Privacy Policy
Effective date: August 5, 2026
This policy describes Patronage Loop, including its remote MCP service, browser-based OAuth sign-in, connected marketing providers, and the public Patronage Loop website. Patronage is the service provider for Patronage Loop. It applies to information processed when you visit the Patronage Loop website or use Patronage Loop through an authorized agent host.
Information Patronage Loop processes
Patronage Loop processes account and authorization information needed to authenticate a person, establish an agent connection, and determine the active Project. This includes account identifiers, connection metadata, granted scopes, selected Project, host and install-source metadata, and timestamps.
When an authorized agent uses Patronage Loop, we record Project activity metadata such as the user and agent connection, host, tool name, read/write classification, outcome, timestamps, and correlation identifiers. When you connect a provider to a Project, Patronage Loop processes the provider data and operations that the connection authorizes. Patronage Loop does not retain provider access tokens, API keys, cookies, raw provider payloads, raw JSON-RPC arguments or results, prompts, consent codes, or approval rationales in its activity or diagnostic records.
Connected providers process information under their own terms and privacy notices. Patronage Loop accesses only the data and operations authorized for the selected Project and rechecks access for each request. You are responsible for ensuring you have authority to connect a Project and its providers.
Why we use this information
We use this information to provide authenticated, Project-scoped marketing operations; maintain security and authorization controls; keep an activity record for administrators; investigate reliability and security issues; and support users. We do not sell personal information or use Patronage Loop data for advertising profiles.
Retention
Patronage Loop retains immutable Project activity metadata for one year. Privacy-safe diagnostic telemetry is retained for 30 days. We retain account and connection information while it is needed to provide the service, comply with legal obligations, resolve disputes, or enforce agreements. We delete or de-identify information when it is no longer needed, subject to those requirements.
Sharing and service providers
We share information with service providers only as needed to host, secure, operate, and support Patronage Loop, or when required by law. These include Cloudflare for hosting, security, durable data storage, and privacy-safe diagnostic storage; the agent host you choose for the authorized connection; and the providers connected to your selected Project. We may also disclose information in connection with a merger, acquisition, financing, asset sale, or other business transaction, subject to applicable law.
Security and international processing
Patronage Loop uses HTTPS to transmit information between your agent host, browser, and Patronage Loop. Access controls, scoped authorization, and approval-aware actions are designed to protect Project data. No internet transmission or storage system is completely secure. Patronage Loop is operated from the United States, and information may be processed there or in other locations where our service providers operate.
Your choices
You can revoke an agent connection through Patronage Loop, which ends that connection's future access. Project administrators can manage Project access. To request access, correction, deletion, or information about our processing, contact hello@patronage.com. We will verify requests before acting on them. Depending on where you live, you may have additional rights under applicable privacy law.
Changes and contact
We may update this policy as Patronage Loop changes. We will post the revised effective date here. Questions about this policy can be sent to hello@patronage.com.