looly

Privacy Policy

Last updated: 14 September 2026

The short version: Looly is a paid, private home for your family's photos. Your originals are stored in EU object storage. Content is never scanned for advertising or AI training, is never sold, and is only visible to the people you invite. We run privacy-respecting analytics without advertising trackers, and nothing advertising-related ever happens without your explicit consent. The full details follow.

1. Who is responsible

The controller for Looly’s processing described here is Tillmann Bedau (Looly), Ebertplatz 10, 50668 Köln, Germany — email: support@looly.app (see the imprint). For any privacy question or request, contact the address above.

2. Hosting, storage and delivery

Our original media files use Cloudflare R2 with EU jurisdiction; our Neon database is configured in Frankfurt, Germany. Cloudflare Workers, Images, WebSockets (Durable Objects), background Workflows and Stream provide request processing, previews, imports and video playback. Stream playback copies and global delivery caches are not covered by R2’s EU storage restriction. Processing and provider access can occur outside the EU. This is not an end-to-end encrypted service: our systems and service providers process content to operate it. Access is restricted to authorised purposes; circle members receive access according to their permissions.

3. Your account and signing in

You sign in with a one-time email code (OTP) or a passkey — there is no password. For this we process: your email address, one-time codes (valid for 10 minutes), passkey public keys if you register one (Looly never receives the private key; your passkey provider may sync it between your devices), and session records including IP address and browser identifier, which you can see and revoke under Settings → Security → Active sessions. Sessions expire after 7 days. The sign-in flow is protected by Cloudflare Turnstile (an invisible bot check that processes your IP address and browser signals). Legal bases: performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in securing the service (Art. 6(1)(f) GDPR).

4. Your photos, videos and family content

The heart of the service: photos, videos (including Live Photos), captions, comments, likes, albums, person tags, and the profiles of the children a circle is about. We process this content solely to provide the service to you and the members of your circles — storage, transcoding, thumbnails, delivery, search within your circles, and export. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); for the data of family members and children who are not themselves users, our legitimate interest and that of the participating family in private, invitation-only family sharing (Art. 6(1)(f) GDPR), with the safeguards described in section 5.

Photo metadata (EXIF), location and camera info

  • The original file is preserved verbatim. Whatever your camera wrote into it — including GPS coordinates — stays inside the original, is available to you when you download originals, and is included in circle exports.
  • Two upload preferences (Settings → Media) control what Looly additionally extracts, stores and shows: capture location and camera model. Turning them off stops extraction and display; it does not edit the original file's bytes.
  • When location is on, we derive a coarse place label ("City, Country") from the coordinates on our own servers using a built-in offline dataset — no external geocoding service is contacted. Display copies shown in the app are re-encoded and carry no EXIF.

Circle admins choose a per-circle download policy (originals / web quality / no downloads). Deleted photos sit in a trash for 30 days (restorable), then are permanently purged; "Delete now" purges immediately.

5. Children's data

Looly exists so parents can share their child's early years privately. Children are not users — accounts belong to adults. A circle stores the child's name, date of birth (which may be in the future, for expecting parents), an optional bio and avatar, and the photos and tags members add. Because children's data deserves particular protection (Recital 38 GDPR), the product is built conservatively: circles are invitation-only and private by default, there are no public links, no advertising inside the app, no content scanning, no facial recognition, and child data is never shared with analytics or advertising providers. Parents stay in control: admins can remove content and members at any time, and deleting a photo, circle or account is honoured as described in section 14.

6. Circles, invites and who sees what

  • Content is visible only to members of the circle it is shared into, according to their role (admin, contributor, follower).
  • Invites are personal: we store the invited email address and a hashed, single-use invite token valid for 7 days. Accepting an invite is protected by Turnstile.
  • Circle admins can see the email addresses of that circle's members on the member list; members see each other's names, avatars and relation labels.
  • A per-circle "last seen" indicator can be switched off by the admin; it is then suppressed on the server, not just hidden.

7. Payments — Stripe as merchant of record

Web subscriptions are sold through Stripe. Stripe acts as merchant of record: your purchase, payment data, invoice and VAT are handled by Stripe as the seller of the transaction, and Stripe is its own controller for the payment relationship (see Stripe's privacy policy). We never see your card details. What we exchange with Stripe: your Looly account ID to attach the purchase, the chosen plan, a consent flag and — if you arrived via a campaign — coarse attribution values (see section 10). Stripe tells us the subscription status and, for receipts, the email you used at checkout. Legal bases: contract performance (Art. 6(1)(b) GDPR) and legal obligations around commercial records (Art. 6(1)(c) GDPR).

App Store purchases and TestFlight

In-app purchases use Apple StoreKit. Apple processes payment and storefront information under its own terms and privacy policy. We receive signed transaction and renewal information, product and transaction identifiers, purchase/expiry status and an app account token linked to your Looly account to verify entitlements and restore purchases. We do not receive your payment-card details from Apple. TestFlight is Apple’s beta distribution service; Apple processes beta installation, crash and feedback information under its TestFlight terms. Purchases in TestFlight use Apple’s sandbox. Legal basis for Looly’s purchase verification: contract performance (Art. 6(1)(b) GDPR).

8. Emails we send

We send email through Cloudflare's email service, from no-reply@looly.app. Two kinds:

  • Transactional (cannot be disabled while you have an account): sign-in codes, invites, export-ready notices, and billing notices such as the trial reminder we send four days before your trial ends.
  • Activity (fully configurable): new-photo notifications, comments, new members, and digests (hourly, daily or weekly). Every activity email carries a working one-click unsubscribe; granular settings live in Settings → Notifications.

Legal bases: contract performance (Art. 6(1)(b)); for activity emails also your settings choices.

9. Push notifications (iOS)

If you enable push on iOS, we store your device token and deliver notifications through Apple's push service (APNs). Notification payloads contain the notification text — for example the child's name as the grouping title, the acting member's name, and a comment excerpt. Apple processes these to deliver the notification. You control categories in the app's notification settings, or disable push entirely in iOS Settings. Legal basis: contract performance of the notification feature you enabled (Art. 6(1)(b) GDPR). The iOS app contains no advertising or tracking SDKs.

10. Product analytics — first-party, no ad trackers

On public pages (optional)

Only after your analytics consent, PostHog Cloud EU counts public page views and explicit actions. We disable browser persistence, session recording, autocapture, person profiles and IP geolocation. The endpoint receives your IP address as part of the network request. Query strings, private URLs and form content are excluded from these events. You can decline analytics separately from advertising, change your choice through Privacy choices, or use your browser’s Do Not Track setting. Legal bases: consent (Art. 6(1)(a) GDPR and, where applicable, § 25(1) TDDDG).

In the product (server-side, with opt-out)

Our servers record a small set of funnel events keyed to your account ID — for example "signed up", "added a child", "viewed the paywall", "checkout started", "subscription activated". These carry no photos, no message content, and no child names; location is limited to a country code derived at the network edge, never from stored IPs. You can turn this off at any time under Settings → Privacy → "Help improve Looly"; when off, our servers stop sending these events for your account. Legal basis: legitimate interest in improving the product (Art. 6(1)(f) GDPR), honoured opt-out.

Campaign attribution and signup measurement

With analytics consent we keep campaign parameters in sessionStorage for the browser tab and associate them with your account after sign-in. Advertising click IDs require advertising consent as well. A random pre-signup identifier is stored only with analytics consent and removed after verification. A promotion code you ask us to apply can be remembered for that checkout independently of analytics. Account-linked events are pseudonymous personal data, not anonymous data. Server-side product usage includes onboarding, search opening and Rewind interactions on web/iOS, never search text or children's names. Account attribution is deleted with your account; contact us to request deletion of associated provider analytics. Consent withdrawal stops future optional collection.

11. Advertising measurement — only ever with consent

On our public marketing pages (never inside the app) we may ask, via the consent banner, whether we can measure advertising: Google tags (Consent Mode v2, enhanced conversions) and the Meta pixel with a matching server-side conversion event. If you accept, these tools may set advertising cookies and receive click identifiers plus a SHA-256-hashed (pseudonymised, still personal-data) version of your email for conversion matching; Google and Meta may process this data outside the EU under their own safeguards. If you decline — or simply never choose — none of this loads and nothing is shared: no ad script, no ad cookie, no server-side ad event. Declining is exactly as easy as accepting, and you can change your decision at any time via in the footer. Legal bases: your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Where an advertising integration is not switched on in production, nothing loads even if you accept.

12. Security, abuse protection and logs

  • Turnstile (Cloudflare) protects sign-in and invite acceptance; it processes your IP address and browser signals to tell humans from bots.
  • Rate limiting uses your IP address transiently (short-lived counters) to stop abuse of sign-in and signup endpoints.
  • We minimise data in application logs: our structured logging excludes query strings, tokens, email addresses or message content, and error logs carry error names only. Operational logs live in Cloudflare's short-term Workers logging.

Legal basis: legitimate interest in a secure, abuse-free service (Art. 6(1)(f) GDPR).

13. Cookies and storage on your device

Authentication, security, preferences and requested app features use necessary storage (§ 25(2) TDDDG). Optional analytics and advertising storage require the choices described above; first-party storage is not automatically exempt from consent. The following list describes the main storage purposes. Native iOS also uses Keychain for credentials, UserDefaults for preferences, GRDB/SQLite for offline metadata and disk caches for photos and pending uploads. Widgets and the share extension exchange app data through the app group. Data you deliberately download or export remains on your device until you remove it.

NameKind / lifetimePurpose
better-auth.session_tokenCookie (HttpOnly), 7 daysKeeps you signed in.
looly_media_tokenCookie (HttpOnly), 1 hour, auto-renewedSigned proof that you may load the photos of your circles.
better-auth-passkeyCookie, minutesShort-lived passkey sign-in challenge.
looly_consentCookie, 12 monthsRemembers your consent decision. Contains no identifier.
looly.bearer, looly.auth-epochlocalStorageSession token for the app and cross-tab sign-out.
looly.qcachelocalStorage, max 24 hCached app data (your profile, photo metadata) so the app opens instantly. Cleared on sign-out.
looly.theme, looly.locale, looly.circle, looly.viewlocalStorageYour display preferences (theme, language, last circle, feed view).
looly.search.recentslocalStorageRecent-search history on this device; submitted searches are processed by our API.
looly.anon_idlocalStorage, until sign-upOptional analytics ID, only with consent; deleted after verification.
looly.onboarding_checkout, looly.passkeyPromptDismissed, looly.introSeenlocalStorageOne-shot UI flags (checkout round-trip, dismissed prompts).
looly.attribution, looly.quiz, looly.capisessionStorage (dies with the tab)Campaign parameters from your landing URL; quiz answers used once to pre-fill onboarding (submitted onboarding details are sent to Looly); consent-gated ad-event carry.

14. How long we keep data

DataRetention
Sign-in codes (OTP)Valid 10 minutes; replaced/expired thereafter.
Sessions7 days, or until you revoke them.
Photos & videosUntil you delete them. Trash keeps deleted items 30 days, then purges permanently (including video copies at our processors).
Circle exports (takeout ZIPs)Download links 7 days, then the archives are deleted.
Lapsed subscriptionsIf your subscription ends, nothing is deleted: your circles become read-only for a ~90-day grace period, then inaccessible until you resubscribe. Export remains available throughout.
Account deletionDeleting your account cancels Stripe subscriptions; Apple subscriptions must be cancelled through Apple. Account deletion then removes your profile, sessions, passkeys, devices, uploaded assets, circles you created, comments, tags, likes, invites and attribution records. Content other members uploaded to a deleted circle stays in their own libraries. Storage cleanup of raw files is completed asynchronously.
Payment recordsHeld by Stripe as merchant of record under statutory commercial and tax retention periods.
Waitlist entriesUntil launch notification or until you ask us to remove you.
Operational logsShort-lived, PII-free (see section 12).

15. Processors and recipients

ProviderWhat forLocation / safeguards
AppleStoreKit purchases, APNs notifications, TestFlight beta distributionApple privacy policy: apple.com/legal/privacy; international processing
MIXI / FamilyAlbumImport source contacted only on your requestIndependent provider; source service may process data outside the EU
Cloudflare, Inc.Hosting, content delivery, EU object storage (photos/videos), image & video processing, bot protection (Turnstile), email deliveryOriginal files stored under EU jurisdiction; Stream processing and playback have no R2 EU-only restriction; Cloudflare, Inc. (USA) is certified under the EU–US Data Privacy Framework; DPA with SCCs.
Neon (Databricks, Inc.)DatabaseHosted in Frankfurt, Germany (AWS eu-central-1); Neon, LLC is covered by Databricks’ EU–US Data Privacy Framework certification; DPA with SCCs.
StripePayments — merchant of record and independent controller for the purchaseStripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (USA), Data Privacy Framework.
PostHog (PostHog, Inc.)Product analyticsEU cloud, hosted in Frankfurt; DPA with SCCs.
Google / MetaAdvertising measurement — only with your explicit consent (section 11)Own responsibility; may process outside the EU under their safeguards.

Authorised circle members receive shared content. We may also disclose necessary information to authorities where legally required and to advisers for legal claims. We do not sell personal data, and there is no advertising inside the product.

16. International transfers

EU storage of originals does not exclude international transfers (section 2). Where a provider's US parent company is involved, transfers rest on the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses, as listed above. Advertising providers under section 11 process data under their own transfer safeguards — and only after your consent.

17. Your rights

You have the rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interest (Art. 21). Consent can be withdrawn at any time with effect for the future (Art. 7(3)). Contact: support@looly.app. You can also complain to a supervisory authority — for us that is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, or any EU supervisory authority of your habitual residence.

Practical self-service versions of these rights are built in: per-photo and per-circle deletion, trash restore, circle export (originals + metadata), notification and analytics opt-outs, media upload preferences, session revocation, and full account deletion in Settings.

FamilyAlbum imports, support and contract declarations

If you request an import, we contact FamilyAlbum (MIXI) with the album link and password you provide, then retrieve the selected album’s media, captions, comments, dates and member names. The link/password are encrypted in our database while the job runs and cleared when it completes, fails, is cancelled or expires. An unconfirmed preview expires after 24 hours. Job progress and imported member mappings support duplicate avoidance and review; imported content then follows normal media retention. Import does not delete the source album. This processing fulfils your request (Art. 6(1)(b) GDPR); other depicted people’s rights still apply.

Support requests, cancellation and withdrawal declarations contain your contact details, contract reference, message and receipt time. We retain what is required to handle the request, document statutory obligations and defend claims, including where records must remain after account deletion (Art. 6(1)(b), (c) and (f) GDPR). Necessary account data is required to provide the service; optional photos, profile fields and measurement choices are voluntary. We do not use automated decision-making with legal or similarly significant effects under Art. 22 GDPR. You may request information about transfer safeguards and copies of applicable safeguards from our contact address.

18. Changes to this policy

We update this policy when the product's data flows change and adjust the date at the top. Material changes are announced in the product or by email.