Privacy Policy
Last updated 30 July 2026 · Momentum Cloud Pty Ltd (ABN 36 145 339 037)
This policy explains how Momentum Cloud Pty Ltd (ABN 36 145 339 037) ("we", "us") handles personal information when you use Hitloop, our bug and feedback capture platform, and when the Hitloop widget is embedded on a website you visit. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Who we are
Momentum Cloud Pty Ltd (ABN 36 145 339 037) operates Hitloop. For privacy enquiries contact privacy@momentumcloud.com.au.
Where a customer embeds the Hitloop widget on their own website, that customer decides what is collected and why. In that situation the customer is the controller of the reports submitted, and we act as their service provider. This policy covers our own handling of that information.
2. Information we collect
Account information. When you create an account we collect your email address and authentication credentials (passwords are hashed by our authentication provider and are never visible to us).
Project configuration. Project names, API keys, allowed origins, team membership and invitation email addresses.
Report content submitted through the widget. When someone submits a report we collect:
- The title, description, request type and severity they enter
- An email address, only if the reporter chooses to provide one
- Screenshots, annotations, screen recordings and files the reporter deliberately attaches
- Technical context such as the page URL, browser user agent, viewport size and timestamp
Screenshots and recordings are captured only when the reporter explicitly starts a capture, and the reporter reviews them before submitting. Because captures reflect whatever is on screen, reporters should avoid capturing screens containing sensitive personal information.
We do not use tracking or advertising cookies, and the widget does not build behavioural profiles of website visitors.
3. How we use information
- To authenticate you and operate your account and projects
- To receive, store, display and organise bug reports for the project they were submitted to
- To deliver optional features you enable, such as AI rewriting of report text, GitHub issue syncing, and agent (MCP) access
- To send transactional messages such as team invitations and password resets
- To secure the service, apply rate limits, prevent abuse and debug faults
- To meet our legal obligations
We do not sell personal information, and we do not use report content for advertising.
4. Service providers we use
We rely on a small number of processors to run the service. Each receives only the data needed to perform its function:
- Supabase — database, authentication and file storage for accounts, reports and attachments
- Lovable — application hosting and delivery of the web app and widget script
- Google (Gemini API) — processes report text only when a user chooses the AI rewrite feature
- GitHub — receives report content only for projects where you enable GitHub issue syncing
Some of these providers process data outside Australia. Where personal information is disclosed overseas we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
5. Disclosure
We disclose personal information only to the service providers above, to members of the project a report belongs to, where you direct us to (for example GitHub sync or an agent integration), or where required by law.
6. Storage, security and retention
Data is encrypted in transit with HTTPS and encrypted at rest by our database and storage provider. Access to reports is enforced at the database level so that only the owning account and invited team members can read a project's data. Attachment links are time-limited signed URLs rather than public files.
We retain reports for as long as the owning project exists. You can delete individual reports at any time from the dashboard, and you can ask us to delete your account and all associated data by emailing privacy@momentumcloud.com.au. Backups are cycled out on our provider's ordinary schedule.
7. Your rights
You may request access to the personal information we hold about you, ask us to correct it, or ask us to delete it. Email privacy@momentumcloud.com.au and we will respond within a reasonable period, normally 30 days. If you are unhappy with our response you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
If you submitted a report through a widget on someone else's website, contact that website operator first — they control that report. We will assist them in actioning your request.
8. Children
Hitloop is a business tool and is not directed at children under 16.
9. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows when it last changed. Material changes will be notified to account holders by email.
10. Contact us
Momentum Cloud Pty Ltd (ABN 36 145 339 037) · privacy@momentumcloud.com.au