Loot is a creative production tool built and operated by KPG Media Ltd. This page explains what data Loot collects when you use it, why we collect it, and what you can do about it.
Your email address and name. We get these when you sign in with Google (which also gives us your Google profile name, but no other Google data) or via a magic-link email. We store them so we can identify you across sessions and show who made what comment or edit.
Briefs, shot lists, captions, comments, mentions, moodboards, schedules — everything you type into Loot. Uploaded media (images, video, audio) is stored in Cloudflare R2; the rest lives in our Postgres database in Ireland (Supabase, eu-west-1).
Your role in each workspace you join, who invited you, and when you were last active.
If you invite a client or teammate by email, we store that email address so the invite can be delivered and matched to them when they accept. If they never join, the address is only used for that invite.
Someone reviewing a shared link without an account gives us a display name (so their comments and approvals are attributed) and holds a temporary session that ends when they close their browser. That's all we hold about a guest.
When you open a brief or content set, Loot records the timestamp you started and last interacted with it. Workspace owners and admins can see this in the Activity panel; nobody else. We don't track the specific section you were looking at, your mouse position, or anything you didn't already type into a comment or caption.
If a search on the Help & guide page finds nothing, you can press a button to send us what you were looking for, plus an optional note. We store only that text, which workspace it came from, and whether you were reading the team or client guide — never who pressed it, and we can't tie it back to you. We read these to write new answers for that page. Nothing is recorded unless you press the button; we don't log what you type as you type it.
Server logs (request paths, timing, error traces) for debugging. Pruned after 30 days. Not joined with your user-facing data for any analytics purpose.
No mouse-tracking, no analytics tools (no Google Analytics, no Mixpanel, no Plausible), no advertising trackers, no behavioural fingerprinting. We don't sell, rent, or share your data with marketing partners. We don't use your content to train AI models, ours or anyone else's. If you choose to connect an external AI tool yourself, that tool's own terms apply to whatever it reads — see Connecting an AI agent.
We pick vendors that are GDPR-aligned. Data processing agreements are in place with each.
Only members of your workspace, scoped by their role and any per-resource access you grant. Anyone with a share-link URL you publish can see whatever that link covers — sharing those links carefully is your responsibility. Workspace owners and admins can additionally see the Activity log for resources in their workspace.
Loot can connect to external AI tools — Notion's agents, Claude, and similar — so they can read your briefs where you already work. This is off by default. Nothing reaches an AI tool unless someone on your team deliberately creates an access token in Settings → Integrations and pastes it into that tool.
Only workspace owners, admins and editors can create one. A token carries that person's own access and nothing more, is limited to a single workspace, and can be revoked at any time from the same screen — revoking takes effect immediately.
When a connection is active, these sections of a brief can be read by the connected tool: concept, script, shot list, moodboard, schedule, props, links, post-production notes, and content-set captions and review comments.
These never leave, whatever is connected: call sheets, talent details, permits, budgets and contracts — the sections that hold personal contact details and commercial terms. Any individual brief can also be excluded entirely from its ⋯ menu. Connected tools can only read; they cannot change anything in Loot, approve content, or send messages on your behalf.
One thing to be clear about: once your content reaches a third-party AI tool, that vendor's privacy terms govern what happens to it, including whether it is retained or used for model training. Our commitments above cover what we do with your content, and we have no control over a tool you connect yourself. If your briefs contain client material, check that vendor's terms before connecting, and treat enabling it as your decision to make.
Loot sets only cookies the product needs to work — the kind UK and EU law classes as strictly necessary, which is why you don't see a consent banner:
Your browser's local storage additionally remembers interface preferences (theme, view modes) on your own device — that data never leaves it. No tracking cookies, no analytics cookies, no third-party or advertising cookies, on this site or the app. If that ever changes we'll ask for consent first.
Content lives as long as your workspace wants it: deleting an item moves it to a trash that's emptied after 14 days, and files no longer referenced by anything are permanently purged on a weekly sweep. If you delete your account, we remove your personal data within 30 days; content you created inside a workspace belongs to that workspace and stays with it, attributed to a deactivated account. Server logs are pruned after 30 days. Questions sent from the Help page are kept until we've written an answer for them, and carry nothing that identifies who sent them.
We process account and content data because it's necessary to provide the service you signed up for (performance of a contract), and operational data — logs, security, service emails like invites and review notifications — under legitimate interest in running Loot reliably and securely. Questions you send from the Help page are processed under that same legitimate interest, in improving the product; they carry no identifier, so they can't be traced back to you. We don't send marketing email.
Your database records stay in the EU (Ireland) and the app is served from London. Some vendors — email delivery in particular — process data in the United States under standard contractual clauses and the UK–US data bridge.
Under UK and EU data-protection law you can request a copy of your data, ask us to delete your account, or have us correct anything inaccurate. Email kashyapgaddam@kpg-media.com and we'll respond within 30 days. If you're unhappy with how we handle your data you can complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU authority.
Loot isn't intended for anyone under 16.
If we change anything material here, we'll email active users before the change takes effect. The "Last updated" date at the top of this page always reflects the most recent change.
KPG Media Ltd
kashyapgaddam@kpg-media.com