Your tokens stay server-side
How looft handles your data, your GitHub access, and the widget that runs on your site. This is a plain-language summary; it will be superseded by our full Terms of Service and Privacy Policy.
What we store
looft keeps only what it needs to turn feedback into GitHub issues:
- Your organisation and portal configuration — repo, origin allow-list, labels, theme.
- Your GitHub identity — login, display name, avatar, and email — from “Sign in with GitHub”.
- Each submission as an issue mirror: the description, page URL, selected element, viewport, and the author.
- Screenshots and attachments editors add, stored per-tenant and embedded in the issue you already own on GitHub.
Billing is deferred during early access, so we collect no payment information.
Security model
The widget runs untrusted on your visitors’ browsers, so it holds no long-lived secrets:
- No tokens in the browser. A GitHub App and a single consent authorise looft. Every GitHub call is made server-side; the page only ever holds the public portal key.
- Origin-bound, short-lived access. Widget requests carry a 15-minute JWT pinned to the requesting origin and checked against each portal’s exact origin allow-list on every call.
- Encrypted at rest. GitHub access tokens and portal secrets are sealed with libsodium and never leave the server in the clear.
- Scoped and rate-limited. CORS reflects only allow-listed origins, every tenant’s data is row-scoped, and the widget API is rate-limited per endpoint.
GitHub access
Issues are opened in the editor’s own name using their GitHub authorisation — never a shared bot account — so changes stay inside your existing review and PR workflow. Copilot assignment and issue-status sync use the same App. Uninstalling the GitHub App immediately deactivates your portals; we keep a tombstone of the connection rather than silently retaining access.
Subprocessors
looft relies on GitHub (identity, issues, Copilot) and our hosting and error-monitoring providers. Screenshots and attachments are stored on infrastructure we operate. We do not sell your data or share it beyond what a submission needs to reach your repository.
Retention & deletion
Submissions live as long as the mirrored GitHub issue is useful to you. To export or delete your organisation’s data, or to revoke access entirely, uninstall the GitHub App or contact us and we will remove it.
Terms (early access)
looft is offered as-is during early access, without warranty, while features and this policy evolve. The software and brand are proprietary. Continued use after we publish full terms constitutes acceptance of them.
Contact
Questions about privacy or security? Email hi@betascreen.media. Operator details are on our imprint.
Last updated: 15 January 2026.