Back to sign in
Legal

Privacy Policy

Effective date: August 30, 2026

1. Who this policy covers

This Privacy Policy explains how Loggia ("Loggia," "we," "us") collects, uses, and protects information when you use the Loggia customer portal at app.loggia.work (the "Service"), operated on behalf of the organization ("your organization") that invited you or that you created an account under.

2. Information we collect

Account information: your name, work email address, a hashed (never plaintext) password or, if you sign in with Slack, your Slack user ID and the name/email Slack shares with us — plus a timestamp of when you accepted this Privacy Policy and our Terms of Service, kept as our record of your consent.

Mobile phone number and SMS data: if a Loggia account owner registers their own mobile number in the app and confirms it with a one-time verification code, we collect that number, the record and timestamp of consent, and the text messages exchanged, in order to send and support the messages they requested (see our SMS Messaging Terms).

Organization data: your organization's name, agent configuration and custom instructions, invite codes, and team member list.

Content you provide: files you upload, and the channel messages you and your teammates post — including messages that mention the AI agent and the agent's responses. Every channel is visible to every member of your organization, the same way a shared team chat works.

Video meetings: if your organization starts a video meeting, our video provider (Daily.co, see Section 5) creates a temporary room and handles the audio/video/chat of participants for the duration of the call. We do not record meetings by default.

Security data: if you enable two-factor authentication, we store a secret key and one-way-hashed backup codes needed to verify your login codes — never the codes themselves in reusable form.

Usage and log data: sign-in timestamps, IP address, and basic technical logs used for security monitoring and abuse prevention.

3. How we use information

We do not sell your personal information, and we do not use your organization's uploaded files or chat content to train any AI model.

4. How your data is isolated

Loggia is multi-tenant: every organization's files, conversations, and team data are logically walled off from every other organization's. Employees of your organization can only see data that belongs to your organization, scoped by server-side access controls — not by client-side settings.

5. Third parties we share data with

We share data only with the service providers needed to run the Service, each acting under its own terms and only for the purpose described below — never sold, and never shared with advertisers:

We do not share your personal information with advertisers, and the Service does not carry third-party advertising.

Mobile opt-in data. No mobile information — including mobile phone numbers and SMS opt-in consent — is shared with third parties or affiliates for their marketing or promotional purposes, and it is never sold. Mobile data is shared only with the messaging provider strictly necessary to deliver the messages you requested. Message frequency varies and is driven by your own activity, typically 1–10 messages per week. Message and data rates may apply. Consenting to receive text messages is not a condition of purchasing any goods or services from Loggia, and is not required to create or use a Loggia account. Reply STOP to any message to opt out, or HELP for help. Full program details are in our SMS Messaging Terms.

6. Data retention

We retain your account, organization, and content data for as long as your account or organization remains active. You or your organization's admin can request deletion at any time (see Section 8).

Retention period. Your organization's admin can set a retention period in Settings > Security policy. Once one is set, content older than that period is removed on a recurring sweep — channel messages, call transcripts, customer chat threads, text-message bodies, the assistant's console history and its stored notes. If no period is set, that content is kept while the organization is active.

Legal hold. If a legal hold is placed on an organization — for litigation, a preservation request, or a regulator's demand — retention sweeps and deletion requests are suspended for that organization while the hold stands, and nothing of its data is removed until the hold is lifted. A hold outranks a deletion request, including the organization's own.

7. Security

We use industry-standard practices including password hashing (bcrypt), rate limiting, encrypted transport (HTTPS), and optional two-factor authentication. No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable, ongoing steps to protect your information.

8. Your rights and choices

Depending on your location, you may have rights to access, correct, export, or delete your personal information. To make a request, contact us at support@loggia.work. Your organization's admin can also remove your account or request deletion of organization data.

How the in-app export and deletion are protected. Exporting your organization's contacts or its whole workspace takes the entire record out of our hands in one action — so we ask the person doing it to prove they are the person, not just that they are signed in. Each export is confirmed with a code from an authenticator app, on a connection secured with HTTPS, and the exact wording of what is being exported is signed by the browser and re-checked by us before anything runs. Deleting a workspace is protected differently, and we would rather say so plainly than overstate it: it is restricted to the account owner, and the owner has to retype the organization's name to confirm — but it is not yet behind the authenticator code or the browser-signed summary. Adding both is work in hand; until it lands, the owner's password and that typed name are what stand in front of a deletion. Enrolling an authenticator is a one-time step in Settings > Two-factor authentication, and the app prompts for it before the first request rather than after it. If you cannot complete that step for any reason, these rights are not conditional on it: email support@loggia.work and we will action the request ourselves.

What a deletion does. When we delete an organization we remove its rows from our live database, unlink its uploaded files from our storage, cancel its queued work, revoke its integrations and standing permissions, and end its signed-in sessions. We also destroy the encryption key belonging to that organization, so any of its content that was stored in encrypted form can no longer be read — by us or by anyone holding a copy of the storage. We keep a dated record of every deletion we carry out, and of every deletion request we decline because a hold is in place.

What a deletion cannot do. Three limits are worth stating plainly rather than leaving you to assume otherwise:

9. Children's privacy

The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from children.

10. Changes to this policy

We may update this policy from time to time. We'll update the effective date above when we do; material changes will be communicated to organization admins.

11. Contact

Questions about this policy or your data can be sent to support@loggia.work.

Loggia is a service of Buzzed LLC, a Michigan limited liability company.
Buzzed LLC, 2222 W Grand River Ave, Ste A, Okemos, MI 48864, United States
Email: support@loggia.work

This policy is governed by the laws of the State of Michigan, United States.