Privacy Policy
Placeholders that must be filled in before publishing
- TODO: COMPANY LEGAL NAME — the registered legal entity operating Loop (e.g. "Loop, Inc." or a DBA). Not yet formed/named as of this draft.
- TODO: COMPANY ADDRESS — a real mailing address (registered agent or business address). Texas is the placeholder state.
- Privacy contact: support@loopaiapp.com
- TODO: EFFECTIVE DATE — set on the date this is actually published, not drafted.
- App name: Loop – AI Concierge (referred to as "Loop" below). Decided 2026-09-28.
1. Introduction
TODO: COMPANY LEGAL NAME ("we," "our," or "us") operates the Loop mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the App.
By using Loop, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the App.
2. Information We Collect
2.1 Information you provide
- Account information: email address and password if you sign up directly, or basic profile info (name, email) if you sign in with Google or Facebook.
- Profile information: interests/preferences, home and work addresses you choose to save, and an optional profile photo/avatar.
- Calendar data: events and schedule information when you connect your device calendar or create plans in the App, used to detect free time and avoid double-booking.
- Friends & group planning: friend connections, group plan invitations, shared plan details, and messages within group chats.
- Feedback: thumbs up/down ratings, feedback tags, and notes on recommendations — this is what trains your personalized ranking.
- Payment information: processed by Stripe (and/or the Apple/Google in-app purchase systems) for Loop Plus subscriptions and business listings; we do not store full card numbers.
2.2 Information collected automatically
- Location data: foreground GPS location when you grant permission, used for nearby recommendations and distance/travel-time calculations. Background location is optional and, where offered, is used only for features you explicitly enable (e.g. arrival/departure-based reminders); you can revoke it at any time in device settings.
- Device & usage information: device type, OS version, app version, and how you interact with the App (screens viewed, recommendations accepted/declined), used for debugging and improving recommendations.
- Push notification tokens: an Expo push token tied to your device, used to deliver reminders and recommendation alerts you've opted into.
- Crash and error reports: collected via Sentry to diagnose and fix bugs. These reports can include device state and a stack trace at the time of the crash.
2.3 Information from third parties
- Google Sign-In / Facebook Login: basic profile information (name, email, profile photo) if you choose social sign-in, via Supabase Auth.
- Google Places API: venue names, locations, ratings, hours, and photos that power recommendations. This data originates from Google and is subject to Google's own privacy policy.
- Google Gemini API: when you use the AI concierge/chat, your query text (and relevant context such as your stated preferences or location) is sent to Google's Gemini API to generate a response and activity descriptions.
3. How We Use Your Information
- Provide personalized activity and event recommendations based on your interests, location, schedule, and feedback history.
- Power the AI concierge chat and generate activity descriptions.
- Show your calendar and detect free time for suggestions.
- Enable social features: friends, group planning, and in-app messaging.
- Process subscription and business-listing payments.
- Send push notifications you've opted into (recommendations, reminders, friend activity).
- Diagnose crashes and improve app stability and performance.
- Improve the recommendation model using your (and, in aggregate, other users') feedback signals.
4. How We Share Your Information
We do not sell your personal data.
- With friends: only what you explicitly choose to share (e.g. a group plan, or your schedule if you grant that permission). You control this in Privacy Settings.
- Service providers who process data on our behalf:
- Supabase — database, authentication, file storage
- Google Places API / Google Maps — venue and map data
- Google Gemini API — AI concierge responses and content generation
- Stripe — payment processing
- Sentry — crash and error reporting
- Expo — push notification delivery
- Aggregated/anonymized analytics: we may share data that cannot identify you individually (e.g. category popularity trends) with business partners.
- Legal requirements: if required by law, court order, or government request.
- Business transfers: in a merger, acquisition, or sale of assets, user data may transfer to the acquiring entity, who would be bound by this policy or a materially similar one.
5. Location Data
Location is core to Loop's recommendations. Foreground location is used to find nearby activities and calculate distance/travel time. Any background location use is opt-in and limited to the feature you enabled it for; you can disable it at any time in your device's Settings app. Your location is never shown to other users directly — group planning uses a calculated meeting point, not your live position.
6. Data Retention
- Account data: retained while your account is active; deleted within 30 days of a confirmed account-deletion request.
- Feedback data: retained to power recommendations; anonymized after account deletion where used in aggregate model training.
- Crash/error reports: retained per Sentry's default retention window for debugging purposes.
- Payment records: retained as required by law for tax and accounting purposes.
7. Your Rights and Choices
- Access & correction: review and update your profile information in-app.
- Deletion: delete your account and associated data from Settings, or by contacting TODO: PRIVACY EMAIL. Account deletion is a supported, irreversible in-app action.
- Location opt-out: revoke location permission in device settings at any time.
- Notification opt-out: disable push notifications in device settings or in-app.
- Data portability: request a copy of your data in a machine-readable format by contacting us.
California residents (CCPA): you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information.
EEA/UK residents (GDPR basics): where applicable, you have the right to access, rectify, erase, restrict, or port your data, and to object to certain processing. Contact us to exercise these rights. TODO: confirm whether Loop is offered in the EEA/UK at launch; if not, this section may be simplified.
8. Data Security
- Data in transit is encrypted via HTTPS/TLS.
- Database access is protected by Supabase Row-Level Security (RLS) policies, so users can generally only access their own data.
- API keys and secrets are kept server-side and are not exposed in client-side code.
- Payment processing is handled by Stripe / the app stores' own PCI-DSS-compliant systems.
9. Children's Privacy
Loop is not directed to children under 13, and our Terms require users to be at least 13 (see Terms of Service for the account age requirement actually enforced by the App). We do not knowingly collect personal information from children under 13. If we learn we've collected such data, we will delete it promptly.
10. Third-Party Links
The App may link to third-party venue websites, ticketing platforms, or map services. We are not responsible for their privacy practices; please review their policies separately.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last Updated" date above and, where required, by an in-app notice.
12. Contact Us
Email: TODO: PRIVACY EMAIL
Address: TODO: COMPANY ADDRESS