Plain-language summary. CaseLoop is a desktop application that runs on your own computer. When you connect a Gmail mailbox, your mail is downloaded directly from Google to your device and stored there, in a local database only you can reach. Your email content never reaches CaseLoop's servers. The AI features that read your mail run locally on your own machine — no email content is sent to OpenAI, Anthropic, Google, or any other AI provider. We do not sell your data, and we do not use it to train AI models.

01Who this policy covers

This policy is published by Loop Holdings, Inc. ("CaseLoop", "we", "us"), and describes how the CaseLoop desktop application handles your information — with particular attention to data obtained through Google APIs, including Gmail.

CaseLoop is used by behavioral health providers — agencies delivering supervised visitation, in-home services, and related family services — to keep case records, correspondence, and documentation in one place.

The CaseLoop Chrome extension is a separate product with a separate data flow, described in its own Chrome extension privacy policy.

02What Google data CaseLoop accesses, and why

CaseLoop asks for the narrowest set of Google permissions that its features actually need. Each one is listed below with the specific feature it exists for. You see and approve this list on Google's consent screen before anything is accessed.

openid, email
Identifying which mailbox you connected. CaseLoop reads your email address so it can label the connected account, store its credentials under the right key, and prevent the same mailbox being connected twice. These are sign-in scopes, not Gmail permissions.
gmail.readonly
Mail sync. CaseLoop reads the messages in your mailbox and stores them on your device so they can be searched, filed against a case, and shown alongside your case records. It also reads attachments, which arrive inside the message and are saved to a local file vault. This is also the permission that lets CaseLoop read your Gmail profile to confirm the connected address.
gmail.send
Sending mail from CaseLoop. Composing a new message, replying, replying all, or forwarding — from inside CaseLoop, on the case you are looking at, so the correspondence is recorded against the case. This permission can only send. It cannot read, list, or manage drafts.
gmail.modify
The mail action toolbar. Acting on a message from inside CaseLoop the way you would in Gmail: marking read or unread, starring, archiving, marking spam, and moving a message to Trash.

What CaseLoop deliberately does not ask for. CaseLoop never requests full mailbox access (https://mail.google.com/). That scope is the only one that permits permanent, immediate deletion of a message, and CaseLoop has no permanent-delete feature anywhere — "delete" means "move to Trash", where you can still recover it. We do not ask for authority the product does not use.

03Where your Google data lives

CaseLoop is a local-first application. The distinction that matters most is between your device and our servers:

  • Mail and attachments — on your device only. When CaseLoop syncs, your desktop application talks directly to Google's servers and writes the results into a local database on your own computer. Message headers, subjects, bodies, participants, and labels are stored there. Attachment files are stored in a local file vault on the same machine.
  • Credentials — on your device only, encrypted. The refresh token that lets CaseLoop reconnect to your mailbox is held in a machine-local vault encrypted with AES-256-GCM, keyed to that specific machine. The account record is held in your operating system's secure storage (Keychain on macOS, the equivalent elsewhere).
  • Never on our servers. No message content, no subject lines, no attachments, no recipient lists, and no Google access or refresh tokens are transmitted to, stored on, or logged by CaseLoop's servers.

CaseLoop's cloud service exists to ship software — the user interface, and signed integration definitions telling the desktop app how to talk to Gmail — not to receive your data. Mail sync traffic is restricted by an outbound allowlist so that the sync process can only reach Google's own Gmail API endpoints.

04AI features and your Gmail data

CaseLoop uses a language model to help triage a busy mailbox. For each newly synced message it classifies whether the message is a request, reports an incident, notifies of a placement change, or contains a commitment with a deadline — so that a coordinator sees what needs action instead of reading every message in order.

This runs entirely on your own computer. The model is bundled with the CaseLoop desktop application and executes locally. The content sent to it — the subject line, the beginning of the message body, the sender's role, and the name of the linked case, if any — never leaves your device, and there is no third-party AI provider in this path. No email content is sent to OpenAI, Anthropic, Google Gemini, or any other external model provider.

We do not use your Google data to develop, improve, or train generalized AI or machine-learning models. Google user data obtained through CaseLoop is used only to provide the user-facing features described in this policy, at your direction, on your device.

05What CaseLoop's servers do store

Using CaseLoop requires a CaseLoop account, which is separate from your Google account. On our servers we hold:

  • Your CaseLoop account — name, email address, and a hashed password. This is the account you sign in to CaseLoop with; it is not your Gmail address unless you happen to use the same one.
  • Product analytics on CaseLoop account activity — for example, a record that a CaseLoop sign-in occurred, with the CaseLoop account email and a timestamp. We use Mixpanel for this. It receives no Gmail data of any kind.
  • Error reports from the application's install and update machinery — technical diagnostics such as an error message and stack trace, with sensitive values redacted, so we can fix crashes. These are scoped to update and installation failures and are not permitted to carry case data or mail content.
  • A record that the Gmail OAuth client was served to your install — when a personal Gmail connection is set up, our server hands your desktop app the OAuth client identifier it needs, and logs the CaseLoop account email that requested it. No Gmail address, mail content, or token is involved.

That is the complete list of what our servers hold in connection with a personal Google account. There is no server-side copy of your mailbox.

06Sharing — and what we never do

  • We never sell your data. Not your Google data, not your case data, not your account data — to anyone, for any purpose.
  • We do not share your Google user data with third parties. Because your mail stays on your device, there is nothing for us to pass on. No advertiser, data broker, or analytics provider receives Gmail content, metadata, or credentials.
  • No human at CaseLoop reads your mail. We have no technical means to do so — it is not on our servers. We would only ever access data you deliberately send us, such as an attachment you include in a support request.
  • No advertising. Your data is never used for advertising or ad personalization.
  • No credit decisions. Your data is never used to determine creditworthiness or for lending purposes.

If your agency has configured CaseLoop to sync records into your own electronic health record system, information you file against a case may be sent to that system at your direction. That is a destination you choose and control, and its handling of the data is governed by your agreement with that vendor.

We may disclose information where required by law, or where necessary to investigate abuse or protect the safety of users — but only information we actually hold, which does not include your mail.

07Google API Services User Data Policy

CaseLoop's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

08Retention and deletion

How long we keep it. Because your Gmail data is stored on your own device, you control its lifetime. Synced mail remains in CaseLoop's local database until you delete it, delete the case it is filed against, or uninstall the application. We apply no retention period to it, because we do not hold it.

Disconnecting a mailbox. In CaseLoop, open the mail account settings and choose Disconnect. This deletes the stored refresh token from the encrypted local vault, deletes the account's credential record, and stops all further syncing. CaseLoop verifies that both were actually removed and tells you if either could not be.

Two things about disconnecting are worth stating plainly:

  • Mail already synced stays on your device. Disconnecting stops CaseLoop reaching your mailbox; it does not erase correspondence already filed against your cases, because those records are part of the case file. To remove that mail, delete it in CaseLoop or uninstall the application.
  • Disconnecting does not revoke your consent at Google. It removes our copy of your credentials — the only thing the application itself can remove. To revoke CaseLoop's access at Google as well, visit myaccount.google.com/permissions and remove CaseLoop. We recommend doing both.

Uninstalling. Removing the CaseLoop desktop application removes the local database, the encrypted credential vault, and the local file vault along with it.

Requesting deletion from us. To have your CaseLoop account and everything associated with it deleted from our servers, email legal@caseloop.co from the address on the account. We will confirm and complete the deletion within 30 days. Since your Gmail data is never on our servers, this covers your account record, analytics events, and any error reports.

09How your data is protected

  • It stays on your machine. The strongest protection is architectural: there is no central store of customer mail to breach.
  • Credentials are encrypted at rest with AES-256-GCM under a machine-derived key, and account records are held in the operating system's secure credential storage.
  • Traffic is encrypted in transit over HTTPS, and mail sync is constrained by an outbound allowlist to Google's own API endpoints.
  • Least privilege by design — CaseLoop requests no Google permission it does not use, and specifically declines full mailbox access.

No system is perfectly secure, and the security of your device matters here more than it does with a cloud product. Full-disk encryption and a strong screen lock are meaningful protections for CaseLoop data.

10Personal Gmail accounts and HIPAA

Please read this if you handle protected health information. Google does not offer a Business Associate Agreement for personal @gmail.com accounts. A personal Gmail mailbox therefore cannot be covered by a BAA, and connecting one to CaseLoop does not change that. CaseLoop records personal Gmail connections as not BAA-covered. If your work requires HIPAA coverage of your mailbox, use a Google Workspace account under your organization's own BAA with Google, or a Microsoft 365 account under the equivalent agreement — not a personal Gmail account.

Nothing in this policy is a representation that a personal Gmail account is HIPAA-compliant, and CaseLoop makes no BAA claim in respect of one.

11Children's privacy

CaseLoop is a professional tool for behavioral health providers and their administrative staff. It is not directed to children and we do not knowingly collect information directly from children. Case records maintained by our customers may concern children; those records are controlled by the provider agency, held on the agency's own devices, and governed by the agency's obligations to the families it serves.

12Changes to this policy

We may update this policy. When we do, we will revise the effective date above, and where a change is material we will notify users in the application. If a change would broaden how Google user data is used, we will seek your consent before it takes effect.

13Contact

Questions about this policy, our handling of Google user data, or a deletion request:

  • Email  legal@caseloop.co
  • Company  Loop Holdings, Inc.
  • Mail  Loop Holdings, Inc. · Idaho, USA