Legal

Privacy Policy.

How Loopn collects, uses, stores, and protects your information. We keep this honest and straightforward.

Effective: June 2026
Last updated: September 2026
Applies to: Loopn Android App and Web App
01

Introduction

Loopn is a verified campus social networking application, available as an Android app and a web app, built exclusively for IT-stream college students and faculty in India. It is developed and operated by Vantcrest Labs Private Limited.

This Privacy Policy explains what information we collect when you use Loopn, why we collect it, how it is stored and protected, and what rights you have over your data. By using Loopn, you agree to the practices described in this policy.

If you do not agree with any part of this policy, please discontinue use of the application.

02

Who We Are

Data Controller
Vantcrest Labs Private Limited
Product Website
03

Who Can Use Loopn

Loopn is currently available to:

  • Students and faculty of SJCET Palai
  • Users who sign in using a verified institutional Google account issued by the college

Access is restricted at the authentication level. Non-institutional email addresses are silently blocked. We do not collect or store any data from users whose login attempt is rejected.

04

Information We Collect

4.1 Information You Provide Directly

  • Full name, profile photo, department, year/semester (students) or designation (faculty)
  • Bio, tagline, portfolio link, skills, projects, social links (optional)
  • Availability status — Open to Collaborate or Open to Opportunities
  • Posts, comments, replies, and reactions you create
  • Direct messages and message requests you send
  • Den room messages — temporary, see Section 7
  • Reports you submit about content

4.2 Information Collected Automatically

  • Supabase-assigned user ID and session data (session tokens) stored on your device, used to keep you signed in
  • App version and basic device metadata sent to Expo for update checks
  • A device push token, if you allow notifications — see Section 11

4.3 Files and Media You Upload

  • Profile photo, post images, post documents/PDFs
  • Images shared in direct messages
  • Den room and DM background images

All uploaded files are stored in Supabase Storage in the Singapore region. Images are compressed to 80% quality before upload.

05

How We Use Your Information

  • To verify your institutional identity at login
  • To create and display your public profile within your campus network
  • To power skill-based search and people discovery
  • To enable posts, comments, reactions, and the campus feed
  • To facilitate connection requests and direct messaging
  • To operate Den rooms — live ephemeral campus rooms
  • To deliver in-app and push notifications relevant to you
  • To enforce community safety through reporting

We do not use your data for advertising. We do not sell, rent, or trade your data to any third party. We do not build behavioural profiles.

06

Data Storage and Security

All application data is stored on Supabase, hosted on AWS infrastructure in Singapore (ap-southeast-1). Under India's Digital Personal Data Protection Act, 2023, this cross-border storage is permitted since Singapore is not a restricted jurisdiction.

  • Row-Level Security on every database table
  • Google OAuth 2.0 — we never store your Google password
  • HTTPS enforced on all data in transit
  • Internal access limited to a single administrator account for moderation and safety only

No system is completely immune to security risks. We encourage you to log out of shared devices.

07

Den Rooms — Ephemeral Messaging

Den is Loopn's live campus room feature. Den rooms are ephemeral by design.

When a room host ends a Den room, the following is permanently and physically deleted:

  • All messages sent in that room
  • All room member records
  • The room itself

This is a hard delete. No archive is kept. No backup of room messages is retained after a room ends.

Individual users may also delete their own messages within an active room — removed immediately.

08

Provisional Accounts

Loopn lets prospective and incoming students at the same institution join temporarily using a signup code, without an institutional college email.

  • A provisional account is anonymous — it has no name, email, or photo attached, only a role marker and the signup code used to create it
  • Provisional access is limited to viewing the feed — no posting, commenting, boosting, or messaging
  • Provisional accounts automatically expire after a fixed period and lose access once they do
  • You can permanently delete your own provisional account at any time from Settings
  • Upgrading to a verified account through institutional Google sign-in replaces your provisional identity with your verified one — it does not create a second account
09

Pages / Club Identities

Any verified user can create a Page to represent a club, society, or organization on campus.

  • Content posted while acting as a Page displays under the Page's name and logo, not the individual member who posted it
  • Page admins are responsible for content posted under their Page
10

Direct Messages

Direct messages are only possible between mutually connected users. All DMs are stored in our database and are not end-to-end encrypted. Messages are stored until either party deletes them or their account is deleted. Media shared in DMs is stored in Supabase Storage.

We do not read your private messages for advertising or profiling purposes. Messages may be reviewed only in response to a valid legal obligation or a serious safety concern.

11

In-App and Push Notifications

Notifications — connection requests, accepted connections, message requests, reactions, comments, replies — are stored in our database and shown when you open the app.

Loopn also sends push notifications to your device via Firebase Cloud Messaging, so you're alerted even when the app is closed. A device push token is generated and stored against your account for this purpose. The token and each notification's content are sent to Expo's push service, which relays them through Firebase/Google to your device.

  • Push notifications are used only to alert you to activity relevant to you — connection requests, messages, reactions, comments, and similar in-app events
  • We do not use push notifications for advertising or promotional messages
  • Your device push token, and the title and body of each notification (which may include a sender's name or a message/post preview), are sent to Expo's push service, which relays them through Firebase/Google to deliver the notification. Both are service providers used only for this purpose, not for advertising or analytics
12

Device Permissions

  • Camera — for capturing profile photos and post images
  • Photo Library / Storage — for selecting images and documents to upload
  • Notifications — for displaying in-app and push notification alerts

We do not request your location, microphone, contacts, or calendar.

13

Third-Party Services

Supabase — Singapore (ap-southeast-1)
Our database, authentication, file storage, and realtime infrastructure. All application data is stored here. Supabase Privacy Policy ↗
Google OAuth 2.0
Used exclusively for sign-in. We receive your institutional email and name at login. Google Privacy Policy ↗
Expo (by Expo Software Inc.)
Provides build infrastructure, over-the-air update delivery, and the push notification service that receives your device push token and notification content and relays them to Firebase/Google. Expo Privacy Policy ↗
Firebase Cloud Messaging (Google)
Used exclusively to deliver push notifications to your device. Receives, via Expo's push service, your device push token and the notification's title and body (which may include a sender's name or a message/post preview). No other profile data is shared with it.

We do not use any advertising networks, analytics platforms, crash reporting tools, or attribution SDKs.

14

Data Retention

  • Profile information (name, photo, bio, contact details) — removed when you delete your account
  • Posts, comments, connections — retained after account deletion, no longer associated with your identity (shown as "Loopn User")
  • Direct messages — retained until deleted by you; after account deletion they remain, shown as "Loopn User"
  • Den room messages — permanently deleted when the room ends
  • Uploaded media — retained until you delete the content; after account deletion it remains, no longer associated with your identity
15

Your Rights

You have the following rights regarding your data:

  • Access — view all profile data you've provided, within the app
  • Correction — edit your profile, skills, projects, links at any time
  • Deletion — delete posts/comments/messages in-app. Delete your account in-app (Settings → Account Management → Delete Account) or via the web form at loopn.in/delete-account. This removes your personal profile information (name, photo, bio, contact details) and your login access. Content you've posted or shared (posts, messages, comments, uploaded media) remains on the platform but is no longer associated with your identity — it displays as "Loopn User"
  • Withdrawal of consent — stop using the app and delete your account
  • Grievance redressal — file a grievance if your data was mishandled
To exercise any data right
16

Children's Privacy

Loopn is designed for college students and faculty. We do not knowingly collect data from anyone under 18. Verified access requires an active institutional college email, which limits use to enrolled students and faculty.

Provisional access (see Section 8) is the one exception — it requires no email. It's intended only for prospective or incoming students of the same institution, not open public signup, and is deliberately time-limited to reduce this exposure.

If you believe a minor has accessed Loopn without proper credentials, please contact us at support@vantcrest.com.

17

Changes to This Policy

We may update this policy from time to time. For significant changes, we'll notify you via an in-app notification. Continued use after an update means you accept the revised policy.

This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, and the Information Technology Act, 2000.

18

Contact Us

For any questions, concerns, or data requests regarding this Privacy Policy:

Website
Company
Vantcrest Labs Private Limited
Grievance Officer
Nirmal Josekutty — support@vantcrest.com