (default ~3h) so you can debug them. We do not use your tunnelled content for any other purpose.

3. How we use data

To operate, secure, and improve the Service; to enforce limits and the AUP; to communicate about your account; and to comply with law. We do not sell your data.

4. Retention

Account data is kept while your account is active. Inspector captures expire automatically (~3h). [Other log retention periods.] You may request deletion of your account data.

5. Sharing

With service providers that host/operate the platform (e.g., our VPS/DNS/TLS providers), under appropriate safeguards; and where required by law. [List sub-processors.]

6. Security

TLS in transit, hashed credentials, scoped/revocable API keys, IP allow/deny and rate limiting, and least-privilege access. No method is 100% secure.

7. Your rights

Depending on your jurisdiction (e.g., GDPR/DPDP), you may access, correct, export, or delete your data, and object to certain processing. Contact [privacy@your-domain].

8. International transfers & children

Data may be processed in [COUNTRIES] under appropriate safeguards. The Service is not directed to children under [AGE].

9. Changes & contact

We may update this policy; changes are posted here. Questions: [privacy@your-domain].