privacy policy
draft — not yet legally reviewed. this is a work in progress, not the final published policy.
Version 2.0 — July 19, 2026 (replaces version 1.0 of June 10, 2026; main changes: gender and occupation-category profile fields; voice notes in chat; group chats and member proposals; “make it home” arrangements; marketing-email preference; notification preferences; voice calls removed from the Service — Agora no longer a processor; AI-assistant transparency wording aligned with the EU AI Act)
TODO — BEFORE PUBLISHING (do not publish until all items are resolved):
- Legal review required. This document must be reviewed by a qualified Dutch privacy lawyer before it is published at /legal/privacy.
- Controller identity. Replace every instance of
[LORO LEGAL ENTITY, e.g. Loro B.V., address, KvK number]with the registered legal entity, registered address, and KvK number.- Supabase hosting region. Confirm and fill in
[SUPABASE PROJECT REGION — confirm, e.g. AWS eu-central-1 (Frankfurt)]in the International Transfers section. Also confirm the project’s database backup retention window and fill in the[N]placeholder in Section 8.- Web build caveats. If a web build ever ships: Deezer searches are routed through corsproxy.io (a third party that would see the query) — it must be removed first, or this policy must be amended.
- Data export. Export is handled by email (privacy@loro-app.com); no in-app export exists yet. Ensure the mailbox is monitored and a fulfilment process exists before publishing.
- Flat details are API-readable.
flat_contextsrows are readable by any authenticated user (the invite blur is UI-level). Either add a restrictive policy/view or keep the softened “in the app” wording in Section 3.5.- Mailboxes. Ensure privacy@, support@, safety@, and legal@ exist and are monitored.
1. Who we are
Loro is a roommate-matching app for the Netherlands (initially Amsterdam and Den Haag) that helps people find compatible roommates based on personality, habits, and lifestyle.
The data controller responsible for your personal data is:
[LORO LEGAL ENTITY, e.g. Loro B.V., address, KvK number]
Privacy questions and requests: privacy@loro-app.com General support: support@loro-app.com Legal / authorities (single point of contact under the EU Digital Services Act): legal@loro-app.com
This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR / AVG).
2. Who can use Loro
Loro is for adults only. You must be at least 18 years old to create an account. This is enforced technically: our database rejects any profile with an age below 18 (or above 80). We do not knowingly process data of anyone under 18; if you believe a minor is using Loro, contact privacy@loro-app.com or report the profile in-app.
3. The data we collect
3.1 Account and sign-in data
- Phone number (international E.164 format) — your primary sign-in, verified via an SMS one-time code sent through Twilio. One-time codes expire after 10 minutes. Your phone number is stored in a separate, restricted table that only you (and no other user) can ever access.
- Email address — collected during onboarding (not separately verified) and stored privately in our authentication system, never on your public profile; or received from Google or Apple if you sign in with those providers.
- Marketing preference — whether you opted in to occasional product emails (off by default; see Section 4).
- Authentication tokens — session tokens (JWTs) managed by our backend provider, Supabase. Sessions expire after 1 hour and refresh automatically.
3.2 Profile information
Collected when you build your profile:
- Display name (2–50 characters), age (derived from your date of birth — the exact birthday itself is not stored), country of origin, gender (man / woman / non-binary), occupation category (a fixed choice such as student or working full-time), bio (max 300 characters), and your “three words”
- Personal photos; optionally a short profile video
- Lifestyle answers: sleep schedule, social energy, up to 6 hobbies, up to 4 dealbreakers, up to 3 prompt answers (max 150 characters each)
- Optionally, a profile “anthem”: a song you pick via Deezer search (track name, artist, album cover, 30-second preview link)
- Your role (seeker, co-living offeror, or renting-out offeror), whether your profile is discoverable, and verification flags
Gender is shown as part of matching/filtering (other users can filter by it); it is collected as a required field. We do not ask for, and you should not add, special-category data such as health, religion, or sexual orientation anywhere in your profile or messages.
3.3 Location
- Country, city, and neighbourhood
- Precise coordinates (latitude/longitude) of the location pin you place on a map during onboarding, stored in an owner-only restricted table and used for the location-overlap part of the match score. Your exact pin is never shown to other users — they see your city and neighbourhood.
3.4 Home details (offerors)
If you offer a room: neighbourhood, city, monthly rent, availability dates, room details, number of current tenants, a description, home photos, house rules, and who you are looking for. Renting-out offerors can have multiple places. Rooms are never public listings — in the app, home details are surfaced to seekers through invites and conversations.
3.5 Messages, voice notes, and group chats
- Text messages (max 2,000 characters), photo messages, voice notes (short audio recordings you choose to send), emoji reactions, shared profiles, edit timestamps, deletion flags, and read receipts.
- Group (“flock”) data: group name and photo, membership, member proposals and votes, the shared chat theme, and your personal mute setting.
- Messages and voice notes are visible only to the participants of a conversation and are kept until the conversation or your account is deleted.
3.6 Matching and activity data
- Every swipe (pass or “vibe”), with who swiped on whom and when, and any comment attached to a vibe
- Your matches, flocks, invites sent/received (including their status), and your invitation-message template if you save one
- Pairwise compatibility scores and their breakdown, cached for a maximum of 24 hours
3.7 Arrangements (“make it home”)
If you and another user record that you have decided to live together: who is involved, the home concerned, the proposed move-in date, and each participant’s confirmation state. This drives in-app status (like the “living with” card and hiding a settled seeker from discovery) and is deleted with your account.
3.8 Payments
- Invite-credit balance and purchase totals; subscription records and Stripe customer/subscription identifiers (only if/when we introduce a subscription — none exists today; see the Terms of Service); and payment audit records (Stripe event id, event type, amount, currency, status). During the current launch period invites are free, and no payment data is created.
- We never store card or payment-method details. Card data is entered only into Stripe’s own secure payment sheet and goes directly to Stripe. Credits are granted only after Stripe confirms a payment server-side.
3.9 Push notifications
- A push subscription identifier from OneSignal, linked to your account so we can deliver notifications (new message, new match, new invite) to your device. Signing out detaches your device.
- Your notification preferences (the master switch and per-category choices) are stored on your device.
3.10 Crash and diagnostic data
- If crash reporting is enabled in a given build, crash stack traces, device/OS context, and sampled performance traces are sent to Sentry. We use no behavioral analytics SDKs — no Firebase Analytics, no Mixpanel, no Amplitude, nothing that tracks how you use the app.
3.11 Safety records
- Reports: if you report another user, we store your report (reason category and optional details, max 1,000 characters). Reports are confidential — visible only to you and to our moderation systems, never to the person you reported.
- Blocks: who you blocked and who blocked you, used solely to enforce mutual invisibility.
- Moderation records: actions we take on content or accounts, and the reasons, kept to handle appeals and meet our legal obligations.
3.12 AI assistant (“ask loro”)
- The in-app help assistant is an AI system (the app tells you so where the conversation starts). The text you type is sent through our server to Anthropic’s Claude model to generate a response. These conversations are not stored in our database — they exist only on your device during the session. No profile fields, identifiers, or account data are attached to the request, and the content is not used to train AI models.
4. Why we process your data, and on what legal basis
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account & sign-in data | Create and secure your account; sign you in | Contract (6(1)(b)); account security: legitimate interest (6(1)(f)) |
| Phone number & verification | Verify you are a real person; reduce fake profiles | Contract; platform safety: legitimate interest |
| Profile information (incl. gender, occupation category) | Build your profile, compute compatibility, power the discover filters, show you to potential roommates | Contract; optional extras (video, anthem, occupation detail): consent — you choose to add them and can remove them anytime |
| Location (incl. precise pin) | Compute location overlap in your match score; show your city/neighbourhood to others | Contract |
| Home details (offerors) | Give invited seekers context about the room | Contract |
| Messages, voice notes & group chats | Deliver chat between matched users and flocks | Contract |
| Swipes, matches, invites, scores | Run the matching mechanic that is the core of the service | Contract |
| Arrangements | Record and reflect a decision to live together in the app | Contract |
| Payment data | Process purchases, grant credits, prevent fraud, keep financial records | Contract; bookkeeping: legal obligation (6(1)(c)) |
| Push identifier | Deliver notifications you have allowed | Consent (your operating-system permission, revocable anytime) |
| Marketing emails | Occasional product updates | Consent (opt-in at onboarding or in notification settings; withdraw anytime) |
| Crash & diagnostics | Fix crashes and keep the app stable | Legitimate interest |
| Reports, blocks & moderation records | Keep the community safe; moderate misuse; handle appeals | Legitimate interest; legal obligation where applicable |
| AI-assistant content | Answer your support questions | Contract |
We do not use your data for automated decisions with legal or similarly significant effects. Compatibility scores and discover ordering only inform and order your matching experience; every decision about matching, inviting, or living together is made by people.
5. What other users can and cannot see
Visible to other signed-in users (while your profile is discoverable):
- Display name, age, occupation (category and optional detail), country of origin, bio, three words
- Your photos and (if added) profile video
- Hobbies, dealbreakers, prompt answers, and your anthem
- Your city and neighbourhood (your exact location pin is never shown)
- Your compatibility score with them
- Gender is used by the discover filters (users can filter by it)
Never visible to other users:
- Your email address — stored only in our authentication system, never on your profile
- Your phone number — stored in a restricted table only you can access
- Your exact location pin and your date of birth
- Your private messages and voice notes (visible only to conversation participants)
- Your swipe activity, payment information, notification settings, and any reports you file
Your controls: the “actively looking” toggle (and the equivalent “pause my account” switch in account settings) removes you from discovery at any time — existing chat partners can still see your profile so conversations keep working. Recording an arrangement also hides a settled seeker from discovery. You can block any user — blocking is mutual invisibility, and the blocked person is never notified.
A note on media files: photos, videos, and voice notes are served from long, unguessable URLs. The app only shows them to the intended audience, but anyone who obtains a direct file link can view that file. Avoid putting sensitive information inside media you upload.
6. Who we share data with (processors and recipients)
We never sell your personal data. We share data only with the service providers below, only as needed to run Loro:
| Provider | What they do for us | What they receive |
|---|---|---|
| Supabase | Core backend: authentication, database, file storage, real-time chat, server functions | The account, profile, location, message and voice-note, match, invite, arrangement, payment-metadata, and safety data described above |
| Stripe | Payment processing for invite packs (when paid packs are active) | Payment amount and currency; your card details (entered directly into Stripe’s own payment sheet — never seen by us); a pseudonymous identifier (your Loro account ID) attached to the payment so we can grant your credits |
| OneSignal | Push notification delivery | Your device push token and account ID; notification content, which includes sender display names and a preview of message text |
| Twilio | SMS phone verification | Your phone number and, on verification, the one-time code you entered |
| Anthropic | AI model behind the in-app assistant | The text of your assistant conversation only — no profile data or identifiers; not used for model training |
| Sentry | Crash reporting and performance monitoring (when enabled) | Crash stack traces, device/OS context, sampled performance traces |
| Deezer | Song search for your optional profile anthem | Only the song search text you type — no account data |
| Mapbox | Map tiles and address search for the onboarding location picker | Standard tile/geocoding requests: the map area or address text, your IP address, and the app identifier |
| Google / Apple | Optional sign-in providers | Standard OAuth sign-in: they learn that you sign in to Loro; we receive your email address from them |
In-app voice calls are not offered, and no real-time call provider processes your data. If we ever introduce calls, this policy will be updated first.
We may also disclose data where the law requires it — for example to competent authorities under a valid order — and we will assess every such request critically.
7. International data transfers
Some of our providers are based in the United States: Stripe, Twilio, OneSignal, Anthropic, Sentry, Mapbox, Google, and Apple. Where personal data is transferred outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and, where the provider is certified, the EU–U.S. Data Privacy Framework, together with the providers’ technical and organisational safeguards.
Our core backend (Supabase) is hosted in [SUPABASE PROJECT REGION — confirm, e.g. AWS eu-central-1 (Frankfurt)]. Deezer is based in the EU (France).
8. How long we keep your data
| Data | Retention |
|---|---|
| Account, profile, photos/video, location, home details, messages and voice notes, swipes, matches, invites, flocks, arrangements, blocks, reports, credit balances | Kept while your account exists; deleted immediately when you delete your account (see below) |
| Compatibility score cache | Maximum 24 hours |
| Payment audit records | Retained after account deletion in anonymized form (Stripe identifiers, amounts, and status only — no link to your profile), as required for financial record-keeping |
| Moderation records for enforced violations | May be retained for a limited period after account deletion where necessary to prevent ban evasion and handle appeals or legal claims |
| Session tokens | Expire after 1 hour (auto-refreshed while signed in; invalidated on sign-out) |
| SMS one-time codes | Expire after 10 minutes |
| AI-assistant conversations | Not stored in our database — held only in your app session |
Account deletion is immediate and cascading. When you delete your account (me → account → delete my account), your account record is deleted and every linked database record — profile, phone number, photos, videos and voice notes, prompt answers, swipes, matches, invites, conversations and messages, flocks, arrangements, blocks, credits, and reports — is deleted with it in the same operation. There is no recovery period.
Uploaded media files: your uploaded photos, videos, and voice notes are deleted from our storage systems at the same time as your account. Media shared inside chat conversations is removed when the conversation itself is deleted.
Backups: deleted data may persist in encrypted database backups for up to [N — confirm Supabase backup retention window] days before those backups expire; backups are never used to restore deleted accounts.
9. Your rights (GDPR / AVG)
You have the following rights, free of charge. We respond within one month.
| Right | How to exercise it |
|---|---|
| Access — a copy of the personal data we hold about you | Email privacy@loro-app.com from your account email |
| Rectification — correct inaccurate data | Edit your profile directly in the app, or email privacy@loro-app.com |
| Erasure — delete your data | In-app: me → account → delete my account (immediate and cascading), or email privacy@loro-app.com |
| Data portability — your data in a machine-readable format | Email privacy@loro-app.com; we will send you an export |
| Objection / restriction — object to processing based on legitimate interest, or ask us to restrict processing | Email privacy@loro-app.com |
| Withdraw consent — for anything based on consent | Remove optional content (video, anthem) in the app; switch off marketing emails in notification settings; disable push in your device settings; withdrawal does not affect prior processing |
Complaints: you have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would appreciate the chance to address your concern first via privacy@loro-app.com, but you are not required to contact us before complaining.
10. Notifications and email
We ask for notification permission in context — never the moment you open the app. In the app (me → notifications) you control the master push switch and per-category preferences; your device’s system settings offer the same master control. Marketing email is opt-in and can be switched off in the same screen at any time; service emails strictly necessary for your account (such as security notices) may still be sent.
11. No advertising, no tracking, no sale of data
- We never sell your personal data.
- The app contains no advertising networks and shows no third-party ads.
- The app contains no behavioral analytics or tracking SDKs — we do not profile how you use the app for marketing.
- We do not use your data for third-party advertising, share it with data brokers, or use your content to train AI models.
Cookie-type storage used by the app and the loro-app.com website is described in our Cookie Policy (/legal/cookies).
12. How we protect your data
- Every database table is protected by row-level security with a default-deny policy — data is only readable by those explicitly allowed.
- Your phone number and exact location pin live in a restricted table accessible only by you; your email never leaves the authentication system.
- Card data never touches our servers — it goes directly to Stripe.
- Server-side verification for all payments and permissions — we never trust the app alone to authorize anything.
No system is perfectly secure. If a data breach affects your rights, we will notify you and the Autoriteit Persoonsgegevens as required by law.
13. Changes to this policy
We may update this policy as Loro evolves. The version and date at the top always reflect the current revision, and a summary of the main changes is included with each version. For material changes, we will notify you in the app or by email before the changes take effect.
14. Contact
Controller: [LORO LEGAL ENTITY, e.g. Loro B.V., address, KvK number] Privacy requests: privacy@loro-app.com General support: support@loro-app.com Legal / authorities (DSA point of contact): legal@loro-app.com
Loro — find your flock.


