Loop Privacy Policy
Version: 2026-07-22 Last updated: 2026-07-22
1. General provisions
This Privacy Policy ("Policy") sets out how personal data of users of the Loop mobile application ("App") is processed, and the measures taken to protect it.
Personal data controller — Vyacheslav Evgenievich Zakharov (an individual, the App's developer; "Controller").
Contact for any question about personal data processing, including access, correction, deletion, withdrawing consent, and appealing a moderation decision: zaharovgrpi@gmail.com.
Distribution territory. The App is distributed in a limited list of countries, including the Russian Federation, but outside the European Economic Area. The current list of countries is shown on the App's store listing page.
By using the App, the user confirms agreement with this Policy. If the user does not agree with the processing terms, they must not use the App.
2. Legal grounds and purposes of processing
The Controller processes personal data:
- based on the data subject's consent (Art. 6(1)(1) of Federal Law No. 152-FZ "On Personal
Data"), expressed by starting to use the App and accepting this Policy and the Community Guidelines;
- to perform the agreement with the user (Art. 6(1)(5) of Federal Law No. 152-FZ) — providing
the App's core functionality (creating circles, sharing photos and reactions).
Purposes of processing:
- providing core functionality — showing photos to circle members and in the widget;
- authenticating the user and restoring access;
- delivering notifications about new posts;
- reviewing reports and moderating content;
- crash diagnostics and product analytics (only with consent — see §4);
- complying with legal requirements.
The Controller does not use personal data for advertising, does not transfer it to data brokers, and does not make legally significant decisions about a user based on it in an automated way.
3. Categories of data subjects and personal data
Data subjects are App users. The following categories of data are processed.
3.1. Data the user provides directly
| Data | When it appears | Purpose |
|---|---|---|
| Display name | When creating a circle or joining by invitation | Shown to circle members under photos |
| Email address | Optional when joining, required when creating a circle | Access recovery, confirming account ownership, deleting the account via the web page |
| Circle name | When creating a circle | Shown to members |
| Photos and videos | When shooting inside the App | Shown to circle members and in the widget |
| Reactions (emoji) | When tapping a reaction | Shown to circle members |
| Report text | When filing a report | Reviewed by a moderator |
3.2. Data generated automatically
| Data | Source | Purpose |
|---|---|---|
| Account identifier | Generated server-side on first launch | Links a device to a circle |
| Access token (JWT) | Generated server-side | Authentication; stored encrypted on the device |
| Firebase Cloud Messaging push token | Firebase SDK on the device | Delivering notifications and updating the widget |
| "App opened" event | The App | Product metric (only with consent) |
| Crash report: exception text, stack trace, app version, device model and Android version | The App, on a crash | Diagnostics (only with consent) |
| Time of joining a circle and posting a photo | Server | Feed ordering, moderation audit |
3.3. Data from connected chats (Telegram / MAX)
If a circle member connects a Telegram or MAX group chat to it, the Loop bot receives images and videos from that chat and posts them into the circle. In doing so:
- the file itself, its type, size, video duration, and the identifiers of the source message and
chat are stored (needed to mirror reactions back onto the message);
- Loop accounts are not created for the chat's message authors: such content is posted under a
service account representing the chat as a whole;
- as a result, a specific chat author cannot be blocked through the App. Such content can be
reported and a moderator can remove it; the source as a whole can be disconnected by a circle member from the "Content sources" screen.
Responsibility for connecting a chat rests with the member who connected it — including for the lawfulness of moving that chat's content into Loop and for having the consent of the people whose images are published there. The App shows this notice on the connect screen. If your image ended up in Loop without your consent, write to zaharovgrpi@gmail.com — it will be removed.
MAX availability by distribution channel. The version of the App distributed through Google Play does not show MAX in the list of sources and does not allow connecting a new MAX chat — this feature exists only in versions distributed outside Google Play (direct install, Galaxy Store). If a MAX chat is already connected to a circle from another version of the App, its photos remain visible to every member of that circle, including those using the Google Play version: the restriction only applies to starting a new connection, not to displaying content already received. Telegram connection is available in every version without exception.
3.4. What is not collected
Location, contacts, call log, SMS, the list of installed apps, advertising identifiers. Special categories of personal data and biometric data are not deliberately processed.
4. Processing, storage and transfer
Actions performed on data: collection, recording, systematization, storage, correction, use, transfer (disclosure), anonymization, deletion. Processing is carried out using automation.
Localization. Personal data of users from the Russian Federation is stored in databases located within the territory of the Russian Federation (Yandex Cloud, Yandex Object Storage), in accordance with Art. 18(5) of Federal Law No. 152-FZ.
Consent for diagnostic telemetry. In app-store builds, the "app opened" event and crash reports are not sent until the user turns on the "Diagnostics and statistics" switch in Settings (off by default). Withdrawing consent stops future sends and deletes any unsent crash report from the device.
Disclosure to third parties and cross-border transfer. To provide part of the App's functionality, data is disclosed to the following recipients:
| Recipient | What it receives | Role | Territory |
|---|---|---|---|
| Yandex Cloud | Account, circle, report, event, and crash data | Hosting, primary storage | Russian Federation |
| Yandex Object Storage | Photo files, previews, video; backups | Media and backup storage | Russian Federation |
| Google Firebase Cloud Messaging | Device push token, circle and photo identifiers in the push body | Notification delivery | Google infrastructure (cross-border transfer) |
| Google Cloud Vision (SafeSearch) | The image itself (a photo, or a video's preview frame) — no author identifier, no circle metadata | Automated screening for signs of prohibited content | Google infrastructure (cross-border transfer) |
| Mail server (Timeweb) | Email address, message text | Sending confirmation and account-deletion links | Netherlands (cross-border transfer) |
| Telegram Bot API | Only for circles with a connected chat: downloading files, setting reactions | Chat integration | Telegram infrastructure (cross-border transfer) |
| MAX Bot API | Same, for MAX* | Chat integration | MAX infrastructure |
\* Connecting a new MAX chat is not available in the Google Play version of the App — see §3.3.
About automated screening. Uploaded images may be sent to Google Cloud Vision to be scored automatically for signs of prohibited content. Google acts as a processor: images are used only to produce that score, are not retained afterwards, and are not used to train Google's models. The result is a signal for a moderator — no content is hidden or deleted automatically, and every decision is made by a person (see Community Guidelines, §6).
Transferring data outside the Russian Federation (Google, Telegram, the mail server in the Netherlands) is a cross-border transfer. Data is not sold and is not shared for advertising. Disclosure to authorized government bodies is possible upon a lawful request.
5. Retention periods
| Data | Retention period |
|---|---|
| Photos and videos | No automatic deletion — kept until deleted by the author, the circle owner, or a moderator, or until the author's account is deleted |
| Account and profile | Until the account is deleted |
Event log (event_logs) | 90 days, then automatically deleted |
Crash reports (crash_logs) | 90 days, then automatically deleted |
| Reports — open | Until reviewed; not automatically deleted |
| Reports — reviewed | 1 year from the review date |
| Email confirmation tokens | 24 hours |
| Account deletion tokens | 30 minutes |
| Database backups | 30 days |
| Deleted object versions in object storage | 30 days |
Scheduled deletion runs as a daily background job, and again on every service restart.
6. Account deletion
An account can be deleted in two ways:
- In the App: Settings → "Delete account" → confirmation.
- Via the web page
/delete-account: available if the account has a confirmed email
address. A one-time link, valid for 30 minutes, is sent to it; deletion happens only after a separate confirmation on the page the link opens.
If there is no confirmed email, the account is deleted from the App on the device where the user is signed in, or by writing to zaharovgrpi@gmail.com.
Permanently deleted: the profile (name, email, identifier), all photos, previews and videos the user uploaded (from the database and object storage), membership in every circle, reactions, push tokens, confirmation and deletion tokens, blocks, invitations and chat-linking codes, and the record of accepting the rules.
Circles created by the user: if no other members remain, the circle and its content are deleted; if members remain, the circle is kept without an owner and their photos are not deleted.
Kept in anonymized form (with no link to the account): the event log, crash reports, and reports the user filed — so that deleting an account cannot be used to withdraw a report about a violation. These records are deleted according to the periods in §5.
Temporarily retained: data remains in database backups for up to 30 days and in deleted object-storage file versions for up to 30 days. Technical entries in infrastructure system logs are kept no longer than 30 days.
7. Security measures
- The connection to the server is HTTPS only.
- The access token is stored encrypted on the device (AES-256, key in the Android Keystore) and is
never written to logs.
- Media links are issued as temporary signed URLs with a limited validity period.
- The account-deletion token is stored server-side only as a SHA-256 hash.
- Access to the moderation panel is protected by a password and a second factor sent by email.
8. Data subject rights
Under Art. 14 of Federal Law No. 152-FZ, the user has the right to:
- obtain information about the processing of their personal data;
- request correction, blocking, or erasure of data that is incomplete, inaccurate, outdated, or
processed unlawfully — name and email are changed in the App's settings, and the account is deleted using the methods in §6;
- withdraw consent to processing — for diagnostic telemetry, via the switch in settings; in
full, by deleting the account;
- appeal the Controller's actions to the authorized body for the protection of personal data
subject rights (Roskomnadzor, the Russian data protection authority) or in court.
For rights that cannot be exercised in the App, write to zaharovgrpi@gmail.com. A response is provided within 30 days.
9. User age
The App is intended for people 16 years of age and older and is not directed at children. The Controller deliberately does not collect data from people under 16. If you become aware that the App is being used by a child under 16, write to zaharovgrpi@gmail.com — the account and related data will be deleted.
10. Changes to this Policy
When this Policy changes materially, its version is updated and the user is asked to accept the current version before their next piece of content is published.