Your Data is the screen where a member reads what we hold about them, who has looked at it, who they are sharing it with, and what leaves their phone when they use an AI feature. They reach it at '''You → Preferences → Your Data'''.
This page is the procedure behind it: the reason you are asked for before you open a record, what the member reads afterwards, and how to answer a ticket that asks who has been looking.
== Before you open a member's record ==
Opening a member from the admin plane asks you '''why''' first. Pick the reason that is actually true. It becomes a sentence on that member's own screen.
Five reasons exist. What you pick on the left is what the member reads on the right:
* '''A support request from this member''' → "You had asked us for help" * '''A billing or subscription question''' → "A question about your subscription" * '''A report about this account''' → "A report about activity on your account" * '''A legal or regulatory obligation''' → "A legal obligation" * '''Investigating a fault''' → "Investigating a fault in the app"
'''The reason holds for 30 minutes, and only for that one member.''' One ticket usually means opening the member, their subscription and their logs. That is one question and it asks once. Moving to a different member asks again, because that genuinely is a different question.
'''There is no way past it.''' If the record of your read cannot be written, the read does not happen. A blank reason is not an option and neither is a wrong one: "Investigating a fault" on a curiosity look is a false statement written into a member's privacy screen.
=== The note box ===
Optional, up to 500 characters, and '''the member never sees it.''' That is what it is for. It can quote the ticket, name the person who filed a report, or carry shorthand for a colleague, none of which is the member's to read. Put the specifics there and keep them out of anything the member sees.
== What the member reads afterwards ==
Under '''Who has looked at your information''', for each read: the date and time, what was looked at in plain words ("Your food diary", "Your account details (name, email and sign-in history)"), and the reason sentence from the list above.
'''They see a role, never a name.''' It reads "Loopa support", "Loopa administrator" or "Mobieus platform operator" depending on who opened it. A member is entitled to know that somebody at Loopa opened their record and why. They are not entitled to which of us it was, and we do not hand that over. It makes a target of an agent doing their job. Say so plainly if you are asked; it is a deliberate choice, not a gap.
The screen shows the last 90 days by default with '''Show all''' for the rest. Rows are kept for the life of the account.
Coach reads appear in their own section above this one, drawn from the coaching record rather than from staff access, and only for members who have had a coach.
== "Who has looked at my data?" ==
Answer from the screen. It is the same list you would read, so send them to it rather than transcribing it:
Everything we record about staff access is on that screen: You → Preferences → Your Data, under "Who has looked at your information". It shows the date, what was opened and why, for the last 90 days, with a Show all for anything older. If a row there does not look right to you, reply and quote the date and I will look into it.
'''If the section is empty, that is the answer, and it is a good one.''' "No one from Loopa support has accessed your account" means exactly that. Do not soften it into a maybe.
=== The one thing not to say ===
'''Do not tell a member the list is a complete account of every human who could ever have seen their data.''' It is a complete account of the reads we instrument, which is the sensitive class (a member's record opened by a named principal), and it is what the privacy policy commits to. It does not cover a member appearing in a list of many members, a bulk export, the separate platform control plane, the marketing CRM that holds signup details, a moderator reading a member's network trail, or an agent reading a ticket the member themselves opened. The privacy policy says where the boundary currently sits; point at that rather than improvising a wider claim.
Safe framing:
That screen records occasions when someone at Loopa opened your record. Section 8 of the privacy policy sets out exactly what that covers today, and we would rather point you at the precise wording than summarise it loosely.
=== "Take that entry off my record" ===
We cannot, and neither can anyone else. The log is append-only: nothing here updates or deletes a row, and the database user the app runs as holds no permission to do either. Rows leave only when the account does.
That record is deliberately impossible to edit, including for us. It exists so the answer to "who looked at my data" cannot quietly change afterwards, and that only works if nobody can amend it. It is removed in full when an account is deleted.
== The rest of the screen ==
'''Who you are sharing with.''' Every family group, accountability partner and coach in one list, each with a Stop sharing control. Stopping is immediate, unilateral and needs no agreement from the other side. Stopping a family share '''does not''' end that member's Premium. The entitlement and the data sharing are separate, and members ask this often enough that it is worth saying before they do.
'''What leaves your device when you use AI.''' One row per AI feature, each opening the full disclosure of exactly what is sent, why, and that Anthropic processes it. Every feature has its own off switch; turning it off is enforced on our side, not just hidden in the app. A member who wants no AI processing at all turns off each feature they have used.
'''Export.''' One request per 7 days. The link is emailed, needs them to sign in again, and dies after 7 days or one download, whichever comes first. A member who lost the link waits out the window or asks us; a second request inside 7 days is refused by the system, not by us.
'''Delete account.''' 30 days of grace, cancellable by signing in during that window. Purchases made through Apple or Google are '''not''' cancelled by deleting the account (the screen says so and links to the right subscription page), so check the member has done that too, or they will keep being charged for an account that no longer exists.
== Things support cannot do ==
* Tell a member which member of staff opened their record. * Edit or remove a row from the access record, on request or otherwise. * Read another member's access record while answering this one. * Open a record without giving a reason. * Cancel an Apple subscription on a member's behalf. There is no such facility; the member does it in their own store settings.
== Escalate to Patrick ==
* A member disputing a row. They say nobody should have opened their record, and the reason does not explain it. * Any request for the identity of a member of staff who read a record. * A regulator, a lawyer, or a member citing Washington's My Health My Data Act, Nevada SB 370, GDPR, PIPEDA or Quebec Law 25 by name. * A member asking for a complete list of everyone who has ever seen their data. The honest answer has a boundary in it, and that answer is worth getting right.
Your Data is the screen where a member reads what we hold about them, who has
looked at it, who they are sharing it with, and what leaves their phone when they
use an AI feature. They reach it at '''You → Preferences → Your Data'''.
This page is the procedure behind it: the reason you are asked for before you open
a record, what the member reads afterwards, and how to answer a ticket that asks
who has been looking.
== Before you open a member's record ==
Opening a member from the admin plane asks you '''why''' first. Pick the reason
that is actually true. It becomes a sentence on that member's own screen.
Five reasons exist. What you pick on the left is what the member reads on the
right:
* '''A support request from this member''' → "You had asked us for help"
* '''A billing or subscription question''' → "A question about your subscription"
* '''A report about this account''' → "A report about activity on your account"
* '''A legal or regulatory obligation''' → "A legal obligation"
* '''Investigating a fault''' → "Investigating a fault in the app"
'''The reason holds for 30 minutes, and only for that one member.''' One ticket
usually means opening the member, their subscription and their logs. That is one
question and it asks once. Moving to a different member asks again, because that
genuinely is a different question.
'''There is no way past it.''' If the record of your read cannot be written, the
read does not happen. A blank reason is not an option and neither is a wrong one:
"Investigating a fault" on a curiosity look is a false statement written into a
member's privacy screen.
=== The note box ===
Optional, up to 500 characters, and '''the member never sees it.''' That is what
it is for. It can quote the ticket, name the person who filed a report, or carry
shorthand for a colleague, none of which is the member's to read. Put the specifics
there and keep them out of anything the member sees.
== What the member reads afterwards ==
Under '''Who has looked at your information''', for each read: the date and time,
what was looked at in plain words ("Your food diary", "Your account details (name,
email and sign-in history)"), and the reason sentence from the list above.
'''They see a role, never a name.''' It reads "Loopa support", "Loopa
administrator" or "Mobieus platform operator" depending on who opened it. A member
is entitled to know that somebody at Loopa opened their record and why. They are
not entitled to which of us it was, and we do not hand that over. It makes a
target of an agent doing their job. Say so plainly if you are asked; it is a
deliberate choice, not a gap.
The screen shows the last 90 days by default with '''Show all''' for the rest.
Rows are kept for the life of the account.
Coach reads appear in their own section above this one, drawn from the coaching
record rather than from staff access, and only for members who have had a coach.
== "Who has looked at my data?" ==
Answer from the screen. It is the same list you would read, so send them to it
rather than transcribing it:
<blockquote>
Everything we record about staff access is on that screen: You → Preferences →
Your Data, under "Who has looked at your information". It shows the date, what was
opened and why, for the last 90 days, with a Show all for anything older. If a row
there does not look right to you, reply and quote the date and I will look into it.
</blockquote>
'''If the section is empty, that is the answer, and it is a good one.''' "No one
from Loopa support has accessed your account" means exactly that. Do not soften it
into a maybe.
=== The one thing not to say ===
'''Do not tell a member the list is a complete account of every human who could
ever have seen their data.''' It is a complete account of the reads we instrument,
which is the sensitive class (a member's record opened by a named principal), and
it is what the privacy policy commits to. It does not cover a member appearing in
a list of many members, a bulk export, the separate platform control plane, the
marketing CRM that holds signup details, a moderator reading a member's network
trail, or an agent reading a ticket the member themselves opened. The privacy
policy says where the boundary currently sits; point at that rather than
improvising a wider claim.
Safe framing:
<blockquote>
That screen records occasions when someone at Loopa opened your record. Section 8
of the privacy policy sets out exactly what that covers today, and we would rather
point you at the precise wording than summarise it loosely.
</blockquote>
=== "Take that entry off my record" ===
We cannot, and neither can anyone else. The log is append-only: nothing here
updates or deletes a row, and the database user the app runs as holds no permission
to do either. Rows leave only when the account does.
<blockquote>
That record is deliberately impossible to edit, including for us. It exists
so the answer to "who looked at my data" cannot quietly change afterwards, and that
only works if nobody can amend it. It is removed in full when an account is deleted.
</blockquote>
== The rest of the screen ==
'''Who you are sharing with.''' Every family group, accountability partner and
coach in one list, each with a Stop sharing control. Stopping is immediate,
unilateral and needs no agreement from the other side. Stopping a family share
'''does not''' end that member's Premium. The entitlement and the data sharing are
separate, and members ask this often enough that it is worth saying before they do.
'''What leaves your device when you use AI.''' One row per AI feature, each opening
the full disclosure of exactly what is sent, why, and that Anthropic processes it.
Every feature has its own off switch; turning it off is enforced on our side, not
just hidden in the app. A member who wants no AI processing at all turns off each
feature they have used.
'''Export.''' One request per 7 days. The link is emailed, needs them to sign in
again, and dies after 7 days or one download, whichever comes first. A member who
lost the link waits out the window or asks us; a second request inside 7 days is
refused by the system, not by us.
'''Delete account.''' 30 days of grace, cancellable by signing in during that
window. Purchases made through Apple or Google are '''not''' cancelled by deleting
the account (the screen says so and links to the right subscription page), so
check the member has done that too, or they will keep being charged for an account
that no longer exists.
== Things support cannot do ==
* Tell a member which member of staff opened their record.
* Edit or remove a row from the access record, on request or otherwise.
* Read another member's access record while answering this one.
* Open a record without giving a reason.
* Cancel an Apple subscription on a member's behalf. There is no such facility; the member does it in their own store settings.
== Escalate to Patrick ==
* A member disputing a row. They say nobody should have opened their record, and the reason does not explain it.
* Any request for the identity of a member of staff who read a record.
* A regulator, a lawyer, or a member citing Washington's My Health My Data Act, Nevada SB 370, GDPR, PIPEDA or Quebec Law 25 by name.
* A member asking for a complete list of everyone who has ever seen their data. The honest answer has a boundary in it, and that answer is worth getting right.