Privacy Policy
What we collect, why we collect it, and how you can control it.
1. Who we are
Loopwell operates the Loopwell habit-tracking wellness application and this website, and is the controller of the personal data described below. You can reach us at any time at support@lumilea.site; we answer data requests within 30 days.
2. What we collect
Collection is deliberately narrow.
| Category | Examples | Why |
|---|---|---|
| Account data | First name, email address, hashed password | To create and secure your account and send service emails |
| Subscription data | Plan, billing status, card brand and last four digits from our payment processor | To run your trial, renewals, cancellations and refunds |
| App activity | Entries you write in your food log, movement minutes you record, habits you tick off, reminder settings, and any optional figures you choose to enter yourself | To deliver the features you subscribed to |
| Technical data | Device type, browser, operating system, approximate region from IP, error logs | Security, fraud prevention and fixing faults |
| Support messages | Whatever you write to us | To answer you |
We do not want health data. We never ask for medical history, diagnoses, test results, medication records or body measurements, and we ask you not to put them in support messages. Anything you type into your own log stays a personal note — we do not analyse it clinically, we do not build a health profile from it, and we never use it for advertising.
On this deployment, your log never leaves your device. The account you create and every entry you make — meals, movement, habits, reminders and any optional note — are stored by your own browser on the device you used, not on our servers. That means we cannot read them, they are not backed up for you, and clearing your browser data removes them. Export them to a file from Settings → Your data whenever you want a copy.
3. How we use it
- Running the app: your habits, log entries, reminders and records.
- Payments, trials, renewals, cancellations and refunds.
- Service emails: trial ending, receipts, password resets, material policy changes.
- Optional product emails, which you can switch off in settings or by unsubscribing.
- Security, abuse detection and technical diagnostics.
- Aggregated, de-identified usage statistics that cannot identify you.
We do not build advertising profiles, we do not use your log for interest-based advertising, and we make no automated decisions with legal or similarly significant effects.
4. Legal bases (EEA and UK)
Where the GDPR applies we rely on contract to provide the app and take payment, legitimate interests for security and service improvement, consent for marketing emails and non-essential cookies (withdrawable at any time), and legal obligation for tax and accounting records.
5. Who else sees it
We do not sell personal information and we do not give it to advertisers or data brokers. We use processors who work under contract for us:
- A payment processor, which receives card details directly — we never store full card numbers.
- Cloud hosting and database providers.
- An email delivery provider for transactional and, if you opt in, product emails.
- An error-monitoring and analytics provider, configured not to sell data.
We may disclose data where the law requires it, or in a merger or acquisition — in which case we notify you before your data comes under a different policy.
6. How long we keep it
Account and log data live as long as your account does. Delete your account and we remove your personal data within 30 days, except records we must retain for tax, accounting or fraud prevention (invoices, typically up to 7 years). Backups roll off within 90 days.
7. Your rights
- Access and export — Settings → Privacy → Export my data.
- Correct your name or email in Settings → Account.
- Delete your account and data in Settings → Privacy.
- Unsubscribe from product emails through any unsubscribe link.
- Object, restrict or withdraw consent by writing to us.
You may also complain to your local data protection authority. California residents may exercise CCPA/CPRA rights to know, delete and correct; we do not sell or share personal information as that law defines it. Email support@lumilea.site from your account address and we respond within 30 days.
8. Security
Data is encrypted in transit with TLS and at rest, passwords are stored as one-way hashes, and production access is limited to staff who need it and protected by two-factor authentication. No system is perfectly secure; if a breach occurs we notify affected users and regulators as the law requires.
9. International transfers
Our providers may process data in the United States and the European Union. Transfers out of the EEA or UK are covered by Standard Contractual Clauses or an equivalent lawful mechanism.
10. Children
Loopwell is for adults aged 18 and over and we do not knowingly collect data from children. Tell us if you believe a child has an account and we will delete it.
11. Cookies
See the Cookie Policy for what this site stores on your device and how to change it.
12. Changes
Material changes are emailed to account holders and dated at the top of this page at least 14 days before they take effect.
Questions: support@lumilea.site.