Published
Privacy policy
Scope and operator
This policy covers the HereLoop App, hereloop.com, regional accounts, membership, and encrypted identity backup. The controller is the HereLoop Service Operator. An account is required to use the App; the public website marketplace is read-only without sign-in.
Information we process
Registration and sign-in process encrypted email or Apple login identifiers, account and consent records, region, device sessions, and security logs. Membership processes store order identifiers and entitlement state. Optional backup stores device-encrypted ciphertext plus limited size, version, and timestamp metadata. Operational analytics cover registration, sign-in, product interaction, coarse country or region, and failures. HereLoop account servers do not upload chat messages, contacts, communication private keys, or precise location.
Purposes and legal bases
We process data to create and secure accounts, maintain sessions, provide backup and membership, fulfill export and deletion requests, prevent abuse, diagnose failures, and produce minimized operational statistics. Legal bases include performing requested services, consent, legitimate interests in service and user security, and legal obligations. Optional consent may be withdrawn without affecting earlier processing.
Campus affiliation and badge
HereLoop stores the school affiliation and masked school-email representation permanently in the selected account region until account deletion. The campus badge shows only that the account controlled a configured school email at the time of verification; it does not continuously prove ongoing enrollment, age, or legal identity.
Device, Mesh, and location
Bluetooth Mesh discovers and relays data directly among devices, so copies may reach participating devices. Location-channel or campus-area features use location or coarse area only after permission. Friendly place names may use Apple's geocoding service. Third-party internet relays may observe connection metadata; enabling Tor reduces the risk of a relay directly seeing your IP address.
Retention
Account records remain while the account is active; sessions end after logout, revocation, or expiry. Raw regional operational events are retained up to 30 days, terminal export or deletion receipts generally 30 days, administrator security audits generally 365 days, and de-identified aggregates up to 25 months. Deletion has a seven-day cancellation window, after which regional account and cloud-backup data are removed except minimal records needed for law, security, fraud prevention, or disputes.
Sharing and third parties
We disclose only necessary data to hosting, database, object-storage, email, Apple sign-in, App Store subscription-verification, and security-monitoring providers. Mesh nodes, chosen recipients, and third-party relays independently receive data you choose to send. We do not sell personal information, use it for targeted advertising, or include third-party advertising analytics SDKs.
Regional storage and transfers
China and global account data use separate databases, caches, object stores, and keys, with no cross-region account failover. Account records stay in the selected account region. Data you intentionally send through Mesh, internet relays, or external recipients may reach another region depending on your communication choice and network path.
Your rights
The account center supports access, export, correction, deletion, withdrawal of optional consent, and device-session management. We may verify identity to protect the account. You may object or complain through the contact address or your local regulator, and you will not be discriminated against for exercising applicable privacy rights.
Children
HereLoop does not collect dates of birth or age declarations, set a minimum age, or claim to verify age or guardian consent. Minors should use the service with guardian guidance and follow local rules for transactions, restricted goods, and contractual capacity.
Security and backup
We use regional isolation, encryption, access control, least privilege, and auditing. Identity backup is encrypted on-device with a recovery password; HereLoop cannot read it or reset a forgotten password. No system can guarantee absolute security, and we will provide legally required incident notices.
Policy changes
We publish each new version and effective date here. Material changes receive reasonable advance notice through the site, App, or account contact. If renewed consent is required, we will request it before the related processing continues.
Contact us
For privacy, data-rights, security, or policy questions, email support@hereloop.com. Do not send recovery passwords, communication private keys, or complete identity documents in ordinary email.
Operator contact
HereLoop Service Operator · support@hereloop.com