Privacy policy
1. Controller & contact
The data controller responsible for this website and the loop me in platform is:
Strana UG (haftungsbeschränkt)
Schackstr. 1 // c/o Kleinhempel & Partner
80539 München, Germany
Email: hello@strana.ai
Managing directors: Jakob Riegger, Guilherme Coelho
For privacy-related inquiries, please contact privacy@strana.ai.
2. Data we collect
Account information
When you create an account, we collect your email address, your password (stored hashed — we cannot read it), and the profile details you choose to add, such as your name, handle, and areas of expertise. If you sign in with Google, we receive your email address and basic profile information from Google instead of a password.
Content you submit
The requests, answers, and messages you exchange through loop me in — including any context your coding agent shares as part of a request — are stored so we can deliver them to the expert you loop in and show you your history.
Usage & technical data
Like almost every website, our servers keep short-lived logs (IP address, browser type, device information, requested pages) to keep the service secure and diagnose problems.
When measurement technologies are enabled, Google Analytics and Meta may also receive information such as pages viewed, interactions, referral information, approximate location, browser and device information, online identifiers, and your consent status. For conversion measurement, Meta may receive signup, checkout, and purchase events together with matching information such as a hashed email address, IP address, user agent, and Meta cookie identifiers where available.
Payment information
Wallet top-ups and expert payouts are processed by our payment provider, Stripe. Your card or bank details go directly to Stripe and are not stored on our servers. We keep records of transactions (amounts, dates, balances) to run the service and to satisfy bookkeeping laws.
3. How we use your data
- Service delivery: to provide, operate, and maintain the loop me in platform — connecting your requests with experts, delivering answers, and managing wallets and payouts.
- Communications: to send you service-related notifications (for example when an expert answers your request), respond to inquiries, and, only with your consent, marketing communications.
- Security & fraud prevention: to detect, prevent, and address technical issues, security threats, and fraudulent activity.
- Analytics & attribution: to understand how the website and platform are used, improve the service, and measure signups, checkout activity, purchases, and the effectiveness of campaigns.
- Legal compliance: to comply with applicable laws, regulations, and legal processes.
We use the analytics and advertising measurement technologies described in Section 10. We do not sell your personal data.
4. Legal basis for processing
We process your personal data under the following legal bases (Art. 6 GDPR):
- Performance of contract (Art. 6(1)(b)): processing necessary to provide our services — account management, delivering requests and answers, and platform access.
- Consent (Art. 6(1)(a)): for marketing communications and optional analytics or advertising technologies where consent is required. You may withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)): for service improvement, security measures, fraud prevention, and limited measurement where permitted, provided our interests do not override your fundamental rights.
- Legal obligation (Art. 6(1)(c)): where processing is required to comply with tax, accounting, or other legal requirements.
5. Your content & AI
loop me in connects AI coding agents with human experts. Here is how your content is handled:
- Shared with your expert: the content of a request is shared with the expert who takes it on — that is the point of the service. It is not shared with other experts or customers.
- No AI training: we do not use your requests, answers, or any other content to train AI models.
- You control the context: you and your agent decide what to include in a request. Please avoid sharing secrets or credentials in requests.
6. Data sharing & service providers
We do not sell your personal data. We share data only as necessary with the following categories of service providers:
- Cloud infrastructure — Amazon Web Services (AWS): hosting and data storage within the European Union.
- Payment processing — Stripe: wallet top-ups and expert payouts, with data stored in EU and US data centers. Stripe is certified under the EU-US Data Privacy Framework.
- Sign-in — Google: only if you choose to sign in with your Google account.
- Analytics — Google Analytics: website and platform usage measurement, including page views, interactions, session statistics, approximate location, and browser or device information.
- Advertising measurement — Meta: the Meta Pixel and Conversions API measure page views, account registrations, checkout activity, and purchases and help attribute those events to campaigns.
Where a provider processes personal data on our behalf, the relationship is governed by applicable data processing terms and safeguards. For details, see our Data Processing Agreement.
7. International data transfers
Your data is primarily processed within the European Union. Where transfers to third countries are necessary:
- Standard Contractual Clauses (SCCs): where data is transferred outside the EU/EEA, we rely on European Commission-approved Standard Contractual Clauses (Art. 46(2)(c) GDPR).
- EU-US Data Privacy Framework: for transfers to US-based sub-processors, including Stripe, Google, and Meta, we additionally rely on the EU-US Data Privacy Framework adequacy decision where applicable.
8. Data retention
We retain your data only as long as necessary for the purposes for which it was collected:
- Account data: retained for the duration of your account plus 30 days after deletion for data export.
- Requests & messages: retained while your account is active; deleted within 30 days of account termination or upon your request.
- Payment records: retained for 10 years as required by German tax law (AO §147).
- Usage logs: anonymized or deleted after 90 days.
- Analytics & advertising measurement data: retained under our applicable account settings and the providers' retention policies, and only for as long as needed for measurement and attribution. Aggregated or de-identified reports may be retained for longer.
- Backup data: removed from backups within 90 days of deletion from production systems.
9. Your rights under GDPR
Under the General Data Protection Regulation, you have the following rights:
- Right of access (Art. 15): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): request deletion of your personal data ("right to be forgotten").
- Right to restriction (Art. 18): request restriction of processing in certain circumstances.
- Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent (Art. 7(3)): withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@strana.ai. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
10. Cookies & tracking
Necessary storage
We use session and security storage that is necessary to keep you signed in, protect the service, and remember your tracking preference.
Google Analytics
We use Google Analytics to measure visits and interactions and improve the service. When analytics storage is granted, Google Analytics may set first-party identifiers such as the _ga cookie to distinguish users and sessions. When storage is denied, Google Consent Mode prevents analytics and advertising cookies from being read or written, but Google may still receive cookieless consent signals and measurements for aggregated reporting and modeling. See the Google Privacy Policy.
Meta measurement
We use the Meta Pixel and Meta Conversions API to measure page views and conversion events such as registration, checkout, and purchase. Depending on the event and your available identifiers, Meta may receive event details, browser or device information, IP address, user agent, Meta cookie identifiers, and a hashed email address. See the Meta Privacy Policy.
Your choices
We store your choice in a cookie_consent cookie for one year. Where the consent banner is shown, accepting enables analytics and advertising storage; denying keeps that storage disabled. You can also block or delete cookies through your browser settings. Deleting the preference cookie may cause the banner to appear again.
11. Security measures
We implement appropriate technical and organizational measures to protect your data (Art. 32 GDPR):
- Encryption: encryption at rest and TLS for data in transit.
- Access controls: role-based access control, multi-factor authentication for administrative access, and the principle of least privilege.
- Infrastructure security: EU-hosted infrastructure with network isolation, firewalls, and monitoring.
- Employee training: all team members receive data protection training.
12. Breach notification
In the event of a personal data breach:
- We will notify the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to your rights and freedoms (Art. 33 GDPR).
- If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay (Art. 34 GDPR).
- Notifications will include the nature of the breach, likely consequences, and measures taken or proposed to address it.
13. Children's privacy
loop me in is designed for professionals. Our services are not directed at individuals under the age of 16 (Art. 8 GDPR), and we do not knowingly collect personal data from children. If we learn that we have collected data from a child under 16, we will delete it promptly.
14. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by posting the updated policy on this page and, where appropriate, via email notification.
For questions about this privacy policy, please contact privacy@strana.ai.
Related documents: Data Processing Agreement | Imprint
Last updated: July 24, 2026