Privacy Policy

Last updated: February 17, 2026

LOOTR (operated by Navaltek Inc.) is an AI-powered opportunity discovery platform at app.lootr.io. This policy explains what data we collect, how we use it, and your rights. We keep it simple.

What we collect

  • Account info — your name and email when you sign up.
  • Payment info — processed by LemonSqueezy. We never see or store your full card number.
  • Usage data — which features you use, pages you visit, and general interaction patterns. This helps us improve the product.

What we don't collect

  • We don't use tracking cookies or third-party analytics that follow you around the web.
  • We don't run ads or share your data with advertisers.
  • We don't sell, rent, or trade your personal data to anyone. Period.

How we use your data

  • Run your account — authenticate you, manage your subscription, send you important updates.
  • Improve the product — understand how people use LOOTR so we can make it better.
  • Support — respond when you reach out to us.

Who we share data with

Only what's strictly necessary:

  • LemonSqueezy — payment and subscription processing.
  • AI Service Providers — AI analysis services for feature functionality.
  • Vercel / Railway — app hosting and backend infrastructure.

That's it. No data brokers, no ad networks, no shady third parties.

Your rights (GDPR & beyond)

Wherever you are in the world, you have the right to:

  • Access — request a copy of all data we have about you.
  • Correct — fix any inaccurate information.
  • Delete — ask us to permanently delete your account and all associated data.
  • Export — get your data in a portable format.
  • Object — opt out of any data processing you're not comfortable with.

Email us at support@lootr.io and we'll handle it within 30 days.

Cookies

We use essential cookies and local storage for authentication, session continuity, and security. We may also use privacy-friendly analytics identifiers when enabled.

Data retention

We keep your data as long as you have an active account. When you delete your account, we delete your personal data within 30 days. Some anonymized, aggregated data (like "X users visited this page") may be retained for analytics — but it can never be traced back to you.

Security

We use encryption in transit (HTTPS everywhere), secure authentication, and follow industry best practices to protect your data. No system is 100% bulletproof, but we take security seriously and continuously improve our defenses.

Changes to this policy

We may update this policy from time to time. If we make significant changes, we'll notify you by email or through the app. The "last updated" date at the top always reflects the latest version.

Contact

Questions? Concerns? Just want to say hi?

support@lootr.io

LOOTR is operated by Navaltek Inc.