HTTPS on every sloose.com address
The website, the app, the API, the documentation and the page your CRM tab loads all answer over HTTPS only.
- A request over plain HTTP gets a permanent redirect to the same address over HTTPS.
- HTTPS responses send HSTS for 180 days, covering every subdomain. A browser that has visited once will not try plain HTTP again.
- Connections must use TLS 1.2 or newer. TLS 1.0 and 1.1 are refused.
We checked each address on 3 October 2026. This is a setting on our domain at Cloudflare.
Where your data lives
- Sloose runs on Cloudflare. The database and the files you import are stored in Cloudflare’s Oceania region, and the database keeps no copies elsewhere.
- Not everything stays there. Requests are handled wherever Cloudflare’s network serves you. The service that meters your plan and the one that knows who has an import open are placed by Cloudflare near where they are first used. The AI gateway’s log, our AI provider, our support tool and our issue tracker are in the United States.The sub-processors are listed below.
- Sloose does not keep the records it creates or updates in your CRM. For each run it keeps each record’s ID, what happened to it, your CRM’s error text and the values it was matched and linked by.
- The token that connects your CRM is encrypted at rest with AES-256-GCM, using a key held in Cloudflare’s secret store and never in the database. The token a Zoho sign-in returns is used to read who you are, then deleted.
- There is no choice of region. If you need one, contact us before you connect your CRM.
How long we keep it
| What | How long |
|---|---|
| Imported files, their corrections, and run history | Your plan’s history window, counted from when the import was last changed or run: 7 days on Free, 30 on Team, 365 on Business and Enterprise. Up to 30 days longer after a change of plan. Deleting an import deletes its files sooner. |
| Sessions, with the address and browser each was made from | Until you sign out, or a month after the session expires. |
| Billing records | 7 years, as Australian tax law requires. |
Closing your organisation. An owner can close it from the app by typing its name. Sloose asks Zoho to revoke every connection, cancels the subscription, and erases the organisation’s data within 30 days. Until then, a closure made by mistake can be undone through support.
Deleting your account. Anyone can delete their own account from Your account. Every session ends, every sign-in method is removed, and Sloose asks Zoho to revoke the CRM connections you made yourself. An organisation’s records then read “a deleted person” where your name and email address were. If you are the only owner of an organisation, close it or make someone else an owner first.
Section 6 of the privacy policy has the full schedule.
AI and your data
The AI runs only when somebody asks it to: a button in the app, such as Draft everything, Ask AI or Explain, or an AI assistant or API client you connected calling an AI tool. Running an import never calls the AI.
An administrator chooses what the AI may see, once for the organisation:
- Allow. Sample values, as they are, except fields excluded from AI. A new organisation starts here.
- Masked. Every value reduced to its shape. The one exception: the distinct values of a column mapped to a picklist or multi-select field are sent, so they can be matched to its options.
- Never. No values at all. The AI works from column names and your field definitions.
Exclude from AI is set per field. An excluded field’s values are never sent, in any form, under any setting. The field’s examples are sent in their place, so they should be made up. A column whose name matches an excluded field is withheld too. That match is by name, so a column under a name nothing recognises follows the organisation’s setting.
Your question, your column names, your field definitions and any formula being asked about are sent under every setting, since the AI has nothing to work from without them. Requests go through Cloudflare’s AI Gateway to Anthropic. The gateway keeps a log of each request and its answer, sample values included, until newer requests replace it. It holds the most recent 10 million.
How the AI handles your data in the docs says what each feature sends.
Accounts and access
Signing in
People sign in with Zoho, with an emailed link and the six-digit code that comes with it, or with a passkey. There are no passwords. Sign-in is rate-limited, and the emailed link is protected by Cloudflare Turnstile. A session lasts eight hours and extends while it is in use.
Two-factor sign-in
- Anyone can add an authenticator app, with backup codes, or passkeys, from Your account, on Sign-in & security.
- Five wrong codes in a row lock the step for 15 minutes.
- Once a factor is added, adding or removing one needs a second factor passed recently.
- Our staff must have a second factor, and must have passed it in the last 12 hours, to use any support tool. A separate administrative token for scripts is kept in Cloudflare’s secret store, never in our code.
Roles and invitations
An organisation has four roles: Owner, Administrator, Builder and Operator. People join only by invitation, an invitation lasts seven days, and it must be accepted by the email address it was sent to. Administrators change roles on People. Nobody can raise their own role.
API tokens
Only an administrator who is signed in can create or revoke an API token. Another token cannot. A token is stored as a hash, and acts at the lower of its own role and its creator’s role today. A token can read, configure and run imports. It cannot manage people, connections or billing.
AI assistants
Assistants that support MCP, such as Claude, connect with OAuth. You approve the assistant on a Sloose page and choose which organisation it may use. Each person sees the apps they allowed under Your account, on Apps with access. Removing one stops every token it was given.

When our staff help you
Only named Dinode staff can reach support tools. To help you, a staff member can view your organisation as one of its members. That view is read-only unless they record a reason and type your organisation’s name. It never creates an API token, an invitation or anything else that would outlast it, and it never changes your billing.
Logs
Every change our staff make, and every time they open your organisation, is recorded in a log that is only ever added to. Your organisation’s settings keep their own history in the app, one entry for each value changed, with who changed it and when. Role changes, removals and invitations are recorded on People.
Your CRM, and the code we run for you
- A connection reads and writes only the modules Sloose found the last time it read your CRM.
- Every write belongs to a run, and the run is recorded. Sloose never deletes a record itself. An update is sent as written, so for a subform or a multi-select lookup your CRM can treat it as removing entries.
- Formulas and helper libraries that run on our side run in a separate Cloudflare Worker with no network access and no access to our secrets or any other data. In your browser they run as spreadsheet formulas do.
- A formula the AI writes is previewed in your browser only if it reads nothing but the row. Anything else waits until you choose to use it.
- Automated checks keep customer identifiers out of Sloose’s code.
What we don’t have yet
- No SOC 2 report and no ISO 27001 certification.
- No single sign-on (SAML or OIDC) and no SCIM.
- No choice of data region.
- No copy of our staff log for you to read, and no export of your change history.
- No status page, no uptime agreement, no published penetration test and no bug bounty.
If one of these stops you, tell us. It helps us decide what to build next.
Report a vulnerability
Email security@sloose.com. Tell us the address, the steps to reproduce it and what you saw. Please do not read other people’s data or disrupt the service while you test. Oursecurity.txt says the same.
Documents
- Privacy policy: what we collect, why, and for how long.
- Data processing addendum: our duties as your processor, breach notice within 72 hours, 30 days’ notice of a new sub-processor, and the EU Standard Contractual Clauses and UK Addendum on request.
- Terms of service.
- security.txt.
Sub-processors
| Sub-processor | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, network, AI Gateway, email | Global network; database and files in Oceania |
| Anthropic, PBC | The AI model | United States |
| Stripe, Inc. | Payments and invoicing | United States, with EU and Australian entities |
| Userback Pty Ltd | Support requests and feedback | Australia; hosted in the United States |
| GitHub, Inc. | A copy of each support request, to track the work | United States |
| Zoho Corporation | Your CRM, its API and Zoho sign-in | Your Zoho account’s data centre |
The DPA is the binding list.