Last updated: 2026-04-15 · Version 1.0
Privacy Policy
Last updated: 2026-04-15
Version: 1.0
1. Introduction
This Privacy Policy explains how LetsLoop Ltd ("LetsLoop", "we", "us", "our") collects, uses, shares, and protects your personal data when you use our flatmate-matching mobile and web application (the "Service"). We are committed to protecting your privacy and handling your personal data transparently and in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using LetsLoop, you acknowledge the practices described in this Policy. If you disagree with any part of it, please do not use the Service.
2. Data Controller
The data controller for personal data processed through LetsLoop is:
LetsLoop Ltd Company number: [TBC] Registered office: [TBC] ICO registration number: [TBC]
Contact (all privacy matters): privacy@letsloop.app
3. What Data We Collect
We collect personal data in four broad categories.
3.1 Signup data
- Email address
- First name (and optionally surname)
- Date of birth (used to verify you are 18 or over; see Section 9)
- Password (stored hashed; we never see your plaintext password)
3.2 Profile data
- Profile photos and any additional images you upload
- Bio / short description you write about yourself
- Flat-sharing preferences (budget range, move-in date, desired area, household size, etc.)
- Quiz answers covering lifestyle preferences (e.g. tidiness, social style, sleep schedule)
- Approximate location at city or neighbourhood level (we do not collect or store precise GPS coordinates)
3.3 Usage data
- Profiles you view, like, pass on, match with, or block
- Messages you send and receive within the Service
- Reports you submit about other users and any moderation actions taken
- Support requests and correspondence with us
3.4 Technical data
- Device identifiers, operating system, app version, browser type
- IP address (used for approximate location and fraud prevention; truncated where practical)
- Log data (timestamps, crash reports, error traces)
- Analytics events (screens viewed, features used, session duration)
- Payment information — collected only when the paid tier launches. Card details will be handled by our payment processor; we will not store full card numbers on our own systems.
4. Why We Use Your Data (Legal Bases)
Under UK GDPR we must have a lawful basis for each purpose. Ours are:
| Purpose | Legal basis |
|---|---|
| Creating and maintaining your account | Contract (Art. 6(1)(b)) |
| Matching you with compatible flatmates | Contract |
| Sending service messages (match notifications, security alerts) | Contract / Legitimate interests |
| Detecting fraud, abuse, and policy violations | Legitimate interests |
| Content moderation (including AI-assisted review of text and images) | Legitimate interests / Legal obligation |
| Analytics and product improvement | Consent (where cookies / trackers are involved) / Legitimate interests (for aggregated analytics) |
| Marketing communications | Consent |
| Responding to legal requests | Legal obligation |
| Age verification | Legal obligation / Legitimate interests |
You can withdraw consent at any time by updating cookie preferences or emailing privacy@letsloop.app. Withdrawal does not affect processing carried out before withdrawal.
5. Who We Share Data With
We do not sell your personal data. We share data only with the following categories of recipients:
5.1 Other users
Your profile (photo, bio, first name, age, approximate area, quiz-derived compatibility indicators) is visible to other LetsLoop users. Messages are visible to the recipient. You control what you publish on your profile.
5.2 Service providers (sub-processors)
We use the following third parties to operate the Service. Each is bound by a data-processing agreement and processes data only on our instructions.
- Vercel Inc. (US) — application hosting and edge delivery
- Firebase / Google LLC (US/EU) — push notifications and mobile analytics
- Google Analytics 4 (Google LLC) (US/EU) — usage analytics (consent-gated)
- PostHog (PostHog Inc., EU Cloud / Frankfurt) (EU) — product analytics, session replay, feature flags. Controller: LetsLoop Ltd. Lawful basis: consent.
- Meta Platforms, Inc. (US/EU) — Meta Pixel for web analytics and future retargeting (consent-gated)
- OpenAI, L.L.C. (US) — AI-assisted content moderation and in-app AI features
- fal.ai / Fal AI, Inc. (US) — image generation and moderation inference
- Deepgram, Inc. (US) — speech-to-text processing for voice features
- Amazon Web Services EMEA SARL or Cloudflare, Inc. — object storage for photos and media
- Payment processor — [TBC]
An up-to-date list is available at letsloop.app/subprocessors.
5.3 Professional advisers
Lawyers, accountants, auditors, and insurers where necessary and under duties of confidence.
5.4 Authorities and legal
Law enforcement, regulators, or courts where we are legally required to disclose, or to defend our legal rights, or to protect the vital interests of users or others.
5.5 Business transfers
If we are involved in a merger, acquisition, or asset sale, your personal data may be transferred; we will notify you and, where applicable, seek consent.
6. International Transfers
Some of our sub-processors are based outside the United Kingdom, primarily in the United States. Where we transfer personal data outside the UK, we rely on safeguards approved under UK GDPR, including:
- the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses (SCCs);
- adequacy regulations where applicable (e.g. UK-US Data Bridge for certified US recipients);
- supplementary measures such as encryption in transit and at rest.
You may request a copy of the relevant transfer safeguards by emailing privacy@letsloop.app.
7. Retention
- Active accounts: we retain your personal data for as long as your account is active.
- Deleted accounts: when you delete your account (or we delete it on your request), we purge your personal data from our production systems within 30 days. Backups are overwritten on a rolling cycle not exceeding 90 days.
- Messages: after account deletion, your messages are removed from your view. Copies visible to your conversation partner are retained in their view unless they also delete.
- Moderation and safety records: limited data about bans, serious policy violations, and reports may be retained for up to 2 years to protect other users and prevent re-registration of banned accounts.
- Anonymised analytics: fully anonymised and aggregated statistics may be retained indefinitely for product and research purposes.
- Legal records: where we are required to retain records for tax, accounting, or legal-defence reasons, we retain them for the period required by law.
8. Your Rights
Under UK GDPR you have the following rights:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — ask us to delete your data, subject to certain exceptions.
- Restriction — ask us to limit how we use your data.
- Portability — receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller.
- Objection — object to processing based on legitimate interests or direct marketing.
- Withdraw consent — where we rely on consent, withdraw it at any time.
- Lodge a complaint — with the UK Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113. We would appreciate the chance to address your concerns first.
To exercise any right, email privacy@letsloop.app. We will respond within one calendar month. We may ask for proof of identity before acting on a request.
9. Children's Data
LetsLoop is strictly for users aged 18 or over. We do not knowingly collect personal data from anyone under 18. We apply an age gate at signup using your date of birth. If we learn that a user is under 18, we will suspend the account and delete the associated personal data as soon as reasonably practicable. If you believe a minor is using LetsLoop, please contact privacy@letsloop.app.
10. Security
We apply technical and organisational measures appropriate to the risks of processing, including encryption in transit (TLS), encryption at rest for stored media, access controls, logging, and vendor risk management. No system is perfectly secure; you are responsible for keeping your password confidential.
11. Changes to This Policy
We may update this Policy from time to time. When we make material changes we will notify you in-app or by email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
Questions, requests, and complaints: privacy@letsloop.app
LetsLoop Ltd [Registered office address — TBC]