Trust & guardrails

Safe to let it act in your name.

The defaults, limits and controls that keep ChurnLoop from ever surprising you or your users.

Trust & control

An agent acting in your name needs guardrails by default.

ChurnLoop defaults to copilot — drafts, then asks. Autopilot is opt-in, per playbook, with hard caps. You can read the trail of every decision ChurnLoop ever made on your behalf.

Modes

Copilot, autopilot, your call.

Every playbook has a mode toggle. Some you'll always want to read first (win-back from you personally). Others should just run (welcome emails on Sunday).

Guardrails

Hard caps on volume and timing. One-click out.

No more than 2 messages per user per week. Quiet hours respected per timezone. Every email includes a one-click unsubscribe — opted-out users are never contacted again.

Audit

Every decision is in the trail.

For each message, each pause, each escalation: the events ChurnLoop saw, the reasoning it followed, the playbook it ran. You can rewind any user's history.

Data

GDPR-native. Your data, your export.

DSR requests are one click — ChurnLoop cascades erasure across all stored events, reflections, and dispatches. Export your raw data to S3 or a Postgres mirror anytime.

Models

No training on your data. Ever.

Your event stream, your users, your sent emails — none of it trains the underlying models. Bring-your-own-key for completions if you prefer.

Escape hatch

Pause everything in one tap.

A red switch in the topbar pauses every playbook, every campaign, every autopilot run. Your audit trail stays. You decide when to resume.

Start today

Get your first briefing tomorrow morning.

Plug in your event stream today. ChurnLoop spends 24 hours learning, then files its first morning briefing — tomorrow morning, 6am your timezone.