Nothing is shared until you share it
Fourteen separate switches for a coach, every one off to begin with, and no button that turns them all on. Turning one off takes back what they could already see, not just what comes next.
The short version, without the legal language. The privacy policy is the binding document. This page is the same thing in sentences you can check against the app, and every claim on it is something the code enforces rather than something we intend.
Fourteen separate switches for a coach, every one off to begin with, and no button that turns them all on. Turning one off takes back what they could already see, not just what comes next.
Not "switched off by default". There is no permission for it in the app at all, for any role including the highest, and a build that adds one fails.
Not a flag on a row. The key your entries were encrypted with is destroyed, and what is left cannot be read by anybody, us included.
If something you can log is not on this list, the answer is that only you see it.
| This | Is seen by | Notes |
|---|---|---|
| Your food, weight, vitals, notes and photos | You alone | A coach sees a field only after you switch it on |
| Your compound names, doses, symptoms and lab values | You alone | Encrypted. A coach never sees any of them, on any grant |
| Which fields you shared, and every time a coach read one | You | Listed in Your Data, with dates |
| Your workout sets, reps and weights | You, and a coach you granted workouts | Numbers are stored unencrypted so your charts and records can be summed |
| How many of a gym's members were active this month | The gym | A count and a month. Never which members |
| Which members those were | Nobody outside Loopa | Not sent, and no field in the report can carry it |
| What an AI feature is about to send | You, before it is sent | Shown every time. Declining cancels the feature, not your day |
| Your password | Nobody, including us | Never stored. Only a verifier that cannot be reversed |
Sharing is per field and every field starts off, deliberately: each one is its own decision. Every read is logged and shown back to you in Your Data with a date. Changing coach is a single act rather than a cleanup you have to remember, so the old forum closes, every standing grant is revoked and every open share is withdrawn in the same moment.
Compound names, amounts, notes, symptoms, severities and lab values are encrypted. None of them ever appears in a web address, a query string or an analytics property, and the server discards anything drug, dose, symptom or lab shaped that a client sends regardless. A coach granted a protocol sees a pattern, a schedule of dose days and a wellbeing trend, and never a name or a number. A peptide protocol cannot be shared with a coach at all.
A gym, club or employer running Loopa sees a handful of numbers about its own members each month and the month they belong to. It cannot see which members those are, and nothing anybody logged crosses that boundary. The report is assembled from a fixed list of counts and accepts nothing outside it, so there is no route a member identifier could take even by mistake.
Two things, said here rather than left for you to find. Workout set numbers are stored in the clear, because every chart, every personal record and every volume total is a sum across them. And a protocol stores a bare schedule unencrypted so a reminder can fire on time, which is a cadence naming nothing. Everything you write in your own words stays encrypted under your own key.
Only if you switched that on. Sharing with a coach is fourteen separate switches, every one of them off until you turn it on, and there is no share-everything button. Turning one off also removes what your coach could see before, not only what happens next. Every time a coach reads something of yours it is listed in Your Data with the date.
No, and there is no setting that would let it. Inside Loopa, no organization role can read a member's health data at all. It is not a permission that is switched off by default; there is no such permission, and the build fails if anybody adds one. An organization sees counts about its own members and a month, never who.
The pattern, the schedule and the trend, and only for the protocol you granted. Never a compound name, never a dose, never a lab value. A peptide protocol has no coach template at all, so there is nothing to grant and nothing to read.
Your entries, notes, symptoms, lab values, compound names and amounts are encrypted with a key belonging to your account. Two things are deliberately not: workout set numbers, because every chart and personal record is a sum over them, and a few plaintext columns the medication engine needs to schedule a reminder, which is a cadence naming nothing.
No. No substance name rides a path, a query string or an analytics property, and the server drops anything drug, dose, symptom or lab shaped that a client sends anyway. Push notifications carry identifiers, not names.
Exactly what you are shown before it is sent, every time, and you can decline; the feature simply does not run. Our AI provider is contractually barred from training on anything we send. Photographs taken in the app for a progress record are never sent to an AI provider at all.
It never reaches us. Signing in uses a zero-knowledge exchange, so what we hold is a verifier that cannot be reversed into your password, and there is nothing in our database for anybody to steal and crack.
No. Your account and everything in it are yours and stay yours. Leaving an organization ends your place in its room and its challenges. Changing coach ends the old relationship in one act: the room closes, every standing grant is revoked and every open share is withdrawn. What you keep is your own history.
The key your entries were encrypted with is destroyed, which makes them unreadable rather than merely marked deleted. You get a confirmation with a reference, and the record that the key was destroyed outlives the account so we can still answer if you ask later.
No. Not your data, not a de-identified extract, not to an advertiser, a broker, an insurer or an employer. Loopa is paid for by the people who subscribe to it, which is the whole of the business model.