Privacy Policy
Privacy, written plainly and precisely.
Anton is a private executive-assistant service provided to organizations for their authorized employees, with a companion app for iPhone and iPad. This policy explains what personal data Loopid GmbH processes, where it is processed, how the Anton editions differ, and how you can exercise your rights.
Last updated
1 September 2026
Controller: Loopid GmbH, Jaiserstraße 40, 82049 Pullach im Isartal, Germany · info@loopid.com
1. Who we are and scope
Loopid GmbH ("Loopid", "we") provides Anton directly to organizations under B2B service agreements for their authorized employees. Anton is not offered to consumers, individual purchasers, or families. We are the controller for this website, for account and device pairing, for customer support, and for operating the Anton service.
This policy covers antonworks.com, the Anton companion app for iPhone and iPad, and the Anton editions Managed, Private and Sovereign. Where a business customer deploys Anton for its team, that organisation decides which sources are connected and how Anton is used; in that case Loopid acts on its instructions for the customer content processed in the service.
2. Data Anton processes
| Category | Examples | Where it comes from |
|---|---|---|
| Account and contact data | Name, email address, organisation, support correspondence | The customer organization or authorized employee, during provisioning, connection, or support |
| Device and pairing identifiers | Anton device identifier, pairing keys, connected-account identifiers, session data | Created during setup and use |
| Connected source content | Emails and drafts, calendar entries, documents you connect or upload, notes and tasks | Only the accounts and sources you choose to connect |
| AI requests and transcripts | Prompts and instructions you give Anton, the text results Anton produces, and text transcripts where you enable transcription | Your use of the assistant |
| Images you attach | Images you explicitly select and attach to a request | Chosen by you, per request |
| Operational data | Limited app and service diagnostics and security logs needed to run the service | Generated while the service runs |
We do not use your content for advertising, we do not sell personal data, and we do not run product-analytics tracking in the Anton app.
3. The Anton app on iPhone and iPad
The app is a control surface for your Anton environment. It shows prepared actions, drafts and briefings, and lets you approve or discard them.
Audio and transcripts. Raw audio is processed on your device. Anton does not upload or retain raw audio recordings as part of this feature. When you enable transcription, only the resulting text transcript is sent to your Anton environment.
Permissions. Face ID or Touch ID protects local access to the app; Anton never receives your biometric templates, which stay on your device under Apple's control. Notifications are optional and used for briefings, reminders and approval requests. The current app does not request access to your camera, contacts, calendar, photo library or location.
External actions Anton can take — such as preparing outbound messages or calling an external service — are subject to the approval and governance controls configured for your environment.
4. Connected accounts
The customer organization determines which accounts and sources authorized employees may connect. Authorized employees can disconnect permitted sources. Anton only reads what a connection grants.
- Gmail. Read for assistance such as summaries, context and prioritisation. Draft creation lets Anton prepare replies for you; it does not give Anton permission to send email on your behalf.
- Google Calendar. Read only when you connect it, to give Anton scheduling context.
- Google Drive. Read only when you connect it, for documents you want Anton to work with.
Disconnecting a source stops further access. Content already stored in your Anton environment is removed on deletion, offboarding or device wipe, as described in section 7.
5. Where data is processed
The Anton editions differ in where your assistant runs and where your Anton memory is kept.
| Edition | Assistant and memory | External AI |
|---|---|---|
| Anton Managed | Runs on Anton infrastructure operated for you, hosted in the European Union. No hardware required. | Used through the service, within the controls configured for your environment. |
| Anton Private | Your Anton memory is kept on your own Anton device on your premises. | Selected requests can be delegated outside, subject to your approval and governance settings. |
| Anton Sovereign | Memory and AI processing run on your own Anton device on your premises. | Outside requests, such as web research, are permissioned and controlled. |
Connections in transit are protected with current transport encryption. Where processing takes place outside the European Economic Area, we rely on an appropriate transfer mechanism such as the European Commission's standard contractual clauses. You can request the current list of service providers and processing locations for your edition at info@loopid.com.
6. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the Anton service, the app and connected-source features you enable | Performance of a contract, Art. 6(1)(b) GDPR |
| Keeping the service secure, preventing abuse, and keeping limited operational logs | Legitimate interests, Art. 6(1)(f) GDPR |
| Optional features that need your permission, such as notifications and transcription | Consent, Art. 6(1)(a) GDPR, which you can withdraw at any time |
| Answering support requests and business correspondence | Contract or legitimate interests, Art. 6(1)(b) and (f) GDPR |
| Meeting accounting, tax and other legal obligations | Legal obligation, Art. 6(1)(c) GDPR |
Anton is not specifically designed to collect special-category data. However, connected sources may contain sensitive or third-party information. The customer organization decides which sources may be connected and remains responsible for the lawful use of those sources.
7. Retention, export and deletion
Customer content remains available until you delete it, disconnect the source, complete offboarding, or wipe the device, subject to legal and security obligations that may require us to keep specific records longer.
Ordinary operational logs have a default retention of 30 days, and error-level operational logs a default retention of 90 days. These periods apply to operational logs only. They do not define how long your customer content or backups are kept.
You can request an export or deletion of your data by writing to info@loopid.com.
8. Your rights
Under the GDPR you have the right to access your personal data and to request correction, deletion, restriction, portability, and objection to processing based on legitimate interests. Where processing relies on consent, you can withdraw it at any time without affecting processing that already took place.
To exercise any of these rights, contact info@loopid.com. You can also lodge a complaint with a data protection supervisory authority in the EU or EEA member state where you live, work, or where you believe an infringement occurred.
9. Changes and contact
We update this policy when the service or applicable law changes. The current version always appears on this page with its "Last updated" date, so you can see when it last changed.
Questions about this policy, or about how your data is processed: Loopid GmbH, Jaiserstraße 40, 82049 Pullach im Isartal, Germany · info@loopid.com.
App Store privacy summary
This is how the data handling of the Anton app maps to Apple's App Store privacy categories.
| Data type | Linked to the user | Used for tracking | Purpose | When collected |
|---|---|---|---|---|
| Contact information: name and email address | Yes | No | App functionality | Only when a user connects an account or provides contact details |
| Identifiers: Anton device, pairing, and connected-account identifiers | Yes | No | App functionality, authentication, and security | During pairing and use |
| Emails or text messages | Yes | No | App functionality | Only from an email account the user connects |
| Other user content: documents, calendar context, notes, tasks, prompts, and text transcripts | Yes | No | App functionality | Only when the user enables the relevant feature or source |
| Photos or videos: images explicitly attached by the user | Yes | No | App functionality | Only when the user chooses to attach an image |
| Other diagnostic data | Yes | No | App functionality and security | Only if limited app or service diagnostics are actually transmitted and retained |
The app does not access your iPhone photo library; it processes only images you explicitly select and attach. No data is used for tracking across apps or websites.