Privacy, plainly

What we can see, and what we cannot.

The short version, without the legal language. The privacy policy is the binding document. This page is the same thing in sentences you can check against the app, and every claim on it is something the code enforces rather than something we intend.

The short answer

Three guarantees, before the detail.

Nothing is shared until you share it

Fourteen separate switches for a coach, every one off to begin with, and no button that turns them all on. Turning one off takes back what they could already see, not just what comes next.

Your gym cannot read your health data

Not "switched off by default". There is no permission for it in the app at all, for any role including the highest, and a build that adds one fails.

Deleting your account destroys the key

Not a flag on a row. The key your entries were encrypted with is destroyed, and what is left cannot be read by anybody, us included.

Who sees what

The whole list, on one screen.

If something you can log is not on this list, the answer is that only you see it.

ThisIs seen byNotes
Your food, weight, vitals, notes and photosYou aloneA coach sees a field only after you switch it on
Your compound names, doses, symptoms and lab valuesYou aloneEncrypted. A coach never sees any of them, on any grant
Which fields you shared, and every time a coach read oneYouListed in Your Data, with dates
Your workout sets, reps and weightsYou, and a coach you granted workoutsNumbers are stored unencrypted so your charts and records can be summed
How many of a gym's members were active this monthThe gymA count and a month. Never which members
Which members those wereNobody outside LoopaNot sent, and no field in the report can carry it
What an AI feature is about to sendYou, before it is sentShown every time. Declining cancels the feature, not your day
Your passwordNobody, including usNever stored. Only a verifier that cannot be reversed
Worth saying plainly

Four things, in full.

A coach sees what you switch on, and nothing else

Sharing is per field and every field starts off, deliberately: each one is its own decision. Every read is logged and shown back to you in Your Data with a date. Changing coach is a single act rather than a cleanup you have to remember, so the old forum closes, every standing grant is revoked and every open share is withdrawn in the same moment.

A medication protocol is the most guarded thing in the app

Compound names, amounts, notes, symptoms, severities and lab values are encrypted. None of them ever appears in a web address, a query string or an analytics property, and the server discards anything drug, dose, symptom or lab shaped that a client sends regardless. A coach granted a protocol sees a pattern, a schedule of dose days and a wellbeing trend, and never a name or a number. A peptide protocol cannot be shared with a coach at all.

An organization sees counts

A gym, club or employer running Loopa sees a handful of numbers about its own members each month and the month they belong to. It cannot see which members those are, and nothing anybody logged crosses that boundary. The report is assembled from a fixed list of counts and accepts nothing outside it, so there is no route a member identifier could take even by mistake.

What is not encrypted, and why

Two things, said here rather than left for you to find. Workout set numbers are stored in the clear, because every chart, every personal record and every volume total is a sum across them. And a protocol stores a bare schedule unencrypted so a reminder can fire on time, which is a cadence naming nothing. Everything you write in your own words stays encrypted under your own key.

FAQ

Questions people actually ask

Can my coach see my food log?

Only if you switched that on. Sharing with a coach is fourteen separate switches, every one of them off until you turn it on, and there is no share-everything button. Turning one off also removes what your coach could see before, not only what happens next. Every time a coach reads something of yours it is listed in Your Data with the date.

Can my gym see my food log?

No, and there is no setting that would let it. Inside Loopa, no organization role can read a member's health data at all. It is not a permission that is switched off by default; there is no such permission, and the build fails if anybody adds one. An organization sees counts about its own members and a month, never who.

What can a coach see about my medication protocol?

The pattern, the schedule and the trend, and only for the protocol you granted. Never a compound name, never a dose, never a lab value. A peptide protocol has no coach template at all, so there is nothing to grant and nothing to read.

Is my health data encrypted?

Your entries, notes, symptoms, lab values, compound names and amounts are encrypted with a key belonging to your account. Two things are deliberately not: workout set numbers, because every chart and personal record is a sum over them, and a few plaintext columns the medication engine needs to schedule a reminder, which is a cadence naming nothing.

Does a compound or a medication name ever appear in a web address?

No. No substance name rides a path, a query string or an analytics property, and the server drops anything drug, dose, symptom or lab shaped that a client sends anyway. Push notifications carry identifiers, not names.

What does the AI see?

Exactly what you are shown before it is sent, every time, and you can decline; the feature simply does not run. Our AI provider is contractually barred from training on anything we send. Photographs taken in the app for a progress record are never sent to an AI provider at all.

What happens to my password?

It never reaches us. Signing in uses a zero-knowledge exchange, so what we hold is a verifier that cannot be reversed into your password, and there is nothing in our database for anybody to steal and crack.

If I leave my gym or my coach, do I lose anything?

No. Your account and everything in it are yours and stay yours. Leaving an organization ends your place in its room and its challenges. Changing coach ends the old relationship in one act: the room closes, every standing grant is revoked and every open share is withdrawn. What you keep is your own history.

What happens when I delete my account?

The key your entries were encrypted with is destroyed, which makes them unreadable rather than merely marked deleted. You get a confirmation with a reference, and the record that the key was destroyed outlives the account so we can still answer if you ask later.

Do you sell any of this?

No. Not your data, not a de-identified extract, not to an advertiser, a broker, an insurer or an employer. Loopa is paid for by the people who subscribe to it, which is the whole of the business model.

App Store Android APK