Privacy Policy
Last updated 28 August 2026
Loop exists to help separated parents co-ordinate family life, which means you trust us with genuinely sensitive information about you and your children. This policy explains exactly what we collect, why, who can see it, where it goes, and the rights you have wherever in the world you live. The short version: your data is yours, we do not sell it, we do not use it for advertising, we do not train AI on it, and your co-parent sees only what you choose to share.
1. Who is responsible for your data
The data controller is Panrock Technologies Ltd, a company registered in England and Wales with company number 17372926, whose registered office is at 24a Aldermans Hill, London N13 4PN, United Kingdom, trading as “CoParent Loop”. You can reach us about anything in this policy at hello@coparentloop.com. We are registered as a data controller with the UK Information Commissioner’s Office under registration number ZC218117.
2. Who this policy is for
This policy applies to everyone who uses Loop, anywhere in the world. Rather than applying a different, weaker standard in countries with lighter privacy laws, we have built Loop around the UK and EU GDPR, among the strictest privacy regimes there are, and we apply that standard to every user by default. Section 17 sets out the extra rights that some countries give you on top.
3. What we collect
Account details: your name, email, phone number and a securely hashed password, plus your chosen plan. Family information you add: children’s names, dates of birth, school, allergies and medical notes; co-parent, caregiver and guest links made by invitation code. Content you create: messages, expense records, payment requests, calendars and schedules, milestones, wishlists, house rules, agreements, documents, photos and drawings. Calls: if you turn recording on, the recording, its transcript and AI summary. Technical basics: device type and app version, and the logs needed to keep Loop secure, working and within its usage limits. We collect no advertising identifiers, no location tracking, and no data from third-party data brokers.
4. Why we use it, and our legal bases
To provide Loop itself, storing and syncing your family’s information between you and the people you link (performance of our contract with you). To run the AI features you invoke (performance of contract). To keep Loop secure, prevent abuse and enforce usage limits (our legitimate interests in running a safe service, balanced against your rights). To handle payments and support (contract). To meet legal obligations, such as tax and responding to lawful requests. We do not rely on legitimate interests for anything you would not reasonably expect, and you can object to that processing at any time.
5. Health and other sensitive information
Health-related notes you choose to add about a child (allergies, conditions, medication) are special category data under UK and EU law, and sensitive personal information under laws such as California’s. We process them only on the basis of your explicit consent, given by choosing to add them, and only to show them to you and the people you have shared that child with. We never use them for any other purpose, and you can delete them at any time, which withdraws that consent.
6. What we never do
We do not sell your personal information, in any sense of the word “sell”, including the broad definitions used in US state privacy laws. We do not share it for cross-context behavioural advertising. We do not show ads. We do not build advertising or marketing profiles. We do not use your content, messages or children’s information to train AI models, and our contracts with our providers prohibit them from doing so either. We do not use tracking cookies or third-party analytics SDKs in the app.
7. The AI features and your data
When you use an AI feature, the relevant text (for example the message you are drafting, or the conversation being mediated) is sent securely to our AI provider, Anthropic, to generate the response, along with first names for readability. Under our commercial API terms with Anthropic, this data is not used to train AI models and is not retained beyond what is needed to return the response and meet Anthropic’s own abuse-monitoring obligations. AI outputs are stored only as part of your own chats and records. The private “solo” AI chat is exactly that: private to your account, and never visible to your co-parent.
8. What your co-parent can see
Privacy between households is a design principle, enforced in our database, not just in the app’s screens. Your co-parent sees only what is explicitly shared with them: the children you have linked, and the schedules, expenses, chats and records belonging to that shared world. They never see your private solo chats, your other relationships, events you have marked private, or anything you have not shared. If you have more than one co-parent, each sees only their own shared world. Caregivers and guests you invite see a further-limited view that you control.
9. Who else processes your data
We use a small number of service providers (“processors”) to run Loop: Supabase (database, authentication and file storage, hosted in Frankfurt, in the EU), Anthropic (AI responses, as described above), Expo and Apple (app delivery, crash-free operation and push notifications), and Apple or Google (subscription payments, acting under their own terms). Each is bound by a written contract to process data only on our instructions and to protect it. We do not share your data with advertisers or data brokers. We disclose data to authorities only where the law genuinely requires it (for example a valid court order) and where we are allowed to tell you, we will.
10. Where your data lives, and international transfers
Your data is stored in the European Union (Frankfurt), whichever country you use Loop from. AI requests are processed by Anthropic in the United States. Where personal data leaves the UK or EEA, we rely on appropriate safeguards: the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus technical measures such as encryption, so that your data keeps essentially the same protection wherever it is processed. You can ask us for details of these safeguards. No other routine transfers outside the UK/EU take place.
11. How we protect it
All data is encrypted in transit and at rest. Access between accounts is controlled by row-level security in the database itself. The “who can see what” rules in section 8 are enforced at the lowest level we control, not merely hidden in the interface. AI credentials and other secrets live only on our servers, never in the app. Passwords are hashed and never stored in a readable form. Access to production systems is limited to those who need it. That said, no service on the internet can be made perfectly secure, and we will never claim otherwise: we reduce risk as far as we reasonably can, and section 12 explains what happens if something still goes wrong.
12. If something goes wrong
If a personal data breach occurs, we will investigate immediately, take steps to contain it, and report it to the ICO within 72 hours where the law requires. Where a breach is likely to result in a high risk to you, we will tell you without undue delay: what happened, what data was involved, what we are doing about it and what you can do to protect yourself. We will also notify other regulators and users where the law where you live requires it. We will not conceal a breach or delay telling you to manage reputation.
13. How long we keep it
We keep your data for as long as your account is active. If you delete individual items, they are removed from your account and from the shared view of anyone you shared them with. If you delete your account, your data is deleted, with a short technical window while encrypted backups cycle out. We may keep a minimal record of the deletion itself, and anything we are legally required to retain, such as payment records for tax purposes. Because shared records, a shared expense log for example, belong to both parents in a relationship, deleting your account removes your access and your private data, but records already shared into a relationship may remain visible to the other parent as part of their own account.
14. Automated decisions
We do not make decisions about you by purely automated means that produce legal effects or similarly significantly affect you. Loop’s AI features generate suggestions for you to accept, edit or ignore; they do not decide anything about you, your children or your arrangements.
15. Messages we send you
We email or notify you about your account and the service: sign-in, invitations, changes to these documents, security notices and things happening in your Loop. We will only send you marketing messages if you have asked for them, and you can stop those at any time without affecting your account. Notification preferences are in the app.
16. Your rights
Under UK and EU GDPR you can: access a copy of your data (Loop’s export tools are the quickest way); correct inaccurate data; delete your data; object to or restrict certain processing; take your data elsewhere (portability); and withdraw consent where processing is based on it. We apply these rights to every Loop user, wherever you live. To exercise any of them, use the in-app tools or contact hello@coparentloop.com. We will respond within one month, and we will not charge you or treat you differently for asking. We may need to verify your identity first, so that nobody else can use these rights against you.
17. Extra rights where you live
California: you have the right to know what personal information we collect, use and disclose, and to request access, correction or deletion; to opt out of sale or sharing, although we do neither; and to limit the use of sensitive personal information, which we already use only to provide the service you asked for. We will not discriminate against you for exercising these rights, and you may use an authorised agent. Other US states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah and Texas, give broadly similar rights, and we apply them to residents of those states. Canada: rights of access and correction under PIPEDA, with complaints to the Office of the Privacy Commissioner. Australia: rights under the Australian Privacy Principles, with complaints to the OAIC. Brazil: rights under the LGPD, including confirmation, access, correction, anonymisation and portability. Switzerland: rights under the revised FADP. If you are in the EEA and we are required to appoint a representative under Article 27 of the EU GDPR, their details will be published here. If a right you have locally is not listed, ask us anyway. Our default is to honour it.
18. Children
Loop is for adults. Information about children is entered by their parents, under parental responsibility, as part of the parents’ own accounts. We do not knowingly collect information directly from children, we do not knowingly allow anyone under 18 to create an account, and children must not use Loop. This includes children under 13 for the purposes of the US Children’s Online Privacy Protection Act. If you believe a child has created an account, tell us and we will delete it.
19. Changes to this policy
If we make material changes (a new processor, a new use of data, a new country we transfer to) we will tell you in the app before the change takes effect. The date at the top always shows the current version.
20. How to complain
Please come to us first at hello@coparentloop.com. We would genuinely rather fix something than have you take it elsewhere. If you are not satisfied, you can complain to the UK Information Commissioner’s Office at ico.org.uk. If you live in the EEA you may complain to your own national data protection authority, and users elsewhere may complain to their local privacy regulator; section 17 names several of them.
Panrock Technologies Ltd, trading as CoParent Loop. Registered in England and Wales, company number 17372926. Registered office: 24a Aldermans Hill, London N13 4PN, United Kingdom. Contact: hello@coparentloop.com.