Privacy policy
Last updated 7 September 2026
Loopah generates, schedules and publishes social posts for brands that connect their accounts. This page says exactly what we store to do that, who processes it, and how you get it removed. No legalese theatre.
Who we are
Loopah (loopah.good-scratch.com) is a product of Good Scratch, operated by BIZWAX WEBDEV SRL, Str. George Vâlsan 12, Sector 6, Bucharest, Romania(CUI RO47632445, Trade Register J2023002795408). That company is the data controller for everything on this page. You can reach us at loopah@good-scratch.com.
What we store, and why
- Your account. Email address and display name, so you can sign in and we can send you account emails (verification, invites). Stored in Firebase Authentication.
- Your brand. Name, colours, fonts, logo, brand voice notes, templates, topics and any examples you upload. This is what Loopah learns from to write and design in your voice.
- Your Instagram connection. When you connect an Instagram professional account we store its account id, username, the access token Meta issues to Loopah, the permissions you granted and when you connected. The token is what lets Loopah publish on your behalf. It is stored server side, refreshed automatically before it expires, and deleted the moment you disconnect.
- Content Loopah makes. Ideas, captions, carousel slides, static images and reels, plus the calendar slots they are scheduled into. Rendered images are stored so a post scheduled days ahead can still publish.
- Performance of published posts. Once a week we read reach, saves, shares, likes and comment counts for posts Loopah published, so the next posts can learn from the last ones. We do not read your followers, your inbox or anyone else's data.
- Blog source (optional). If you point Loopah at your blog, we store the public URLs and text of your articles to turn them into posts.
- Billing. Your plan, token balance and top-ups. Payments run through Stripe; Stripe holds your card details, we never see them.
- Your own AI key (optional). If you bring your own Google Gemini key, it is stored server side and used only for your brand's generations.
Who processes it
Loopah runs on a small set of providers, each doing one job:
- Google Cloud / Firebase (database, file storage, sign-in) and Google Gemini (the model that writes and lays out your posts). Your brand voice and the topic of each post are sent to Gemini to generate content; Google does not use API inputs to train its models under its API terms.
- Vercel hosts the application.
- Meta (Instagram API) receives the content you approve and returns publishing results and post metrics.
- Stripe handles payments.
- Twilio SendGrid sends account emails.
- Our own operations alerts (a private Telegram channel for the Loopah team) carry brand names, post titles and publish results so we notice failures. No tokens, no personal data of your followers.
We do not sell data, we do not run advertising, and we do not share your data with anyone not listed above.
How long we keep it
- Instagram access tokens: until you disconnect the account or delete your brand, then removed immediately.
- Brand data, content and calendar: while your account is active. Deleted within 30 days of a deletion request.
- Post performance metrics: while your account is active, then deleted with the rest.
- Billing records: as long as tax law requires, then deleted.
Your rights
You can see everything Loopah holds about a brand inside the app. You can disconnect Instagram at any time from the brand's page, which deletes the token. You can ask for a copy of your data or for full deletion by email; how deletion works is on the data deletion page. If you are in the EU you also have the right to complain to your data protection authority.
Requests from public authorities
If a public authority asks us for personal data, we first check that the request is lawful and properly issued, we disclose only the minimum the request lawfully requires, and we keep a record of the request, our legal reasoning and what was provided. We have received no such request to date.
Cookies
Loopah uses the cookies Firebase needs to keep you signed in. No advertising or tracking cookies.
Changes
If this page changes in a way that matters, we will say so on the page and, for account holders, by email.