Looped Privacy Policy
Last Updated: August 13, 2026
This Privacy Policy explains what information Looped ("Looped", "we", "us") collects and processes, why we do it, and the choices you have. Looped is a platform for creators to build a verified media kit, connect their social accounts to display real metrics and audience insights, share a public link that brands and partners can view, and embed live stats on their own websites and pages. Professional-networking features may be offered over time.
This policy is written to reflect Looped's current product behavior and backend systems — including paid subscription plans, free previews generated from publicly available information, connected social accounts and verified metrics, audience insights, public media kits and share-link analytics, embeddable widgets, secure account recovery, notifications, discovery ranking, and optional contact syncing.
1. Summary
We collect and use information to:
- Create your account and build your media kit and professional profile
- Generate a free preview of your media kit using publicly available information about a social account handle you provide
- Connect your social accounts to display verified metrics (reach, engagement) and audience insights on your kit
- Publish a public, shareable media kit that brands and partners can view without a Looped account
- Provide the Looped Widget, an embeddable element that displays your stats on third-party sites and pages you control
- Process payments and manage your subscription if you purchase a paid plan
- Show you analytics about who views your media kit and where your widget is embedded
- Let you publish portfolio work ("campaign" / content cards) and control its visibility
- Power discovery and recommendations using signals like impressions, dwell time, and saves
- Enable networking features like follows and direct messages
- Deliver notifications (in-app, push, and email where enabled)
- Protect the community via reporting, blocking, and moderation workflows
We do not sell your personal data to data brokers and we do not run third-party targeted advertising based on your activity on Looped.
2. Information We Collect
2.1 Account and Profile Information
When you create or update an account, we collect:
- Email address and (if provided) phone number
- Password (stored as a one-way hash, not plaintext)
- Name and profile details you choose to provide (bio, headline, location)
- Your categories ("niches") selected during onboarding and shown on your profile
- Social usernames/handles you choose to add (e.g., Instagram/TikTok/YouTube) and other profile fields
- A profile handle/username (unique, case-insensitive), used to display and resolve your profile
- Your chosen media-kit template/style and kit layout settings (e.g., which posts appear as Brand Work or Content Spotlight)
2.2 Third-Party Sign-In (Google)
If you sign in or register using Google, we receive information from your Google account, including:
- Your Google account email address
- Your display name
- Your Google profile picture (if available)
- A Google account identifier used to link your Looped account to your Google account
We use this information to create or log you into your Looped account. We do not access your Google contacts, calendar, or any other Google services beyond basic profile information. Your Google sign-in is governed by Google's own privacy policy in addition to this one.
2.3 Subscriptions, Payments, and Billing
Looped offers paid plans (currently Kit Pro and Looped Widget, billed monthly or annually). If you purchase a plan, we and our payment processor collect and process:
- Payment card or payment method details, which are collected and stored by our payment processor, Stripe — Looped never sees or stores your full card number
- Billing name, billing email, and billing address (where required for payment processing or tax purposes)
- Subscription records: your plan, billing cycle, subscription status, renewal dates, and transaction history
- Invoices, receipts, refund records, and tax-related information where legally required
Stripe processes your payment information under its own privacy policy and acts as a payment processor on our behalf. We use subscription status to determine which features are available on your account and to send you billing-related communications (receipts, renewal notices, failed-payment alerts), which are transactional and sent regardless of marketing preferences.
2.4 Free Preview from Publicly Available Information
If you use Looped's free tier, you can generate a preview media kit by providing a single social account handle. To build this preview, we retrieve publicly available information associated with that handle — such as the public profile name, photo, follower count, and public posts and their publicly visible metrics — directly from the public web.
- We only retrieve information that is already publicly visible to anyone on the internet. We do not access private accounts, log in to any platform on your behalf, or collect non-public data through this feature.
- You should only generate previews for social accounts that you own or are authorized to manage.
- We use third-party data-collection infrastructure providers (currently Decodo) to retrieve this public information reliably. These providers act as service providers processing data on our behalf.
- Preview data is not verified through an account connection. To display verified metrics and audience insights, you must connect the account directly (see Section 2.13).
- We may periodically refresh preview data while your preview kit is active, and we remove preview data from active systems when it is no longer needed to provide the preview or when you upgrade and connect the account directly.
2.5 Device and Security Data
To protect your account and detect unauthorized access, we collect:
- IP address at login (used for new-device detection and security logging)
- Device/browser information (user agent string) at login
- A device fingerprint derived from the above (stored as a one-way hash, not raw values) used to identify trusted devices
- Email verification and device verification records (codes, attempt counts, expiration timestamps)
- Password reset security records (request/completion events, token metadata, and expiration timestamps)
This data is used solely for account security purposes, including two-factor device verification when you log in from a new device.
2.6 Device Permissions and Media Access
Looped may request access to device capabilities to support specific features:
- Photo library / camera: Used when you upload a profile photo, cover photo, or portfolio media. We only access photos you explicitly select or capture; we do not scan or index your photo library.
- Contacts: Only accessed if you opt into contact syncing (see Section 2.9). Requires your explicit permission each time.
- Push notifications: Only enabled if you grant permission. Used to deliver notifications you configure in your settings.
2.7 Content You Create and Share
Looped allows you to create a media kit and portfolio items — including Brand Work (paid or gifted collaborations) and Content Spotlight (self-selected posts). We collect:
- The media and text you upload (images/videos, titles, descriptions, metadata), including your profile photo and cover image
- Visibility settings you choose (e.g., public vs draft/private)
- Any settings that hide a portfolio item from appearing on your profile or in discovery (if you enable them)
Images and videos you upload are stored with our cloud storage and content-delivery provider so they can be displayed on your kit.
2.8 Networking Data
We collect information about your connections and interactions, including:
- Follows (who you follow and who follows you)
- Direct messages and conversation metadata (participants, message content, timestamps, read state)
2.9 Contact Sync (Optional)
If you choose to enable contact syncing and grant device permission, Looped will read contact identifiers from your device (such as phone numbers and email addresses) for the purpose of:
- Matching you with people you know who are already on Looped
- Notifying you when someone from your contacts joins Looped (if you enable those notifications)
Privacy-by-design note: Looped is designed to avoid storing your raw address book. We normalize contact identifiers and store cryptographic hashes (HMAC) for matching rather than storing full contact lists in plaintext. We also store sync state (e.g., whether sync is enabled, permission status, and last sync time).
2.10 Discovery, Ranking, and Analytics Signals
To improve discovery and recommendations and to measure product performance, we collect engagement and analytics signals such as:
- Content impressions (when an item is shown)
- Dwell time (e.g., time spent viewing content in the detail modal)
- Saves (when a user saves content)
- Category affinity updates derived from the above signals
- Session identifiers used for deduplication and feed ordering
These signals may be used to rank and diversify your discovery feed and to generate aggregated analytics.
2.11 Notifications and Device Information
If you enable notifications, we collect:
- In-app notification records (type, message, actor metadata, timestamps, read state)
- Push notification subscription data (e.g., Expo push tokens; and, where applicable, web push endpoints/keys)
- Notification preferences (global and per-type settings)
2.12 Safety and Moderation Data
To keep Looped safe, we collect:
- Reports you submit (category, reason, reported entity identifiers)
- Block relationships (who you blocked and the block type)
- Moderation actions and logs (where applicable)
2.13 Connected Social Accounts (Verified Metrics and Audience Insights)
When you connect a social account (Instagram, TikTok, or YouTube) to verify your metrics, you authorize Looped to access certain read-only information from that platform on your behalf. Depending on the platform, this connection is made through our data provider Phyllo or directly through the platform's official API (for example, Meta's Instagram API or TikTok's developer API). The information accessed includes:
- Account details: username/handle, account type, and basic profile information
- Performance metrics: follower/subscriber counts, engagement rate, reach/impressions, and average views
- Content: your posts and their media (images, video, carousels), thumbnails, captions, per-post metrics (views, likes, comments), post URLs, and timestamps
- Audience insights: aggregated, de-identified demographics about your followers, such as age ranges, gender split, and top countries/locations
We use this to display verified metrics and audience insights on your media kit and widget and to let you feature selected posts as portfolio work. This access is read-only — Looped never posts, messages, or takes actions on your connected accounts — and you can disconnect an account at any time. Audience insights are provided to us in aggregate and do not identify your individual followers. Your connection and use of platform data is also governed by each platform's terms and, where applicable, by Phyllo's privacy practices.
Paid plans may allow multiple connected accounts; the same practices in this section apply to each account you connect.
2.14 Your Public Media Kit (Shareable Link)
Looped lets you publish a media kit and share it via a public link (for example, loopedsocial.com/yourhandle). Anyone with the link can view your kit without a Looped account. Your published kit may include your name, handle, photo, location, category, bio, verified metrics, audience insights, selected portfolio/brand work, and a way to contact you.
You choose what to publish, can keep items in draft, and can deactivate or let your share link expire. Information you publish to your kit is, by design, publicly viewable by anyone who has the link.
2.15 The Looped Widget (Embeds on Third-Party Sites)
The Looped Widget lets you embed a live element displaying your stats (and other kit information you choose) on websites and pages you control — for example, a personal site, a Notion page, a Canva site, or a Wix site. When you create and place a widget:
- We generate embed URLs and image URLs tied to your account so the widget can render your information on the third-party page
- We collect technical data needed to serve and measure the widget, such as render/load counts, the referring page or domain where the widget is displayed, embed format parameters, and timestamps
- Visitors to a page containing your widget see the information you have chosen to display; by embedding a widget on a public page, you are making that information publicly viewable there
- We process limited technical data about widget viewers (such as network metadata and non-identifying request data) to serve the widget, measure performance, and prevent abuse — we do not use widget requests to build advertising profiles of viewers
The third-party site hosting your widget has its own privacy practices, which we do not control. You can remove or deactivate a widget at any time, after which it will stop rendering your information.
2.16 Media Kit and Widget Analytics
When someone views your public media kit, we collect limited analytics to show you how your kit is performing, such as the number of views, unique viewers (counted using a randomly generated session identifier), and the date and time of views. We use this to provide dashboard insights (for example, "who's looking"). We similarly measure widget renders so you can see where and how often your widget is being displayed.
Viewers of a public kit or widget are typically brands or prospective partners and may not have Looped accounts. We process only limited technical data about them — such as a session identifier and, for security and anti-abuse purposes, network metadata.
2.17 Product Analytics
We use a product-analytics provider (PostHog) to understand how people use Looped — for example, which onboarding steps are completed and which features are used — so we can improve the product. These are product-usage events tied to a user or session identifier. We do not use them for third-party advertising, and we do not sell this data.
3. How We Use Your Information
We use your information to:
- Provide core app functionality (account, profile, portfolio, messaging, follows)
- Generate free preview kits from publicly available information about handles you provide
- Verify and display your metrics, audience insights, and selected posts from connected accounts
- Create, host, and publicly display your media kit through your share link, subject to your visibility choices
- Serve and render your Looped Widget on third-party pages where you embed it
- Process payments, manage subscriptions, and determine feature access based on your plan
- Provide analytics about who views your media kit and where your widget renders
- Display your public profile and public portfolio items to other users
- Enforce your visibility choices (draft/private items remain private)
- Rank and personalize discovery using engagement signals (impressions, dwell time, saves) and category affinity
- Deliver notifications you opt into (in-app, push, and email/digest where available)
- Send transactional billing communications (receipts, renewal and payment notices)
- Operate secure account recovery and fraud prevention for login/reset flows
- Detect, prevent, and respond to abuse, fraud, and safety issues
- Maintain and improve performance, reliability, and debugging (including product and aggregated analytics)
4. Visibility Controls (Draft vs Public)
- Draft/private content: Items you mark as draft/private are intended to be visible only to you.
- Public content: Items marked public may appear in discovery and on your profile, subject to any additional "hide from profile" style settings you choose (if available).
- Your media kit: You control what your published kit shows and can keep items in draft. While a share link is active, your published kit is viewable by anyone who has the link; you can deactivate or expire the link at any time.
- Your widget: You control what your widget displays and where you embed it. Removing the embed or deactivating the widget stops it from rendering.
We design discovery, profile, kit, and widget surfaces to respect these controls.
5. How We Share Information
We share information only as needed to operate Looped:
- With other users: Your public profile fields and public portfolio items are visible to other users.
- With people you share your kit or widget with: When you publish a media kit and share its link, or embed a widget on a page, anyone who views that link or page can see the information you've chosen to publish.
- Service providers: We use infrastructure and delivery providers that process data on our behalf under contractual obligations. These include cloud hosting and content storage/delivery, payment processing (Stripe), email delivery (e.g., SendGrid), push notification delivery (e.g., Expo), social-account data aggregation (Phyllo), public-data collection infrastructure (Decodo), product analytics (PostHog), and authentication providers (e.g., Google for OAuth sign-in).
- Legal and safety: We may disclose information to comply with law, respond to lawful requests, or protect users and the integrity of the service.
We do not sell your personal data to third-party data brokers.
6. Data Retention
We retain information as long as needed to provide the service and comply with legal obligations.
- If you delete your account, we will remove your content and profile from active systems. Some information may persist in backups or logs for a limited period, and some records may be retained where legally required or necessary for safety and abuse prevention.
- Billing and transaction records are retained as required for accounting, tax, and legal compliance, even after account deletion.
- If you disconnect a social account, we stop syncing new data from it and remove associated connected-account records from active systems.
- Free preview data is retained while your preview kit is active and removed from active systems when no longer needed or when you connect the account directly.
- Media-kit view and widget-render analytics are retained to provide your insights and may be aggregated over time.
7. Your Choices and Rights
Depending on your location, you may have rights such as access, deletion, correction, and portability. Regardless of where you live, Looped aims to provide:
- Access to your account/profile data
- The ability to update profile fields and visibility settings
- Account deletion
- Control over notification preferences
- The ability to enable/disable contact sync (if offered) and disconnect it
- The ability to connect and disconnect social accounts
- The ability to choose your media-kit template and to deactivate or expire your public share link
- The ability to remove or deactivate widgets you have embedded
- The ability to manage, cancel, or change your subscription at any time through your account settings — cancellation is available in-product without contacting support
8. Security
We use industry-standard safeguards designed to protect your information, including:
- Encrypted transport (HTTPS) for all data in transit
- One-way password hashing (passwords are never stored in plaintext)
- Payment details handled exclusively by our PCI-compliant payment processor (Stripe) — Looped never stores full card numbers
- Email verification for new accounts
- Two-factor device verification when a login is detected from a new or unrecognized device
- Device fingerprints stored as one-way hashes (not raw IP addresses or user agents)
- Read-only connections to social platforms — Looped never posts, messages, or takes actions on your connected accounts
No system is perfectly secure; please use a strong password and keep your device secure.
9. Age Requirement
Looped is intended only for people who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with personal information, please contact us at [email protected] and we will take steps to delete it. If we become aware that we have collected personal information from someone under 18, we will delete that information promptly.
10. International Users
If you access Looped from outside the United States, your information may be processed in the United States or other locations where Looped or its service providers operate.
If you are located in the European Economic Area, the United Kingdom, or another region with data-protection laws, additional rights and protections may apply. See "Your Choices and Rights," and contact us to exercise them.
11. Changes to This Policy
We may update this policy from time to time. We will update the "Last Updated" date above. If changes are material, we will provide additional notice in the app or by email where appropriate.
12. Contact Us
Questions about privacy: [email protected].