loopalong

Privacy Policy

Effective date: August 13, 2026  ·  Last updated: August 13, 2026

Loopalong is a personal taste journal — a place to track and share the things you love, from restaurants to films to music. This policy explains in plain language exactly what data we collect, how we collect it, why we collect it, who we share it with, and what rights you have over it.

If you have questions, email us at privacy@loopalong.com.

Section 1

Who We Are

Loopalong is operated by Luca Silberberg.

Privacy contact
privacy@loopalong.com
Section 2

What Data We Collect and How

We collect data in three ways: directly from you, automatically when you use the app, and from third-party services you use to sign in.

Data you give us directly

DataWhen you provide it
Email addressWhen you create an account
NameWhen you sign in with Apple or Google
UsernameWhen you set up your profile
Profile photoOptionally, when you edit your profile
BioOptionally, when you edit your profile
Items you saveName, category, rating, your notes, and metadata (address, release year, etc.)
Photos you uploadOptional photos you attach to saved items
Wishlist and pinned itemsWhen you save or pin something
Follow relationshipsWhen you follow or unfollow someone
Blocked usersWhen you block someone
Approximate locationOnly if you explicitly grant permission — used to surface nearby restaurants and hotels

Data collected automatically when you use the app

DataWhy it's collected
IP addressCollected automatically with every network request by our backend infrastructure
Device type and operating systemCollected to ensure compatibility and for security monitoring
App versionCollected to support troubleshooting and app updates
Session timestampsCollected when you open and close the app
Device locale and time zoneCollected to format dates and content correctly

Data from third-party sign-in providers

When you sign in with Apple or Google, those services share your name and email address with us. We do not receive your Apple or Google passwords.

Section 3

Why We Collect Your Data

We only collect data we actually need. The table below explains why we collect each type and — for users in the EU and UK — the legal basis under GDPR.

PurposeData usedGDPR legal basis
Providing the app (collection, sync, profiles, social features)Account info, content, follow relationshipsPerformance of a contract
Respecting your privacy settings (per-item and account-level)Visibility flags, account privacy togglePerformance of a contract
Security, abuse prevention, and debuggingIP address, device data, session logsLegitimate interest
Responding to support requestsEmail, account infoLegitimate interest
Surfacing nearby restaurants and hotelsApproximate locationConsent (you must explicitly grant permission)
Delivering push notifications (if you opt in)Device push notification tokenConsent (you must explicitly enable notifications)
App stability and crash diagnosticsDevice type, OS version, app versionLegitimate interest
What we don't do: We do not use your data for advertising. We do not sell your data. We do not use your content to train AI models. AI tools used in our internal development process do not have access to personal user data.
Section 4

Who We Share Your Data With

We do not sell your personal data to anyone. We share data only with the service providers listed below, and only to the extent necessary to operate the app.

Backend infrastructure

Supabase (supabase.com/privacy) stores your account, profile, and content data on secure cloud infrastructure hosted on Amazon Web Services. Supabase acts as a data processor on our behalf.

Sign-in providers

Apple (apple.com/legal/privacy) and Google (policies.google.com/privacy) authenticate you when you use Sign in with Apple or Sign in with Google. They receive only what is necessary for authentication; we do not share your app activity with them.

Content search APIs

When you use the search feature, we send your search query — and, for restaurant and hotel searches, your optional approximate location — to the following APIs. We do not send your account identifier, username, or profile to these services.

App platform

Loopalong is built using Expo (expo.dev/privacy), a mobile development platform. Expo may collect technical diagnostic data — such as crash reports and device identifiers — to support app stability and update delivery. This data is governed by Expo's privacy policy.

Legal disclosures

We may disclose your data if required by law, court order, or to protect the rights and safety of Loopalong or its users.

Section 5

International Data Transfers

Loopalong is operated from the United States. If you access the app from the EU, UK, or other regions with data protection laws, your data is transferred to and processed in the United States.

Supabase uses Standard Contractual Clauses approved by the European Commission to lawfully transfer data from the EEA and UK to the United States. You can review Supabase's data transfer practices at supabase.com/privacy.

Section 6

Public vs. Private Content

By default, items you save are visible to your followers. You can change the visibility of any individual item to "Just me" at any time from the item's detail screen.

You can also set your entire account to Private. When your account is private, new followers must send a follow request that you approve before they can see your content.

Content marked "Just me" is never visible to other users, regardless of your account privacy setting.

Section 7

Data Retention and Deletion

We keep your data for as long as your account exists.

When you delete your account

Deletion is available at Profile → Settings → Delete Account. The following is permanently removed from our active systems:

Deletion is irreversible. We cannot recover deleted accounts or their data.

Backup retention

Our infrastructure provider (Supabase/AWS) retains encrypted database backup snapshots for up to 30 days after deletion before final purge. Your data is not accessible or used during this window, but it may exist in encrypted form until the backup expires.

Section 8

Your Rights

All users

You can at any time:

EU and UK users (GDPR)

You have the right to:

To exercise these rights, email privacy@loopalong.com. We will respond within 30 days. If you believe we have not complied with your rights, you have the right to lodge a complaint with your local data protection authority.

California users (CCPA / CPRA)

You have the right to:

To exercise your California rights, email privacy@loopalong.com. We will respond within 45 days.

Section 9

Children's Privacy

Loopalong is not directed at children under 13, or under 16 in the EU and UK. We do not knowingly collect personal information from children under these ages.

By using the app, you represent that you meet the applicable minimum age requirement. If we become aware that a child below the minimum age has registered, we will promptly delete their account and all associated data. To report a concern, contact privacy@loopalong.com.

Section 10

Security

We use industry-standard security practices to protect your data:

No system is completely secure. In the event of a security incident, we will work quickly to investigate, contain, and remediate the issue.

Section 11

Data Breach Notification

If we become aware of a data breach that affects your personal information, we will:

Section 12

Push Notifications

If you opt in to push notifications, we collect your device push notification token to deliver notifications to you. You can withdraw this consent at any time in your device's notification settings. Revoking permission stops future notifications and does not affect any other data we hold.

Section 13

Changes to This Policy

If we make material changes to this policy, we will update the "Last updated" date and post the revised policy at this URL. For significant changes, we may also notify you in-app. Continued use of Loopalong after a change takes effect constitutes acceptance of the updated policy.

Section 14

Contact

For privacy questions, data requests, or concerns:

Email
privacy@loopalong.com

We aim to respond to all privacy inquiries within 30 days.