Privacy Policy

last updated · september 17, 2026

This Privacy Policy explains how Commonplane, Inc. ("Commonplane," "we," "us") collects, uses, and shares information in connection with the Perfloop website at perfloop.ai (the "Site") and the Perfloop product and services (the "Service"). Perfloop is a product of Commonplane, Inc.

Who we are

For the Site and for personal information about prospective customers and website visitors, Commonplane, Inc. is the data controller. For personal information in customer source code, session records, or telemetry that the Service processes on a customer's behalf, the customer is generally the controller and Commonplane is the processor. That processing is governed by the customer's agreement and, where applicable, a Data Processing Addendum. It is described in detail on our Security & Data Access page.

Information we collect

Information you provide. When you request early access or contact us, we collect your email address and any information you choose to include, such as the workload or repository you describe. If you create a Perfloop account, we collect identifiers such as your name and email through our authentication provider. An early-access submission also includes its page URL, referrer, campaign attribution, time, and browser user agent.

Information collected automatically. When you visit the Site, our hosting infrastructure records standard technical data — IP address, referring URL, the pages you request, and browser and device type — in server logs. The Site does not use advertising or cross-site tracking cookies.

Customer data. When a customer connects a repository or telemetry source, the Service accesses and processes that data as set out on our Security page. For Axiom, the customer submits exact dataset or saved-view names and a query-only token. Perfloop can read field names and types and time-bounded aggregate results, including grouping values authorized by that scope. Connected telemetry sources can return metric labels and values, log aggregates, sampled stacks, function and file names, build identifiers, profile labels, and selected profile files. Loki queries can also return log text within set time and size limits. The Service can retain account and tenant records, connection scope, encrypted connection credentials, repository metadata, query definitions and captured results, session transcripts, tool records, proposed changes, proof artifacts, and operational telemetry.

How we use information

We use personal information to:

  • respond to your inquiries and provide access to the Service;
  • operate, maintain, secure, and improve the Site and Service;
  • authenticate users and protect against fraud, abuse, and security incidents;
  • communicate with you about early access and product updates;
  • comply with legal obligations and enforce our terms.

We do not sell your personal information. We do not use customer code or telemetry to train AI models. Selected customer content can be sent to the approved model providers listed below. OpenAI Responses requests set store=false; the provider's account terms and abuse-monitoring retention can still apply. Details are on the Security page.

Legal bases (EEA and UK)

Where the GDPR or UK GDPR applies, we rely on: your consent (for example, marketing emails); our legitimate interests in operating and securing the Site and Service and in responding to you; performance of a contract where you are a customer; and compliance with legal obligations. You may withdraw consent at any time.

How we share information

We share personal information only with service providers that process it on our behalf, under contract and only as needed to run the Site and Service:

  • Google Cloud Platform — hosting of the Service and Vertex AI model inference for controller and operator tasks.
  • OpenAI — model inference for case, triage, and model-build sessions. Requests set store=false; OpenAI's applicable retention terms still apply.
  • WorkOS — user authentication, identity, and early-access waitlist records and email.
  • Axiom — operational logs, traces, and metrics. A tenant setting that is off by default can enable diagnostic capture of customer or source-derived agent content. Perfloop also queries a customer's Axiom account when the customer connects it.
  • Vercel — hosting and access logs for the Site.
  • Slack — operator alerts for new early-access requests and customer support communications.
  • Email and business-operations services — the systems we use to receive and respond to inquiries.

We may also disclose information where required by law or legal process, or to protect rights, safety, and security; and in connection with a merger, acquisition, or sale of assets, subject to this Policy. A current subprocessor list for the Service is available on request.

International transfers

We are based in the United States. We and our providers can process information in the United States and other countries. Where required, we use the transfer safeguards in our provider and customer agreements. These can include the Standard Contractual Clauses.

Data retention

We retain personal information for as long as needed for the purposes described here — to maintain your account or respond to you — and as required by law. Marketing contacts are retained until you unsubscribe or ask us to delete them. Customer-data retention for the Service is specified in the data-access contract on the Security page.

Security

We protect information with the technical and organizational measures described on our Security page, including encryption in transit and at rest, least-privilege access, and a contained agent-execution architecture. No method of transmission or storage is completely secure.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to the processing of your personal information, and to withdraw consent.

  • EEA, UK, Switzerland: you may exercise the GDPR rights above and lodge a complaint with your supervisory authority.
  • California, where applicable: you may request to know, access, correct, and delete personal information. We do not sell or "share" personal information for cross-context behavioral advertising, and we will not discriminate against you for exercising your rights.

To exercise any right, email privacy@perfloop.ai. We will verify your request and respond as required by law.

Cookies

The Site does not use advertising or cross-site tracking cookies. The authenticated Service can use cookies that are necessary for sign-in, session security, and related product functions.

Children

The Site and Service are not directed to children under 16, and we do not knowingly collect personal information from them.

Changes

We may update this Policy. We will post the updated version with a new "last updated" date and, where appropriate, provide additional notice.

Contact

Commonplane, Inc.
2093 Philadelphia Pike #9449
Claymont, DE 19703
privacy@perfloop.ai