Privacy Policy
Version 1.3 · Last updated: August 14, 2026
1. Who we are
LoopUsIn is a shared family-planning service that helps families coordinate childcare, calendars, groceries, and other everyday tasks.
LoopUsIn is built and provided by Roel Jorissen as an individual. Bekkevoort Belgium.
This Privacy Policy explains how I collect and use your personal information when you use the application. It applies to all users worldwide.
Contact via info@loopusin.com
2. Information I collect
Personal Information
“Personal information” means any information that relates to an identified or identifiable individual. When you use LoopUsIn, I collect the following types of personal information:
Account Details
When you create an account or sign up for the Service, I collect:
- Your name
- Email address
- Password (stored securely)
Family Data You Create
As you use the Service, you may voluntarily create and submit family-related information, including:
- Family groups
- Details about children
- Calendar entries
- Events, planning Lists, groceries, chores, and related checklist content
- Event/List audience choices, participant roles, and invitation status
- Any other personal or family information you choose to enter
Event and List Invitations
An organizer can share one Event or List with selected LoopUsIn users outside their family group. A recipient receives access only after explicitly accepting the invitation. Acceptance does not join either person's family group and does not expose unrelated household data. Depending on their role, accepted participants may see the title, description, date, location, checklist content, and the limited identity and participation information needed to coordinate that resource.
Invitation secrets are carried in the link and are not stored in plaintext. LoopUsIn stores a cryptographic token hash and may temporarily store a masked email hint or email hash for a recipient-bound invitation. Organizers can revoke unused invitations and remove participants. Removing access prevents future access but cannot recall information someone already viewed or copied outside LoopUsIn.
Technical Data
I automatically collect certain technical information about your device and your use of the Service, such as:
- Device type and operating system
- Browser type and version (if using the web version)
- IP address
- Usage events (for example, how you interact with features, pages viewed, and actions taken)
This data helps me keep the app running smoothly, fix bugs, and improve performance.
Privacy-preserving Web Analytics
LoopUsIn uses Vercel Web Analytics to understand aggregate traffic and page usage across the public website and signed-in application. This processing helps me measure whether pages are useful, diagnose traffic changes, and improve the Service. Where the GDPR applies, I rely on my legitimate interests in operating and improving a useful, reliable Service, balanced against your rights through the minimization controls described here.
Before a page view is sent, LoopUsIn excludes all invitation-entry routes, removes query strings and URL fragments, and replaces known Event and template record identifiers with route placeholders. I do not send names, email addresses, account identifiers, family content, invitation credentials, or custom action events to Vercel Web Analytics.
Vercel Web Analytics does not use analytics cookies. Vercel states that it records anonymous, aggregate page-view data without associating it with an individual or stored IP address. A daily visitor hash derived from the incoming request is automatically reset after 24 hours. A minimized data point may include the redacted page path, timestamp, referrer, country or region derived from the request, device type, browser, operating system, and analytics script version. Aggregate reporting data is available for the reporting window associated with the Vercel plan and may be retained longer by Vercel as described in its service documentation.
You can learn more in Vercel's Web Analytics privacy and compliance documentation. You may object to this limited processing by contacting me using the details below.
Google Calendar Integration (optional)
LoopUsIn offers an optional Google Calendar integration. If you connect it through Google's OAuth consent screen, LoopUsIn may import or export the limited calendar fields covered by the scopes you approve, such as event titles, dates, times, descriptions, locations, or free/busy availability. The integration is used only to provide the calendar features you request. Google handles your credentials, and you can revoke access in your Google Account settings. Your use of Google Calendar is also governed by Google's Privacy Policy and Terms of Service, including the Google API Services User Data Policy and its Limited Use requirements.
Microsoft Outlook Integration (optional)
LoopUsIn also offers optional integration with Microsoft Outlook (including Outlook Calendar) to help you sync family events and keep your shared family schedule up to date. To enable this feature, you must voluntarily connect your personal Microsoft account through the Service using Microsoft’s secure OAuth 2.0 process (via the Microsoft Graph API). You will be redirected to Microsoft’s consent screen, where you can review and explicitly approve the exact permissions requested. When authorized, I may access limited Outlook data such as event titles, dates, times, descriptions, locations, attendees, and free/busy availability — only the scopes you grant and only to provide the integration features within LoopUsIn. I do not use this data for any other purpose, nor do I share it with third parties except as strictly necessary to operate the integration or as required by law. Your Microsoft account credentials are never shared with me — Microsoft handles all authentication. You can revoke access at any time directly in your Microsoft Account settings (account.microsoft.com → Privacy → App permissions). Once revoked, I can no longer access your Outlook data. Your use of Microsoft Outlook is also governed by Microsoft’s Privacy Statement and Terms of Service. I fully comply with Microsoft’s API terms and data protection requirements.
3. How we use your information
I use the personal information we collect from you only for the following purposes:
- To provide and improve our services - including creating and managing your account, delivering the features you request, and enhancing the app’s performance, security, and user experience based on how people actually use it.
- To authenticate you - verifying your identity when you log in or access certain features.
- To send important transactional notifications - such as account confirmations, password rests, security alerts, or service updates.
- To prevent and detect abuse - protecting the app and our users from fraud, spam, unauthorized access, or service updates.
- To comply with legal obligations - responding to valid legal requests, enforcing our Terms of Service, or meeting regulatory requirements.
I never sell your personal data to any third parties for monetary compensation (or any other form of “sale” as defined by privacy law like the CCPA/CPRA). I also process your personal data only in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws where they apply.
4. How I share (or don’t share) your information
I never sell your personal information to any third parties for money or any other form of compensation. I only share your information in the very limited ways described below:
Within Groups and Shared Events/Lists
Data added to a family group is visible to authorized members according to their roles and feature access. Separately, one Event or List can be shared with accepted participants outside the family group. That resource-level access does not grant access to the family directory, other Events, chores, groceries, calendars, financials, settings, or unrelated household information.
With Trusted Service Providers
I use a small number of carefully selected third-party providers to help run the service securely and reliably. These include:
- Supabase — for backend database hosting and storage
- Vercel — for hosting and delivering the web application and providing minimized, aggregate Web Analytics
- Resend — for account, invitation, and service messages
- Google or Microsoft — only when you choose to connect the relevant calendar or sign-in integration
These providers process data only as needed to deliver the selected service, under their applicable terms and data-protection arrangements. The current processor and subprocessor record is reviewed when a provider or processing region changes.
Data Location
Primary account and family data is configured in Supabase's European Union region. Hosting, email, authentication, and optional integration providers may process limited data in other regions as described below.
International Data Transfers
When a provider processes personal data outside the European Economic Area, the applicable transfer mechanism and safeguards are recorded and reviewed, such as an adequacy decision or Standard Contractual Clauses where required.
Legal Requirements
I may disclose your information if I am legally required to do so (for example, in response to a valid court order or government request) or to protect the rights, safety, and security of LoopUsIn, our users, or the public. You remain in full control: you decide what to share inside your family groups, and you can delete your entire account (and all associated data) at any time from your profile settings.
5. Data retention
Active Event/List content is kept until an authorized user deletes it, the owning account is deleted, or another documented lifecycle rule applies. Security and operational records use shorter maximum periods:
- Used or expired invitation-continuation credentials are deleted within 24 hours.
- Recipient email hashes and hints are erased when an invitation becomes terminal; the terminal invitation security record is deleted within 30 days.
- Identifiable Events security-audit records are kept for up to 30 days.
- Reduced pseudonymous Events audit records are kept through day 90 and are then deleted.
- Raw first-party usage telemetry and retention-run counts are kept for no more than 90 days.
- Vercel Web Analytics resets its visitor-session hash after 24 hours; aggregate reporting follows the reporting window and retention practices of the applicable Vercel plan.
When you delete your account, LoopUsIn removes active account data and Events-linked identifiers from its active database and deletes the authentication identity. Limited non-content operational records may remain only for the periods above, for a specific legal obligation, or in isolated provider backups until their confirmed expiry cycle. Backups are not used as normal application data, and deletions must be reapplied after a disaster restoration.
6. Your privacy rights
As an individual user of LoopUsIn, you have strong rights over your personal information. I make it easy for you to exercise these rights.
You can always:
- Access the personal information I hold about you
- Correct or update inaccurate information
- Delete your account and active associated data, subject to the short security and backup periods described above
- Request a copy of your data in a portable format (e.g., JSON)
- Object to or restrict certain processing of your data
How to exercise your rights
Simply email me at info@loopusin.com. I will respond within one month (and usually much faster). For security reasons, I may ask you to verify your identity before fulfilling your request.
GDPR Rights (for users in the European Union or UK)
If you are located in the EU/EEA or the UK, you also have the right to:
- Withdraw your consent at any time (where consent is the legal basis for processing)
- Lodge a complaint with your local data protection authority
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know, delete, and opt-out of the sale of your personal information. (As stated earlier, I never sell your data.)
Family Accounts & Children’s Data
Adults control their own accounts. Group owners and authorized guardians can manage shared resources and information about children or loved ones only within the permissions and legal authority they have. One adult's role does not automatically give them authority to erase another adult's independent account. If you are a parent or legal guardian and believe data about a child was provided without proper authority, contact me so it can be reviewed and removed where appropriate. I will never discriminate against you for exercising these rights.
7. Security of your information
I take the security of your personal and family information very seriously. I implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, misuse, or alteration.
These measures include:
- Encryption of data in transit (using HTTPS/TLS) and at rest
- Secure storage of passwords (hashed and salted — I never store them in plain text)
- Regular security updates and monitoring of the infrastructure
- Strict access controls — only I (as the developer) have access to the production systems, and only when strictly necessary
- Use of industry-standard backend services (Supabase) that are independently audited and certified for security and data protection
While no system is completely impenetrable, I continuously work to keep your data safe. If I ever become aware of a security incident that affects your personal information, I will notify you and the relevant authorities as required by law.
8. Cookies and similar technologies
LoopUsIn uses small files called cookies and similar technologies (such as local storage and session storage) to make the app function properly and to provide the best possible experience.
What we use cookies for:
- Essential / Strictly necessary cookies — These keep you logged in, remember your preferences (such as language or theme), and enable core features like family group sharing, calendar syncing, and secure authentication (including Google and Microsoft OAuth logins).
- Performance and improvement — Cookieless, minimized Vercel Web Analytics page views and limited first-party operational events help me understand aggregate use, fix bugs, and improve the Service. They do not track you across other websites or apps.
I do not activate advertising cookies, cross-site trackers, Google Analytics, PostHog, or Vercel Speed Insights. Vercel Web Analytics is active as described in Section 2 and does not use analytics cookies. LoopUsIn may also record limited first-party usage events in its own Supabase database for security, reliability, and feature improvement; those raw records use the 90-day maximum described above and invitation-link routes are excluded.
You can control or delete cookies at any time through your browser or device settings. Please note that disabling essential cookies may stop some features of LoopUsIn from working correctly.
If you have any questions about the specific cookies used, feel free to contact me at info@loopusin.com.
9. Changes to this privacy policy
I may update this Privacy Policy from time to time to reflect changes in LoopUsIn (for example, new features or integrations), updates to applicable laws, or improvements in how I handle data.
If I make any material changes (changes that meaningfully affect your rights or how your data is used), I will:
- Post the updated Privacy Policy in the app and on this page
- Notify you by email (if you have provided one) or through an in-app message
The new version will be effective on the date I specify at the top of the policy. Your continued use of LoopUsIn after the changes take effect means you accept the updated Privacy Policy. I encourage you to review this page periodically to stay informed.
10. Contact
Questions? Reach us at info@loopusin.com.