Data & security
Who can see your documents, how previews are isolated, what a connected agent can do, and where your data is stored.
Who can see a document
Access in Markloop works at two levels: the workspace and the project. Some screens call a workspace an organization.
- Workspace. A workspace holds your team, your projects and your billing. Workspace owners and admins can see every project in it.
- Project. Everyone else sees only the projects they are members of. Folders inside a project have the same access as the project. There are no folder- or file-level permissions.
Reviewers you invite
A reviewer you invite to a project can read its documents, add comments and reply to comments.
The reviewer can't:
- change, upload or delete documents,
- get the source file of a document, unless you turn on MCP access for them,
- see other projects in your workspace,
- see your team list or billing.
Project editors and owners can get the source through their agent. A reviewer gets it only with MCP access, which you turn on in the project's People dialog.
Share links
A share link gives access to one document without signing in. Use share links with care:
- Anyone who has the link can see the rendered document, and anyone you forward the link to can open it too. A share link has no private mode.
- If Allow comments is on, anyone with the link can add comments under a name they type.
- If Older versions is on, anyone with the link can open older versions. If it is off, they see only the current version.
- Use Expires to set a date after which the link stops working.
- To cut off access, click Turn off link in the Share dialog. Access ends immediately. To keep sharing with a smaller group, click New link address instead; the old link stops working and you send the new one only to the people who should keep access.
Only project owners and workspace admins can create or change share links. Markloop stores only a hash of the link token, not the token itself.
How Markloop shows HTML documents
A document is HTML written by you or your agent, so it can contain scripts. Markloop shows each document in a sandboxed frame:
- Scripts in the document can run, so interactive documents work.
- The document runs in an isolated origin. It can't read your Markloop session, your cookies or other Markloop pages.
What a connected agent can do
You connect an agent (Claude, ChatGPT, Cursor and others) through the Markloop MCP server. For the steps, see Connect your AI tool. For the full list of tools, see MCP tools.
Sign-in and scope
- The agent signs in with OAuth: you approve the connection in your browser, and the agent never gets your password.
- When you approve, you pick the workspace and the scope: all projects you can edit, or only the projects you select.
- You can give access to up to 10 workspaces.
- The agent acts as you and reaches only the projects your role and the scope allow.
- A reviewer's agent can connect only if a project owner turns on MCP access for that reviewer. That agent can read documents (including the source) and comments, and add comments and replies. It can't upload versions.
Disconnect an agent
Open Connect agent in the Markloop app, then click Scope & access:
- Disconnect this workspace removes the agent's access to the current workspace. Access to other workspaces continues.
- Disconnect everywhere removes access to all workspaces and signs out every connected agent. Each one must sign in again.
When you change the scope, connected agents must sign in again before they can continue (see Troubleshooting).
Read and write actions
Each tool is marked as read-only or write, and your AI client can use these marks to ask you before a write action.
- Read tools list projects and files, download documents and versions, and read comment threads.
- Write tools create documents, upload new versions, publish copies, and add comments or replies.
- No tool deletes a document, a version or a comment.
- A new version doesn't replace an older one. All versions stay in the version history.
- Markloop refuses an upload if the document changed after the agent downloaded it, so the agent can't overwrite changes it hasn't seen.
Publish and republish
Publish copies a document into another project, for example a project in your client's workspace. Republish sends a newer version of your document to that copy.
- Comments never move between the original and the copy. Your internal comments stay in your project, and your client's comments stay on the copy.
- Republish makes the new content the current version your client sees. The client's older versions stay in the history. Markloop refuses the republish if the copy changed after the agent last read it.
- The agent can publish only into projects you can edit.
Where the AI runs
Markloop doesn't run an AI model on your documents. Your agent downloads the document and the comments, makes the changes on your computer or in your AI tool, and uploads a new version. Markloop doesn't use your documents or comments to train AI models.
Where we store data
- Account data, comments and document records are stored in our database (Neon Postgres, London, UK).
- Document files (HTML and versions) are stored in Cloudflare R2 object storage.
- Preview thumbnails of uploaded documents are generated with Cloudflare.
- The application runs on Vercel, in the London (UK) region.
- Product analytics in the app use PostHog, so we can see how features are used.
- Email (invitations, comment summaries, security notices) is sent through Resend.
- Payments are handled by Stripe, which holds your card details.
Some providers can process data outside the European Economic Area. The Privacy Policy lists the providers and the safeguards that apply.
How long we keep data
These periods come from the Privacy Policy:
- Account data: deleted within 90 days after you close your account, except records the law requires us to keep.
- Backups: kept for up to 30 days, then overwritten.
- Support messages: kept for up to 2 years after the matter is resolved.
- Usage and security logs: kept for up to 12 months, then deleted or anonymised.
- Billing records: kept for the period tax law requires (in Poland, usually 5 years).
Close your account or export your data
There is no self-serve button to close an account or export everything. Email hi@markloop.io and we'll handle it.
Before you close your account, save the documents you want to keep. Your agent can download any document and its versions for you, for example: "Download the current version of every document in the Acme project."
Legal terms and questions
Send questions about data and security to hi@markloop.io.
