Loopa Privacy Policy & Consumer Health Data
This page carries two documents: the Mobieus Privacy Notice, which covers this site and the Mobieus platform, and the Consumer Health Data Privacy Policy that supplements it for health information. The Loopa app is governed by its own policy, written for the app and linked from inside it, at loopa.mobieus.io/privacy.
Loopa Privacy Policy
Mobieus Partners LLC, d/b/a Mobieus and Loopa
- Effective date: June 15, 2026
- Last updated: September 15, 2026
- Version: 5.3
This Privacy Notice for Mobieus Partners LLC (doing business as Mobieus and Loopa) ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our website at https://mobieus.io or https://loopa.mobieus.io, or any website of ours that links to this Privacy Notice
- Use a community hosted on the Mobieus platform, including our own Loopa community and its mobieusHealth features
- Download and use our mobile application (Mobieus Community Platform), or any other application of ours that links to this Privacy Notice
- Engage with us in other related ways, including any marketing or events Our roles. For our marketing sites and for communities we operate ourselves, including Loopa, we decide how your personal information is used and are the responsible party (the "controller"). For communities operated by our customers, the community operator is the responsible party and we process member information on the operator's behalf as a service provider; the operator's own privacy practices also apply to you, and requests about that community should go to its operator first.
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at privacy@mobieus.io.
SUMMARY OF KEY POINTS
This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by using our table of contents below to find the section you are looking for.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. Learn more about personal information you disclose to us.
Do we process any sensitive personal information? Some of the information may be considered "special" or "sensitive" in certain jurisdictions, for example your racial or ethnic origins, sexual orientation, religious beliefs, or health information. We do not process sensitive personal information, with one exception: if you choose to use mobieusHealth (including through Loopa), we process the health and wellness information you log, with your explicit consent, solely to provide those features. Learn more in "WHAT ABOUT CONSUMER HEALTH DATA?"
Do we collect any information from third parties? We do not collect any information from third parties.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific categories of third parties. Learn more about when and with whom we share your personal information.
How do we keep your information safe? We have adequate organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Learn more about how we keep your information safe.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. Learn more about your privacy rights.
How do you exercise your rights? The easiest way to exercise your rights is by submitting a data subject access request, or by contacting us. We will consider and act upon any request in accordance with applicable data protection laws.
TABLE OF CONTENTS
1. WHAT INFORMATION DO WE COLLECT?
2. HOW DO WE PROCESS YOUR INFORMATION?
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
5. WHAT IS OUR STANCE ON THIRD-PARTY WEBSITES?
6. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
7. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
8. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
9. HOW LONG DO WE KEEP YOUR INFORMATION?
10. HOW DO WE KEEP YOUR INFORMATION SAFE?
11. DO WE COLLECT INFORMATION FROM MINORS?
12. WHAT ABOUT CONSUMER HEALTH DATA?
13. WHAT ARE YOUR PRIVACY RIGHTS?
14. DO WE RESPOND TO BROWSER OPT-OUT SIGNALS (GPC / DO-NOT-TRACK)?
15. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
16. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
17. DO WE MAKE UPDATES TO THIS NOTICE?
18. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
19. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
20. APPLE HEALTH (HEALTHKIT) AND APPLE CAREKIT
21. HEALTH CONNECT AND CONNECTED DEVICE SERVICES
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
- names- phone numbers- email addresses- mailing addresses- usernames- passwords- contact preferences- contact or authentication data Sensitive Information. We do not process sensitive information, except for the health and wellness data described below, which we process only when you opt in to mobieusHealth and only with your explicit consent.
Health and Wellness Data (mobieusHealth). If you enable mobieusHealth, whether inside a community that offers it or through our Loopa consumer service, we collect the health and wellness information you choose to log. Depending on the trackers you use, this may include food and meal logs, food photos you submit for analysis, body weight, water intake, vital signs, body measurements, physical activity, supplements, menstrual cycle data, health goals, and the never-eat exclusion lists you configure. If you switch on any of Loopa’s health tracks or protocols it also includes which one you turned on and what you record against it. That covers the schedule you set, the names, amounts and notes you type, each entry you log with its date and time, symptoms with the severity you chose, a daily wellbeing check-in, and lab results you type in exactly as you entered them, with no reference ranges of any kind. The itemised list for each track is in the Loopa app’s own privacy policy, which governs the app and is kept current with it: loopa.mobieus.io/privacy. A progress photograph also carries the time it was taken, read from the picture’s own information or sent by the app at the moment you take it, and left blank where neither says. This data is collected only when you enter it, is encrypted at rest with keys unique to your account, and is never sold or used for advertising. See "WHAT ABOUT CONSUMER HEALTH DATA?" for details on how this data is protected and your rights over it.
Family Group Data. If you create or join a Loopa Family Group, we collect the group membership itself (who organizes it, who belongs to it, and when each person joined or left), the invitations you send (the email address you type, or a single-use link token, and its expiry), and, only if you separately opt in to the shared family pantry, the pantry items you add: the item name, an optional quantity, and your name shown alongside them so the household can tell who added what. We do not collect your contacts. Invitations are typed or picked one at a time, by you, and you see the message before it is sent. Your food diary, weight, water, vital signs, body measurements, progress photos, targets, allergen lists and never-eat lists are never shared with a family group, in either direction. Sharing covers the subscription and, with your explicit opt-in, the pantry. It never covers the diary.
Payment Data. We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number, and the security code associated with your payment instrument. All payment data is handled and stored by Stripe. You may find their privacy notice link(s) here: https://stripe.com/privacy.
Application Data. If you use our application(s), we also may collect the following information if you choose to provide us with access or permission:
- Geolocation Information. We may request access or permission to track location-based information from your mobile device, either continuously or while you are using our mobile application(s), to provide certain location-based services. If you wish to change our access or permissions, you may do so in your device's settings.
- Push Notifications. We may request to send you push notifications regarding your account or certain features of the application(s). If you wish to opt out from receiving these types of communications, you may turn them off in your device's settings. This information is primarily needed to maintain the security and operation of our application(s), for troubleshooting, and for our internal analytics and reporting purposes.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
In Short: Some information. Such as your Internet Protocol (IP) address and/or browser and device characteristics. Is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
Like many businesses, we also collect information through cookies and similar technologies. The information we collect includes:
- Log and Usage Data. Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files.
- Device Data. We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services.
- Location Data. We collect location data such as information about your device's location, which can be either precise or imprecise.
Google API
Our use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
Design and research surveys
In Short: If you take part in a design survey, we record your answers, whatever you choose to tell us about yourself, your IP address, and a cookie. We do not ask for your name or email address, and your answers are not connected to your Loopa account.
From time to time we invite people to help us choose between design directions, which logo or color palette to use, for example. These invitations go out by email, and the survey pages are not linked from anywhere on this site. Taking part is optional, and nothing is recorded until you agree on the first screen.
When you take part, we record:
- Your answers. Which option you picked in each comparison, which option was shown on the left, and how long you spent deciding. We record the position because the left-hand option tends to win slightly more often on any side-by-side question, and knowing which side each option was on is what lets us read the result as a preference for the design rather than for the position.
- What you choose to tell us about yourself. An age range, how you describe yourself, and how familiar you already are with Loopa. Every one of these can be skipped, and “Rather not say” is a complete answer that we record as given.
- Your IP address, and a cookie in your browser. Both are there to count one response per household, so that a single enthusiastic participant cannot decide the result for everyone.
We do not ask for your name, email address, account, or device identifier, and the survey will not accept them if they are sent. Responses are held separately from Loopa accounts and are not joined to them.
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes only with your prior explicit consent.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
- To create and authenticate accounts and otherwise manage user accounts.
- To deliver and support the delivery of services to the user.
- To respond to user inquiries/offer support to users.
- To send administrative information to you.
- To fulfill and manage your orders.
- To enable user-to-user communications.
- To request feedback.
- To send you marketing and promotional communications. You can opt out of our marketing emails at any time. For more information, see "WHAT ARE YOUR PRIVACY RIGHTS?" below.
- To deliver targeted advertising to you.
- To provide the health and nutrition tracking features you enable. If you opt in to mobieusHealth, we process the health and wellness data you log solely to deliver those features to you, such as displaying your trackers, generating reports and trends, sending the reminders you configure, and running the AI analysis you request. We do not use this data for advertising or marketing.
- To protect our Services.
- To identify usage trends.
- To determine the effectiveness of our marketing and promotional campaigns.
- To save or protect an individual's vital interest.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.
If you are located in the EU or UK, this section applies to you.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information: Consent; Performance of a Contract; Legitimate Interests; Legal Obligations; and Vital Interests.
If you are located in Canada, this section applies to you. We may process your information if you have given us specific permission (express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (implied consent). You can withdraw your consent at any time.
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
In Short: We may share information in specific situations described in this section and/or with the following categories of third parties.
Vendors, Consultants, and Other Third-Party Service Providers. We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf and require access to such information to do that work. The categories of third parties we may share personal information with are as follows:
- AI Platforms- Cloud Computing Services- Payment Processors- Social Networks- Website Hosting Service Providers- Sales & Marketing Tools- Data Storage Service Providers We also may need to share your personal information in the following situations: Business Transfers (in connection with any merger, sale of company assets, financing, or acquisition); When we use Google Maps Platform APIs; Affiliates; and Business Partners.
Consumer health data. We do not sell your health and wellness data and we do not share it with advertisers, social networks, or sales and marketing tools. Health data leaves our systems only in four cases: to our hosting and infrastructure providers as part of encrypted storage, to our AI Service Providers when you invoke an AI feature (and only the inputs needed to run that request), to a Loopa Coach for the individual categories you have switched on for them (see section 12), and where we are legally required to disclose it. Our agreements with AI Service Providers prohibit them from using your inputs to train their models.
5. WHAT IS OUR STANCE ON THIRD-PARTY WEBSITES?
In Short: We are not responsible for the safety of any information that you share with third parties that we may link to or who advertise on our Services, but are not affiliated with, our Services. Any data collected by third parties is not covered by this Privacy Notice. We are not responsible for the content or privacy and security practices and policies of any third parties.
6. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
In Short: We may use cookies and other tracking technologies to collect and store your information. We may use cookies and similar tracking technologies (like web beacons and pixels) to gather information when you interact with our Services. To the extent these online tracking technologies are deemed to be a "sale"/"sharing" under applicable US state laws, you can opt out of these online tracking technologies by submitting a request as described below under section "DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?" Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Notice.
Design survey cookie
If you take part in a design survey (see “WHAT INFORMATION DO WE COLLECT?”), we store a cookie in your browser recording that you have responded, so that we count one response per household. It holds nothing about you and nothing about your answers, and it is not used for advertising or analytics.
Google Analytics
We may share your information with Google Analytics to track and analyze the use of the Services. To opt out of being tracked by Google Analytics across the Services, visit https://tools.google.com/dlpage/gaoptout. For more information on the privacy practices of Google, please visit the Google Privacy & Terms page.
Google Ads
We use Google Ads to measure our advertising campaigns and to show Mobieus ads to people who have visited our site (remarketing), using Google Consent Mode. By default Google's consent is set to denied, so no advertising cookies are stored and there is no personalized tracking; Google's tag sends only cookieless, aggregate signals. When you turn on the Advertising category in our cookie preferences, advertising cookies and full measurement are enabled, and we clear them if you turn the category off. For more information on the privacy practices of Google, please visit the Google Privacy & Terms page.
7. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.
We provide the AI Products through third-party service providers ("AI Service Providers"), including Anthropic. Your input, output, and personal information will be shared with and processed by these AI Service Providers to enable your use of our AI Products. You must not use the AI Products in any way that violates the terms or policies of any AI Service Provider. Our AI Products are designed for the following functions: AI automation, AI document generation, AI insights, AI search, AI translation, Image analysis, Text analysis, and Natural language processing. All personal information processed using our AI Products is handled in line with our Privacy Notice and our agreement with third parties.
AI in mobieusHealth. mobieusHealth includes AI-powered nutrition features, such as meal analysis, food photo recognition, an automated never-eat safeguard that double-checks AI meal output against the exclusion list you configure, and a coaching chat. AI features run only when you trigger them. Nothing is sent in the background, and nothing is sent at all if you do not use them.
What gets sent depends on the feature. Single-purpose tools send only their own input, a food photo, a meal description, a restaurant menu you paste.
The coach sends more than that, and you should know what. So it can answer in your terms rather than in general, each message you send to the coach is accompanied by a summary drawn from what you have already logged: your weight, goal and progress; today's calories, macros and water against your targets; your logging streak; your age and sex; your diet style and the foods you never eat; the supplements you take and their doses; today's activity; the habits you track; notable readings from your vitals and measurements; and any medical conditions, prescription medications, and pregnancy or nursing status you have entered. The coach screen itself lists exactly what would be sent for your account, under "What the coach can see about you". That list is generated from your own record, so it is always current.
The coaching AI is told which kinds of medication protocol are switched on and the goal settings they create, the type only, never a medication name, a dose or a lab value. What reaches it is “a GLP-1 protocol is active” and the protein, calorie, fiber and training figures that follow from it, so that its advice about food and training matches what you are doing.
A progress photograph you upload from the web is checked for its orientation, and only with your prior consent to that feature. If you have given it, the picture is sent to the AI provider for the single question of which way up it is, and for nothing else. A photograph taken in the app is never sent to any AI provider, the app records which way up it is at the moment you take it, so there is nothing to ask.
None of this is used to train our AI Service Providers' models, used to advertise to you, or sold. If you would rather none of it left the app, do not use the coach: the trackers, charts and reports all work without it.
You are shown what is about to be sent, before it is sent. In Loopa, the coaching chat and the eating-out helper each show you a disclosure the first time you use them, and again whenever what they send changes: exactly which of your details are included (assembled from your own record, so a detail you have never entered is never listed) why they are needed, that Anthropic processes them, how long Anthropic keeps them, and that they are not used to train models. You can continue or decline, with no penalty for declining, and the choice is enforced on our servers rather than only in the app. Each of those features can be switched off individually under More › Preferences › Your Data, which also shows what every AI feature you have used sends and when you last used it.
8. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
In Short: We may transfer, store, and process your information in countries other than your own. Our servers are located in the United States. If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws as comprehensive as those in your country. We have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses.
9. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law. No purpose in this notice will require us keeping your personal information for longer than three (3) months past the termination of the user's account. Health and wellness data in mobieusHealth is encrypted with keys unique to your account; when your account is deleted, those keys are permanently destroyed, which renders the encrypted health records unrecoverable immediately.
A medication protocol record is kept while your account is open and goes when your health data goes; the schedule and its cadence go with it. Progress photographs are kept while your account is open, and deleting your account unlinks them from disk.
Family Group data. Group membership and invitation records are kept while the group exists and for no more than three (3) months after it is dissolved or you leave it. Invitations expire automatically after seven (7) days and are deleted on the same schedule. Shared pantry items belong to the household rather than to one person: if you turn off participation, leave the group, or delete your account, the items you contributed remain available to the remaining members, but your name is removed from them and they are shown as added by a former member. If the group is dissolved, its shared pantry is retained for the same three (3) month window and then removed. Your personal pantry is never affected by any of this.
Design survey responses. We delete the IP address recorded with a survey response within ninety (90) days of that survey closing. After that the response carries nothing that identifies you or your browser, and we keep the remaining anonymous answers for as long as they are useful for design decisions.
10. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through a system of organizational and technical security measures. All traffic to the Services is encrypted in transit using TLS. Health and wellness records in mobieusHealth are additionally encrypted at rest using AES-256-GCM envelope encryption with a data encryption key unique to each user, so one user's health records cannot be read with another user's keys. However, despite our safeguards, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. You should only access the Services within a secure environment.
If you run a medication protocol, the compound names, amounts and notes you typed, the note on any dose, every symptom and severity you recorded, your wellbeing check-ins and the lab values you entered are encrypted with that same key. Three parts of a protocol are stored as ordinary text: the cadence of the schedule you set, the route, and the site on the body map you chose, a reminder has to fire on the right day at the right hour, and the rotation map has to be drawn, and neither can be done from a value nobody can read. None of the three names a substance or an amount.
11. DO WE COLLECT INFORMATION FROM MINORS?
In Short: The Services are not directed to children under 13, and Loopa and mobieusHealth require users to be at least 18.
We do not knowingly collect personal information from, or market to, children under 13 years of age, consistent with the U.S. Children's Online Privacy Protection Act (COPPA) and equivalent laws in Canada. If we receive actual knowledge that a child under 13 has provided personal information to us without verifiable parental consent, we will delete that information as quickly as is reasonably practical.
Our Loopa consumer service and all mobieusHealth features are intended for adults and require users to be at least 18 years of age; we do not knowingly collect health and wellness data from anyone under 18. Other communities hosted on the Mobieus platform may admit users aged 13 to 17 only with the permission and supervision of a parent or guardian, as described in our Terms of Service; the community operator is responsible for its own membership rules and for any additional consent required.
If you become aware of any data we may have collected from a child in violation of the above, please contact us at privacy@mobieus.io.
12. WHAT ABOUT CONSUMER HEALTH DATA?
In Short: Health data you log in mobieusHealth is opt-in, encrypted per user, never sold, never used for advertising, and destroyed when you delete your account.
This section also serves as, and is available as, our standalone Consumer Health Data Privacy Policy. It applies to the health and wellness information you log through mobieusHealth, whether in a community that offers it or through our Loopa consumer service, including reproductive or menstrual cycle data if you use the cycle tracker. We are not a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act (HIPAA), and the Services are not intended for HIPAA-regulated use. Your health data in mobieusHealth is consumer health data, and we handle it as follows:
- Opt-in only. We collect health data only when you enable mobieusHealth and accept its end-user agreement, and only the data you choose to log. You can stop logging at any time.
- Encryption. Health records are encrypted at rest with AES-256-GCM envelope encryption using a data encryption key unique to your account.
- No sale, no ads. We do not sell consumer health data, and we do not use it for targeted advertising, marketing segmentation, or any analytics unrelated to delivering the features you use.
- AI processing. Health data is shared with our AI Service Providers only when you invoke an AI feature, and only to fulfill that request. Single-purpose features send only their own input; the coaching chat also sends a summary of what you have logged, including any medical conditions, prescription medications, and pregnancy or nursing status you have entered. Section 7 lists it in full. Our agreements prohibit those providers from using your inputs to train their models.
- A Loopa Coach, if you have one. A coach is an independent person, not our employee, and they are paid a commission on subscriptions that begin through their link, so we treat what they can see as a disclosure to a third party rather than an internal one. You get a coach by tapping a link they gave you, either when you sign up or, since 20 August 2026, at any time after. Nothing reaches them until you switch it on. The consent screen starts with every category off, you choose them one at a time from weight, activity, fasting, nutrition, cycle, supplements and streaks, and one per health track or protocol you run, and you can switch any of them off at any moment. Each protocol category shows your coach a bounded summary and nothing else (patterns and counts, the days your entries fall on, and short-window averages). None of them ever shows the compound or substance name, any amount, any lab value, a note on any entry, or your supply and calculator figures, and testosterone therapy support never shows libido, even where you record it. The consent screen names exactly what each category shows before you turn it on, and the app’s own policy lists them: loopa.mobieus.io/privacy. Peptide protocols are never shared with a coach; there is no toggle for them, by design. Switching one off cuts their access to that category including the history, not just what you log afterwards. Every time your coach opens one of your categories it is recorded, and you can read that record yourself in the app under “Who looked, and when”; it distinguishes your coach glancing at their list of clients from your coach opening you and reading. Blocking or leaving your coach cuts all of it immediately, and affects neither your subscription, nor your price, nor your access to their forum. A coach cannot change anything in your account: a meal plan they build is an offer you accept or turn down, and what they can send you is rate-limited. A coach gives general wellness guidance, not medical advice.
- A protocol summary is made when you ask and is not stored. If you run a medication protocol you can generate a summary of it for your prescriber, as a PDF or a spreadsheet, over a window you choose. It is built at the moment you ask for it and handed straight to you as a download, no copy of it is kept on our side, and there is no link to expire or revoke. Making one is written into your own access record, so you can see afterwards that you made it and when.
- Community operators. If you use mobieusHealth inside a community operated by one of our customers, that operator receives your seat and billing status for the community. Your encrypted health records are keyed to your account.
- Deletion. Deleting your account permanently destroys your encryption keys, rendering your health records unrecoverable. You can also export your data as CSV before deleting.
- A record of who read it. In Loopa, every occasion on which a coach, a member of our support staff or an administrator opens your record is written to a record you can read yourself, under More › Preferences › Your Data. Nobody can open a member's record without first choosing a reason, and that reason is shown to you alongside the date and what was opened. The record cannot be edited or deleted by anyone here; it is removed only when the account is. Section 8 of the Loopa privacy policy sets out what it covers and what it does not.
- Everyone you share with, in one place. The same screen lists every family group, accountability partner and coach who can see any part of your health record, what each of them can see, and a control that ends any of them immediately. Ending a family share does not affect anyone's subscription.
- Shared family pantry. If you opt in to a Loopa Family Group's shared pantry, we treat the items you add as consumer health data, even though a list of food in a cupboard is not a health status on its face. A pantry can imply a dietary condition in aggregate, a list of only gluten-free products suggests one, and Loopa itself reads the pantry when planning meals around your allergens, so we apply the protections in this section to it rather than arguing it is out of scope. That means opt-in consent before anything is shared, consent you can withdraw instantly by turning participation off, no sale, no advertising, and deletion with your account. Items you added remain with the household if you leave or delete your account, but your name is removed from them and they show as added by a former member. These items are visible to the other members of your group by design, which is why they are not encrypted with your personal health keys, the consent screen says so before you turn it on.
- Where our health information comes from. The studies, clinical guidelines and government documents behind the health information Loopa shows you are published in full at loopahealth.app/sources, grouped by topic and linked to the original. Medicine interaction information is drawn from FDA product labeling through the openFDA drug labeling API, which FDA updates weekly, and Loopa quotes the label sentence rather than paraphrasing it. Loopa is not a medical provider and does not prescribe, dispense or recommend medication.
- Breach notification. If a breach of security involving unsecured, identifiable health data occurs, we will notify affected users and the Federal Trade Commission as required by the FTC Health Breach Notification Rule. Washington, Nevada, and Connecticut residents. If you live in Washington or Nevada, you have additional rights over consumer health data under the Washington My Health My Data Act, Nevada SB 370, and the consumer health data provisions of the Connecticut Data Privacy Act, including the right to confirm whether we collect or share your consumer health data, access it, obtain a list of third parties with whom it has been shared, withdraw consent, and have it deleted. To exercise these rights, or to appeal a decision on a request, contact us at privacy@mobieus.io or submit a data subject access request.
13. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: Depending on your state of residence in the US or in some regions, such as the European Economic Area (EEA), United Kingdom (UK), Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time, depending on your country, province, or state of residence. If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority.
Withdrawing your consent: If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time by contacting us using the details in "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?" below.
If you have questions or comments about your privacy rights, you may email us at privacy@mobieus.io.
14. DO WE RESPOND TO BROWSER OPT-OUT SIGNALS (GPC / DO-NOT-TRACK)?
Global Privacy Control. We recognize the Global Privacy Control (GPC) browser signal as a valid request to opt out of the "sale" or "sharing" of personal information and of targeted advertising under applicable US state privacy laws. When our site detects a GPC signal from your browser, advertising cookies and related targeted-advertising technologies are treated as opted out for that browser.
Do-Not-Track. Most web browsers and some mobile operating systems also include a Do-Not-Track ("DNT") feature. No uniform technology standard for recognizing and implementing DNT signals has been finalized, and we do not currently respond to DNT signals other than GPC as described above.
15. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information.
Categories of personal information we collect
In the preceding twelve (12) months, we have collected the categories of personal information described in Section 1 above: identifiers (such as name, email address, phone number, mailing address, username, and IP address); account credentials; commercial information (subscription and purchase records); internet and other network activity (log, usage, and device data); geolocation data (where you grant permission); communications you send us; and, only if you opt in to mobieusHealth, the health and wellness information described in Sections 1 and 12. We collect this information from you directly, automatically from your devices, and from the Connected Services you choose to link. We use it for the purposes described in Section 2 and retain it as described in Section 9.
Sale, sharing, and targeted advertising
We do not sell personal information for money, and we do not sell or share consumer health data for any purpose. If you enable the Advertising category in our cookie preferences, advertising cookies used for our Google Ads remarketing may constitute "sharing" of personal information for cross-context behavioral advertising, or "targeted advertising," under some state laws. You can opt out at any time by turning off the Advertising category in our cookie preferences, by using a browser that sends the Global Privacy Control signal (see Section 14), or by submitting a data subject access request. We do not sell or share the personal information of anyone we know to be under 16, and we do not use or disclose sensitive personal information for purposes other than those permitted by law.
Your rights
Depending on your state, you may have the right to: know whether we process your personal information and access it; correct inaccuracies; delete personal information we hold about you; obtain a portable copy; opt out of targeted advertising, sale or sharing, and certain profiling; and limit the use of sensitive personal information. We will not discriminate against you for exercising any of these rights.
How to Exercise Your Rights
To exercise these rights, you can contact us by submitting a data subject access request, by emailing us at privacy@mobieus.io, or by referring to the contact details at the bottom of this document. You may designate an authorized agent to submit a request on your behalf; we may ask the agent for proof of authorization and may ask you to verify your identity directly. We will verify requests using information associated with your account before acting on them.
Appeals
If we decline to act on your request, we will explain why. You may appeal our decision by replying to our response or emailing privacy@mobieus.io with the subject line "Privacy Appeal." If your appeal is denied, you may contact your state attorney general to submit a complaint.
16. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: You may have additional rights based on the country you reside in.
Canada
If you are located in Canada, we process your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial private-sector privacy laws, including Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25, Alberta's PIPA, and British Columbia's PIPA. In particular:
- Consent. We rely on your consent to collect, use, and disclose personal information, and we obtain your express (opt-in) consent before collecting sensitive information such as the health and wellness data you log in mobieusHealth. You can withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice; withdrawing consent for health data means disabling mobieusHealth or deleting your account.
- Privacy Officer. Our Data Protection Officer also serves as our Privacy Officer for Canada and, for Quebec residents, as the person in charge of the protection of personal information. You can reach them at privacy@mobieus.io or at the mailing address in Section 18.
- Your rights. You may request access to and correction of your personal information, and Quebec residents may additionally request that computerized personal information be communicated in a structured, commonly used technological format (data portability) and may request de-indexing in certain circumstances. Submit requests through our data subject access request form or by email.
- Cross-border processing. Our servers are located in the United States, so your personal information is transferred to, stored, and processed in the United States, where it may be subject to access by US authorities under US law. We use contractual and technical safeguards, including the encryption described in Section 10, to protect it.
- Breach notification. If a breach of security safeguards involving your personal information creates a real risk of significant harm, we will notify you and report the breach to the Office of the Privacy Commissioner of Canada (and, for Quebec residents, to the Commission d'accès à l'information) as required by law, and we maintain records of all breaches.
- Complaints. If you believe we are processing your personal information unlawfully, you may complain to our Privacy Officer, to the Office of the Privacy Commissioner of Canada, or to your provincial privacy regulator.
Other regions
Residents of Australia, New Zealand, and the Republic of South Africa also have the right to request access to or correction of personal information at any time. If you believe we are unlawfully processing your personal information, you have the right to submit a complaint to the relevant regulator in your jurisdiction.
17. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws. We may update this Privacy Notice from time to time. An update is shown by the "Last updated" date and the version number at the top of this notice.
18. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may contact our Data Protection Officer (DPO) by email at privacy@mobieus.io, or contact us by post at:
Mobieus Partners LLCData Protection Officer30 N Gould St, Suite RSheridan, WY 82801United States
19. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. To request to review, update, or delete your personal information, please fill out and submit a data subject access request.
In Loopa you do not have to ask us. Under More › Preferences › Your Data in the app, or Settings › Your Data on the web, you can read what we hold and how each category is protected, read the record of who has opened your record and why, stop any sharing immediately, switch off individual AI features, request an export, and delete your account.
Export. We assemble everything you created or generated and email you a link. Opening it requires signing in again, and it stops working after seven days or one download, whichever comes first. One export can be requested every seven days.
Deletion. Deleting your account is available in the app and on the web, without contacting us. There is a thirty-day grace period during which signing in cancels the deletion; after that it is irreversible, and it removes your health records, your photographs, every sharing grant in both directions, your AI conversation history, your export bundles and the access record itself. A subscription bought through Apple or Google is not cancelled by deleting your account, only the store can do that, and the app links you to the right place.
20. APPLE HEALTH (HEALTHKIT) AND APPLE CAREKIT
In Short: Our iOS app can sync with Apple Health using HealthKit, and it offers a Care Plan built on Apple CareKit. This data stays under your control, is used only to provide the app's features to you, is never used for advertising or marketing, is never sold, and is never stored in iCloud by us.
Apple Health (HealthKit). With your explicit permission, the Loopa iOS app reads and writes health data through Apple's HealthKit framework so your log stays in sync with Apple Health. Connecting is optional and entirely your choice; nothing is read or written until you grant access, and you can turn any category on or off, or disconnect, at any time in the app or in Settings › Privacy & Security › Health.
The specific health data the app can read from Apple Health is: body weight, body-fat percentage, waist circumference, blood pressure, heart rate, resting heart rate, blood glucose, step count, exercise minutes, water intake, sleep analysis, and workouts. The app writes back only the data you log yourself (weight, body-fat, waist, blood pressure, resting heart rate, blood glucose, water, and workouts) so your other health apps agree.
Apple CareKit. The app's Care Plan feature is built on Apple's CareKit framework. Your Care Plan and the items you check off are stored in a CareKit store on your device and are used only to show you your routine and your progress.
How this data is handled. Health and Care Plan data obtained through HealthKit or CareKit is used solely to provide the app's features to you, your log, trends, reminders, Care Plan, and coaching. Consistent with Apple's requirements, we do not use it for advertising or marketing, we do not use it for use-based data mining, we do not sell it, and we do not store it in iCloud. Health data you sync to our servers is encrypted with keys unique to your account, and deleting your account destroys those keys and renders the data unrecoverable (see the deletion section above).
Lab results in Apple Health’s clinical records can be read into your lab log, on iPhone, if you grant it. Only the markers you approve are read, only when you ask for them, and nothing is ever written back into your clinical records. What comes across is the marker, its value and its unit, kept exactly as it arrived and encrypted with your key like the rest of your record.
21. HEALTH CONNECT AND CONNECTED DEVICE SERVICES
In Short: You can connect Loopa to Google Health Connect on Android and to third-party health-device clouds. IHealth, Withings, and Oura. We access this data only with your authorization, use it only to provide the app's features to you, never sell it, and let you disconnect at any time.
Google Health Connect (Android). With your explicit permission, the Loopa Android app reads health data through Google's Health Connect so your log stays in sync. Connecting is optional and entirely your choice; nothing is read until you grant access in the Health Connect permission screen, and you can revoke access at any time in Health Connect or by disconnecting in the app. The data the app reads through Health Connect is: step count, body weight, water intake, and exercise sessions.
Connected device clouds (iHealth, Withings, Oura). You may connect your account to third-party health-device cloud services. IHealth Labs, Withings, and Oura, to bring readings from those devices into your log automatically. When you connect one of these services, you sign in on that provider's own website and authorize Loopa to access your data using OAuth; we never see, receive, or store your password for that service. With your authorization, we retrieve health measurements from the connected service and add them to your log and trends. Depending on the provider and the devices you use, this may include: body weight and body composition, blood pressure, heart rate and resting heart rate, blood oxygen (SpO₂), body temperature, blood glucose, sleep, and daily activity such as steps.
To keep the connection working, we store the access and refresh tokens the provider issues to us, encrypted with keys unique to your account, on our servers; we do not store your credentials for the provider. We retrieve data on a periodic schedule and, where the provider supports it, when the provider notifies us that new data is available. You can disconnect any service at any time from the app's settings, which deletes our stored tokens and ends our access going forward. Data already synced into your log remains until you delete it or delete your account.
How this data is handled. Data obtained through Health Connect or a connected device cloud is used solely to provide the app's features to you, your log, trends, reminders, and coaching. We do not use it for advertising or marketing, we do not sell it, and health data synced to our servers is encrypted with keys unique to your account; deleting your account destroys those keys and renders the data unrecoverable (see the deletion section above). Each connected service is a separate company with its own privacy policy and terms, which govern how it handles your data on its side; we are not responsible for the privacy practices of those services.
Lab results are an iPhone matter. Reading lab results out of Apple Health’s clinical records is an iPhone feature, described in Section 20; nothing equivalent is read from Health Connect, and no lab result is ever written to it.
Consumer Health Data Privacy Policy
Effective date: August 1, 2026 · Last updated: September 15, 2026 · Version 1.3
Mobieus Partners LLC, d/b/a Mobieus and Loopa ("we," "us," "our") provides this Consumer Health Data Privacy Policy to describe how we collect, use, share, and protect consumer health data, and the rights you have over it, including rights under the Washington My Health My Data Act, Nevada SB 370, and the consumer health data provisions of the Connecticut Data Privacy Act. It supplements our Privacy Policy. If this policy conflicts with the Privacy Policy with respect to consumer health data, this policy controls.
1. What consumer health data we collect
We collect consumer health data only if you opt in to mobieusHealth (including through our Loopa consumer service) and only the data you choose to log or sync. Depending on the trackers and connections you use, this may include:
- Food and meal logs, food photos you submit for analysis, and the never-eat exclusion lists you configure;
- Body weight, body-fat percentage, body measurements, and vital signs such as blood pressure, heart rate, resting heart rate, blood oxygen (SpO₂), body temperature, and blood glucose;
- Water intake, physical activity, workouts, step counts, sleep, and exercise minutes;
- Supplements and their doses, health goals, habits you track, and menstrual cycle data if you use the cycle tracker;
- Medical conditions, prescription medications, and pregnancy or nursing status, if you choose to enter them;
- A medication protocol, if you switch one on: which kind, the schedule you set, the compound names, amounts and notes you type, each dose you log with its site on the body map, symptoms with a severity, a daily wellbeing check-in, lab results exactly as you entered them, and your Off-Ramp check-in answers;
- Health data you authorize us to receive from connected services: Apple Health (HealthKit), Apple CareKit, Google Health Connect, iHealth, Withings, and Oura.
2. Sources of consumer health data
We collect consumer health data directly from you when you log it, and from the connected health platforms and device clouds listed above when you explicitly authorize each connection. We do not collect consumer health data from data brokers, advertisers, or any other third parties, and we do not infer health data about you from your other activity.
3. Why we collect it and how we use it
We collect and use consumer health data solely to provide the mobieusHealth features you enable: displaying your trackers and logs, generating trends and reports, sending reminders you configure, syncing with the connected services you authorize, and running the AI features you invoke (such as meal analysis, food photo recognition, the never-eat safeguard, and the coaching chat). We do not use consumer health data for advertising, marketing segmentation, or any analytics unrelated to delivering the features you use.
4. How we share consumer health data
We do not sell consumer health data, and we do not share it with advertisers, social networks, or sales and marketing tools. Consumer health data leaves our systems only in these cases:
- Infrastructure providers. Our hosting and cloud storage providers store your data in encrypted form as part of operating the Services.
- AI Service Providers. When you invoke an AI feature, the inputs needed to run that request are processed by our AI Service Providers (including Anthropic). Single-purpose tools send only their own input; the coaching chat also sends a summary of what you have logged, which the coach screen lists for your account under "What the coach can see about you." Our agreements prohibit these providers from using your inputs to train their models.
- Legal requirements. Where we are required to disclose data by law, legal process, or to protect vital interests.
- A Loopa Coach, if you have one. A coach is an independent person, not our employee, and they are paid a commission on subscriptions that begin through their link, so we treat what they can see as a disclosure to a third party rather than an internal one. You get a coach by tapping a link they gave you, either when you sign up or, since 20 August 2026, at any time after. Nothing reaches them until you switch it on. The consent screen starts with every category off, you choose them one at a time from weight, activity, fasting, nutrition, cycle, supplements and streaks, and one per health track or protocol you run, and you can switch any of them off at any moment. Each protocol category shows your coach a bounded summary and nothing else (patterns and counts, the days your entries fall on, and short-window averages). None of them ever shows the compound or substance name, any amount, any lab value, a note on any entry, or your supply and calculator figures, and testosterone therapy support never shows libido, even where you record it. The consent screen names exactly what each category shows before you turn it on, and the app’s own policy lists them: loopa.mobieus.io/privacy. Peptide protocols are never shared with a coach; there is no toggle for them, by design. Switching one off cuts their access to that category including the history, not just what you log afterwards. Every time your coach opens one of your categories it is recorded, and you can read that record yourself in the app under “Who looked, and when”; it distinguishes your coach glancing at their list of clients from your coach opening you and reading. Blocking or leaving your coach cuts all of it immediately, and affects neither your subscription, nor your price, nor your access to their forum. A coach cannot change anything in your account: a meal plan they build is an offer you accept or turn down, and what they can send you is rate-limited. A coach gives general wellness guidance, not medical advice.
You may also share categories with a buddy or an accountability partner. That works the same way: you choose per category, nothing is shared by default, and you can stop at any time.
If you use mobieusHealth inside a community operated by one of our customers, that operator receives your seat and billing status only; your encrypted health records are keyed to your account.
5. How we protect it
All traffic is encrypted in transit using TLS. Consumer health data is encrypted at rest using AES-256-GCM envelope encryption with a data encryption key unique to your account, so one user's health records cannot be read with another user's keys. Access to production systems is restricted, and we do not store health data in device backups we control or in iCloud.
What that encryption does and does not do. Your key is wrapped by a platform key held on our servers, not by any passphrase of yours. It defeats a stolen database, a stolen backup or a stolen disk. It does not put your record beyond our own reach: a small number of our staff, working on the server itself, can decrypt it, and every occasion on which one of them opens a member's record is recorded and shown to that member. Some information is stored as ordinary text rather than encrypted. Fasting times, generated meal plans and weekly insights, habit check-ins, anything posted in a community, the subscription identifiers an app store gives us, and, for a medication protocol, the cadence of its schedule, the route and the body-map site, none of which names a substance or an amount.
6. How long we keep it
Consumer health data is retained while your account is active. Deleting your account permanently destroys your per-account encryption keys, which renders your encrypted health records unrecoverable immediately. You can export your data as CSV before deleting. A medication protocol record is kept while your account is open and goes when your health data goes; a summary you generate for your prescriber is never stored.
7. Your rights
If you are a resident of Washington or Nevada, or a Connecticut resident with rights over consumer health data, you have the right to:
- Confirm whether we are collecting, sharing, or selling your consumer health data, and access that data;
- Obtain a list of the third parties and affiliates with whom we have shared consumer health data, with contact information where required;
- Withdraw your consent to our collection and sharing of consumer health data (you can do this by disabling mobieusHealth trackers, disconnecting connected services, or deleting your account);
- Have your consumer health data deleted, including from our backups within the timeframes allowed by law.
Three of these you can exercise yourself, without asking. In Loopa, More › Preferences › Your Data lists everyone who currently receives any part of your health record (family groups, accountability partners, coaches) and what each one can see, alongside what each AI feature sends and to whom. The same screen ends any of those immediately, switches off individual AI features, and deletes your account. Withdrawing consent there takes effect on our servers straight away, not at the next request.
We will not discriminate against you for exercising these rights. Residents of other states and Canada have the rights described in our Privacy Policy, which we honor for health data regardless of where you live.
8. How to exercise your rights, and appeals
Submit a data subject access request or email privacy@mobieus.io. We will authenticate your request using information associated with your account and respond within the time required by applicable law. If we decline your request, you may appeal by replying to our response or emailing privacy@mobieus.io with the subject line "Health Data Appeal." Washington residents whose appeal is denied may contact the Washington State Attorney General at atg.wa.gov; residents of other states may contact their state attorney general.
9. Breach notification
If a breach of security involving unsecured, identifiable health data occurs, we will notify affected users and the Federal Trade Commission as required by the FTC Health Breach Notification Rule, and will make any notifications required under state breach laws and, for Canadian residents, PIPEDA and Quebec Law 25.
10. A note on HIPAA
We are not a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act (HIPAA), and mobieusHealth is a consumer wellness product, not a HIPAA-regulated service. The protections in this policy come from the FTC Act, the FTC Health Breach Notification Rule, state consumer health data laws, and our contractual commitments to you.
11. Contact us
Mobieus Partners LLC, Attn: Data Protection Officer, 30 N Gould St, Suite R, Sheridan, WY 82801, United States. Email: privacy@mobieus.io. Phone: (+1) 307-295-2230.