looploop

Privacy Policy

Effective Date: July 13, 2026


This Privacy Policy explains how looploop GbR collects, uses, stores, and protects your personal data when you use the looploop mobile application and the associated website at https://www.looploopapp.com and https://app.looploop-food.com. It applies to all users of the Service regardless of their country of residence and has been prepared in accordance with the General Data Protection Regulation (GDPR). Please read this policy carefully before using the Service.


1. Data Controller

The data controller responsible for the processing of your personal data is:


looploop GbR

Represented by: Fabian Lupp and Daniel Lupp

Virchowstraße 2a, 66424 Homburg, Germany

Phone: +49 152 06090531

E-Mail: team@looploopapp.com

Website: https://www.looploopapp.com and https://app.looploop-food.com


2. Overview of Data Processing

The following is a summary of the personal data we collect and why. Detailed information is provided in the sections below.

  • Account data: your chosen login method data (Apple-relayed e-mail, Google Account data, or phone number) and your username (used to create and manage your Account).
  • Profile data: optional profile picture (visible to all authenticated users of the App). 
  • Food Personality data: dietary preferences and allergy information, cuisine preferences, and kitchen equipment (used to generate personalised recipe suggestions. Includes health-related information processed on the basis of your explicit consent).
  • User Content: recipes, images, instructions, and notes you create (stored and displayed as part of the Service).
  • Activity data: personal usage statistics such as recipes viewed, created, saved, and cooked (displayed to you and, with your explicit consent, analyzed to understand your preferences and personalize your app experience).
  • Social data: friend connections, Group memberships, and shared Recipe Copies (used to provide the social features of the Service, which includes making your profile visible to friends of your friends).
  • Push notification data: your opt-in consent status and device token via Firebase Cloud Messaging (used to deliver general notifications and, provided you have given your explicit analytics consent, personalized notifications based on your app activity).
  • Marketing communication consent: your opt-in status, e-mail address, double-opt-in confirmation data (IP address and timestamps), your newsletter interaction data (whether an e-mail was opened and which links were clicked), and, depending on your choice during subscription, your in-app usage data (processed via our e-mail service provider Brevo to manage newsletter delivery and, if consented to, to provide personalized e-mail content).
  • Technical app data: device identifiers, usage logs, and crash reports via Firebase Analytics and Firebase Crashlytics (used to operate and improve the App, and, with your explicit consent, to analyze user behavior and create pseudonymized user profiles/clusters for personalized content and notifications).
  • Website analytics data: anonymised behavioural data via Google Analytics 4 (used to understand our website and app subdomain usage).
  • Vercel Analytics and Speed Insights data: anonymised, cookie-free visitor and performance data collected via Vercel Web Analytics and Vercel Speed Insights on our website and app subdomain (used to understand usage patterns and to improve the performance of the Service).
  • Website error data: technical error reports via Sentry (used to identify and resolve errors on our website and app subdomain).
  • reCAPTCHA data: behavioural and interaction data collected by Google reCAPTCHA on our website and app subdomain (used to protect against automated abuse).
  • Website server log data: IP address, browser information, and standard log data (used for technically error-free operation of our web infrastructure).


3. Legal Bases for Processing

We process your personal data on the following legal bases under the GDPR:

  • Article 6(1)(b) GDPR: processing is necessary for the performance of the contract between you and us, that is, for providing the Service including, for instance, account management, recipe suggestions, Groups, and Deep Link sharing.
  • Article 6(1)(a) GDPR: processing is based on your consent, for example, in relation to app analytics (via Firebase Analytics), personalized push notifications, marketing communications (including newsletter open and click tracking and, where selected, personalized e-mail profiling), website and subdomain cookies (including Google Analytics 4 and Google reCAPTCHA, in conjunction with Section 25(1) TDDDG), your profile picture, and your Food Personality data.
  • Article 6(1)(f) GDPR: processing is based on our legitimate interests in operating, securing, and improving the Service, for example through Firebase Crashlytics, Vercel Web Analytics, Vercel Speed Insights, Sentry, and server log files.
  • Article 9(2)(a) GDPR: processing of special categories of personal data, specifically allergy and dietary health information in your Food Personality, is based on your explicit consent given at the time of optional configuration.

App Analytics and Personalized Push Notifications: Provided you have given us your explicit consent (Art. 6(1)(a) GDPR), we analyze your usage behavior within the App (e.g., your interactions, viewed recipes, applied filters, and saved items) using Firebase Analytics. We use this analytics data to create pseudonymized user segments or profiles to better understand your preferences. Based on this analysis, we may send you personalized push notifications tailored to your individual interests and cooking habits via Firebase Cloud Messaging.

Withdrawal of Consent: Where processing is based on your consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal. For personalized push notifications and app analytics, you can do this by disabling push notifications in your device settings or by withdrawing your analytics and tracking consent directly within the App under Settings.


4. Data Collected Through the App

(4.1) Account Data

When you register for looploop, we collect the necessary authentication data associated with your chosen login method (Apple Sign-In, Google Sign-In, or Phone Number) and your chosen username. If you register using Apple Sign-In, Apple may provide us with a relayed or anonymised e-mail address. If you register using Google, we receive basic authentication info. If you register via phone number, we use it strictly for authentication purposes via SMS verification codes. Your account data is stored on Google Firebase servers, used solely to create and manage your account, and is deleted upon account deletion.

(4.2) Food Personality Data

The Food Personality feature allows you to configure dietary preferences, including allergy information such as lactose, gluten intolerance, vegan or vegetarian preferences, ingredient dislikes, preferred cuisines, and available kitchen equipment. This information is used exclusively to generate personalised recipe suggestions and is not shared with other users or third parties. As this data includes health-related information, it constitutes a special category under Article 9 GDPR and is processed on the basis of your explicit consent. You may update or delete your Food Personality at any time in the App settings.

(4.3) User Content

You may create private recipes including images, ingredient lists, instructions, and notes. This content is stored on Google Firebase servers and is visible only to you, unless you choose to share it via a Group or Deep Link. You retain full ownership of your User Content. Upon account deletion, all your original User Content is permanently deleted. However, by actively sharing a recipe with others, you provide them with their own independent copy. These shared Recipe Copies will remain accessible in the recipients' accounts even after your account is deleted. Upon account deletion, we will fully anonymize these copies by removing your username and profile picture. Please note that any personal data you voluntarily enter into free-text fields (such as recipe titles, ingredient lists, or instructions) cannot be automatically detected or removed by our system and will remain visible in the shared copies. It is your responsibility to ensure you do not include personal identifiers within the recipe text itself.

(4.4) Profile Picture

You may optionally upload a profile picture, which is stored on Google Firebase and visible to other authenticated users of the Service. You may change or remove it at any time in the App settings. Processing is based on your consent under Article 6(1)(a) GDPR. 

(4.5) Activity Data

The App automatically generates personal usage statistics such as recipes viewed, created, searched, and shared, your most frequently cooked recipes, and the number of active chats and friends. This data is stored on Firebase servers, visible to us and you, and permanently deleted upon account deletion. To reset Activity Data without deleting your Account, contact us at team@looploopapp.com.

Please note: The broader tracking of your app interactions (such as visited screens, clicks, and session durations) is strictly separated from this functional data and only takes place if you have given your explicit consent for Firebase Analytics (see Section 7.1). To reset Activity Data without deleting your Account, contact us at team@looploopapp.com.

(4.6) Social Data and Groups

When you add friends or join Groups, we store the corresponding connection data including friend relationships, Group memberships, and recipe suggestion history. Please note that to facilitate social connections within the App, your profile information (such as your username and profile picture) may be visible to your friends' extended network ("friends of friends"). When you share a Recipe Copy, that copy is stored independently and remains unaffected even if you delete the original recipe or your Account. You are informed of this at the time of sharing via an in-app pop-up notification.

(4.7) Push Notifications via Firebase Cloud Messaging

If you consent to push notifications, the App uses Firebase Cloud Messaging (FCM), operated by Google LLC, to deliver notifications about Group activity and other relevant updates. A unique device token generated by FCM is stored on our Firebase servers solely to route notifications to your device. You may withdraw consent at any time via your device's notification settings. Processing is based on your consent under Article 6(1)(a) GDPR. For further information, see https://policies.google.com/privacy.

(4.8) Login Data and Authentication

Phone Number and Google Sign-In registrations are authenticated via Firebase Authentication (Google LLC). Apple Sign-In registrations are authenticated via Apple's identity services. In all cases, we receive only the data necessary to verify your identity. Passwords are never stored in plain text.

5. AI-Powered Recipe Import

The App offers an AI-assisted recipe import feature powered by Google Gemini, integrated via Firebase AI Logic (Google LLC). When you use this feature, the content you submit, including uploaded photos and pasted text, is transmitted to and processed by Google's systems in accordance with Google's applicable terms of service and privacy policies. We do not store the raw submitted content beyond what is technically necessary to complete the import. 

The AI import function is subject to the following usage limits per Account: a maximum of 5 photo uploads and a maximum of 7 URL imports, each calculated over a rolling period of 7 days from the time of the respective use. This means the limit does not reset at the start of a fixed calendar week, but on a continuous rolling basis relative to each individual import. 

We strictly separate your AI-interactions from your Food Personality. Sensitive health data, such as allergies or dietary restrictions, are stored locally/in our isolated Firebase database and are strictly never transmitted to Google Gemini or any other third-party AI system.


6. Deep Links and Recipe Preview

You may share individual recipes externally using a Deep Link. Recipients without the App installed are redirected to our website where a limited recipe preview is displayed. By sharing a Deep Link, you acknowledge that the preview is publicly accessible to anyone who opens the link. When recipients visit our website via a Deep Link, we collect standard server log data as described in Section 9.2. This data is not associated with your Account or the recipient's identity.


7. Analytics and Crash Reporting

(7.1) Firebase Analytics

We use Firebase Analytics, an analytics service provided by Google LLC. This service will only be activated if you have given your explicit consent during the App onboarding process or within the App settings (Art. 6(1)(a) GDPR). If you provide your consent, we collect pseudonymised App usage data (KPIs), including but not limited to the following, in order to continuously improve the user experience, identify technical errors, and optimise our marketing strategies:

  • Interactions & User Flow: Clicks on buttons and links, utilisation of specific features, visited screens, the sequence of your navigation (user flows), as well as drop-off rates (e.g., during the onboarding process).
  • Usage Intensity & Retention: Frequency of App openings (sessions), session duration, return rates (retention), and periods of inactivity.
  • Acquisition & Entry Points: Information regarding how you accessed the App (e.g., via specific deep links, advertising campaigns, App Store searches, or external referrals).
  • E-Commerce & Conversions: Tracking of (future) in-app purchases, subscription sign-ups, and the completion of specific calls to action (conversions).
  • Technical Baseline Data: Device model used, operating system version, default system language, and approximate location data (at a country or city level only; no precise GPS tracking is performed).
  • Pseudonymous Identifiers: We use App installation IDs (App Instance IDs) generated by Google to distinguish "unique users". These IDs do not allow us to directly identify you personally (e.g., by your real name or address).
  • Personalised Notifications: If you have additionally opted in to receive push notifications, we use your pseudonymised analytics data to create user segments. This allows us to send you tailored notifications, recipe suggestions, and app updates via Firebase Cloud Messaging.
  • The collected data is generally transferred to and stored on Google servers. You may withdraw your consent at any time with future effect via the App settings. Without your active consent, absolutely no tracking of your usage behaviour will take place. 

(7.2) Firebase Crashlytics

We use Firebase Crashlytics, operated by Google LLC, to collect crash reports and technical diagnostic data when the App experiences an error, including device type, operating system version, App version, and a technical event log. It does not include personal content. Processing is based on our legitimate interest under Article 6(1)(f) GDPR. Both Firebase Analytics and Crashlytics operate under a GDPR-compliant Data Processing Agreement with Google LLC.


8. Third-Party Services and Data Processors

The operation of the Service involves the following third-party service providers:

(8.1) Google Firebase (Google LLC)

All Firebase services are operated by Google LLC under a GDPR-compliant Data Processing Agreement. The following Firebase services are configured to store and process data exclusively on servers located in Frankfurt am Main, Germany (Google Cloud region europe-west3), and no transfer of data to third countries outside the European Economic Area takes place in connection with these services: Firebase Firestore, Firebase Storage, Firebase Crashlytics, Firebase Analytics, Firebase Remote Config, Firebase App Check, Firebase Performance, and Firebase Cloud Messaging. With your consent, we use Google Analytics for Firebase to analyze App usage and Firebase Cloud Messaging to deliver personalized notifications. Google may process your device identifiers and usage data for this purpose.

Firebase Authentication is a global infrastructure service operated by Google LLC via the Google Identity Platform. Unlike the regional services listed above, Firebase Authentication may process certain data, including IP addresses, device information, and authentication tokens, on servers located outside the European Economic Area, including in the United States. Such transfers are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework (DPF) and, where necessary, governed by Standard Contractual Clauses in accordance with Article 46(2)(c) GDPR, which Google has committed to in its applicable Data Processing Terms. Firebase Functions is used exclusively within the europe-west3 region and does not transfer data outside the European Economic Area. Firebase AI Logic is subject to a separate arrangement regarding data processing locations and is described in Section 8.2.

(8.2) Google Gemini via Firebase AI Logic (Google LLC)

The AI recipe import feature processes content you submit, such as uploaded photos and pasted text, via Google Gemini, accessed through the Gemini Developer API and integrated via Firebase AI Logic, both operated by Google LLC. The Gemini Developer API provides global access to Google's AI models, which means that submitted content may be processed on servers located anywhere in the world, including outside the European Economic Area and in the United States. We have no control over the specific geographic location in which processing takes place, as Google dynamically routes requests to available server capacity. Such international transfers are governed by Standard Contractual Clauses approved by the European Commission in accordance with Article 46(2)(c) GDPR, which Google has committed to in its applicable Data Processing Terms. The content you submit for AI import is not stored by Google beyond what is technically necessary to process the individual request and is not used to train AI models without your consent. For further details, see https://policies.google.com/privacy and https://firebase.google.com/support/privacy.

(8.3) Apple Inc.

Apple provides the App Store distribution platform and the Apple Sign-In authentication service where used. Apple is an independent data controller for data it collects through its own services. For details, see https://www.apple.com/privacy.

(8.4) Vercel Inc. (Website and App Subdomain Hosting)

Our website at https://www.looploopapp.com and our app subdomain at https://app.looploop-food.com are hosted on the Vercel platform, operated by Vercel Inc., 340 Pine Street, Suite 900, San Francisco, CA 94104, USA. Vercel processes server log data and technical request data on our behalf as a data processor. In addition, we use Vercel Web Analytics and Vercel Speed Insights to analyse visitor traffic and page loading performance. These services collect aggregated, anonymised data and do not use cookies or persistent identifiers. See Section 9.4 for further details. Vercel is based in the United States. Data transfers to the United States are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses in accordance with Article 46(2)(c) GDPR. For further information, see Vercel's privacy policy at https://vercel.com/legal/privacy-policy.

(8.5) Sentry (Functional Software Inc.)

We use Sentry, an error monitoring service operated by Functional Software Inc., 132 Hawthorne St, San Francisco, CA 94107, USA, to collect technical error reports from our website and app subdomain. When an error occurs, Sentry automatically captures diagnostic information including the error type, browser and operating system version, the URL where the error occurred, and potentially the visitor's IP address. This information is used exclusively to identify and resolve technical errors. Processing is based on our legitimate interest under Article 6(1)(f) GDPR. Data transfers to the United States are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses. For further information, see https://sentry.io/privacy.

(8.6) Google reCAPTCHA (Google LLC)

We use Google reCAPTCHA, a service operated by Google LLC, on our website and app subdomain to protect our forms and services against automated access and abuse. reCAPTCHA analyses the behaviour of website visitors, including mouse movements, typing patterns, and interaction timing, to determine whether the user is human. In doing so, it transmits data to Google's servers, which may include your IP address, browser information, and behavioural data. This data is processed by Google in accordance with Google's privacy policy. reCAPTCHA accesses information stored on your terminal equipment. It is therefore only loaded after you have given your prior consent via our cookie banner. Processing is based on your consent under Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR, which you may withdraw at any time with future effect. Data transfers to the United States are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses. For further information, see https://policies.google.com/privacy and https://policies.google.com/terms.

(8.7) Brevo (Newsletter and Contact Form)

We use Brevo, an e-mail marketing platform operated by Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany (part of the Brevo group, Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France), to manage our newsletter and to receive and process enquiries submitted through our contact form. Brevo processes this data exclusively on our behalf as a processor under a Data Processing Agreement pursuant to Article 28 GDPR. As a matter of principle, processing takes place on servers located within the European Union. For the operation of its service, however, Brevo uses sub-processors (for example for hosting infrastructure and IT security). This may involve transfers of data to third countries, in particular the United States. Brevo safeguards such transfers by way of Standard Contractual Clauses approved by the European Commission in accordance with Article 46 GDPR; in addition, the relevant US providers are as a rule certified under the EU-US Data Privacy Framework (DPF). Newsletter data stored at Brevo comprises your e-mail address, the date and time of your subscription request and of your double-opt-in confirmation, the IP address used, your confirmation status, your chosen subscription type (Personalized or Standard), your newsletter interaction data (opens and link clicks) and, where you have consented to a personalized newsletter, the contact attributes described in Section 10. Contact form data stored at Brevo comprises the name, e-mail address and message content you submit. We additionally receive an automated notification informing us that a new entry exists; this notification does not contain any personal data. For further information, see Brevo's privacy policy at https://www.brevo.com/legal/privacypolicy/.


9. Data Collected on Our Website and App Subdomain

The following sections apply to data collected when you visit our main website at https://www.looploopapp.com and our app subdomain at https://app.looploop-food.com.

(9.1) Cookies and Cookie Consent

Our website and app subdomain use cookies. The storing of, and access to, information on your terminal equipment is governed by Section 25 TDDDG. Technically necessary cookies are stored without consent on the basis of Section 25(2)(2) TDDDG; the associated processing of personal data is based on our legitimate interest under Article 6(1)(f) GDPR. All other cookies and comparable technologies, including those used for Google Analytics 4 and Google reCAPTCHA, are only stored or accessed after you have given your prior consent via our cookie banner, in accordance with Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR. Our cookie banner allows you to reject optional cookies just as easily as to accept them. You may adjust or withdraw your cookie preferences at any time with future effect via the cookie settings on our website.

(9.2) Server Log Files

When you visit our website or app subdomain, your browser automatically transmits technical information stored in server log files by our hosting provider Vercel. This includes your IP address, browser type and version, operating system, the referring URL, pages visited, the date and time of your request, and the amount of data transferred. This data is used solely to ensure the security and technically error-free operation of our web infrastructure. Raw log data containing potentially identifiable information, such as IP addresses, is routinely deleted or anonymized by our hosting provider after a short retention period. Aggregated and anonymized usage statistics derived from these logs may be retained for longer periods for analytical purposes. Processing is based on our legitimate interest under Article 6(1)(f) GDPR.

(9.3) Google Analytics 4

We use Google Analytics 4 (GA4), operated by Google LLC, to analyse how visitors interact with our website and app subdomain. GA4 collects information about page views, session duration, and traffic sources. Google Analytics 4 does not store IP addresses: IP data is used only transiently to derive an approximate location and is then discarded. GA4 is only activated after you have given your prior consent via our cookie banner, in accordance with Article 6(1)(a) GDPR. You may withdraw your consent at any time via the cookie settings on our website. Data may be transferred to the United States on the basis of the European Commission's adequacy decision for the EU-US Data Privacy Framework (DPF) and, in addition, Standard Contractual Clauses in accordance with Article 46(2)(c) GDPR. For further information, see https://policies.google.com/privacy.

(9.4) Vercel Web Analytics and Speed Insights

We use Vercel Web Analytics, a feature provided by Vercel Inc., on our website https://www.looploopapp.com/ and app subdomain at https://app.looploop-food.com to analyze visitor traffic and performance. In addition, we use Vercel Speed Insights to measure page loading performance. Both services collect aggregated, anonymised data. They do not use cookies and do not create persistent identifiers that would allow you to be recognised across sessions or websites. Processing is based on our legitimate interest under Article 6(1)(f) GDPR in ensuring the performance and security of our web infrastructure. As Vercel Inc. is based in the United States, data transfers are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses. For further information, see https://vercel.com/legal/privacy-policy.

(9.5) Sentry (Error Monitoring)

We use Sentry to automatically detect and report technical errors on our website and app subdomain. When an error occurs during your visit, Sentry captures diagnostic data including the error type, your browser and operating system version, the URL where the error occurred, and potentially your IP address. This data is used solely to identify and resolve technical errors and is not used to track your behaviour or for advertising. Processing is based on our legitimate interest under Article 6(1)(f) GDPR. For further information, see https://sentry.io/privacy.

(9.6) Google reCAPTCHA

Our website and app subdomain use Google reCAPTCHA to protect contact forms and other interactive elements from automated abuse. reCAPTCHA analyses your interaction behaviour and transmits data to Google's servers. Because reCAPTCHA accesses information stored on your terminal equipment, it is only loaded after you have given your prior consent via our cookie banner. This processing takes place on the basis of your consent under Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR, which you may withdraw at any time with future effect via the cookie settings on our website.  For further information, see https://policies.google.com/privacy.

(9.7) Contact Enquiries

If you contact us via our website contact form or by e-mail, the information you provide will be stored and used solely to respond to your enquiry. Enquiries submitted via our contact form, including your name, e-mail address and the content of your message, are transmitted to and stored within Brevo, which acts as our processor (see Section 8.7). We additionally receive an automated notification informing us that a new enquiry exists; this notification does not contain any personal data. If you contact us directly by e-mail, your message is stored in our e-mail inbox. Processing is based on Art. 6(1)(b) GDPR where your enquiry relates to a contract, and otherwise on our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR). We will not pass this data on to third parties without your consent. Data is retained only for as long as necessary to process your enquiry and is then deleted, subject to mandatory statutory retention obligations.


10. Newsletter

You may optionally subscribe to our email newsletter through a dynamic web interface accessed via the App settings or our website. To ensure compliant delivery, we utilize a Double Opt-In (DOI) verification procedure. When you request a subscription, a confirmation email is sent to your address; your subscription only becomes active once you click the verification link inside that email. To be able to demonstrate that you have validly consented, we store the IP address used at the time of your subscription request and at the time of your confirmation, the corresponding timestamps, and the content of the confirmation. This log data is processed on the basis of our obligation to demonstrate consent (Art. 7(1) in conjunction with Art. 5(2) GDPR).

Depending on your selections at the time of subscription, we process your data in one of two ways based on your explicit consent under Article 6(1)(a) GDPR:

(A) Personalized Newsletter (With App-Tracking Connection): If you explicitly consent to a personalized subscription, we link your e-mail address and Firebase User ID with your in-app usage data (such as viewed recipes, cooking habits, and filter preferences) and store the resulting attributes and segments as contact attributes in our newsletter system operated by Brevo (see Section 8.7). This data is processed to create a profile (profiling) in order to send you tailored recipe suggestions, cooking tips, and marketing offers that match your specific interests. Health-related information from your Food Personality, such as allergies or intolerances, is never transmitted to Brevo and is never used for this profiling.

(B) Standard Newsletter (Without App-Tracking Connection): If you choose the standard subscription or have disabled in-app tracking, we process your e-mail address solely to send you general recipe updates, company news, and promotional offers. Your in-app behavior is strictly separated and not analyzed for this purpose.

Data Storage and Processor: Upon confirming your subscription, your e-mail address, subscription and confirmation timestamps, the IP address used, your DOI confirmation status, and your chosen selection (Personalized or Standard) are transmitted to and stored within our newsletter system operated by Brevo (see Section 8.7). Brevo acts as our processor under a Data Processing Agreement pursuant to Article 28 GDPR. Details on the processing locations and on transfers carried out by Brevo's sub-processors are set out in Section 8.7.

Newsletter Tracking: Our newsletters contain a tracking pixel and links that are tracked individually. This allows us to see whether and when an e-mail was opened and which links were clicked. This analysis is carried out by Brevo on our behalf and serves to measure the reach of our newsletter and to improve the relevance of our content. It is based on your consent under Article 6(1)(a) GDPR, which you give when subscribing and which you may withdraw at any time with future effect by unsubscribing.

Withdrawal of Consent: You have the right to withdraw your newsletter consent at any time with future effect. You can completely unsubscribe from all marketing communications by clicking the "Unsubscribe" link provided at the bottom of every newsletter email or by contacting us at team@looploopapp.com. Upon complete unsubscription, your e-mail address will be removed from our active mailing list and placed on a suppression list at Brevo to ensure that you do not receive any further newsletters. Records evidencing your double opt-in consent are retained for the period set out in Section 12. Alternatively, if you only wish to withdraw your consent for the personalized profiling (Option A) but want to continue receiving the standard newsletter (Option B), you can simply disable in-app tracking within the App settings. In this case, we will immediately cease using your app usage data for marketing purposes.


11. International Data Transfers

The majority of personal data we process is stored and processed within the European Economic Area. Our core Firebase infrastructure is configured to operate exclusively on servers in Frankfurt am Main, Germany, meaning that no international data transfer takes place in connection with these services.

The following services may involve the transfer of personal data to servers outside the European Economic Area, including in the United States. The United States does not provide the same level of data protection as the European Union. Where such transfers take place, we ensure that appropriate safeguards are in place, either through the European Commission's adequacy decision for the EU-US Data Privacy Framework (DPF) or through Standard Contractual Clauses approved by the European Commission in accordance with Article 46(2)(c) GDPR:

  • Firebase Authentication (Google LLC): IP addresses, device information and authentication tokens may be processed on servers outside the EEA, as described in Section 8.1. Firebase AI Logic and Google Gemini (Google LLC): AI processing requests may be routed to servers outside the EEA, as described in Section 8.2.
  • Google reCAPTCHA and Google Analytics 4 (Google LLC): data may be transferred to Google servers in the United States.
  • Vercel Inc.: server log, analytics and performance data from our website and app subdomain may be transferred to the United States.
  • Sentry (Functional Software Inc.): error diagnostic data may be transferred to the United States.
  • Brevo (Brevo GmbH / Brevo SAS): newsletter and contact form data is processed on servers within the European Union. Brevo's sub-processors, for example for hosting infrastructure and IT security, may transfer data to third countries, in particular the United States, as described in Section 8.7.
  • Apple Inc.: data processed in connection with Apple Sign-In and App Store distribution.

For further details on the safeguards applicable to each provider, please refer to the links provided in Section 8.


12. Data Retention

We retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. The following retention principles apply:

  • Account data, Food Personality data, User Content, Activity Data, profile pictures, social data, and FCM device tokens are retained for as long as your Account is active and are permanently deleted upon account deletion.
  • Recipe Copies shared with other users before account deletion remain stored as independent items in the recipients' accounts and are not deleted as a result of the original creator deleting their Account. To ensure your privacy, we will fully anonymize these remaining copies upon the deletion of your account by permanently removing your system-generated identifiers (such as your username and profile picture). Please note that any personal information you voluntarily include in free-text fields (such as recipe titles, ingredients, or instructions) cannot be automatically detected or deleted, and will therefore be retained in these shared copies.
  • Technical log data and error reports are retained only for as long as strictly necessary to resolve technical issues and ensure system security, after which they are automatically deleted. Analytics data is retained for a longer period necessary to analyze long-term trends and evaluate app performance. Once the data is no longer needed for these analytical purposes, it is securely deleted or fully anonymized.
  • Newsletter subscription data stored in our newsletter system at Brevo is retained until you unsubscribe. Upon unsubscription, your e-mail address is removed from the active mailing list and added to a suppression list so that you do not receive any further newsletters. Records evidencing your double opt-in consent (IP addresses, timestamps, confirmation) are retained for up to three years after the end of the year in which the consent relationship ended, in order to be able to defend against potential legal claims (Art. 6(1)(f) GDPR), and are then deleted.
  • Contact enquiry data is retained until the enquiry is resolved and is then deleted, subject to mandatory statutory retention periods.

Where we are required by law to retain data for longer periods, we will do so for the legally required duration and delete it once that obligation has expired.


13. Your Rights Under the GDPR

As a data subject, you have the following rights under the GDPR. To exercise any of these rights, please contact us at team@looploopapp.com. We will respond within the timeframes required by applicable law, generally within one month.

(13.1) Right of Access

You have the right to obtain confirmation as to whether we process personal data about you and, if so, to receive a copy of that data along with information about its purposes, categories, recipients, and retention periods.

(13.2) Right to Rectification

You have the right to request the correction of inaccurate personal data and the completion of incomplete personal data.

(13.3) Right to Erasure

You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal basis applies, or where the data has been processed unlawfully. This right does not apply where we are required by law to retain the data or where it is necessary for the establishment, exercise, or defence of legal claims.

(13.4) Right to Restriction of Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while we verify the accuracy of data you have disputed.

(13.5) Right to Data Portability

Where processing is based on your consent or contract performance and is carried out by automated means, you have the right to receive the personal data you have provided in a structured, commonly used, and machine-readable format and to transmit it to another controller where technically feasible.

(13.6) Right to Object

Where processing is based on our legitimate interests under Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will cease processing unless we can demonstrate compelling legitimate grounds or processing is necessary for legal claims. Where processing is for direct marketing purposes, you have an unconditional right to object at any time.

(13.7) Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. To withdraw specific consents, please use the relevant in-app setting or contact us at team@looploopapp.com.

(13.8) Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. The competent supervisory authority for looploop GbR is the Unabhängiges Datenschutzzentrum Saarland (UDZ Saarland), Fritz-Dobisch-Str. 12, 66111 Saarbrücken, Germany. This right is without prejudice to any other administrative or judicial remedies available to you.


14. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration. These measures include encrypted data transmission via TLS for all communication between the App and our servers, authentication mechanisms to prevent unauthorised account access, and GDPR-compliant data processing agreements with all third-party service providers who process data on our behalf. Please be aware that no method of data transmission over the internet is completely secure. We cannot guarantee absolute security and encourage you to use a strong password and keep your login credentials confidential.


15. Age Restrictions

The Service is intended for users who are at least 14 years of age and is not directed at children. The core functions of the Service, such as creating and managing your Account, creating and saving recipes, Groups and Deep Link sharing, are provided on the basis of Article 6(1)(b) GDPR and do not require your consent. The processing of special categories of personal data (health data) within the 'Food Personality' feature, specifically the selection of allergies and intolerances such as gluten or lactose intolerance, is restricted to users who are at least 16 years of age. Before you can enter allergy-related data, you must confirm that you have reached the age of 16 and give your explicit consent via a dedicated in-app confirmation (Article 9(2)(a) GDPR). Users below the age of 16 may use the App and provide non-sensitive dietary preferences (for example vegan or vegetarian preferences, ingredient dislikes, or available kitchen equipment), but the allergy fields remain deactivated for them. We do not knowingly collect health-related data from persons under the age of 16. If we become aware that we have inadvertently collected such data from a minor, we will delete that specific information and, if necessary, the corresponding Account without undue delay.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or the features of the Service. For material changes, we will notify you in advance via an in-app notification or by e-mail to your registered address and will update the effective date at the top of this document. We encourage you to review this Policy periodically. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Policy.


17. Contact and Data Subject Requests

If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or have any concern relating to the processing of your personal data, please contact us at:


looploop GbR

Fabian Lupp and Daniel Lupp

Virchowstraße 2a, 66424 Homburg, Germany

Phone: +49 152 06090531

E-Mail: team@looploopapp.com

Website: https://www.looploopapp.com



© 2026 looploop GbR. All rights reserved.