1 What we collect
Account info
Your email address, password (stored hashed, never in plain text), display name, and the username you choose. If you add them later: profile photo, bio, and the cities and taste tags you set during onboarding.
Your activity
The places you save, notes you write, loops you create, who you follow, comments you leave, and content you mark as public, followers-only, or private. We store who recommended a place to you if you tag them when saving.
Device info
Device model, OS version, and app version, used for crash reports and to debug issues.
Location
If you grant permission, we use your device’s location while the app is open to show nearby places and centre the map on you. We don’t store your location history. We don’t track your location in the background.
Photos
If you grant permission, we access your photo library only when you choose a photo to attach to a place, loop, or your profile. We don’t scan or index your library.
2 What we don’t collect
We don’t collect your contacts, calendar, microphone, camera roll metadata, advertising identifier, or browsing activity outside loopa. We don’t run third-party analytics, marketing trackers, or advertising SDKs.
3 What we do with your data
We use it to run the app: show you relevant places, surface what people you follow are saving, send in-app notifications based on your settings, and prevent abuse.
We don’t sell your personal data. We don’t use it to build advertising profiles. We don’t share it with third parties for their own marketing.
4 Who we share it with
Service providers who help us run loopa. Each one only sees the data it needs to do its job:
- Neon (database hosting, EU — London region) stores your profile, saves, loops, follows, and notifications.
- Cloudflare (image storage and delivery) stores photos you upload and place photos ingested from Google.
- Google Places API receives the search terms you type and the location you’re searching near, so it can return matching places. Google’s own terms apply to this data — see Google’s privacy policy.
- Mapbox receives map tile requests from your device when you use the map. This includes approximate location data needed to load the right tiles.
- Apple processes your sign-in if you use Sign in with Apple (when available), and delivers any in-app updates.
Other loopa users can see your profile, saves, and loops according to your privacy settings. You control whether your account is public or private, whether your saves are visible to followers only, and whether other people can find you by email.
Legal requests. We’ll comply with valid legal orders. We’ll push back on overbroad ones and notify you where we’re legally allowed to.
Sale or restructure of the business. If Loopa Technologies Ltd is acquired or restructured, your data may transfer to the new entity. They would be bound by this policy.
5 Your privacy controls
In Settings → Privacy you can:
- Make your account private, so only approved followers can see your saves and loops
- Restrict your saves to followers only while keeping your profile public
- Hide yourself from being found by email
- Block other users, so they can’t see your profile, follow you, or interact with your content
- Report content or accounts that violate our rules
6 Your rights
You can view, edit, or delete your data from Settings. If you’re in the UK or EU, you have additional rights under UK GDPR and EU GDPR: access, rectification, erasure, portability, restriction, and objection. To make a request, get in touch via Settings → Help centre. We respond within 30 days.
7 How long we keep your data
We keep your data while your account is active. When you delete your account, we delete your profile, saves, notes, loops, follows, and notifications within 30 days. We may keep minimal records of blocked accounts and prior moderation actions to prevent abuse.
8 Where your data is stored
Your data is stored on servers in the European Union (London region). Place data requests go to Google’s servers; map tile requests go to Mapbox’s servers. Both may process requests outside the EU.
9 Children
loopa is not for children under 13. We don’t knowingly collect data from anyone under 13. If you believe a child has signed up, contact us via Settings → Help centre and we’ll delete the account.
10 Security
We use HTTPS for all data in transit. Passwords are hashed using industry-standard algorithms. Your auth session is stored on your device.
No system is perfectly secure. If we ever discover a breach affecting your data, we’ll notify you and the relevant authorities as required by law.
11 Changes to this policy
We may update this policy. When we make material changes, we’ll notify you in the app before they take effect.
12 Contact
Privacy questions: get in touch via Settings → Help centre, or email hello@loopaapp.co.