Privacy policy
Your record belongs to you.
Effective September 21, 2026. Version 2026-09-21.
1. Scope and controller
This policy explains how ChangeLoop 7 collects, uses, stores, and shares information when you use the website, account, seven-day cycles, AI-supported analysis, and subscription features. The independent operator of ChangeLoop 7 is the data controller where applicable.
2. Information we collect
We collect your account email, salted password hash, session and security metadata, intake answers, chosen method, daily completion records, weekly reflection, generated analyses, cited sources, cycle history, and compact long-term profile. We also record request identifiers, revisions, rate-limit events, provider outcomes, and token or usage counts needed to operate and protect the service.
PayPal processes payment credentials. ChangeLoop 7 receives subscription identifiers, plan, status, and billing-event data, but does not store full card or bank details.
The authenticated browser tab keeps a temporary dossier copy in session storage so the interface can recover during that tab's session. The copy is accessible to scripts running on the same origin, is not represented as encrypted browser storage, and is cleared by the product on sign-out or account deletion. The server-side encrypted dossier remains the long-term record.
3. How we use information
We use information to authenticate accounts, preserve the long-term dossier, run the product's fixed analysis checkpoints, generate weekly plans, show the correct day, process subscription access, prevent duplicate charges or model calls, troubleshoot failures, enforce limits, respond to support requests, and provide export or deletion controls.
We do not sell personal information, use the dossier for third-party advertising, or provide an open-ended AI chat.
4. AI processing
At fixed checkpoints, bounded excerpts from the dossier may be sent to configured AI providers. Account email and payment details are not intentionally included in model prompts. Providers can change as reliability and availability change; the current provider list is available on request. AI output can be incomplete or wrong. Source metadata checks do not guarantee that every generated interpretation is accurate.
5. Service providers and transfers
We use Cloudflare for hosting, database, security, and delivery; PayPal for subscriptions and billing; Crossref for source-metadata checks; and configured AI providers for bounded analysis. These providers process data under their own terms and may operate internationally. We limit the data sent to each provider to what is reasonably needed for that function.
6. Legal bases
Where a legal basis is required, processing is based on performance of the service contract, legitimate interests in security and reliable operation, compliance with law, and consent where required. You may withdraw consent without affecting earlier lawful processing.
7. Retention
Your active dossier and cycle archive remain while the account exists because future cycles use prior results. Expired sessions and workflow locks are removed by scheduled maintenance. Authentication rate-limit buckets are normally removed after 24 hours, failed or incomplete analysis receipts after seven days, and completed idempotency-response caches after 30 days. First-party attribution events are normally retained for no more than 13 months. Payment, fraud-prevention, and legally required records may follow longer applicable periods. After a verified deletion request, active account data and linked first-party funnel events are deleted or de-identified; encrypted backup copies may remain for up to 30 additional days before scheduled expiry, unless law or fraud prevention requires longer retention.
8. Security
We use salted password hashes, HttpOnly SameSite cookies, encrypted secrets, revision checks, request limits, same-origin protections, and provider fallbacks. No service can guarantee absolute security. Do not enter medical records, payment credentials, government identifiers, another person's confidential information, or details unnecessary for the exercise.
9. Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or review of automated processing. Use in-product export and deletion controls where available, or email privacy@changeloop7.com. We may verify account ownership before acting.
10. Children
ChangeLoop 7 is for adults aged 18 or older. We do not knowingly collect data from children. Contact us if you believe a child has provided information.
11. Automated output
The service proposes a testable cognition, sourced examples, bounded methods, and a seven-day framework. Weekly completion data and your reflection inform the next cycle. This output supports a voluntary personal exercise and is not used to make employment, credit, insurance, legal, medical, or similarly significant decisions.
12. Changes and complaints
Material changes will be dated on this page. You may contact us first at the privacy address above. You may also complain to the data-protection authority available in your country when that right applies.
13. Google sign-in, when enabled
If you choose Google sign-in, Google provides a unique account identifier and verified email address. We use these to create or authenticate your account and retain the account binding, legal acceptance record, and security metadata. We do not request access to Gmail messages, Google Drive files, or your contacts. Existing accounts are not automatically merged solely because email addresses match; linking requires verification of the existing account.
Short-lived, encrypted authorization attempts and secure cookies protect the sign-in process. Authorization attempts expire after ten minutes. A Google reauthentication proof for sensitive account actions expires after five minutes and can be used once. Expiry prevents use but does not mean immediate deletion of the database row. Google access and ID tokens are processed for verification and are not intentionally persisted in the application database. Google also processes sign-in information under its own Privacy Policy.
14. Installed app and offline storage, when enabled
The installable web app uses a service worker to cache a generic offline notice. That service-worker cache does not store your dossier, authentication API responses, payment responses, or AI requests, and it does not queue or replay offline submissions. This is separate from the temporary dossier copy in session storage described above. Installing the app does not make private records available offline or change your subscription.
15. Website analytics and attribution
We use Cloudflare Web Analytics to measure aggregate page views and real-user page performance. We also use a first-party, session-scoped journey identifier to understand whether a visit leads to registration, successful generation, a completed introductory cycle, checkout, or payment. We may store UTM source, medium, campaign, content and term values, the referring hostname, and landing path. We do not put your email, intake answers, dossier text, prompts, or model output into these analytics records.
The journey identifier is kept in session storage rather than an advertising cookie. After registration, events are linked through a one-way account reference so the master dashboard can show grouped source performance without displaying identities. Cloudflare may separately process limited technical information and use strictly necessary security cookies when delivering and protecting the service. See Cloudflare's Privacy Policy for its processing terms.