LOONI — Privacy Policy
Last updated: 14 July 2026
This Privacy Policy explains how LOONI ("LOONI", "we", "us"), a service operated by AUTONOOMI LABS LLC, collects, uses, stores, and protects information when a business ("Customer") uses LOONI to operate an AI receptionist and booking assistant, including when a Customer connects third-party accounts such as Google or Microsoft.
Contact: support@autonoomi.com · App: https://looni.io
1. Who this policy covers
LOONI is a business-to-business product. The "user" connecting accounts is the business owner or their staff. This policy covers data we process on behalf of that business, including data from connected Google and Microsoft accounts and data exchanged with the business's own customers through LOONI's messaging channels.
2. Information we access and why
a. Google account data
When a Customer connects a Google account, LOONI requests only the scopes needed for the feature being enabled:
Google Calendar (https://www.googleapis.com/auth/calendar) — to read availability and to create, reschedule, and cancel appointments on the Customer's calendar so the AI receptionist can book on their behalf. We read free/busy and event details only to manage bookings, and we subscribe to calendar change notifications to keep availability in sync.
Gmail (https://www.googleapis.com/auth/gmail.readonly, https://www.googleapis.com/auth/gmail.send) — available only if and when the Customer explicitly enables the Gmail email channel. Used solely to read inbound customer emails addressed to the business and to send the business's replies. Gmail access is optional and off by default; most Customers use LOONI's own managed inbox instead.
Basic profile (openid, email, profile) — to identify the connected account and display which account is linked.
We request the minimum scopes required for the features a Customer turns on, and only at the time they connect that feature.
b. Microsoft account data
When a Customer connects a Microsoft/Outlook account, LOONI requests Calendars.ReadWrite, User.Read, and offline_access to provide the same calendar booking and sync functionality described above for the Customer's Outlook calendar.
c. Conversation and booking data
To operate the receptionist, LOONI processes messages exchanged through the Customer's channels (web chat, WhatsApp, SMS, phone calls, email), along with booking details, contact details provided by the business's customers, and business configuration (services, hours, knowledge base).
3. How we use the information
We use connected-account and conversation data only to provide and improve the LOONI service for the Customer: scheduling and managing appointments, answering inquiries, sending confirmations and reminders, and keeping calendars and conversations in sync. We do not use Google or Microsoft user data for advertising, and we do not sell it.
4. Limited Use disclosure (Google)
LOONI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, data obtained through Google APIs is used only to provide or improve user-facing features that are prominent in LOONI; is not transferred to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition; is not used for advertising; and is not read by humans except with the Customer's explicit consent, to comply with law, or for security/abuse/debugging where required and with safeguards.
5. Storage, security, and sub-processors
5a. SMS and Mobile Information
LOONI sends SMS on behalf of the business to that business's own customers: appointment confirmations, reminders, and replies to messages the customer sent first. We never send unsolicited or marketing SMS. Message frequency varies. Message and data rates may apply. Reply STOP to unsubscribe at any time, or HELP for help.
No mobile information or phone numbers will be shared with third parties, affiliates, or partners for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties under any circumstances.
5b. Access tokens and refresh tokens for connected accounts are stored encrypted and used only to call the relevant provider APIs on the Customer's behalf. We host data with reputable cloud infrastructure providers and use a limited set of sub-processors strictly to deliver the service (for example: cloud hosting and database, AI model providers for generating responses, messaging/telephony providers, and email delivery). Sub-processors act on our instructions and are bound by confidentiality and data-protection obligations.
6. Data retention and deletion
We retain connected-account and conversation data for as long as the Customer's account is active and as needed to provide the service. A Customer may disconnect a Google or Microsoft account at any time from the LOONI dashboard, which revokes LOONI's stored tokens for that account. Customers may request deletion of their data by contacting us; upon account termination we delete or de-identify Customer data within a commercially reasonable period, except where retention is required by law.
7. Revoking access
A Customer can revoke LOONI's access at any time by disconnecting the integration in the LOONI dashboard, or directly via their Google Account permissions page or Microsoft account permissions. Revoking access stops further data access; previously processed data is handled per Section 6.
8. International users
LOONI serves businesses globally. Data may be processed in countries other than the Customer's own; we apply appropriate safeguards consistent with applicable data-protection law.
9. Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, notifying Customers.
10. Contact
Questions about this policy or your data: support@autonoomi.com, AUTONOOMI LABS LLC.