mobieusKnow Handling organization tickets History #510
Author
Patrick Bass
Submitted
Aug 24, 2026 7:33am
Summary
Video posting: what unlocks it, what mobieusVerified opens, and what to escalate
+ '''Tickets about a gym, club or employer running Loopa.''' The member-facing article is ''Joining an organization'' on the Loopa knowledge base; send members there rather than paraphrasing.
'''Tickets about a Loopa organization: joining one, belonging to one, and leaving one.''' The member-facing articles are ''Joining an organization'', ''Creating an organization'' and ''Organization forum guidelines'' on the Loopa knowledge base. Send members there rather than paraphrasing.
== What an organization is, in one paragraph ==
'''A private group inside Loopa: a room, and challenges.''' A gym, a club, a team at work, a family, a few friends. Anybody with Loopa Premium can create one; anybody at all can join one with a code or a link. Joining, posting, entering a challenge and appearing on a leaderboard are '''free for every member''', including on Loopa Basic. An organization is not listed anywhere and cannot be searched for. A code or a link is the only way in.
'''A member can belong to as many organizations as they like''', with a different role in each.
== What you can and cannot see ==
'''You cannot see a member's health record, and neither can anybody at their organization.''' There is no role, no setting and no permission for it. Say this plainly.
'''You cannot see an organization's invite code, and you must never read one back, repair one or guess one.''' Whether a particular code is live is something only the organization can answer.
What you can establish from a ticket is which organization the member means, what they were doing, and which of the answers below fits. Looking an organization up by name, reading its roster, reading its audit history and changing its status are '''platform administrator''' actions. That is an escalation, not a first response.
== "My code does not work" ==
Work through these in order.
+ # '''Read the code back.''' Codes never contain '''O, I, L, U, 0 or 1''' — those are the characters that get misread. If the member typed one, they misread something on the poster. Ask what they are looking at.
+ # '''The code may have been retired.''' Organisations issue a new code whenever an old one has travelled further than intended, and the old one stops working the moment they do. Ask the organisation for the current one.
+ # '''Joining may be closed.''' A closed organisation answers exactly as an unknown code does, deliberately — telling a stranger "right code, we are closed" confirms the code is real. Only the organisation can tell you which it is.
+ # '''Rate limiting.''' Thirty attempts an hour per address. Somebody who has been retyping for a while will start getting "we could not check that code just now". It clears on the hour.
1. '''Read the code back.''' Codes never contain '''O, I, L, U, 0 or 1'''. Those are the characters that get misread. If the member typed one of those, they misread something. Ask what they are looking at.
1. '''The code may have been rotated.''' An organization issues a new code whenever an old one has traveled further than intended, and the old one stops the moment they do. Nobody is removed when that happens. Ask the organization for the current code.
1. '''The code may have expired.''' An organization can set a code to run out after a day, a week or a month. Same answer: ask them for the current one.
1. '''The organization may be suspended, or deleted.''' Either answers exactly as an unknown code does, deliberately. Telling a stranger "right code, we are shut" confirms the code is real.
+ '''Do not offer to correct a code for them.''' Loopa deliberately refuses to guess: a repaired mistype can resolve to a ''different'' organisation, and the member has no way to tell it happened.
'''Do not offer to correct a code.''' A repaired mistype can resolve to a different organization, and the member has no way to tell that it did. Loopa refuses to guess for the same reason.
A member who is '''already in that organization''' gets a different answer ("you are already in this organization"), which is not a broken code and needs no action.
== "Can my gym see my food log?" ==
+ '''No, and there is no setting that would let it.''' An organisation sees nine counts about its own members each month — active, Premium, plans shared, plans accepted and so on — and the month. It cannot see which members those are, and nothing anybody logged crosses that boundary.
'''No, and there is no permission that would let them.''' An organization gives its members two things: a private room, and its challenges. That is the whole list.
+ This is structural rather than a policy: the connection that carries those numbers accepts a fixed list of counts and rejects anything else by name, and a test fails the build if a member identifier is added to it. You can say this plainly.
No role, whether member, admin or the person who owns it, can read a member's food log, weight, workouts, activity, measurements, progress photos, cycle, fasting or vital signs. No role there can send a member a plan or a recommendation either.
+ '''An individual coach is a separate question.''' See ''Handling coach access and consent tickets''. A coach sees only the categories the member switched on, and being in an organisation grants no coach anything.
You can say this structurally rather than as a policy: what a role may do is a fixed list of actions, anything outside it is refused, and there is no health-shaped entry on the list to grant. A test fails the build if one appears.
+ == "I left and my data is gone" ==
'''A coach is a separate question.''' Somebody who coaches at a gym is a coach because the member chose them and switched categories on, not because they work there. See ''Handling coach access and consent tickets''.
+ It is not. Leaving switches the app back to Loopa and '''deletes nothing''' — the account with the organisation and everything in it stays exactly where it is, reachable again with the same join code.
== "What does a challenge share?" ==
+ What they are most likely seeing is an empty Loopa account, because signing in to Loopa is signing in to a different account from the one they had with their organisation. Confirm which they are looking at before escalating.
'''One number, and only if the member opted in.''' Their total for the challenge's measure, over the challenge's dates. No daily breakdown, no history, nothing about anything else they log.
+ == "My organisation left Loopa" ==
A member who has not opted in '''contributes nothing and appears nowhere'''. Loopa shows them the exact sentence describing what entering shares before they enter.
+ Their account and their history are theirs and stay where they are. An organisation that stops working with us takes nothing with it, because it never held their health data.
'''A member who wants out of a challenge leaves it themselves''', from the challenge screen, at any time, including after it has finished. Nothing of theirs appears on that board afterwards. Point them at the control rather than doing anything on their behalf.
+ A suspended organisation stops branding the app, so members will see the Loopa palette again. That is expected, not a fault.
== "I joined another group and lost my old one" ==
'''Joining one organization never removes a member from another.''' If a room has disappeared for them, one of these happened:
* They '''left''' it themselves.
* They were '''removed''' by an owner or admin.
* The organization was '''suspended'''. The room is read-only, not gone.
* The organization was '''deleted''' by its owner.
Nothing about their own account is affected in any of those cases. Their subscription, their history and everything they logged are untouched, and posts they wrote in a room they left stay in that room.
== "I cannot leave my organization" ==
'''Check whether they own it.''' Owners cannot simply leave. An owner '''hands the organization to another member''' or '''deletes it'''. Both controls are on their own manage screen, and both are things they do themselves.
Everyone else, admins and ordinary members alike, leaves with one tap. If an admin or member reports that Leave is not working, that is worth escalating rather than explaining.
'''Transferring''' needs the new owner to already be a member of that organization. If the person they want to hand it to is not in the group yet, they join first with the code.
'''Deleting is permanent and has no undo.''' It takes the room and every post in it, every membership, and every challenge with its entries and results. Make sure a member asking about deletion knows that before they do it, and never do it for them.
== "Our organization is suspended" ==
'''Read-only.''' The room stays visible and readable, nobody new can join, nobody can post, and any member can still leave. Everything anybody logged is untouched, and reporting still works inside the room.
A member who cannot see the room at all is not looking at a suspension. Check whether they are still a member.
== "Somebody in our room is out of line" ==
'''Report is on every post''', and a report reaches Loopa's moderators rather than the organization. The member does not have to be an admin and does not have to tell anybody at the organization.
Owners and admins moderate their own room and only their own room. '''Loopa's moderation sits above them''', which is exactly why a report is worth using even when the person it concerns is the person running the group.
'''A mute is scoped to one room''' and wears off. It is not a report, and it is not a sanction anywhere else in Loopa.
== Escalate ==
+ * A member who believes an organisation saw something individual about them. Treat as a privacy incident, not a support question.
+ * A request to change who owns an organisation. Ownership transfers need the new owner to be an identity-verified person and are logged; only Patrick performs them.
+ * Anybody asking for a member list, an export of members, or "just the emails" from an organisation. There is no such export, because there is no such data — and the ask is worth recording.
* '''A member who believes somebody at an organization saw something individual about them.''' Treat as a privacy incident, not a support question.
* '''An organization asking for a member list, an export, or "just the emails".''' There is no such export, because there is no such data. The ask is worth recording.
* '''An organization asking to be given any view of members' health data, however framed.''' There is nothing to enable; the answer is no, and it is not a feature request to file.
* '''An admin or ordinary member who genuinely cannot leave an organization.''' That should always work.
* '''A request to remove or change an organization from the outside''': suspension, forced transfer, deletion. Platform administrators only.

'''Tickets about a gym, club or employer running Loopa.''' The member-facing article is ''Joining an organization'' on the Loopa knowledge base; send members there rather than paraphrasing.

== "My code does not work" ==

Work through these in order.

'''Read the code back.''' Codes never contain '''O, I, L, U, 0 or 1''' — those are the characters that get misread. If the member typed one, they misread something on the poster. Ask what they are looking at.

'''The code may have been retired.''' Organisations issue a new code whenever an old one has travelled further than intended, and the old one stops working the moment they do. Ask the organisation for the current one.

'''Joining may be closed.''' A closed organisation answers exactly as an unknown code does, deliberately — telling a stranger "right code, we are closed" confirms the code is real. Only the organisation can tell you which it is.

'''Rate limiting.''' Thirty attempts an hour per address. Somebody who has been retyping for a while will start getting "we could not check that code just now". It clears on the hour.

'''Do not offer to correct a code for them.''' Loopa deliberately refuses to guess: a repaired mistype can resolve to a ''different'' organisation, and the member has no way to tell it happened.

== "Can my gym see my food log?" ==

'''No, and there is no setting that would let it.''' An organisation sees nine counts about its own members each month — active, Premium, plans shared, plans accepted and so on — and the month. It cannot see which members those are, and nothing anybody logged crosses that boundary.

This is structural rather than a policy: the connection that carries those numbers accepts a fixed list of counts and rejects anything else by name, and a test fails the build if a member identifier is added to it. You can say this plainly.

'''An individual coach is a separate question.''' See ''Handling coach access and consent tickets''. A coach sees only the categories the member switched on, and being in an organisation grants no coach anything.

== "I left and my data is gone" ==

It is not. Leaving switches the app back to Loopa and '''deletes nothing''' — the account with the organisation and everything in it stays exactly where it is, reachable again with the same join code.

What they are most likely seeing is an empty Loopa account, because signing in to Loopa is signing in to a different account from the one they had with their organisation. Confirm which they are looking at before escalating.

== "My organisation left Loopa" ==

Their account and their history are theirs and stay where they are. An organisation that stops working with us takes nothing with it, because it never held their health data.

A suspended organisation stops branding the app, so members will see the Loopa palette again. That is expected, not a fault.

== Escalate ==

  • A member who believes an organisation saw something individual about them. Treat as a privacy incident, not a support question.
  • A request to change who owns an organisation. Ownership transfers need the new owner to be an identity-verified person and are logged; only Patrick performs them.
  • Anybody asking for a member list, an export of members, or "just the emails" from an organisation. There is no such export, because there is no such data — and the ask is worth recording.
'''Tickets about a gym, club or employer running Loopa.''' The member-facing article is ''Joining an organization'' on the Loopa knowledge base; send members there rather than paraphrasing.

== "My code does not work" ==

Work through these in order.

# '''Read the code back.''' Codes never contain '''O, I, L, U, 0 or 1''' — those are the characters that get misread. If the member typed one, they misread something on the poster. Ask what they are looking at.
# '''The code may have been retired.''' Organisations issue a new code whenever an old one has travelled further than intended, and the old one stops working the moment they do. Ask the organisation for the current one.
# '''Joining may be closed.''' A closed organisation answers exactly as an unknown code does, deliberately — telling a stranger "right code, we are closed" confirms the code is real. Only the organisation can tell you which it is.
# '''Rate limiting.''' Thirty attempts an hour per address. Somebody who has been retyping for a while will start getting "we could not check that code just now". It clears on the hour.

'''Do not offer to correct a code for them.''' Loopa deliberately refuses to guess: a repaired mistype can resolve to a ''different'' organisation, and the member has no way to tell it happened.

== "Can my gym see my food log?" ==

'''No, and there is no setting that would let it.''' An organisation sees nine counts about its own members each month — active, Premium, plans shared, plans accepted and so on — and the month. It cannot see which members those are, and nothing anybody logged crosses that boundary.

This is structural rather than a policy: the connection that carries those numbers accepts a fixed list of counts and rejects anything else by name, and a test fails the build if a member identifier is added to it. You can say this plainly.

'''An individual coach is a separate question.''' See ''Handling coach access and consent tickets''. A coach sees only the categories the member switched on, and being in an organisation grants no coach anything.

== "I left and my data is gone" ==

It is not. Leaving switches the app back to Loopa and '''deletes nothing''' — the account with the organisation and everything in it stays exactly where it is, reachable again with the same join code.

What they are most likely seeing is an empty Loopa account, because signing in to Loopa is signing in to a different account from the one they had with their organisation. Confirm which they are looking at before escalating.

== "My organisation left Loopa" ==

Their account and their history are theirs and stay where they are. An organisation that stops working with us takes nothing with it, because it never held their health data.

A suspended organisation stops branding the app, so members will see the Loopa palette again. That is expected, not a fault.

== Escalate ==

* A member who believes an organisation saw something individual about them. Treat as a privacy incident, not a support question.
* A request to change who owns an organisation. Ownership transfers need the new owner to be an identity-verified person and are logged; only Patrick performs them.
* Anybody asking for a member list, an export of members, or "just the emails" from an organisation. There is no such export, because there is no such data — and the ask is worth recording.