Loopa Privacy Policy
Last updated: 4h ago
Loopa Privacy Policy
Mobieus Partners LLC, doing business as Loopa Sheridan, Wyoming, United States
Effective: September 5, 2026 · Last updated: September 5, 2026 · Version 5.0
What changed in 5.0: Consumer health data now has its own document, at /consumer-health-data. Washington's My Health My Data Act requires that policy to stand alone and to carry nothing beyond what the consumer health data laws ask for, so folding it into §15 of this policy was never going to satisfy it. §15 now points there. Nothing about what Loopa collects, shares or does has changed; what changed is where the consumer health data disclosures live and that they are now reachable in the app as well as on the web.
What changed in 4.9: §4.4 widens the description of a shared family meal to match where you can now start one. You can share a whole meal or a single food out of your food diary, turn on a switch to offer a food at the moment you log it, or send one of your saved meals without logging it at all. What travels is unchanged. The same frozen copy of the same fields, held for the same seven days, deleted the same way. The one addition to the description is that a meal's date is the day you sent it when it came from a saved meal you had not logged.
What changed in 4.8: Loopa now carries a bariatric and medical weight-management track, and §3 names what it records: which procedure or route you tell us you are on and the dates you enter, which stage of the eating plan you are in, the supplement reminders you set, symptoms you flag with a severity and, on some of them, the food that preceded one, and a list of foods you mark as sitting well or not. The severities, the notes, the food names and any question you write for your care team are encrypted with your own key. §3.5 says what Loopa works out from it, where the published reference calendar would put you, whether a supplement schedule you set has two doses too close together, and how far your weight has moved from its lowest point since your procedure, and says that none of it is medical advice. §5 adds one coach category, bariatric support, and lists item by item what it shows and the longer list of what it never shows. Loopa does not decide whether surgery is right for you, does not recommend a procedure, and never sets a dose.
What changed in 4.7: A medication protocol now records four more things you choose to enter, and §3 names each: a food-noise slider on the daily check-in (offered with a GLP-1 protocol or the Off-Ramp program), a question for your prescriber you can write beside a symptom, a check-in or a lab result, a refill date and pharmacy lead time on a compound's supply record, and DEXA and bone-density results among the lab markers. §3.5 describes what Loopa works out from your protocol logs: a pattern of your own days across the dose cycle, a weekly lean-mass protection score, which foods you logged in the hours before a symptom, and a weekly plan, and says that every one of them describes what you recorded and none of them is advice about the medication. §5 says that each coach protocol category now carries two more items, which calendar days are dose days and which of your days your logs put among your strongest and roughest, as labels only, and that a category you switched on before this change stays exactly as it was until you confirm it again. §8 lists the one new piece of ordinary text: the version of the disclosure you confirmed.
What changed in 4.6: Loopa now supports medication protocols you switch on for yourself. GLP-1, testosterone therapy, hormone therapy, and multi-compound and peptide protocols you define yourself. Loopa does not give medication advice. It records what you report and shows it back to you, and every question about the medication itself belongs with your prescriber. §3 says what each protocol records: the schedule you set, the compound names, amounts and notes you type, every dose you log with the place on the body map, symptoms with a severity, a daily wellbeing check-in, lab results you enter, and your answers to the Off-Ramp check-ins: all of it encrypted with your own key. §5 adds three coach categories, each of which shows a symptom pattern as counts, which days your doses fall on, and 14-day wellbeing averages, and never a compound name, an amount, a lab value, a note or libido; peptide protocols are never shared with a coach and have no toggle. §6 says what the coaching AI is told and what it is never told. §8 lists what is stored as ordinary text and why, §9 says how long the record is kept, §11 covers the summary you can generate for your prescriber, and §§12 and 13 cover reading lab results from Apple Health. Progress photographs now carry the time they were taken, so a comparison lines up in the right order.
What changed in 4.5: An organization inside Loopa is a group with a private room and its own challenges, and §5 now describes one as it works. You can belong to as many as you like and own more than one; each has a single owner, who can hand it to another member or delete it; and a challenge shares one total, for one measure, over one stretch of dates, with the other members of that organization, and only if you enter it. No role in an organization can reach your health record, in any part, by any route. There is no permission for it in the system. §3 says what we record about your membership, describes the picture an organization's owner or administrator can give it, and describes a second record: every administrative act on an organization, which holds no health data, which §9 keeps for 90 days and then deletes, and which §8 names among the things stored as ordinary text. An organization inside Loopa holds no partner account and no purchase of yours is recorded against one. A gym that runs Loopa for its own members at its own address is a separate arrangement, and §5 now sets it apart in its own paragraph.
What changed in 4.4: When you photograph a meal, Loopa now shows you what it read from the picture and you correct it before any of it is logged. Two things follow, and §3 and §9 both say so. While that screen is open we hold what was read from your photograph (the foods and their portions) encrypted with your own key, for 24 hours, so you can come back and finish; it goes the moment you log the meal or the day after, whichever is first, and when you do log it we keep the pair (what we read, and what you said it actually was) so we can tell how often the estimate is wrong and in which direction. It is encrypted like the rest of your food record and it goes when your health data goes. The photograph itself is still processed and discarded, exactly as before.
What changed in 4.3: Two small, honest corrections rather than any new collection. Your hydration goal can now count every liquid you log rather than plain water alone, and when it does, the daily total Loopa writes back to Apple Health and Health Connect is that whole fluid total: §4 says so, because more of what you logged leaves the app for your other health apps than before. Separately, if you set Focus targets. Up to three kinds of drink, or saved items, that you want tracked on their own: the list of what you chose to watch is stored as ordinary text, and §8 now names it among the things that are not encrypted. The volumes themselves stay encrypted where they always were, and nothing new is collected about you.
What changed in 4.2: Two additions. You can now show your coach a single workout or activity session. One item at a time, with a note if you want one, and take it back whenever you like. §3 says what that creates, §5 says how it works, and the first time you share with a coach we show you what they will see and record that you agreed. Separately, §5 now sets out what belonging to an organization inside Loopa gives you: a private room and its challenges, and nothing else. No role in an organization can see your health record, because there is no permission in the system that would allow it.
What changed in 4.1: Two settings (a high protein target, and a fast of 48 hours or longer) now show you a health notice and record that you read it and chose to continue. §3 says what that record holds, §6 says how long it is kept, and §8 says it is not encrypted. It is yours to see and to withdraw at any time, and it goes when your health data goes.
What changed in 4.0: Loopa can now be run by an organization: a gym, a club, an employer, an association. §3 says that your membership of one is recorded, and §5 has a new section stating exactly what an organization can see about you: counts, for a month at a time, and nothing else. No role in an organization can see your health record, including the person who owns it, because the permission does not exist. Joining one is your choice, leaving is one tap, and neither affects your subscription, your history or your data.
What changed in 3.9: §6's description of the per-account AI usage record now names every field it holds, including which plan you were on when the feature ran. That row still holds no health content, and it is what makes the free tier's daily limits knowable.
What changed in 3.8: mobieusVerified (the optional identity check) now has its own description. §3 says what you hand over when you choose to do it and how long the document is kept, and §5 says exactly what crosses to the other Mobieus communities you belong to: that you are verified, and nothing else. Verification is optional and nothing in Loopa requires it.
What changed in 3.7: §6 now describes two things that were true and undescribed: the per-account record of how often you use an AI feature (no health content in it, and it is what makes the free tier's daily limits knowable), and the shared estimate cache, which stores a fingerprint of foods rather than anything of yours.
What changed in 3.6: Loopa records structured workouts now: sessions, exercises, sets, reps and weights, and §5 states how that is shared. Workouts, body measurements and progress photos are each their own category on the coach consent screen, so sharing one shares only that one, and all three start off like every other category. §3 already listed workouts, measurements and progress photographs among what we collect, and that is unchanged.
What changed in 3.5: Loopa has friends now, and §5 describes exactly what one can see: your display name, your profile photo, and your streak badge if you leave that switched on. Nothing you log. Sharing anything from your health record still takes a separate accountability-partner grant, category by category, which §5 already described and which is unchanged. §3 records the small amount of new information a friendship creates, §5 states that we never read your contacts and that no search here matches an email address or a phone number, and §10 lists what a deleted account takes with it.
What changed in 3.4: the record of who has read your health data is now a screen you can open. More → Preferences → Your Data in the app, Settings → Your Data on the web. It shows what is encrypted and what is not, every coach and staff member who opened your record and the reason they gave, everyone you are currently sharing with and a button that stops each of them, and exactly what each AI feature sends. §8 is rewritten to describe it, including what it still does not cover.
Version 3.3, below, replaced the version dated August 20, 2026. What changed there, and why it was a correction rather than an addition: three statements in the previous version did not match how the system actually works, and we would rather say that plainly than quietly reword it.
We said your health data was encrypted with a key that belonged to you alone. Each member does have their own key and it is stored wrapped, both true, but the key that unwraps it is ours, held on the server, not derived from anything you know. So the encryption defeats a stolen database, backup or disk, and it does not put your record beyond our reach. §8 now says who holds the key, and lists what is not encrypted at all.
We said meal photographs are discarded unless you turn photo history on, in which case they are stored encrypted. There is no photo-history setting, and the retention mode that exists in our code does not encrypt. Photographs are discarded, which was the operative half and remains true; the rest is gone.
We said you could see the record of who read your health data. You cannot yet. There is no screen for it, and §8 now says so and tells you to ask us. We also narrowed the claim about administrator access to what the log actually covers, and said which routes it does not.
Separately, §6.1 now describes the one case where a direct message reaches an AI: after somebody reports it.
The previous entry, for version 3.2, is unchanged and still describes §5: you can now join a coach at any time rather than only when you sign up, so the coach section no longer applies just to people who arrived through a link; every control it describes is now in the app as well as on the web; the record of when your coach opened your data now distinguishes them glancing at a list of clients from them opening you and reading, and you can read that record yourself; and we say plainly what a coach is shown about your identity. Version 3.1 introduced Loopa Coach; version 3.0 rewrote this policy for Loopa rather than for the Mobieus platform generally.
The short version
Loopa is a health and fitness app. You tell it what you ate, what you weigh, how you slept and how you moved, and it works out what that means for your goal.
We treat that as what it is: some of the most personal information you will ever put into an app. So:
- Loopa is for adults. You must be 18 or older. We do not knowingly collect anything from anyone younger.
- Your health data is encrypted with a key of your own. Every member gets their own key, so a stolen copy of our database is unreadable on its own. There is a limit worth stating plainly: we hold the second key that unwraps yours. That is what lets a small number of our staff reach your record when there is a real reason to, and it means we cannot honestly tell you nobody here is able to read it. What we can tell you is what §8 sets out, who, when, and under what control.
- Deleting your account destroys that key. Not "marks a row deleted": destroys it, which makes everything you ever stored permanently unreadable, including by us.
- We do not sell your information, and we never will. No advertising network receives it. No data broker receives it. Your health data is never used to target an advertisement, on Loopa or anywhere else.
- We do not use your data to train anybody's AI model. Our AI provider is contractually barred from training on it.
- A friend sees your name, your photo and your streak badge. That is the whole list. Friends never see what you log: sharing any of that is a separate decision you make category by category, and you can stop it at any time.
- We never read your contacts. There is no address-book permission in either app, and no search in Loopa matches an email address or a phone number.
- You can take it all with you in a spreadsheet, any time, without asking us.
The rest of this page is the detail. If any of it is unclear, write to privacy@mobieus.io and a person will answer.
1. Who we are
Mobieus Partners LLC ("we", "us", "our") is a Wyoming limited liability company. We operate Loopa at loopa.mobieus.io and loopahealth.app, and the Loopa apps for iPhone, iPad, Android and Wear OS.
For everything described here we are the controller of your personal information. We decide what is collected and why, and we are accountable for it.
| Privacy contact | privacy@mobieus.io |
| Postal | Mobieus Partners LLC, Sheridan, WY, United States |
| Data protection contact | The privacy address above reaches the person responsible for privacy at Mobieus. Under Quebec's Law 25 that person is our designated Privacy Officer. |
| EU / UK residents | We are established only in the United States. If you are in the EU, EEA, Switzerland or the UK, you may contact us at the address above, and you may also complain to your local supervisory authority. See §14. |
2. Loopa is for adults
You must be at least 18 years old to create a Loopa account or use any part of Loopa. This is a condition of the Terms of Service, not a suggestion.
We do not knowingly collect personal information from anyone under 18. Loopa is not directed to children, is not listed in any children's category on the App Store or Google Play, and contains no content or feature designed to appeal to children.
If we learn that an account belongs to someone under 18, we close it and delete the data. If you believe a person under 18 has given us information, write to privacy@mobieus.io and we will act on it.
A Loopa Family Group is a billing and sharing arrangement between adults. Every member of a Family Group must independently be 18 or older, and the app will not admit a member whose account does not meet that bar.
3. What we collect
3.1 What you give us
Account. Your email address, a username, and optionally a display name, a profile photo and a short bio.
Your password is never stored. Not by us, not anywhere, in any form: not even as a hash. Loopa signs you in with OPAQUE (RFC 9807), a modern authentication standard in which your password computes a proof of who you are rather than being handed over to be checked. On the web, that proof is computed on your own device and your password never leaves it. In the iOS and Android apps, your password is sent once over TLS, used to compute the same proof on our servers, and discarded immediately. It is never written to a database, a log or a backup. Either way there is no password in our database to steal, which is exactly why we chose OPAQUE over a conventional password hash.
Health and wellness information. Only what you choose to record, and only for the features you switch on:
- Food and drink you log, including meals, portions, macronutrients, calories and photographs of meals
- What a meal photograph was read as, and what you corrected it to. Photographing a plate produces a list of foods and portions you review before anything is logged. We hold that list for 24 hours while you are deciding, and once you log the meal we keep what was read alongside what you said it actually was, so we can measure how good the estimate is. Both are encrypted with your own key and both go when your health data goes. The photograph is not kept
- Body weight, body fat percentage, waist and other body measurements
- Vital signs: blood pressure, heart rate, resting heart rate, blood glucose, blood oxygen, body temperature
- Sleep, steps, exercise minutes and workouts
- Water intake, fasting windows, habits, goals and progress photographs
- Supplements you take and their doses
- Medications you add to your list, including the name, strength, dose, how often you take it, and the date and time of each dose you log
- A medication protocol, if you switch one on. Loopa carries four kinds. GLP-1, testosterone therapy, hormone therapy, and multi-compound and peptide protocols you define yourself. What we record is which kind you turned on, the schedule you set for it, and the compound names, amounts and notes you type in. The names, the amounts and the notes are encrypted with your own key
- Each dose you log against a protocol, with the date and time you recorded it and, where the route has a body map, the site you tapped
- Symptoms you record against a protocol, with the severity you chose from one to five and anything you wrote in the note
- Your daily wellbeing check-in. Energy, mood, sleep quality and motivation, each on a five-point scale, libido only if you switch that slider on yourself, and food noise on the same scale when you run a GLP-1 protocol or are in the Off-Ramp program. It is treated exactly as the symptom journal is: encrypted with your key, yours to change or delete, and never part of what a coach is shown
- A question for your prescriber, if you write one beside a symptom, a check-in or a lab result. It is your own words (Loopa never suggests one) encrypted with the entry it sits on, listed for you in the order you wrote them, and placed on the first page of the summary you generate for your prescriber (§11.1)
- A refill date and a pharmacy lead time, if you enter them on a compound's supply record. Loopa works out a reorder-by date from them and from the run-out date it already computes, and reminds you on that day unless you switch the reminder off
- Lab results you type in: the marker, the value, the unit you used, and a note if you add one. The markers now include DEXA lean mass, DEXA fat mass, bone mineral density and a T-score. Loopa keeps the numbers exactly as you entered them, converts nothing, and holds no reference ranges of any kind
- A bariatric or medical weight-management track, if you switch one on. What we record is which of the thirteen routes you told us you are on: from exploring surgery, through each of the procedures, to the non-surgical and long-term tracks: along with the dates you enter for a procedure, a scheduled operation, the start of a pre-operative programme or a balloon removal, and which stage of the eating plan you are in. You choose all of it; Loopa never infers a procedure from anything else
- Your supplement schedule on that track, meaning which of the published nutrient lines you have switched on or off, any amount you set yourself in place of the published range, and the times of day you asked to be reminded. There is no product or brand anywhere in it, and no field to put one in
- Symptoms you flag on that track, with the severity you chose from one to five, anything you wrote in the note, and (on the symptoms where the app offers the field) the food that preceded it. The severity, the note and the food are encrypted with your own key
- Foods you mark as sitting well or not, with the stage you were in when you first answered and when you last did. The food name is encrypted with your own key, and the app keeps one answer per food rather than a running list, so a later answer replaces an earlier one
- A protocol your care team sends in, if you invite them to and then accept it. It replaces the published reference schedule for you, you can see exactly what it changes before you accept it, and you can withdraw it at any time. What they write is encrypted with your own key
- Your Off-Ramp check-in answers, if you join the Off-Ramp program: the answers you give to that week's prompts, week by week, and where you have got to in it
- The time a progress photograph was taken. A progress photograph now carries a capture time, read from the picture's own information or sent by the app at the moment you take it, and left blank where neither says, so a comparison lines up in the right order
- Medical conditions, prescription medications, allergies and foods you avoid, and whether you are pregnant or nursing. Used to keep the app's suggestions safe for you
- Menstrual cycle information, if you track it
- Your age and sex, which the calorie and macro calculations require
- Health notices you accepted. Two settings show you a health notice first: a protein target above 1.2 g per pound of your goal weight, and a fast planned for 48 hours or longer. When you choose to continue we record which notice it was, the version of its wording, the date and time, whether it came from the app or a browser, and the figure you were looking at when you decided (the g/lb target, or the planned hours). It is what makes "you were told" a fact rather than an assertion, and you can see the whole of it in the app under Your Data and withdraw any entry.
Coaching setup. At setup we ask why you are here, how you want to be coached, what has got in the way before, and what previous attempts taught you. You can skip any of it.
Community content. Posts, comments, direct messages, reports you file, and anything else you publish in the Loopa community.
Identity verification, only if you choose it. mobieusVerified is optional. Nothing in Loopa requires it, and declining costs you nothing but the badge and the community features it opens early. If you do start it, you give us your legal name as it appears on your identity document, the type of document, an image of it, and a short selfie video for the liveness check. A person at Mobieus reviews them.
The document image and the liveness video are deleted 90 days after the decision. What remains afterwards is the outcome (verified or not, your legal name, the document type, and the date) because that is the record of a check we are accountable for having made. Your legal name is shown to nobody but you: it appears on your own verification screen and nowhere else in the app.
Organization membership, only if you join one. If you enter an organization's invite code, we record which organization it is, when you joined, when you left, and your role in it (member, administrator or owner) including any change to that role and who made it. You may belong to several, and each membership is its own record. That record is what opens the organization's private room and its challenges to you, and, where the organization runs Loopa itself at its own address, what puts its name and color in your app. §5 says what an organization can and cannot see, which never includes anything about you individually.
An organization's picture, if one is uploaded. An owner or an administrator can give their organization a picture. It belongs to the organization and is chosen by the people who run it: it is not a photograph of any member, and it holds nothing about anybody's health. What we store is a square JPEG our own server writes from what was uploaded (the file as it arrived is not kept) and it is shown to that organization's members. Deleting the organization deletes the picture: the file itself, not only our record of it. Replacing an organization's picture deletes the one it replaced, in the same way.
A record of what is done to an organization. Separately from your membership, every administrative act on an organization is recorded: created, renamed, suspended, handed to a new owner, its invite code retired, a member joining, leaving, removed, promoted, demoted or muted, a challenge created, changed, closed or deleted, the room moderated, and the organization deleted. Each entry holds the organization, who acted, the role they acted in, what they acted on and when: and, where somebody entered a challenge, the sentence they were shown saying what entering shares. It holds no health data. It outlives the organization itself, because it is the only remaining record that the organization existed and that somebody deleted it, and we keep it for 90 days and then delete it. Only our own administrators can read it; no owner or administrator of an organization can.
A session you show your coach. If you have a coach and you show them one workout or one activity session (§5), we record which session it was and its name, the note you wrote if you wrote one, when you shared it, and when you took it back. The first time you share with a coach we also record that you agreed to it: the version of the wording you were shown, the date, whether you were on iPhone, Android or the web, the app version (the wording lives in the app, so the version is what says which words you read) and a one-way hash of the address you connected from, never the address itself.
Support correspondence. What you write to us, and what we write back.
3.2 What connected services give us, with your permission
Nothing below is connected unless you connect it, and you can disconnect any of it at any time.
| Source | What it sends us |
|---|---|
| Apple Health (HealthKit) | Weight, body fat, waist, blood pressure, heart rate, resting heart rate, blood glucose, steps, exercise minutes, water, sleep and workouts. Loopa also writes back what you log: weight, body composition, workouts, and your daily fluid total, which is your whole fluid intake when you have turned on "Count all liquids", and your water alone when you have not |
| Android Health Connect | The equivalent categories on Android |
| Withings | Weight and body composition, blood pressure, sleep and activity from your Withings devices |
| Oura | Sleep, readiness, heart rate and activity |
| iHealth | Weight, blood pressure, blood glucose, blood oxygen, heart rate, temperature, sleep and activity |
| Wear OS watch | Quick logs you record on the watch |
3.3 What a friendship creates
Very little, and none of it is health data. When you use Friends we store:
- the connection itself, who asked, who answered, when, and its current state
- your discoverability choices: who may send you a request, whether a username search returns you, whether friends see your streak badge, whether your health achievements appear on your profile
- any invite links you create, as a one-way hash. The link itself is shown to you once and is never stored, so a copy of our database contains no working link
- anyone you have blocked, which only you can see
- any report you file about another member, with the reason you chose, whatever you wrote, and a snapshot of that member's profile as it read at the time
We do not store your contacts, because we never read them.
3.4 What we collect automatically
Your IP address, device type and operating system version, app version, the pages or screens you open, and the times you do it. On the web, cookies and similar technologies. See §7.
Where you got to in the app tour. If you take the guided tour, we store which step you reached and whether you finished it, skipped it or are partway through: nothing else about it. It is kept with your account rather than on the handset so the tour picks up where you left off on another device, and it goes when your account does.
If you turn on notifications we store a push token: issued by Apple on iPhone and iPad, by Google's Firebase Cloud Messaging on Android, or by your browser's own push service on the web. A token identifies the installation, not you, and deleting the app or turning notifications off invalidates it.
3.5 What we work out from all of it
Body mass index, calorie and macronutrient targets, weight-trend forecasts, streaks, energy balance and the insights and suggestions the app shows you. These are derived from the above, not collected separately.
Interaction alerts. If you add medications or supplements, Loopa checks them against FDA-approved product labeling and against the food and drink you have logged, and records any interaction those labels state. Each alert holds the pair, where the label states it, the label's own sentence, and whether you have marked it reviewed. The check runs entirely on our servers against a copy of the FDA's public labeling data. nothing about you is sent to the FDA or to anyone else to perform it.
Daily summaries. We compute one summary row per day from what you logged, so your trends and reports can be drawn without re-reading your whole history. It contains nothing you did not log; it is arithmetic on your own entries, and it is encrypted like they are.
What we work out from a bariatric or medical weight-management track. If you run one, three things are computed from your own entries and from published guidance, and none of them is medical advice. Where the reference calendar would put you compares the date you entered for your procedure against the day ranges in the published reference stages. It is shown beside where you actually are, never in place of it, and it never moves you: if your care team has sent in a protocol, or you have told us they advance you at your visits, then nothing but their instruction changes your stage. Supplement timing conflicts compare the reminder times you set against the published rule that iron and calcium are taken at least two hours apart, and offer you a time that clears it; the app never changes a time you set. How far your weight has moved from its lowest point since your procedure is a percentage worked out from weights you logged, and it is compared against a threshold: 10 per cent by default: only to decide whether to offer you a set of reading and a summary to take to an appointment. It decides nothing about your health, and no one is notified.
What we work out from a medication protocol. If you run one, four more things are computed from your own entries and nothing else. Your pattern buckets each day by how many days it fell after a logged dose and averages what you recorded on those days: check-ins, symptoms, sessions completed: and, once three full cycles are logged, names the days your logs put among your strongest and roughest. A weekly lean-mass protection score is a number from 0 to 100 built from the days you met your protein goal, the resistance sessions you completed and the direction of your lean-mass estimate; it is cached week by week, encrypted like the rest. Symptom and food patterns count how often a symptom was logged within three hours of a food you had logged, and are shown only once a symptom has five entries and the food appears before at least half of them. Your week places training days around those patterns and marks dose days as calendar markers. Every one of these describes what you recorded; none of them interprets it, none of them is advice about the medication, and each says "still learning" rather than guessing before it has enough of your logs.
Referrals. You have an invite code. If somebody uses it we record that their account came from yours, when, and whether they finished setting up. That is the whole of it. We never tell you who used your code, only how many people have, and we never tell them anything about you: what they know is what you wrote in the invite yourself.
We check for the obvious abuse: a code used on the account that owns it, an account already attributed to somebody, a burst of sign-ups against one code in a short window, and whether two accounts arrived from the same connection, and we keep the outcome of that check so the same decision is not made twice. Nothing about it produces a payment, a discount or a price, so there is nothing here that decides what anybody is charged.
Sending an invite never touches your contacts. The app hands the message to whichever mail or chat app you choose and you pick the recipient there. Loopa does not ask for permission to read your contacts, does not hold one, and never learns who you sent it to.
3.6 What we deliberately do not collect
We do not collect precise geolocation. We do not collect your contacts, your calendar, your photo library beyond the individual images you attach, your call or message logs, or your browsing outside Loopa. We do not fingerprint your device for advertising, and Loopa contains no advertising SDK of any kind.
We never receive your card number, bank details or full payment credentials. Those go to Apple, Google or Stripe, who tell us only whether a subscription is active.
We never receive your voice. When you log something by asking Siri or Gemini, the assistant does the listening on your device and sends Loopa only the finished instruction: an amount, a food name, a duration. No audio recording reaches us, and none is stored by us in any form. What your assistant itself keeps is governed by Apple's and Google's own policies, not this one.
4. Why we use it, and our legal basis for doing so
For readers in the EU, EEA, UK or Switzerland, the third column is our Article 6 basis, and Article 9 where health data is involved.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account, sign you in, keep you signed in | To provide what you asked for | Performance of a contract |
| Store, display and chart what you log | The core of the product | Performance of a contract, and your explicit consent for health data (Art. 9(2)(a)) |
| Calculate targets, trends and forecasts | The core of the product | Performance of a contract; explicit consent for health data |
| Generate AI meal plans, coaching replies and food estimates | A feature you switch on and use | Performance of a contract; explicit consent for health data |
| Sync with a device or health platform you connected | You asked us to | Your consent, withdrawable by disconnecting |
| Send you reminders and notifications you configured | You asked us to | Performance of a contract; consent where required |
| Take payment and manage your subscription | To sell you the thing you bought | Performance of a contract; legal obligation for tax records |
| Keep the service secure, prevent abuse, investigate fraud | To keep Loopa working and safe | Legitimate interests |
| Screen a new member's forum posts against the Community Guidelines before publishing | To keep the community safe, and because the app stores require it of an app carrying user content | Legitimate interests |
| Understand which features are used, in aggregate | To improve the product | Legitimate interests; consent for analytics cookies |
| Respond to your support requests | To help you | Performance of a contract; legitimate interests |
| Comply with law, respond to lawful requests, defend claims | We must | Legal obligation; legitimate interests |
Where consent is the basis, you can withdraw it at any time. Stop using the feature, disconnect the service, or delete the data, and withdrawing does not affect anything done before you withdrew.
We do not use your information for automated decision-making that produces legal or similarly significant effects. The AI coach makes suggestions. It does not decide anything about you, it cannot change your subscription or your access, and you are free to ignore it.
5. Who we send it to
A clinician you choose. If you create a report (§11.1) and send someone the link, they can read what is in it. That is the entire point of the feature and it happens only when you do it. We do not send it for you, and we do not know who you sent it to.
We share personal information only with the companies below, only for the purpose named, and only under a written contract that forbids them from using it for their own purposes.
| Who | What they receive | Why |
|---|---|---|
| Anthropic PBC | The health context described in §6, and what you type into the coach. Separately, the text of a forum thread or reply you post while you are a new member, for the moderation check in §6.1 | Runs the AI features and the community content filter |
| Stripe, Inc. | Email, name and payment details you enter on the web | Processes web payments. Stripe is the controller of its own payment data. |
| Apple Inc. | Purchase receipts; a push token if you enable notifications | In-app purchases and push notifications on iPhone and iPad |
| Google LLC | Purchase receipts; a Firebase Cloud Messaging token if you enable notifications | In-app purchases and push notifications on Android |
| Withings, Oura Health, iHealth Labs | An authorization token you granted | Reads the data you asked us to sync |
| FatSecret, Open Food Facts | The food name or barcode you searched for | Food and nutrition lookup. They do not receive your identity or your log. |
| Giphy (Snap Inc.) | Your search term, if you insert a GIF in the community | GIF search |
| Google Analytics | Web usage of loopa.mobieus.io, only if you accept analytics cookies | Aggregate usage measurement. Not used in the mobile apps. |
| Our own mail server | Your email address and the message | Sends account email. Operated by us, not a third party. |
We also disclose information when the law requires it, when we must to establish or defend legal claims, or to protect the rights and safety of our members, and to a buyer or successor if Mobieus is acquired or merges: in which case this policy continues to apply until you are told otherwise, and you will be told before your information becomes subject to a different one.
If you are mobieusVerified
Verification belongs to you, not to one account, so it is recognised across every Mobieus community you belong to. Loopa, and any gym, club or employer running on Mobieus.
What crosses is one fact: that you are verified. Not your identity document, not the liveness video, not your date of birth, and nothing you have logged. A community you join learns that the person behind your account passed an identity check, which is what lets it open features a brand-new account waits for. It learns nothing else about the check and nothing at all about your health record, which stays governed by everything else in this policy.
It is asked for only about you. A community can ask whether one of its own members is verified. It cannot ask about anybody else's.
If you have friends in Loopa
A friendship in Loopa is a social connection, not a data-sharing arrangement. Somebody who is your friend can see:
- your display name
- your profile photo
- your streak badge. How many days in a row you have logged something, but only if you leave "Show my streak to friends" switched on. It is on by default and it is one number. It does not say what you logged, or what any of it was.
- how many friends the two of you have in common
That is the entire list. A friend cannot see your weight, your food diary, your fasting, your cycle, your measurements, your vital signs, your photos, your targets or your allergen list. Sharing any of that is a separate, per-category decision you make when you invite somebody as an accountability partner, described above, and ending a friendship, or blocking somebody, ends that sharing too, in both directions and immediately.
How people find you. Three ways, and no others:
- an invite link you create and hand to somebody, which expires after seven days and which you can revoke at any time
- a username search, and only if you have chosen to appear in one. The default is that somebody has to type your exact username; you can widen that or switch it off entirely
- friends of friends, only if you switch that on
We never read your contacts. Neither app asks for the address book, and no part of Loopa matches an email address or a phone number to a member. If you type somebody's email address into the search, it finds nothing, because the search only ever looks at usernames.
Blocking is private. If you block somebody, they are not told, and nothing in the product will let them work it out. You each disappear from the other's view of Loopa.
Your health achievements are yours. Badges like "Ten Pounds Gone" are computed from your health record, so they are off your public profile unless you turn them on. You always see your own.
Everyone you are connected to, and everything each of them can see, is listed on your Your Data screen, with a button that ends each one.
If you are in a Family Group
A Family Group shares one Premium subscription between up to six adults. On its own it shares no health data at all: nobody in the group, including the person who pays, can see another member's food diary, weight, water, vital signs, measurements, photographs, medications or targets. Two things cross, and each is a separate decision you make for yourself.
The shared pantry, if you switch it on. What you add to it: the item, the quantity and your name beside them: is visible to the other members, and any of them can edit or remove it.
A meal you choose to share. You can send a meal to the rest of your Family Group, so that one person can build it and everybody else can log it in a tap. You can send a whole meal or a single food out of your own food diary, offer a food at the moment you log it, or send one of your saved meals without logging it at all.
- What goes with it is a frozen copy of that meal: the foods, their portions, the calories and macronutrients for each one, which meal of the day it was, and its date: the day you ate it, or the day you sent it when it came from a saved meal you had not logged. Your name goes with it, because the people receiving it are being told who cooked.
- Nothing else travels. Not the rest of your diary, not the day it sat in, not your weight, your targets, your allergen list or anything you have not sent. A photograph of the plate is never sent. It stays in your own encrypted storage and no other member can open it.
- It is a copy, not a window. Changing or deleting the meal in your own diary afterwards does not change what they already hold, and does not reach into what any of them logged.
- They decide what to do with it. Log it as it came, adjust the portion first, change it and pass their own version on, or ignore it. Anything they log becomes their own diary entry, encrypted with their own key, and it records that it came from you.
- You see how it landed. How many people logged it, and which of them. That is the same visibility a Family Group already gives its members of each other's names, and nothing more.
- A shared meal expires after seven days if nobody acts on it. Anything already logged is untouched.
It is one switch, and it is yours. "Family meal sharing" lives under Preferences in the app and in your health settings on the web, and it is on to begin with. Turning it off stops meals reaching you and stops you sending them: both directions, across every group you belong to. Nobody is told you turned it off; a member who has is simply not on the list, and anything already waiting for you is hidden rather than deleted, and comes back if you turn it on again in time.
Because a shared meal has to be readable by everybody you sent it to, and nobody else holds your key, the frozen copy is stored without your personal encryption on it. It is reachable only through a live membership of the group it was sent to, it goes when the seven days are up or when either of you deletes their account, and the copy anybody logs from it is encrypted with their own key like every other entry in their diary.
If you belong to an organization
An organization is a group inside Loopa: a gym, a club, a team at work, a set of friends who wanted a room of their own. This section applies only if you have joined one. If you have not, none of it happens to you.
You join by entering an invite code or opening an invite link, and you decide to do it. Organizations are private (there is no directory, no browse and no search) and nobody at one can attach your account without you. You may belong to as many as you like, and each is separate from the others: its own members, its own room, its own challenges, and your own role in each.
What joining gives you is a private room and the organization's challenges. The room is a forum space for its members. The challenges are its own contests, which you enter or ignore as you please. That is the entire list, and it is the entire list in both directions.
What an organization can never see is your health record, in any part, by any route. Not your food log, not your weight, not your photographs, not your measurements, not your workouts, not your cycle, not your vital signs. This is not a setting that happens to be switched off. There is no permission for it in the system, so there is nothing for anyone at your organization to be granted, ask for, or be given by mistake, including the person who owns it. No role there can recommend anything to you, and nothing you show your coach can be addressed to anybody at your organization.
A challenge shares one number, and only if you enter it. A challenge counts one measure over one stretch of dates: workouts logged, active minutes, steps, distance, water logged, days with a completed fast, or a daily check-in. Entering is a separate decision for each challenge, and the screen tells you which measure and which dates before you make it. What is shared is your total for that measure over that window, with the other members of that organization. Never a day of it, never where the number came from, never anything else about you. A leaderboard is named or anonymous, whichever the organization chose; on an anonymous one, the only row anybody can put a name to is their own. Coming out of a challenge takes you off the board.
What an owner and an administrator can do. Every organization has exactly one owner, and the owner may make other members administrators. Between them they change the organization's name, description, picture and accent color; share the invite code and retire one in favor of a new one; remove a member; mute a member in the room; create, close and delete the organization's challenges; and moderate that room. A mute applies to that room and to nothing else in Loopa. None of it touches anything you have logged, and moderation of the wider Loopa community stays with us.
Suspension and deletion. We can suspend an organization, which makes it read-only: nobody posts, nobody new joins, and its members go on reading their own history and can leave at any point. Its owner can delete it, which is permanent: the room and every post in it, every challenge and every result go, and there is no undo. Deleting your own Loopa account does the same to any organization you own, and ends every other membership you hold.
What we record about it. Which organizations you belong to, when you joined each, when you left, and your role in each. Separately, every administrative act on an organization is recorded; §3 says what is in that record and §9 says that it is kept for 90 days.
Leaving. One tap, and it deletes nothing. The room closes for you, you come out of any of its challenges that are still running, and your account, your subscription, your history, your data and every other organization you belong to are untouched. Results you already recorded stay on the boards they are on, because other people took part in those contests. The same is true if the organization is suspended or its owner deletes it.
A gym that runs Loopa for its own members is a different arrangement, and not one of the organizations described above. It is a partner of ours, with its own agreement and its own Loopa at its own address, and its name and color appear in your app. Once a month it sees counts about its members as a group: how many were active, how many hold Premium, how many are both, how many plans its coaches shared and how many were accepted, how many joined, how many left, and how many stayed 90 and 180 days. Those figures describe a set of people. They never name one. Its agreement with us forbids using anything it learns through Loopa in any employment, promotion, discipline, pay, insurance, benefits or membership-pricing decision about an individual, with no exception, and forbids requiring you to join or to share anything with a coach. If a coach there coaches you inside Loopa, what they see is what you switched on, per category, on your own consent screen, and you can switch any of it off at any moment; that organization cannot create the permission, cannot inherit it, and cannot see through it; and every time your coach opens your data it is logged and you can read the log.
If you have a Loopa Coach
This section applies only to members who have a coach. If you do not, nothing here happens to you, no coach can see anything of yours, and the coach screens do not appear in your app at all.
There are two ways to have one. You can sign up through a coach's referral link, which is how it worked before. Or, as of August 20, 2026, you can already be a member and tap a coach's link to join them. The link is the only way in either case, because a coach gives it to a specific person. There is no directory and no code to type. We record which of the two happened, because they are different decisions: one is choosing a coach while choosing Loopa, the other is deciding, with a history already behind you, to hand some of it to a named person.
A Loopa Coach is an independent person, not our employee, and they are paid a commission on subscriptions that start through their link, including yours. Because of that we treat what they can see as a disclosure to a third party rather than something internal, even though the data never leaves our systems.
Nothing reaches your coach until you turn it on. The consent screen starts with every category off. You choose them one at a time: weight, activity, workouts, body measurements, progress photos, nutrition, fasting, cycle, supplements, streaks, and, if you run one, GLP-1 support, testosterone therapy support, hormone therapy support and bariatric support. And you can turn any of them back off whenever you like. There is no button that turns them all on at once, and your coach is not allowed to make sharing a condition of coaching you.
The three protocol categories show a pattern, and nothing else. Each of them shows your coach exactly five things: which symptoms you logged and how they cluster around dose days, as counts; which days of the week your doses fall on; your 14-day averages for energy, mood, sleep quality and motivation; which calendar days are dose days, as markers on your coach's programming calendar; and which of your days your logs put among your strongest and roughest, as those two words only. They never show the compound name, any amount, any lab value, a note on any entry, the check-in scores behind a label, a question you wrote for your prescriber, your food-noise entries, or your supply and calculator figures, and testosterone therapy support never shows libido, even where you record it. Each of the three is its own switch, so turning one on says nothing about the others.
Bariatric support shows a shape, not a record. If you run a bariatric or medical weight-management track, this category shows your coach four things: which stage of the eating plan you are in and how long you have been in it; how many days you logged in the last two weeks, with your average protein and fluid against that stage's own target; how many of your supplement reminders are switched on, as a number; and which symptoms you flagged and how often over the last 30 days. It also shows that your care team has sent us a protocol, if they have. It never shows a supplement name or amount, a lab result or lab date, your weight, the notes you write on a symptom, the food beside one, your food-tolerance list, a question you wrote for your care team, or anything your care team wrote in their protocol. A coach supports the training and the habits; they cannot change your stage, your supplements or your lab schedule.
A consent you gave before September 2, 2026 is not widened for you. The calendar items are new. A protocol category you switched on before they existed keeps showing exactly what it showed then, and your coach receives no calendar markers from it, until you read the updated list and confirm it again in the app. We record which version of the list you confirmed.
Peptide protocols are never shared with a coach. There is no toggle for them, by design. There is no category to switch on, nothing for a coach to ask for, and no screen on their side where one could appear.
Workouts, body measurements and progress photos are three separate choices. Sharing your training log does not share your measurements, and neither one shares your photos. A coach who can see that you trained still cannot see your waist measurement or open a photo unless you switched that category on by itself.
You have one coach at a time. Joining a coach ends any previous coaching relationship in the same act: that coach's private forum closes for you immediately, every category you had switched on for them is switched off, and anything you had shown them is withdrawn from their view. What they sent you stays in your own history, where you can still read it. Your subscription, your price and everything you have logged are untouched.
Showing your coach one session. Separately from the categories above, you can show your coach a single workout or activity session, with a note if you want to add one. It is one item, chosen by you, and it opens nothing else: showing a session does not open your training log, and nothing is ever shared on a schedule or by itself. There is no route in Loopa that puts anything of yours in front of a coach without you choosing that item.
- The first time you share with a coach, we show you what they will see and record that you agreed. §3 lists what that record holds. It holds nothing you logged, and it is asked for per coach. A new coach is a new decision, not the renewal of an old one.
- You can take a share back whenever you like, and it leaves your coach's view in that moment. Your own record of what you showed and when stays with you, including after you withdraw it.
- Leaving a coach, or joining a different one, withdraws everything you had open with them at the same time as it switches every category off.
Everything in this section is in the app as well as on the web. You will find it under More, then Preferences, then Your coach. That matters: a control you can only reach from a browser is not really a control, so the switches, the record of who looked, stopping sharing and leaving are all two taps from the app's menu. Sharing a new session is done in the app, where the screen setting out what your coach will see lives; in a browser you can read what your coach has sent you, accept or decline it, and withdraw any share you have open.
- Turning a category off cuts your coach's access to it immediately, including the history. It is not "from now on": permission is checked every single time your coach opens anything, so a category you switch off is closed even for data they could see yesterday.
- Every time your coach opens one of your categories, it is recorded. Who, which category, when, and whether they were looking at a list of their clients or had opened you specifically. Those are different things and we used to record them identically, which made the record overstate. You can read it yourself, under "Who looked, and when".
- What your coach is told about who you are is the name on your profile. If you have not given a name, they see your username with any email domain removed: never your email address, and never your account identifier.
- Blocking your coach cuts all of it at once, along with their ability to send you anything. It does not change your subscription, your price, or your access to their forum.
- Leaving your coach ends the relationship and revokes everything. Your subscription, your price and your history are untouched. If you later tap their link again you rejoin with every category off, exactly like a new client. Nothing you switched off comes back on by itself.
- Your coach never sees a category you have not enabled. Not blurred, not hidden behind a count, not as an empty placeholder, and never as a prompt asking them to ask you for it. It simply is not there.
- Your coach cannot change anything in your account. They can send you a short note, offer you a meal plan, and recommend a routine or point at a session of yours they would like you to repeat. Every one of those is an offer: you accept it or you decline it, and if you accept, your own account is what writes it. A routine you accept is copied into your own library and stays yours, including after the relationship ends.
- What your coach can send you is limited. A small number of short notes a day, and a small number of posts to their group. That limit exists because someone paid on your subscription should not be able to use your app as a mailing list.
- A coach gives general wellness guidance, not medical advice. Anything clinical belongs with your own clinician.
You can also share with a buddy or an accountability partner. That works the same way and on the same terms: you choose, per category, and you can stop at any time.
Beyond that, and beyond what you choose to share yourself, we do not share your information with anyone. Specifically:
- We have never sold personal information and we will not.
- We do not share personal information for cross-context behavioral advertising. Loopa carries no advertising.
- Your health data is never disclosed for any advertising or marketing purpose, by us or by anyone we send it to.
- Your health data is never used to train an AI model. Anthropic's commercial terms bar it from training on data submitted through its API, and our contract with them reflects that.
- We do not disclose health data to data brokers, insurers, employers or credit reference agencies.
6. Artificial intelligence in Loopa
Loopa's meal planner, coach, food estimation and other AI features are powered by Anthropic's Claude models, accessed through Anthropic's API. Anthropic processes the request and returns a result; it does not retain the content to train models.
What is sent, and when. Only when you use an AI feature, and only what that feature needs. The coach may include:
- Your weight, goal, progress and BMI
- Today's calories, macronutrients and water against your targets
- Your calorie and macro targets, and your logging streak
- What you told us at coaching setup
- A fast you are currently in
- Your age, sex, and what brought you to Loopa
- Medical conditions, prescription medications, and whether you are pregnant or nursing
- Your diet style and the foods you never eat
- The supplements you take, with doses
- Today's steps and workouts, and the habits you are tracking
- Which kinds of medication protocol you have switched on, and the protein, calorie, fiber and training settings they set
- Notable readings from your vitals and measurements
The last three of those exist for your safety: the app cannot avoid recommending a food you are allergic to, or a fasting protocol that is wrong while you are pregnant, unless it knows.
The coaching AI is told which kinds of protocol are switched on and the goal settings they create: the type only, never a medication name, a dose or a lab value. What reaches it is "a GLP-1 protocol is active" and the protein, calorie, fiber and training figures that follow from it, so that its advice about food and training matches what you are doing.
A progress photograph you upload from the web is checked for its orientation, and only with your prior consent to that feature. If you have given it, the picture is sent to the AI provider for the single question of which way up it is, and for nothing else. A photograph taken in the app is never sent to any AI provider. The app records which way up it is at the moment you take it, so there is nothing to ask.
The app tells you this at the point of use. The coach screen shows the list assembled from your own data, so if you have entered no medications, it does not tell you medications are sent. Your name, email address, username and account identifier are not included.
AI output is not medical advice. It is generated by a language model, it can be wrong, and it is not a substitute for a clinician. Do not use it to diagnose, treat, or change a medication.
If you would rather no health information reach an AI provider at all, do not use the AI features. Everything else in Loopa works without them.
We count how often you use an AI feature, and that record is about you. For each AI feature we keep a row saying which feature ran, that it was your account, whether you were on the free tier or Premium at the time, when, how many tokens it used and whether it succeeded, was refused, or was answered from cache. It holds no health content. Not the food, not the question, not the answer, and it exists for three reasons: two of Loopa's AI features have a daily limit on the free tier and the count is how the limit is known; we cap what the whole service can spend in a month; and we need to see when something is failing. You can ask us to delete it under §9, and it goes when your account does.
Estimates are shared between members, and that sharing contains nothing of yours. When the nutrient estimator works out what is in a set of foods, we keep the answer so nobody has to pay for the same question twice. What is stored is a one-way fingerprint of the foods and their amounts, the model that answered, and the nutrients: a fact about food, true for anyone who eats it. No account, no date and no log is stored with it, so it is not a record of you, it is not linked back to you, and deleting your account does not need to touch it. Your own logged day, and the estimate as it appears on your screen, stay in your account and are covered by everything else in this policy.
6.1 The community content filter
There is one place AI runs whether or not you asked for it, and it is fair that you know.
When a member who is new to Loopa posts a thread or a reply in the forums, the text of that post is sent to Anthropic and classified against the Community Guidelines before it publishes. If the classifier is confident the post breaks a rule, the post is held for a moderator instead of going live. Once a member is established, their posts are not checked at all.
- Only forum threads and replies. Not your direct messages, not your health log, not anything you have not chosen to publish.
- One exception, and it only happens after a report. If somebody reports a specific message or post (or you report one) the reported item's text is sent to Anthropic once, to help a human moderator triage it. That is a response to a report, not screening: nothing is read this way unless a person has flagged that particular item, and a moderator makes the decision either way.
- Only the post. The title and body, HTML stripped and length-capped. Your name, email address, account identifier and health data are not sent.
- No retention and no training. Anthropic returns a verdict and does not keep the content to train models.
- It fails open. If the call errors or times out, the post publishes.
We do this because a community where anyone can publish anything to everyone needs a first line that is faster than a person, and because the app stores require one of an app that carries user-generated content. Everything the filter holds still goes to a human.
7. Cookies and tracking
In the mobile apps: none. The Loopa iPhone and Android apps contain no advertising SDK, no analytics SDK, no tracking pixel and no third-party tracker. We do not use Apple's advertising identifier, we do not use Google's advertising ID, and there is nothing to ask you to permit under App Tracking Transparency because we do not track you across other companies' apps or websites.
On loopahealth.app: none. That site sets no cookies and runs no analytics.
On loopa.mobieus.io: cookies that are strictly necessary to sign you in and keep your session secure, and. only if you accept them. Google Analytics and Google Tag Manager for aggregate usage measurement. The banner appears before any analytics tag loads, "Decline" means no analytics cookie is set, and you can change your mind at any time. We use Google Consent Mode so the choice is passed on rather than merely remembered locally.
Global Privacy Control. We honor the GPC signal. If your browser sends it, we treat it as a valid opt-out of any sale or sharing of personal information and of targeted advertising, without you having to do anything else. Because we do not sell, share or advertise, the practical effect is that analytics is disabled.
8. How we protect it
Health data is encrypted with a key of your own. Every member has their own random 256-bit data encryption key. Health values are encrypted with it using AES-256-GCM before they are written to the database, and your key itself is stored only in wrapped form. A database dump, on its own, is useless. This covers your food logs, vitals, measurements, profile, supplements and progress photographs: and, if you run a medication protocol, the compound names, amounts and notes you typed, the note on any dose, every symptom and severity you recorded, your wellbeing check-ins and the lab values you entered.
We hold the key that unwraps yours, and you should know what that means. Your key is wrapped by a platform key that lives on the server, not by anything you know or carry. There is no passphrase of yours anywhere in it. So this is encryption that defeats a stolen database, a stolen backup or a stolen disk. It is not encryption that puts your record beyond our own reach: a small number of our staff, working on the server itself, can decrypt it. We would rather say that than let the word "encrypted" do work it has not earned.
Not everything is encrypted, and here is what is not. Your fasting times, the meal plans and weekly insights we generate for you, your habit check-ins, the record of health notices you accepted, the fluid Focus targets you chose to watch (the fact that you follow green tea, not how much of it you drank) the record of administrative acts on an organization, which names an act and who performed it and carries no health content at all, anything you post in the community, and the subscription identifiers your app store gives us are stored as ordinary text. So are three parts of a medication protocol: the cadence of the schedule you set, the route, and the site on the body map you chose. A reminder has to fire on the right day at the right hour, and the rotation map has to be drawn, and neither of those can be done from a value nobody can read. None of the three names a substance or an amount. So is the version of the coach-sharing disclosure you confirmed for each protocol category. A number that says which list you read, and nothing about your health. None of it is trivial, and we are not going to pretend the list is shorter than it is.
Your password is never stored. See §3.1.
Every tenant has its own database. Loopa's data is not commingled with any other community on the Mobieus platform, and no query can reach across that boundary.
Beyond that: TLS on every connection, no plaintext secrets in the codebase, per-user API keys rather than shared ones, append-only audit logging for privileged actions, rate limiting, and access to production limited to the people who need it.
No system is perfect, and we will not pretend otherwise. If a breach affects your personal information we will notify you and the relevant regulators within the deadlines the law sets: 72 hours to the supervisory authority under the GDPR, and without unreasonable delay under US state and Canadian law.
9. How long we keep it
| What | How long |
|---|---|
| Account and health data | While your account is open, and until you delete it |
| Meal photographs | Processed and discarded. The photograph is used to identify the food and is deleted once it has been, along with its thumbnail. There is no photo-history setting; if we ever add one we will say so here first |
| What a meal photograph was read as | 24 hours, or until you log the meal, whichever comes first. It is what the review screen shows you and what lets you come back and finish. Encrypted with your key |
| What you corrected a photo estimate to | While your account is open, and it goes when your health data goes. It is the pair (what we read, and what you said it was) and it is what tells us whether the estimate is any good. Encrypted with your key |
| Progress photographs | While your account is open. Deleting your account unlinks them from disk |
| A meal you shared with your Family Group | While your account is open, and it goes when your health data goes. It stops being actionable after 7 days, and what any member logged from it is their own diary entry from then on |
| A medication protocol record | While your account is open, and it goes when your health data goes. The schedule and its cadence go with it |
| Community posts and comments | While your account is open; you may delete them sooner |
| Direct messages | Until deleted by a participant |
| Support tickets | 2 years after resolution, 3 years if closed |
| Record of which members viewed data you shared with them | 365 days |
| Record of sharing consents you gave or withdrew | 365 days |
| Record of a session you showed your coach | While your account is open, including after you take it back, so you can always see what you showed and when |
| Record that you were shown the coach-sharing screen and agreed | While your account is open. It holds no health data |
| Record of health notices you accepted | While your account is open, and it goes when your health data goes. Withdrawing one MARKS it rather than erasing it, because a withdrawn acknowledgment is still the record that one was given: deleting the account deletes both |
| Sign-in attempts | 30 days |
| Read notifications | 90 days |
| Administrative audit log | Kept indefinitely. It is hash-chained and append-only precisely so that nobody, including us, can quietly edit the record of what an administrator did. It contains actions, not health data. |
| Record of administrative acts on an organization | 90 days, then deleted. It outlives the organization it describes, because deleting an organization removes its room, its challenges and its results and this is the only record left that any of it happened. It contains acts, not health data |
| Billing and tax records | 7 years, because tax law requires it |
| Analytics (web, if you accepted it) | Per Google Analytics retention, currently 14 months |
The point of a history app is history, so we do not silently expire your logs. They are yours until you say otherwise.
We keep a record of who reads your health data, and most of it you can now read yourself.
Open More → Preferences → Your Data in the app, or Settings → Your Data on the web. Under "Who has looked at your information" you will find every time a Loopa Coach opened something of yours (their name, the date, and which category) and every time Loopa support or an administrator opened your record, with their role, the date, what they looked at, and the reason they gave. Nobody at Loopa can open a member's record without picking a reason first, and that reason is what you see. If nobody has, it says so.
If you share data with a buddy or in a challenge, every time one of them views a category of it is recorded (who, what category, and when) and kept for a year. That particular record does not have its own screen yet; ask us and we will tell you what it says.
Separately, and in a log that cannot be edited or deleted after the fact, we also record any bulk export of a health record, with its date range and row count, and any occasion on which somebody signs into your account under our support-impersonation process. We keep that indefinitely, because a record that can be trimmed is not an answer to "who has seen my data".
The boundary still matters, so here it is. What you see covers a coach reading your data, a member of our staff opening your record in our own tools, and an operator signing in as you. It does not cover an engineer reading the database directly, because no application-level log can see that. The honest control there is who we allow near a database, not a log entry, and it does not cover our software reading your data to run the app, which is constant and has no person on the other end.
Ask at privacy@mobieus.io and we will tell you what either log says for you.
10. Deleting your account, and what that actually does
You can delete your account yourself, without asking us:
- In the app: More → Delete Account
- On the web: Account settings → Delete account
- Or write to privacy@mobieus.io and we will do it
Deletion removes your account and cascades through every health table, and. This is the part that matters. it destroys your encryption key in the same transaction. Everything you ever stored becomes permanently undecryptable, by us and by anyone who ever obtains a copy of the database. Progress photographs are unlinked from disk. There is no undo and no recovery, so export first if you want a copy.
It takes every meal you shared with your Family Group, and your record of the ones they shared with you. A meal one of them already logged stays in their diary, as an ordinary entry of theirs, with your name no longer attached to it.
It also takes your social side with it: every friendship in both directions, every request you had sent or received, every invite link you had created, every block you had placed, and every organization membership you held, including any organization you owned, which is deleted with everything in it. Blocks other people placed on you stop mattering the moment the account is gone.
Two things survive, and both are required: records we must keep for tax and accounting, and moderation records where content was removed for violating the rules: kept so a banned account cannot simply return. A report you filed about somebody else is part of that moderation record and is kept, with your identity removed from it. Neither includes your health data.
Deleting your account does not cancel a subscription bought through Apple or Google. Cancel that in the App Store or Google Play, or you will keep being charged.
11. Taking your data with you
Every member can export, at any time, without asking:
- CSV and Excel. Your complete health history, from Health → Export
- PNG. Charts, for the ones you want as a picture
- Account export. Your profile and community content
- Family meals. Every meal you shared with your Family Group and every one they shared with you, with what you did about each, included in the account export
This satisfies the right to data portability. If you want something we do not already offer, ask.
11.1 Sharing a report with a clinician
Loopa can build a summary for a doctor, dietitian or pharmacist: your intake, weight trend, nutrient adequacy, medications and any interaction alerts, over a window you choose. It is made only when you ask for it, and it is shared only by you.
- The file is stored encrypted with your own key, outside anything the web serves.
- It is reachable only through a link containing 256 bits of randomness. There is no list of reports to browse and no way to guess one.
- The link expires on a date you set (seven days by default, ninety at most) and you can revoke it at any moment. Revoking does not merely switch the link off: it deletes the file.
- You may put a passcode on it, which we store only as a hash.
- Every attempt to open it is recorded, successful or not, so you can see whether it was used. We keep the opener's network address only as a one-way hash: enough to tell you the same reader came back twice, not enough for us to identify them.
- We never email the report and never send it anywhere ourselves. It goes where you send it and nowhere else.
- Deleting your account deletes the reports and their files, and any outstanding link stops working.
A protocol summary is made when you ask and is not stored. If you run a medication protocol you can generate a summary of it for your prescriber, as a PDF or a spreadsheet, over a window you choose. It is built at the moment you ask for it and handed straight to you as a download. No copy of it is kept on our side, and there is no link to expire or revoke. Making one is written into your own access record, under "Who has looked at your information", so you can see afterwards that you made it and when.
12. Apple Health and Apple CareKit
If you connect Apple Health, Loopa reads only the categories you tick and writes back only what you ask it to write. Beyond that:
- HealthKit data is never used for advertising or any similar service, and never will be.
- HealthKit data is never sold, rented, or disclosed to data brokers, insurers, employers or marketers.
- HealthKit data is never stored in iCloud. It is stored on your device and on our own servers, encrypted as described in §8.
- HealthKit data is used only to provide the health features you are using, and to nothing else.
- Lab results in Apple Health's clinical records can be read into your lab log, on iPhone, if you grant it. Only the markers you approve are read, only when you ask for them, and nothing is ever written back into your clinical records. What comes across is the marker, its value and its unit, kept exactly as it arrived and encrypted with your key like the rest of your record.
- You can revoke access at any time in Settings → Health → Data Access & Devices → Loopa, or by disconnecting inside Loopa. Revoking stops future syncing; data already synced stays until you delete it.
Loopa's Care Plan is built on Apple's CareKit framework. It runs on your device, and the checklist data it produces is treated exactly like the rest of your health data.
13. Android Health Connect
If you connect Health Connect, Loopa reads only the data types you grant and writes back only what you ask it to.
Our use of Health Connect complies with the Google Play Health Apps policy and the Health Connect Permissions policy:
- Health Connect data is used only to provide the features you are using, showing your data, calculating targets, and generating the insights you asked for.
- Health Connect data is never used for advertising, marketing, or any similar purpose.
- Health Connect data is never sold or transferred to a data broker, insurer, employer, or information-resale service.
- Health Connect data is not used to determine credit or lending eligibility, and is not shared for those purposes.
- We transfer Health Connect data to Anthropic only where you use an AI feature that needs it, as a service provider under contract, and for no other purpose.
- We do not read data types we do not need, and we ask for a permission only when the feature that uses it exists.
- Lab results are an iPhone matter. Reading lab results out of Apple Health's clinical records is an iPhone feature, described in §12; nothing equivalent is read from Health Connect, and no lab result is ever written to it.
- Revoke access at any time in Settings → Apps → Health Connect → App permissions → Loopa. Deleting the Loopa app removes its Health Connect permissions.
14. Your rights
Everyone, wherever you live, has these rights on Loopa. We do not make them conditional on your jurisdiction:
- Know what we hold about you and why
- Access a copy
- Correct anything wrong
- Delete your account and everything in it
- Export your data in a portable format
- Withdraw consent to anything you consented to
- Object to processing based on legitimate interests
- Restrict processing while a dispute is resolved
- Be free from retaliation for exercising any of the above
How. Most of it you can do yourself in the app. For anything else, write to privacy@mobieus.io from your account email. We reply within 30 days, and we will tell you if we need longer. We do not charge for this. We may ask you to confirm your identity: only to be sure we are not handing your health data to somebody else.
Authorized agents. In the US you may use an authorized agent; we will ask for proof of the authorization and may ask you to confirm it directly.
Appeals. If we refuse a request, we will tell you why, and you may appeal by replying with the word "Appeal". A different person reviews it and answers within 45 days. If we deny the appeal we will tell you how to complain to your state Attorney General.
Complaints.
- EU / EEA: your national data protection authority. The list is at edpb.europa.eu
- UK: the Information Commissioner's Office, ico.org.uk
- Switzerland: the Federal Data Protection and Information Commissioner
- Canada: the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information du Québec
- United States: your state Attorney General
We would rather you came to us first, but you are not required to.
15. If you are in the United States
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done either in the preceding 12 months, including for consumers we know to be under 16.
Categories collected in the last 12 months (California terminology): identifiers; customer records; commercial information (purchases); internet activity; sensitive personal information. Specifically health data, and account credentials in the OPAQUE form described in §3.1. Sensitive personal information is used only to provide the service you asked for and to keep it secure, which are the purposes California permits without a separate right to limit; we do not use it to infer characteristics about you.
We do not collect biometric identifiers, precise geolocation, government identifiers, or information about racial or ethnic origin, religion, philosophical beliefs, union membership, sexual orientation or immigration status.
Consumer health data. If you live in Washington (My Health My Data Act), Nevada (SB 370), or Connecticut, your health data on Loopa is consumer health data, and it has its own policy: Loopa Consumer Health Data Privacy Policy. Washington requires that document to stand on its own, so it is a separate page rather than a section of this one, and it is the one to read for those rights. That expressly includes the medications and supplements you record, the times you log taking them, and the interaction alerts we derive from them, and it includes any report you generate for a clinician. The whole of this policy applies to it, and specifically: §3 lists what we collect, §4 why, §5 exactly who receives it, §8 how it is protected, §9 how long it is kept, §10 how to have it destroyed, and §14 how to exercise your rights. We do not sell consumer health data and we have never collected a signed authorization to do so, because there is nothing to authorize. We do not use a geofence around any health care facility, and Loopa contains no geofencing capability of any kind. Washington residents may email privacy@mobieus.io and we will confirm deletion, including by notifying anyone we sent it to.
State rights. Residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and any other state with a comprehensive privacy law have the rights in §14. Where a state gives a right to opt out of profiling with legal or similarly significant effects, note that we do not do that at all.
Loopa is not a HIPAA covered entity. We are not a health plan, a clearinghouse, or a health care provider that bills electronically, so the health data you record here is not protected health information under HIPAA and HIPAA's rules do not govern it. That is precisely why this policy, and the encryption behind it, are written the way they are.
16. If you are in Canada
We handle personal information in accordance with PIPEDA and, for Quebec residents, Law 25.
We rely on your consent, which is express for health information given the sensitivity, and which you may withdraw at any time subject to legal and contractual limits we will explain if they apply. We collect only what the purpose requires.
Your personal information is stored and processed in the United States, and is subject to lawful access there. Our service providers named in §5 operate in the United States and elsewhere.
Quebec residents also have the right to data portability (§11) and to be informed of automated decision-making: we make none, as §4 states. Our Privacy Officer is reachable at privacy@mobieus.io, and you may complain to the Commission d'accès à l'information du Québec.
17. International transfers
We operate from the United States and your information is stored there. If you are in the EEA, UK or Switzerland, that is a transfer outside your region.
We rely on the European Commission's Standard Contractual Clauses, and the UK Addendum where applicable, in our contracts with the service providers in §5, together with the technical measures in §8: in particular per-user encryption, which limits what any transfer actually exposes.
Ask at privacy@mobieus.io if you want details of the safeguards for a specific transfer.
18. Links to other services
Loopa links to Apple, Google, and the services you connect. Once you follow a link or authorize a connection, that company's own privacy policy governs what it does. We have no control over them and cannot answer for them. Read theirs.
19. Changes to this policy
We will update this page when what we do changes. The version number and date at the top always tell you which version you are reading.
For a change that materially affects your rights or expands how we use your information, we will tell you in the app and by email before it takes effect, and where the law requires consent we will ask for it rather than assume it. Continuing to use Loopa after a change takes effect means you accept the updated policy.
20. Contact
| Privacy | privacy@mobieus.io |
| Support | support@mobieus.io |
| Post | Mobieus Partners LLC, Sheridan, WY, United States |
A person reads that mailbox. Write in plain language; you do not need to cite a statute to get a straight answer.