Loop Privacy Policy
Version: 2026-09-28 Last updated: 2026-09-28
1. General provisions
This Privacy Policy ("Policy") sets out how personal data of users of the Loop mobile application ("App") is processed, and the measures taken to protect it.
Personal data controller — Vyacheslav Evgenievich Zakharov (an individual, the App's developer; "Controller").
Contact for any question about personal data processing, including access, correction, deletion, withdrawing consent, and appealing a moderation decision: zaharovgrpi@gmail.com.
By using the App, the user confirms agreement with this Policy. If the user does not agree with the processing terms, they must not use the App.
2. Legal grounds and purposes of processing
The Controller processes personal data:
- based on the data subject's consent, expressed by accepting this Policy and the Community
Guidelines;
- to perform the agreement with the user — providing the App's core functionality (creating
circles, sharing photos and reactions).
Purposes of processing:
- providing core functionality — showing photos to circle members and in the widget;
- authenticating the user and restoring access;
- delivering notifications about new posts;
- reviewing reports and moderating content;
- crash diagnostics and product analytics (while the diagnostics switch is on — see §4);
- measuring advertising campaigns (see §3.5);
- complying with legal requirements.
The Controller does not sell personal data, does not transfer it to data brokers, does not build advertising profiles of users, does not show advertising inside the App, and does not make legally significant decisions about a user based on personal data in an automated way.
3. Categories of data subjects and personal data
Data subjects are App users. The following categories of data are processed.
3.1. Data the user provides directly
| Data | When it appears | Purpose |
|---|---|---|
| Display name | When creating a circle or joining by invitation | Shown to circle members under photos |
| Email address | Optional when joining, required when creating a circle | Access recovery, confirming account ownership, deleting the account via the web page |
| Circle name | When creating a circle | Shown to members |
| Photos and videos | When shooting inside the App | Shown to circle members and in the widget |
| Reactions (emoji) | When tapping a reaction | Shown to circle members |
| Report text | When filing a report | Reviewed by a moderator |
3.2. Data generated automatically
| Data | Source | Purpose |
|---|---|---|
| Account identifier | Generated server-side on first launch | Links a device to a circle |
| Access token (JWT) | Generated server-side | Authentication; stored encrypted on the device |
| Firebase Cloud Messaging push token | Firebase SDK on the device | Delivering notifications and updating the widget |
| "App opened" event | The App | Product metric (while the diagnostics switch is on) |
| Crash report: exception text, stack trace, app version, device model and Android version | The App, on a crash | Diagnostics (while the diagnostics switch is on) |
| Device operational trace: installation, session, operation, push and content identifiers; stages, timestamps, durations, outcomes, error codes, app/OS version and device model | The App and the push-delivery server | Investigating push, widget-refresh and background-processing failures (while the diagnostics switch is on; the FCM token, message body and exception text are not written to the trace) |
| Time of joining a circle and posting a photo | Server | Feed ordering, moderation audit |
3.3. Data from connected chats (Telegram / MAX)
If a circle member connects a Telegram or MAX group chat to it, the Loop bot receives images and videos from that chat and posts them into the circle. In doing so:
- the file itself, its type, size, video duration, and the identifiers of the source message and
chat are stored (needed to mirror reactions back onto the message);
- Loop accounts are not created for the chat's message authors: such content is posted under a
service account representing the chat as a whole;
- as a result, a specific chat author cannot be blocked through the App. Such content can be
reported and a moderator can remove it; the source as a whole can be disconnected by a circle member from the "Content sources" screen.
Responsibility for connecting a chat rests with the member who connected it — including for the lawfulness of moving that chat's content into Loop and for having the consent of the people whose images are published there. The App shows this notice on the connect screen. If your image ended up in Loop without your consent, write to zaharovgrpi@gmail.com — it will be removed.
MAX availability by distribution channel. The version of the App distributed through Google Play does not show MAX in the list of sources and does not allow connecting a new MAX chat — this feature exists only in versions distributed outside Google Play (direct install, Galaxy Store). If a MAX chat is already connected to a circle from another version of the App, its photos remain visible to every member of that circle, including those using the Google Play version: the restriction only applies to starting a new connection, not to displaying content already received. Telegram connection is available in every version without exception.
3.4. What is not collected
Location, contacts, call log, SMS, the list of installed apps. Special categories of personal data and biometric data are not deliberately processed.
3.5. Advertising and first-run measurement
The Google Play and App Store versions measure where installs come from and at which step of the first run people stop, so that money spent on advertising can be told apart from money wasted. The following is processed for that purpose, and only while the diagnostics switch is on:
| Data | Source | Recipient |
|---|---|---|
| Install attribution: the campaign, creative and placement identifiers Google Play reports after an install, Google's own click identifier, and the times of the click and of the install (Android only) | Google Play Install Referrer | The Controller |
| A device identifier for analytics: on Android the advertising identifier (a resettable identifier the device provides), on iOS the identifier for vendor (IDFV); on both, Firebase's random app instance identifier | The App | Google (Firebase / Google Analytics, Google Ads) |
| Which screens were opened and which steps were completed: for example that the "create a circle" or "join" path was chosen, a circle was created, an invitation was opened in the system share menu, a widget was added, a first moment was sent — and the category of an error if a step failed | The App | Google (Firebase / Google Analytics, Google Ads) |
| Advertising identifier and the fact of an install (Android only) | The App | TikTok |
The full referrer address is never stored — only the allowlisted identifiers above, each length- bounded. Only step names and values from closed lists are sent to Google: no Loop account identifier, e-mail address, name, circle, invitation or moment identifier, moment content or text is included, and this data is not linked to a Loop account. The App does not use the iOS advertising identifier (IDFA) and does not ask for permission to track. The advertising identifier can be reset or its use limited in the device's own Android settings, independently of the App.
Versions outside Google Play and the App Store (direct installation, Galaxy Store) do not measure advertising and send none of this data to Google.
4. Controlling diagnostic telemetry
In app-store builds, the "app opened" event, first-run funnel steps, crash reports and device operational traces are collected from first launch. The app's first screen says so and links to this Policy.
Collection can be switched off at any time with the "Diagnostics and statistics" switch in Settings. Switching it off stops future sends and deletes unsent diagnostic data from the device; the choice is remembered and is not reset by app updates.
Before registration these events carry only a random installation identifier and are linked to no account; once an account is created they are associated with it. Deleting the account resets the installation identifier. Server push-send results are retained only for registered devices and are used with the client trace when investigating a support report.
5. Retention periods
| Data | Retention period |
|---|---|
| Photos and videos | No automatic deletion — kept until deleted by the author, the circle owner, or a moderator, or until the author's account is deleted |
| Account and profile | Until the account is deleted |
Event log (event_logs) | 90 days, then automatically deleted |
Crash reports (crash_logs) | 90 days, then automatically deleted |
Operational traces (diagnostic_events, diagnostic_reports) | 7 days from server receipt, then automatically deleted |
| Reports — open | Until reviewed; not automatically deleted |
| Reports — reviewed | 1 year from the review date |
| Email confirmation tokens | 24 hours |
| Account deletion tokens | 30 minutes |
| Database backups | 30 days |
| Deleted object versions in object storage | 30 days |
Scheduled deletion runs as a daily background job, and again on every service restart.
6. Account deletion
An account can be deleted in two ways:
- In the App: Settings → "Delete account" → confirmation.
- Via the web page
/delete-account: available if the account has a confirmed email
address. A one-time link, valid for 30 minutes, is sent to it; deletion happens only after a separate confirmation on the page the link opens.
If there is no confirmed email, the account is deleted from the App on the device where the user is signed in, or by writing to zaharovgrpi@gmail.com.
Permanently deleted: the profile (name, email, identifier), all photos, previews and videos the user uploaded (from the database and object storage), membership in every circle, reactions, push tokens, operational diagnostic traces, confirmation and deletion tokens, blocks, invitations and chat-linking codes, and the record of accepting the rules.
Circles created by the user: if no other members remain, the circle and its content are deleted; if members remain, the circle is kept without an owner and their photos are not deleted.
Kept in anonymized form (with no link to the account): the event log, crash reports, and reports the user filed — so that deleting an account cannot be used to withdraw a report about a violation. These records are deleted according to the periods in §5.
Temporarily retained: data remains in database backups for up to 30 days and in deleted object-storage file versions for up to 30 days. Technical entries in infrastructure system logs are kept no longer than 30 days.
7. Security measures
- The connection to the server is HTTPS only.
- The access token is stored encrypted on the device (AES-256, key in the Android Keystore) and is
never written to logs.
- Media links are issued as temporary signed URLs with a limited validity period.
- The account-deletion token is stored server-side only as a SHA-256 hash.
- Access to the moderation panel is protected by a password and a second factor sent by email.
8. Data subject rights
The user has the right to:
- obtain information about the processing of their personal data;
- request correction, blocking, or erasure of data that is incomplete, inaccurate, outdated, or
processed unlawfully — name and email are changed in the App's settings, and the account is deleted using the methods in §6;
- withdraw consent to processing — for diagnostic telemetry, via the switch in settings; in
full, by deleting the account;
- appeal the Controller's actions to the authorized personal-data protection body or in court
under applicable law.
For rights that cannot be exercised in the App, write to zaharovgrpi@gmail.com. A response is provided within 30 days.
9. User age
The App is intended for people 16 years of age and older and is not directed at children. The Controller deliberately does not collect data from people under 16. If you become aware that the App is being used by a child under 16, write to zaharovgrpi@gmail.com — the account and related data will be deleted.
10. Changes to this Policy
When this Policy changes materially, its version is updated and the user is asked to accept the current version before their next piece of content is published.