Loopalong is a personal taste journal — a place to track and share the things you love, from restaurants to films to music. This policy explains in plain language exactly what data we collect, how we collect it, why we collect it, who we share it with, and what rights you have over it.
If you have questions, email us at privacy@loopalong.com.
Who We Are
Loopalong is operated by Luca Silberberg.
privacy@loopalong.com
What Data We Collect and How
We collect data in three ways: directly from you, automatically when you use the app, and from third-party services you use to sign in.
Data you give us directly
| Data | When you provide it |
|---|---|
| Email address | When you create an account |
| Name | When you sign in with Apple or Google |
| Username | When you set up your profile |
| Profile photo | Optionally, when you edit your profile |
| Bio | Optionally, when you edit your profile |
| Items you save | Name, category, rating, your notes, and metadata (address, release year, etc.) |
| Photos you upload | Optional photos you attach to saved items |
| Wishlist and pinned items | When you save or pin something |
| Follow relationships | When you follow or unfollow someone |
| Blocked users | When you block someone |
| Approximate location | Only if you explicitly grant permission — used to surface nearby restaurants and hotels |
Data collected automatically when you use the app
| Data | Why it's collected |
|---|---|
| IP address | Collected automatically with every network request by our backend infrastructure |
| Device type and operating system | Collected to ensure compatibility and for security monitoring |
| App version | Collected to support troubleshooting and app updates |
| Session timestamps | Collected when you open and close the app |
| Device locale and time zone | Collected to format dates and content correctly |
Data from third-party sign-in providers
When you sign in with Apple or Google, those services share your name and email address with us. We do not receive your Apple or Google passwords.
Why We Collect Your Data
We only collect data we actually need. The table below explains why we collect each type and — for users in the EU and UK — the legal basis under GDPR.
| Purpose | Data used | GDPR legal basis |
|---|---|---|
| Providing the app (collection, sync, profiles, social features) | Account info, content, follow relationships | Performance of a contract |
| Respecting your privacy settings (per-item and account-level) | Visibility flags, account privacy toggle | Performance of a contract |
| Security, abuse prevention, and debugging | IP address, device data, session logs | Legitimate interest |
| Responding to support requests | Email, account info | Legitimate interest |
| Surfacing nearby restaurants and hotels | Approximate location | Consent (you must explicitly grant permission) |
| Delivering push notifications (if you opt in) | Device push notification token | Consent (you must explicitly enable notifications) |
| App stability and crash diagnostics | Device type, OS version, app version | Legitimate interest |
Who We Share Your Data With
We do not sell your personal data to anyone. We share data only with the service providers listed below, and only to the extent necessary to operate the app.
Backend infrastructure
Supabase (supabase.com/privacy) stores your account, profile, and content data on secure cloud infrastructure hosted on Amazon Web Services. Supabase acts as a data processor on our behalf.
Sign-in providers
Apple (apple.com/legal/privacy) and Google (policies.google.com/privacy) authenticate you when you use Sign in with Apple or Sign in with Google. They receive only what is necessary for authentication; we do not share your app activity with them.
Content search APIs
When you use the search feature, we send your search query — and, for restaurant and hotel searches, your optional approximate location — to the following APIs. We do not send your account identifier, username, or profile to these services.
- Google Places API — restaurants and hotels
- TMDB — films and shows
- Google Books API — books
- Spotify Web API — music (queries are routed through our own server to protect our API credentials; Spotify does not receive your account details)
App platform
Loopalong is built using Expo (expo.dev/privacy), a mobile development platform. Expo may collect technical diagnostic data — such as crash reports and device identifiers — to support app stability and update delivery. This data is governed by Expo's privacy policy.
Legal disclosures
We may disclose your data if required by law, court order, or to protect the rights and safety of Loopalong or its users.
International Data Transfers
Loopalong is operated from the United States. If you access the app from the EU, UK, or other regions with data protection laws, your data is transferred to and processed in the United States.
Supabase uses Standard Contractual Clauses approved by the European Commission to lawfully transfer data from the EEA and UK to the United States. You can review Supabase's data transfer practices at supabase.com/privacy.
Public vs. Private Content
By default, items you save are visible to your followers. You can change the visibility of any individual item to "Just me" at any time from the item's detail screen.
You can also set your entire account to Private. When your account is private, new followers must send a follow request that you approve before they can see your content.
Content marked "Just me" is never visible to other users, regardless of your account privacy setting.
Data Retention and Deletion
We keep your data for as long as your account exists.
When you delete your account
Deletion is available at Profile → Settings → Delete Account. The following is permanently removed from our active systems:
- Your profile (name, username, bio, profile photo)
- All items you saved, including ratings, notes, and metadata
- Photos you uploaded and attached to items
- Your wishlist and pinned items
- Your follow relationships and blocks
Backup retention
Our infrastructure provider (Supabase/AWS) retains encrypted database backup snapshots for up to 30 days after deletion before final purge. Your data is not accessible or used during this window, but it may exist in encrypted form until the backup expires.
Your Rights
All users
You can at any time:
- View and edit your profile, items, and privacy settings inside the app
- Change any item's visibility (Shared or Just me)
- Set your account to Private
- Block or unfollow other users
- Delete your account (Profile → Settings → Delete Account)
- Contact us at privacy@loopalong.com to request data export, correction, or targeted deletion
EU and UK users (GDPR)
You have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data ("right to be forgotten")
- Portability — receive your data in a structured, machine-readable format
- Restriction — ask us to limit processing of your data in certain circumstances
- Object — object to processing based on legitimate interest
- Withdraw consent — at any time, for processing based on consent (such as location access or push notifications). Withdrawing consent does not affect processing that occurred before withdrawal.
To exercise these rights, email privacy@loopalong.com. We will respond within 30 days. If you believe we have not complied with your rights, you have the right to lodge a complaint with your local data protection authority.
California users (CCPA / CPRA)
You have the right to:
- Know — request details about what personal information we collect, use, and disclose
- Delete — request deletion of your personal information
- Correct — request correction of inaccurate personal information
- Opt out of sale or sharing — we do not sell or share your personal information as defined under CCPA/CPRA, so this right is not currently applicable
- Limit use of sensitive personal information — we do not use sensitive personal information beyond what is necessary to provide the service
- Non-discrimination — we will not discriminate against you for exercising your privacy rights
To exercise your California rights, email privacy@loopalong.com. We will respond within 45 days.
Children's Privacy
Loopalong is not directed at children under 13, or under 16 in the EU and UK. We do not knowingly collect personal information from children under these ages.
By using the app, you represent that you meet the applicable minimum age requirement. If we become aware that a child below the minimum age has registered, we will promptly delete their account and all associated data. To report a concern, contact privacy@loopalong.com.
Security
We use industry-standard security practices to protect your data:
- TLS encryption for all data in transit between the app and our servers
- Row-Level Security (RLS) on our database, ensuring users can only access data they are permitted to see
- OAuth 2.0 for third-party sign-in (Apple and Google)
- API key restrictions limiting each third-party API key to its authorized use case only
No system is completely secure. In the event of a security incident, we will work quickly to investigate, contain, and remediate the issue.
Data Breach Notification
If we become aware of a data breach that affects your personal information, we will:
- Notify relevant data protection authorities within 72 hours where required by GDPR
- Notify affected users promptly via email or in-app notice, where required by applicable law
- Describe the nature of the breach, what data was affected, and what steps we are taking
Push Notifications
If you opt in to push notifications, we collect your device push notification token to deliver notifications to you. You can withdraw this consent at any time in your device's notification settings. Revoking permission stops future notifications and does not affect any other data we hold.
Changes to This Policy
If we make material changes to this policy, we will update the "Last updated" date and post the revised policy at this URL. For significant changes, we may also notify you in-app. Continued use of Loopalong after a change takes effect constitutes acceptance of the updated policy.
Contact
For privacy questions, data requests, or concerns: