1Who we are
Loup Learn ("Loup", "we", "us") is operated by:
Melis SakicBašigovci bb
75270 Živinice
Bosnia and Herzegovina
Email: supportloup@gmail.com
We are the data controller for the personal data described in this policy, except where this policy says a third party acts as an independent controller (Section 7).
Loup is run by one person. We have not appointed a Data Protection Officer because we are not required to. Privacy questions go to the email above.
2Scope
This policy covers the Loup Learn mobile application for Android and iOS (the "App") and the Loup Learn website at loup-mobile.netlify.app (the "Site").
It does not cover third-party websites, apps or stores you reach from Loup, such as Amazon, the apps in your device's share sheet, Google Play or the Apple App Store. Their own policies apply there.
3What Loup does
Loup shows a vertical feed of short cards. Each card contains a hook, a lesson written in our own words, and a credit naming the book and chapter it was drawn from. You choose one or more topics when you first open the App. Liking a card keeps you inside that book so its lessons appear in order, and each card shows how many people have liked it. The App counts how long you read each day against a daily goal you can change in Settings, and can send you one daily reminder if you ask for it. Between cards, Loup shows a clearly labelled "Sponsored" native ad. Each card also has a "Get the book" link.
4Data we collect and why
4.1 Data you give us
| Data | When | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Topics you select | Onboarding, and later in Settings | Build your feed | Performance of a contract, Art. 6(1)(b) |
| Reactions: like, unlike, "not interested in this book", "report this card" | When you tap them | Personalise the feed; hide books you do not want; count how many people like a card; review reported content | Contract, Art. 6(1)(b). For reports also our legitimate interest in content quality and legal compliance, Art. 6(1)(f) |
| Your daily reading goal, in minutes | Set to a default when you start; changed in Settings | Show your progress; decide whether a reminder is worth sending | Contract, Art. 6(1)(b) |
| The text of a message you send us | When you email us | Answer you | Legitimate interest in handling enquiries, Art. 6(1)(f) |
| A notification token for your device, and your device's time zone | When you turn on the daily reminder | Send you the reminder at a sensible local hour | Consent, Art. 6(1)(a) |
Reports contain no free text. A report records only which card, which book and when.
The daily reminder is off until you turn it on. When you do, your device asks whether Loup may send you notifications, and Firebase Cloud Messaging issues a registration token: an identifier for this installation of the App on this device. The App sends the token together with your device's time zone, as a name such as "Europe/Paris", and we store both on your own row in our database, beside your anonymous identifier. They are used for one thing, sending the reminder at a reasonable local time. They are never combined with data from other companies, never used for advertising, and never leave our infrastructure and the providers in Section 7. Turning the reminder off in the App erases the token and takes you off the sending list immediately; we keep no separate "reminders on" flag, so the token is the whole of the preference. The time zone stays on your profile until the account is deleted. This is not part of the consent dialog in Section 5. You asked for the reminder yourself, so refusing analytics or personalised ads does not stop it arriving.
To pick the hour and the words, the reminder also uses data about you. Once a night we work out the hour of the day you usually read, from your card events of the last 14 days, and store it as a single number on your profile. The reminder text may name the next lesson in the book you most recently liked and say how many minutes are left to your daily goal. We keep a log of each reminder we sent, with the day, the time, a delivery identifier and any error, for 30 days, so that we never send the same reminder twice and so that after seven ignored reminders in a row we stop, until you read again. Section 4.2 lists these items and Section 10 explains the profiling involved.
4.2 Data created by using the App
| Data | Details | Purpose | Legal basis |
|---|---|---|---|
| Anonymous user identifier | A random identifier issued by our authentication provider on first launch. It is not derived from your device, name or email. | Keep your topics and progress across sessions | Contract, Art. 6(1)(b) |
| Account timestamps | When the identifier was created and when the App was last used | Maintain the account; remove inactive accounts | Contract; legitimate interest in housekeeping |
| Card events | For each card: event type (view, like, unlike, share, hide, report), the card, book and topic identifiers, the time, and for views the dwell time in milliseconds | Serve the next cards; keep your place in a book; measure whether the App works | Contract, Art. 6(1)(b) |
| Reading time | The number of seconds you read on each calendar day, by your device's local date | Show your progress against your daily goal; decide whether a reminder is worth sending | Contract, Art. 6(1)(b) |
| Derived scores | A numeric affinity score per topic and per book; per book, your position and whether you liked, dropped or finished it; per card, "times shown", "last shown" and how fully you read it, all computed from your card events | Rank and de-duplicate your feed | Contract, Art. 6(1)(b) |
| Reminder scheduling data | Only if you turned the reminder on: the hour you usually read, derived nightly from 14 days of card events; a "paused" mark set after seven ignored reminders; and a 30-day log of reminders sent (day, slot, time, delivery identifier, error) | Send the reminder at the right hour, never twice, and stop when you ignore it | Consent, Art. 6(1)(a), as part of the reminder |
| Like counts | The number of likes each card holds, shown to every user as a bare number. It does not reveal who liked the card. | Show which lessons people found worth keeping | Legitimate interest in presenting the feed, Art. 6(1)(f) |
The scoring above, and the usual reading hour, are profiling in the GDPR sense: they use your behaviour to predict which cards you will find interesting and when you are likely to read. They produce no legal effect and no similarly significant effect on you. They only decide the order of free lessons in a feed and the time of an optional notification. See Section 10.
4.3 Technical data collected automatically
| Data | Collected by | Purpose | Legal basis |
|---|---|---|---|
| IP address, request headers and timestamps in server logs | Our backend and authentication provider (Supabase) | Security, abuse prevention, debugging outages | Legitimate interest, Art. 6(1)(f) |
| Crash reports: stack trace, device model, OS version, app version, free memory, whether the app was in the foreground, a Crashlytics installation identifier | Firebase Crashlytics | Find and fix crashes | Consent, Art. 6(1)(a), in the EEA, UK and Switzerland; legitimate interest elsewhere |
| Usage analytics: app instance identifier, device model, OS version, app version, language, approximate country and region (derived from IP, which is not stored), session start and length, first open, and the events listed in the Appendix | Firebase Analytics (Google Analytics for Firebase) | Understand how the App is used in aggregate: retention, cards read per session, share rate | Consent, Art. 6(1)(a), in the EEA, UK and Switzerland; legitimate interest elsewhere |
| Advertising data: advertising identifier (Google Advertising ID or Apple IDFA, only if you allow it), IP address, device and app information, your consent choices (IAB TCF string), ad interactions | Google AdMob and the Google User Messaging Platform | Show ads and, if you allowed it, personalise them; measure ad performance; detect fraud | Consent, Art. 6(1)(a), for personalised ads and for any ads in the EEA, UK and Switzerland; legitimate interest in funding a free App for non-personalised ads elsewhere |
We do not collect your name, email address, phone number, contacts, photos, precise location, health data or any other special-category data. We do not access your microphone, camera or files. The only permissions the App asks you for are Internet access and, if you turn on the daily reminder, permission to show notifications (Section 4.1). The advertising SDK additionally declares access to the Android advertising ID, covered by the advertising row above. The App reads the device's motion sensor solely to detect a shake, which opens Google's ad inspection tool; the readings never leave the device and are not stored.
4.4 Data stored only on your device
The App keeps a local database on your device so it works offline and starts fast. It contains cached topics, books and cards, your profile (identifier, topic choices and daily goal), your position in books you are reading, the cards you liked, your reading time per day, per-card counters of how often a card was shown to you, whether you asked for the daily reminder and how often we have asked you about it, and a queue of card events waiting to be sent. The App also stores your consent choices, as written by the Google User Messaging Platform, and a cache of book cover images. This data stays on the device until you clear the App's storage or uninstall the App. We cannot see or retrieve it. A reinstall starts with a new anonymous identifier; the old one is not reused.
4.5 Sharing a card
When you tap Share, the App renders the card into an image containing the book's title and author, the card's hook and lesson or a quoted passage, the chapter it came from and the Loup name, then hands it to your device's share sheet. The image contains nothing about you: no identifier, date or reading statistics. We record that you shared the card. We do not learn which app you shared to, who received it, or anything else about the recipient. The app you share to is governed by its own privacy policy.
4.6 "Get the book" links
"Get the book" opens the book's page at an online bookshop, such as Amazon, in your browser. Today these are ordinary links: we are not enrolled in any affiliate programme and earn nothing when you buy. When you tap the link we record nothing. From that point the bookshop collects data under its own policy, including the fact that you arrived from Loup. If we ever join an affiliate programme we will say so here first, with the disclosure the programme requires.
4.7 The Site
The Site is a static page. It sets no cookies and runs no analytics scripts. It loads the Poppins font from Google Fonts, so your browser sends your IP address and browser details to Google when the page loads. The Site is hosted by Netlify, Inc., which keeps standard access logs (IP address, user agent, pages requested) for security for up to 30 days.
5Consent, ads and analytics
5.1 In the EEA, the UK and Switzerland
Analytics, crash reporting and the advertising SDK are configured to stay off when the App starts. On first launch the App shows Google's consent dialog (the User Messaging Platform). Depending on your answers:
- You accept. The advertising SDK initialises, personalised or non-personalised ads are requested according to your choices, and analytics and crash reporting are turned on. Your choices are passed to Google Analytics as Consent Mode signals so that Google respects them too.
- You decline. Analytics and crash reporting stay off. Ads that require consent are not requested. Google may still serve "limited ads", which use no advertising identifier and no personalisation; where none is available, the ad slot in your feed shows a static note instead.
You can change your choices at any time in Settings, Privacy, Privacy options. Withdrawing consent does not affect processing that already took place while consent was valid.
5.2 Everywhere else
Outside the regions above, the consent dialog does not appear and ads and analytics run by default under our legitimate interest in funding and improving a free App. You can still limit them:
- iOS: if Apple's App Tracking Transparency prompt appears, refusing it stops the advertising identifier being used. You can also turn off "Allow Apps to Request to Track" and "Personalized Ads" in Settings, Privacy & Security.
- Android: Settings, Google, Ads lets you delete or reset your advertising ID and opt out of ad personalisation.
- If your region gives you a right to object to analytics or personalised advertising, email us and we will honour it.
5.3 Age-appropriate ads
The App is not directed to children (Section 11). We do not tag ad requests as child-directed. The maximum ad content rating in our AdMob account is T (Teen), which excludes mature ad content.
6How long we keep data
| Data | Retention |
|---|---|
| Anonymous identifier, topics, daily goal, timestamps | Until you ask us to delete them, or until the account has been inactive for 24 months, after which we delete it and everything linked to it. |
| Card events, reading time and derived scores | Same as the account. Deleting the account deletes them. |
| Time zone and usual reading hour | Kept on your profile after the reminder is turned off, and deleted with the account. |
| Reminder send log | 30 days, then deleted automatically each night. |
| Server logs with IP addresses | Kept by Supabase on a short rolling basis, between one and seven days depending on our plan. |
| Firebase Analytics user-level data | 2 months, as set in our Google Analytics property. Aggregated reports that cannot identify anyone are kept indefinitely. |
| Crashlytics crash reports | 90 days (Google default). |
| Notification token | Erased the moment you turn the daily reminder off in the App, and with the account when the account is deleted. |
| Advertising data held by Google | Governed by Google's retention rules, see Section 7. |
| Emails you send us | Up to 3 years so we can answer follow-ups, then deleted. |
| Data on your device | Until you clear the App's storage or uninstall. |
Card events cannot outlive the account they belong to. Content tables (topics, books, cards) contain no personal data.
7Who receives your data
We use the following service providers. All act as processors on our instructions unless noted.
| Provider | What they do for us | Data involved | Location |
|---|---|---|---|
| Supabase, Inc. | Hosts our database, authentication and API | Everything in Sections 4.1 to 4.3 except analytics, crash and ad data | Ireland (AWS eu-west-1), in the European Union. Supabase itself is a US company. |
| Google LLC and Google Ireland Ltd, Firebase Analytics | Usage analytics | Section 4.3, analytics row | United States and other Google locations |
| Google LLC and Google Ireland Ltd, Firebase Crashlytics | Crash reporting | Section 4.3, crash row | United States and other Google locations |
| Google LLC and Google Ireland Ltd, Firebase Cloud Messaging | Deliver the daily reminder to your device | The notification token in Section 4.1 and the text of the reminder, which may name the next lesson in a book you liked and the minutes left to your goal | United States and other Google locations. On iOS, Google hands the message to Apple's Push Notification service, which delivers it. |
| Google LLC and Google Ireland Ltd, AdMob and User Messaging Platform | Ad serving and consent management. Google acts as an independent controller for the personal data it processes to serve ads, under Google's Privacy Policy and how Google uses information from sites or apps that use its services. Consent choices are recorded in the IAB Transparency and Consent Framework format and may be read by the ad-technology partners listed in the consent dialog. | Section 4.3, advertising row | United States and other Google locations |
| Google LLC, Google Fonts | Font delivery for the Site | IP address, browser details | United States |
| Netlify, Inc. | Hosts the Site | Access logs | United States, with a global content delivery network |
| Online bookshops linked from "Get the book", such as Amazon | Sell the books. Each bookshop is an independent controller; we have no agreement with them and receive nothing from them. | Data the bookshop collects after you leave the App | United States and regional sites |
| Apple Inc. and Google LLC (app stores) | Distribute the App; process crashes and reviews you send them | Governed by their own policies | Various |
We do not sell personal data. We do not share personal data with data brokers. We disclose data to authorities only where the law requires it and only what it requires.
8International transfers
Our database is hosted in Ireland, inside the European Union. Google and Netlify process data in the United States and elsewhere. We ourselves are located in Bosnia and Herzegovina, which has no EU adequacy decision.
For data of people in the EEA, UK and Switzerland, transfers to the United States rely on:
- the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Data Privacy Framework, for providers certified under them, and
- the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum, built into each provider's data processing terms, for everything else.
Our own access to the database from Bosnia and Herzegovina is covered by the Standard Contractual Clauses in Supabase's Data Processing Addendum. Because we offer Loup to people in the EU and UK, the GDPR and UK GDPR apply to us directly, so you keep every right in this policy wherever we sit.
You can ask us for a copy of the relevant safeguards.
9Your rights
Depending on where you live you may have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate data;
- erase your data;
- restrict processing while a dispute is resolved;
- object to processing based on legitimate interest, including analytics and non-personalised ads where they rely on it;
- data portability: receive the data you provided in a machine-readable format;
- withdraw consent at any time, in Settings or in your device settings (Section 5);
- withdraw consent to the daily reminder by turning it off in the App, which erases your notification token from our servers (Section 4.1);
- not be subject to automated decisions with legal or similarly significant effects (we make none, Section 10);
- complain to a supervisory authority (Section 9.3).
9.1 How to exercise them
Because Loup accounts are anonymous, the only thing that ties data to you is your anonymous identifier. To act on your data we need that identifier. You can find and copy it in the App under Settings, About, Your ID. Email it to supportloup@gmail.com with your request. We cannot act on requests that do not include the identifier, because we have no other way to find your data, and we will not link an identifier to a person by any other means.
We respond within one month. We may extend this by two further months for complex requests and will tell you if so. Requests are free unless they are manifestly unfounded or excessive.
9.2 Deleting your data yourself
- Local data: uninstall the App or clear its storage in your device settings.
- The daily reminder: turn it off in the App. Your notification token is erased from our servers at once and no reminder is sent again. Refusing or revoking the notification permission in your device settings stops the reminder arriving, but only turning it off in the App removes the token. Your time zone and usual reading hour stay on your profile until the account is deleted.
- Server data: email us your identifier as described above. Deletion removes your identifier, topics, daily goal, card events, reading time, book progress, scores, time zone and reminder log, and takes your likes out of the like counts. Aggregated analytics that cannot identify you are unaffected. Google deletes analytics tied to your app instance when you reset your advertising ID or reinstall, and on request through us.
If you uninstall without asking for deletion, your server data remains until the inactivity period in Section 6 expires, because we cannot tell an uninstall from a long pause.
9.3 Complaints
You can complain to the data protection authority where you live or work. In the EEA that is your national authority (list of members); in the UK the Information Commissioner's Office; in Switzerland the FDPIC. Where we are established, it is the Agency for Personal Data Protection in Bosnia and Herzegovina. We would appreciate the chance to address your concern first.
9.4 Is providing data mandatory?
You do not have to give us anything to use Loup. The anonymous identifier and the card events are created by using the App; without them the feed cannot remember where you are or adapt to you. Consent to analytics and ads is never a condition of using the App.
10Automated decision-making and profiling
Loup ranks cards for you using a scoring query that combines your topic and book affinity scores, how recently you saw a card, a target mix of card sizes, and a random component. Affinity scores rise when you like, finish or share a card and fall when you skip it quickly, unlike it or hide a book, and they decay over time. The only outcome is the order in which free content appears. If you turned the daily reminder on, a nightly job also takes the hour at which you most often read over the last 14 days and sends the reminder about half an hour after it, and the sender stops after seven ignored reminders in a row. The only outcome there is the timing of one optional notification. There is no decision about you with legal or similarly significant effects, and no human review is needed. You can reset the effect by changing topics, hiding books, turning the reminder off, or asking us to delete your data.
11Children
Loup is intended for adults. It is not directed to children under 16, and we do not knowingly collect personal data from anyone under 16, or under 13 in the United States, or under the applicable age of digital consent where you live. The content is general adult non-fiction and the App is rated 12+ on the App Store and Teen on Google Play. If you believe a child has used Loup and you want their data removed, email us with the identifier and we will delete it. We do not use child-directed ad settings because the App is not aimed at children; if you are a parent and this concerns you, do not let a child use the App.
12Content, intellectual property and accuracy
This section explains what Loup's content is and is not, because it affects both how we handle personal data and what you can expect from the App.
- Lessons are our own words. Every card is an original, paraphrased summary of an idea from a published book, written and reviewed by us. Cards do not reproduce book text, except that "passage" cards may quote works in the public domain, and other cards may include a short quotation of a sentence or less with attribution. Book titles, author names and covers are used only to identify the source.
- No affiliation. Loup is not affiliated with, endorsed by or sponsored by any author, publisher or bookshop we link to. Opinions and interpretations in the lessons are ours.
- Not professional advice. Cards on psychology, health, money, philosophy or any other subject are general educational content. They are not medical, psychological, financial, legal or other professional advice, and they are not a substitute for reading the book or consulting a professional. Do not make decisions about your health, finances or wellbeing based on a card.
- Accuracy. We work to summarise faithfully, but we do not warrant that any card is complete, accurate or current. Use "Report this card" if you think one is wrong; we review reports.
- Rights holders. If you own rights in a book and believe a card exceeds a paraphrase or fair quotation, email supportloup@gmail.com with the card's hook and the book title. We will review and, where warranted, retire the card promptly. Include your name, the work concerned, the basis of your claim and a statement that you are authorised to act for the rights holder.
- Our content. The Loup Learn name, logo, card designs, hooks, lessons, "why it matters" texts, the feed scoring logic and the App and Site code are owned by us or our licensors. Share images generated by the App may be shared for personal, non-commercial purposes with the Loup credit intact. Any other reproduction, scraping, or use of our content to train machine-learning models requires our written permission.
- User-generated content. Loup has no comments, uploads or public profiles. The only thing other users see of your activity is that a card's like count includes your like, as a number with no name attached.
13Disclaimer and limitation of liability
To the fullest extent permitted by law:
- Loup is provided "as is" and "as available", free of charge, without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, accuracy and non-infringement.
- We are not liable for any indirect, incidental, special, consequential or punitive damages, or for loss of data, profits or goodwill, arising from your use of, or inability to use, the App, the Site, any card, or any third-party site reached through them, including ads and "Get the book" links.
- Our total liability to you for all claims connected with the App or Site is limited to the amount you paid us in the twelve months before the claim, which for a free App is zero, or the minimum amount the applicable law allows.
- Nothing in this section limits liability that cannot be limited under the law of your country, including liability for death or personal injury caused by negligence, for fraud, or your statutory consumer rights and data-protection rights.
These terms are governed by the law of Bosnia and Herzegovina, without prejudice to mandatory consumer protections in your country of residence.
14Security
- All traffic between the App, the Site and our servers is encrypted in transit.
- Every user table in our database has row-level security: a session can read and write only rows belonging to its own identifier. Content tables are read-only for the App.
- The App never contains the database's administrative key. Content is written only from a tool operated by us.
- Analytics, crash and advertising SDKs are configured not to collect anything until the consent flow has resolved (Section 5). The notification token is not one of these three and is not covered by that dialog: it exists only once you turn the daily reminder on, and turning it off erases it (Section 4.1). The reminder sender runs inside our database and a small function of ours; the tables it writes are not readable by the App at all.
- We keep no passwords or payment details because Loup has neither.
No system is perfectly secure. If we learn of a breach that is likely to put your rights at risk we will notify the competent authority within 72 hours and, where required, notify you through the App or the Site.
15Region-specific notices
15.1 United States
Loup does not sell personal information. If personalised advertising through AdMob counts as "sharing" or "targeted advertising" under your state's law, for example in California, Colorado, Connecticut, Virginia, Texas or Oregon, you can opt out through the device controls in Section 5.2 or by emailing us. We do not knowingly process sensitive personal information and we do not offer financial incentives for data. We do not discriminate against anyone for exercising privacy rights. Our business is currently below the revenue and volume thresholds at which most US state privacy laws apply; we honour the rights above voluntarily.
15.2 Brazil, Canada and other countries
Residents of other countries with privacy laws have the rights those laws grant. Use the contact in Section 1. Where the law requires a named contact person, such as the "encarregado" in Brazil, it is Melis Sakic at the email in Section 1.
16Changes to this policy
We will change this policy when the App changes, for example if we add optional email or Google sign-in, a paid ad-free tier, or a new bookshop partner. Material changes will be announced in the App before they take effect and the "Last updated" date at the top will change. Continued use after the effective date means you have read the new version. Previous versions are available on request.
17Contact
Melis SakicBašigovci bb, 75270 Živinice, Bosnia and Herzegovina
supportloup@gmail.com
AAppendix: analytics events the App logs
Sent to Firebase Analytics only after consent (Section 5). Parameters are identifiers of content, never free text.
| Event | Parameters |
|---|---|
onboarding_complete | topic_count |
feed_session_start | none |
card_view | card_id, book_id, topic_id, size, dwell_ms, read_tier, in_series |
card_like, card_unlike, card_share, card_hide | card_id, book_id, topic_id |
series_start | book_id |
series_drop, series_finish, series_unlike | book_id, cards_read |
ad_load_failed | ad_type, error_type |
ad_not_available | placement, retry_pending |
system_consent_granted, system_consent_denied | none |
Firebase also logs its automatic events (first open, session start, app update, OS update, and on Android app removal). Automatic screen tracking is disabled.