Privacy Policy

Effective Date: July 6, 2026

Data Controller: The Loop app (published on Google Play by the developer "Ramas App") is operated by D. Samarska, an independent app developer based in Ancona, Italy.
Contact: ramas.app111@gmail.com

This Privacy Policy describes how Loop ("we," "us," "our," or "the app") collects, uses, and protects your information.

Summary

Note: If you use the Deep Loop AI feature, the content you submit is processed through our backend and AI providers to generate responses. See Section 3 for details.

1. Information Stored on Your Device

The following data is stored locally on your device, encrypted. We do not collect or store it on our servers. The only information that ever leaves your device is the limited data described in Sections 2 and 3 below (including the Deep Loop AI feature and limited technical data) — everything else stays on your device:

Encryption: Sensitive data is encrypted using AES-256-GCM authenticated encryption. Encryption keys are stored in your device's hardware-backed secure storage (Android Keystore or iOS Keychain).

Deletion: You may delete all local data at any time via Settings > Delete my data. Uninstalling the app also removes all local data.

2. Information We Collect

2.1 Usage Analytics

We collect limited, non-identifying usage events to understand how the app is used and improve it:

These events contain no personal information, no user content, and no identifiers that can be linked to you. Analytics are stored on Supabase servers in Frankfurt, Germany (EU).

Legal basis (GDPR): Legitimate interest in understanding app usage and improving the service (Art. 6(1)(f)).

2.2 Device Identifier

When you use the Deep Loop AI feature, we generate a random device identifier (UUID) to:

This identifier is randomly generated on your device, is not linked to your identity or any account, and cannot be used to identify you personally. It is stored on Supabase (EU).

Legal basis (GDPR): Legitimate interest in fair use enforcement and abuse prevention (Art. 6(1)(f)).

2.3 IP Address

Your IP address is temporarily processed for:

IP addresses are stored for a maximum of 25 hours and are then automatically deleted. This retention period covers the active rate-limiting window plus a buffer for timezone handling and security review. They are not linked to your identity, content, or usage patterns beyond rate limiting.

Legal basis (GDPR): Legitimate interest in security and abuse prevention (Art. 6(1)(f)).

2.4 Subscription Information

If you purchase a subscription (monthly or annual), the transaction is processed by Apple App Store or Google Play Store and managed via RevenueCat. We receive:

We do not receive or store your payment details such as credit card numbers, billing addresses, or bank account information.

Legal basis (GDPR): Performance of contract (Art. 6(1)(b)).

2.5 Creator/Promo Codes

If you activate a creator or promotional code, we store:

This data is linked to your pseudonymous RevenueCat identifier, not to your name. Creators can see only aggregated totals (number of sign-ups, purchases, and commission owed) — never your identity, your entries, or your activity in the app. It is used solely for promotional attribution and commission accounting, and does not involve advertising, profiling, or third-party data sharing.

Legal basis (GDPR): Performance of our agreement with the creator and our legitimate interest in operating a referral program and paying creators accurately (Art. 6(1)(b) and 6(1)(f)).

3. AI-Powered Features (Deep Loop)

3.1 How Deep Loop Works

The thoughts and feelings you share in Deep Loop may reveal information about your mental or emotional state — a special category of personal data under Article 9 GDPR (see Recital 35). We process it only on the basis of your explicit consent under Article 9(2)(a), which you give on the consent screen before your first Deep Loop session and can withdraw at any time in Settings. You may decline, and declining does not affect the rest of the app.

When you use the Deep Loop AI dialogue feature:

  1. Your message and recent conversation history are transmitted over an encrypted (HTTPS) connection to our server (Supabase, Frankfurt, EU)
  2. The content is forwarded to OpenAI (USA) to generate an AI response
  3. The AI response is returned to you
  4. Your conversation content is NOT stored on our servers or OpenAI's servers after the response is delivered

OpenAI processes this data under their API Data Usage Policy, which states that API inputs are not used for model training. We do not include your name, email, or any account identifier in requests to OpenAI.

Abuse prevention: If our systems detect attempts to misuse or attack the AI feature (for example, prompt-injection or "jailbreak" attempts), we may log a salted, irreversible hash (a "fingerprint") of the input — not the text itself — together with the matched pattern, a hashed network identifier and a partial device identifier, for a limited period to keep the service safe. The raw text of your Deep Loop input is never stored on our servers.

Data transfer: Data transmitted to OpenAI is processed in the United States. This transfer is conducted under OpenAI's Standard Contractual Clauses in accordance with GDPR Chapter V.

3.2 AI Safety and Limitations

If you encounter concerning AI content, please contact us at ramas.app111@gmail.com.

Legal basis (GDPR): Your explicit consent, which we obtain on the consent screen before your first Deep Loop session and which you may withdraw at any time in Settings (Art. 6(1)(a)). Where the content you choose to share reveals information about your mental or emotional state — a special category of personal data under Article 9 GDPR — we rely on your explicit consent under Art. 9(2)(a) for processing it. For the limited abuse-prevention logging described above, our legal basis is our legitimate interest in keeping the service secure (Art. 6(1)(f)).

Record of consent: To be able to demonstrate that you gave (or withdrew) this consent, as required by Art. 7(1) GDPR, we keep a minimal consent record: the fact and time you granted or withdrew consent, the version of the consent wording you saw, and the pseudonymous device/subscription identifier it relates to. This record contains no thought content and no name. It is kept as evidence that our processing was lawful (Art. 17(3)(b)/(e)) even after other data is deleted, and does not itself reveal special-category data.

4. Voice Input

When you use voice input to speak your thoughts:

We do not receive, store, access, or transmit your voice recordings. Audio is processed on-device in real time by your operating system and converted to text. We receive only the transcribed text; the audio is never stored.

5. Crash Reporting

We use Firebase Crashlytics (operated by Google LLC) to collect crash reports when the app encounters errors. This includes:

Crash reports do NOT include your name, thoughts, entries, reflections, or any user-generated content. Crash data is retained for 90 days and used solely to diagnose and fix bugs.

Legal basis (GDPR): Legitimate interest in app stability and error diagnosis (Art. 6(1)(f)).

6. Specialist Directory

6.1 What We Display

Loop includes an optional directory of independent wellness specialists (therapists, psychologists, coaches). Specialist profiles are provided by the specialists themselves and include name, credentials, bio, photo, contact information, languages, location, and professional type.

6.2 Featured and Sponsored Listings

Some specialists may appear as "Featured" or have promoted visibility. This placement is arranged directly between the specialist and Loop by Ramas, clearly labeled, and based on listing agreements — NOT on your personal data, behavior, or usage patterns.

Important: We do NOT use your personal data, thoughts, emotions, session history, or app activity to target, recommend, or personalize specialist listings.

6.3 Independent Professionals

Specialists are independent professionals, not employees or agents of Loop by Ramas. We do not verify credentials, licenses, or qualifications. We do not guarantee the quality of their services. You must verify credentials independently before engaging any specialist.

7. Sharing Features

7.1 Progress Report Sharing

You may choose to generate and share a PDF progress report with a specialist. This feature is:

We do not receive, transmit, or store shared reports.

7.2 Anonymity Consideration

Even when sharing anonymously, your progress data and patterns may contain information that could potentially identify you to a recipient who knows you. You are solely responsible for the content you choose to share and the consequences of sharing.

8. Push Notifications

Push notifications are scheduled and delivered locally on your device. Your notification preferences are stored only on your device. No notification content, timing, or preferences are transmitted to our servers.

9. Third-Party Services

ServicePurposeData ProcessedLocation
SupabaseBackend, analytics, AI routingAnonymous events, device UUID, IP (temporary)Frankfurt, EU
OpenAIAI dialogue responsesConversation content (not stored after response)USA
RevenueCatSubscription managementPseudonymous ID, subscription eventsUSA
Firebase CrashlyticsCrash reportingDevice info, crash logsUSA
Apple App StorePayments, distribution (iOS)Payment processing (we do not receive payment details)USA
Google Play StorePayments, distribution (Android)Payment processing (we do not receive payment details)USA
Google FontsTypographyIP address (for font loading)USA

For transfers to the USA, we rely on the following safeguards: our transfers to OpenAI and RevenueCat are based on the EU Standard Contractual Clauses (SCCs) incorporated in our signed data processing agreements with them (neither provider is certified under the EU-U.S. Data Privacy Framework); our transfers to Google (Firebase Crashlytics, Google Fonts) rely on Google LLC's certification under the EU-U.S. Data Privacy Framework, supported by a signed data processing agreement; transfers to Apple (App Store) are covered by Apple's data protection measures and safeguards under GDPR Chapter V. Voice input is processed on-device and is not transferred to Apple or Google.

10. Data Retention

Data TypeRetention Period
Local data (thoughts, entries, history)Until you delete or uninstall the app
Device UUIDKept only while needed for fair-use and abuse prevention: on your device until you delete; server-side copies auto-deleted (request cooldown ~24h, security log 30 days, free-trial usage up to ~1 year); erased on request (see Section 12, Your Privacy Rights)
IP addressMaximum 25 hours (automatically deleted)
Analytics eventsRaw events kept up to 90 days, then rolled up into non-identifying daily aggregates retained indefinitely
Crash reports90 days
Creator-code & referral records (code, pseudonymous ID, purchase/commission events)While the code is active and as required for commission payout and accounting, then deleted or anonymized
Subscription recordsPer RevenueCat retention policy

11. Children's Privacy

Loop is for adults only and is not intended for anyone under 18 years of age. We do not knowingly collect personal information from anyone under 18.

Age verification is required during app setup via date-of-birth entry. Users who indicate they are under 18 are blocked from using the app.

If we discover that someone under 18 has provided information to us, we will promptly delete any associated data. If you believe someone under 18 has used Loop, please contact us immediately at ramas.app111@gmail.com.

12. Your Privacy Rights

All Users

European Users (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights:

To exercise these rights, contact ramas.app111@gmail.com. We will respond within 30 days (or as required by law).

California Users (CCPA/CPRA)

If you are a California resident, you have the following rights:

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use sensitive personal information for purposes other than those disclosed in this Privacy Policy.

13. Security

We implement technical and organizational measures to protect your data:

While we implement reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

14. Do Not Track

Loop does not respond to "Do Not Track" browser signals because the app does not track users across third-party websites or applications.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective Date" at the top of this policy. For significant changes, we will provide notice within the app.

Your continued use of Loop after changes constitutes acceptance of the updated Privacy Policy. If you do not agree with changes, you should stop using the app and delete your data.

16. Contact

D. Samarska — operator of the Loop app (published on Google Play as "Ramas App")
Ancona, Italy
Email: ramas.app111@gmail.com

For privacy inquiries, data requests, or complaints, please email us. We aim to respond within 30 days.