← Back to home

Privacy Policy

Effective 13 May 2026 · Last updated 8 September 2026

In short: we collect what LOQI needs to work: your email, the places you pin, and the location you ask recommendations for. We store your account and content in the EU, we never sell your data, and you can have it deleted any time at privacy@loqimaps.com. LOQI Recommendations are powered by Anthropic (Claude) and Google, so some of what you search is shared with them to answer your request.

1. Introduction

This policy explains what personal data LOQI processes, why, on what legal basis, how long we keep it, and who we share it with. It covers both the LOQI website (loqimaps.com, including the waitlist) and the LOQI mobile app.

This is a plain-language summary of how we handle your data. It is not a substitute for legal advice. Because LOQI processes location and user content, we recommend having the final version reviewed by a qualified professional.

2. Who we are (data controller)

LOQI is operated by Grande Developers, a Dutch general partnership (vennootschap onder firma), registered with the Netherlands Chamber of Commerce (KvK) under number 42091088, at De Clercqstraat 76 3, 1052 NK Amsterdam, Netherlands.

For any privacy or legal question, or to exercise your rights, contact us at privacy@loqimaps.com.

3. What data we collect and why

We only collect what we need to run LOQI. Per category we describe the purpose, the legal basis under the GDPR, how long we keep it, and who we share it with (see sections 4 to 9).

Account data

  • Your email address, to sign you in, manage your account, and send transactional email.
  • Your password is never stored in a readable form. Authentication runs through Supabase Auth; passwords are stored hashed and we cannot see them. If you sign in with Google or Apple, we do not manage a password at all.
  • Your profile photo, username and display name.
  • With social login: the name and avatar the provider (Google or Apple) passes to us.

Content you create

  • Pins (saved places): name, location or coordinates, category, notes and photos.
  • Ratings and likes.
  • Shared maps and who takes part in them.
  • Follow relationships (who follows whom).

Location

  • The location of the places you pin.
  • The area or location you request recommendations for.

Location is sensitive data. We use it only for the map and recommendation features, not for anything else.

Usage and technical data

  • Basic usage data needed to run the app (which actions you take), used to show your feed and notifications.

Website and waitlist data

  • If you join the waitlist on loqimaps.com: your email, an approximate IP address and user agent (via our host), the signup timestamp, and the tier or position assigned to you.

The signup fingerprint

When you create an account we store a keyed cryptographic fingerprint of your email address, computed with a secret key that never leaves our server. It is not your address and cannot be turned back into one, and without that key nobody can test whether a particular address appears in the list.

We keep this fingerprint if you delete your account, for one reason only: it stops the same address being used again and again to collect the free starter coin. We do this on the basis of our legitimate interest in preventing fraud (Recital 47 GDPR). It is used for nothing else, it is never shared, and you can object to it at privacy@loqimaps.com.

4. Why we collect it and legal basis (GDPR)

We rely on the following legal bases under Article 6(1) GDPR:

  • Performance of a contract (Art. 6(1)(b)) for core functions: creating and running your account, storing your pins, showing your feed, and delivering features you use.
  • Consent (Art. 6(1)(a)) where it applies, such as location. You can withdraw consent at any time.
  • Legitimate interest (Art. 6(1)(f)) for keeping the service secure and working (for example basic technical logging), and for using pins in LOQI Recommendations and trending, which you can object to at any time (see section 5).

5. LOQI Recommendations

LOQI Recommendations are powered by AI (Anthropic, Claude) through a server-side Supabase Edge Function (recommend-spots). The app never talks to an AI service directly; the API keys are server-side secrets. The models used are claude-sonnet-4-6 and claude-haiku-4-5. We also use Google Places (New) for place data and reviews.

What we send to Anthropic when you request a recommendation

  • The free-text search you type.
  • The location or area you want the recommendation for.
  • From friends' pins: the name, category and note of candidate places.
  • Google review snippets of candidate places, so they can be ranked.

Claude uses a web-search tool to answer, which means your search query may also reach the open internet through Anthropic.

What we send to Google: place searches and the retrieval of reviews and metadata.

According to Anthropic's commercial terms, data submitted through their API is not used to train their models. We state this based on their current published terms; because provider terms can change, this should be verified against their live commercial terms.

Your control: in the app you can exclude your own pins from recommendations and trending using the privacy toggle.

Your pins in other people's recommendations

When someone you are connected to asks LOQI for a recommendation, the name, category and note of your saved places can be used as candidates for their result, and can appear in trending. We do this on the basis of our legitimate interest in making recommendations that come from real people rather than from advertising, which is the point of LOQI.

You can object at any time. In the app, under Settings, there is a switch that excludes your own pins from LOQI Recommendations and from trending. Turning it off stops this processing for you from that moment on, and no reason is required.

6. How Plus and Max are billed

The Plus and Max subscriptions are billed through Apple's in-app purchases (App Store) and Google's in-app purchases (Play Store), managed via RevenueCat. Apple's and Google's billing, cancellation and refund rules apply, not ours: cancellation and refunds run through your own App Store or Play Store account. We do not process or store any payment details or card numbers.

7. Who we share data with (processors)

We share data only with the providers that help us run LOQI:

  • Supabase, for hosting, database and authentication.
  • Anthropic and Google, for recommendations (see section 5).
  • Apple and Google, for payments (see section 6).
  • Google, for the map itself. LOQI’s maps are rendered by Google Maps. Whenever you open or move a map, the area you are looking at is sent to Google so it can return the map tiles.
  • RevenueCat, for managing subscriptions and receipts. It receives your LOQI account id and the purchase events from Apple and Google.
  • Resend, for sending transactional email.
  • Sentry, for crash reporting, so we are told when the app breaks.
  • PostHog, for product analytics. Only if you turn it on yourself under Settings.
  • Google, for advertising through AdMob. Not active in the current version of the app: no ads are shown and no advertising identifier is read. If we introduce ads, they would be for users on the free plan only, and only after you have answered the tracking permission question on your phone.
  • Meta (Facebook and Instagram), for advertising measurement and audiences, only after you have given consent.
  • Apple, when you use voice input, your speech is sent to Apple's speech recognition service to be turned into text; when the app shows a city name for a location, Apple's geocoding service converts the coordinates into a place name. Apple Inc., Cupertino, USA; see apple.com/legal/privacy.

We never sell your personal data.

Other parties your device may contact

Venue websites, when you open a place, the app may load that venue's own website to find its Instagram link. That website then sees your IP address and device type, exactly as it would if you opened it in a browser. We do not choose or control those websites.

8. Data location and international transfers

Our database and authentication (Supabase) run on AWS in the eu-west-1 (Ireland) region, so within the EU. The personal data we store, being accounts, pins, locations and photos, stays in Europe.

For recommendations, some data is sent to Anthropic and Google, both US companies, which means a transfer outside the EU takes place. If you accept marketing cookies, advertising data is also sent to Meta, a US company, which is another transfer outside the EU relying on the EU-US Data Privacy Framework. When you use voice input, or when the app shows a city name for a location, that data is sent to Apple, a US company, which is another transfer outside the EU. Where such transfers occur, they rely on the recipient's transfer safeguards (typically the EU Standard Contractual Clauses or the EU-US Data Privacy Framework). This should be confirmed against each provider's current data-processing terms.

9. Data retention

We keep your account data and content for as long as your account exists. If you request deletion, we remove your personal data. Waitlist data is kept until you request deletion, or up to 90 days after launch once a reward has been claimed or declined, or until LOQI ceases operating.

10. Your rights

Under the GDPR you have the right to access, correct, delete, and port your data, to object to processing, and to withdraw consent. You can exercise any of these by emailing privacy@loqimaps.com, and you can have your account deleted. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

11. Cookies and tracking

On the website

We use Vercel Analytics, which does not use cookies. For advertising, we use the Meta Pixel and Meta Conversions API to measure how our ads perform and to reach relevant audiences. These load only after you accept marketing cookies in our consent banner. If you decline, no Meta tracking runs and no Meta cookie is set. You can change your choice any time through the Cookie preferences link in the footer. We do not use Google Analytics. The advertising tracking relies on your consent under Article 6(1)(a) GDPR, which you can withdraw at any time.

In the app

Nothing on your phone is tracked without you being asked first.

  • Advertising. The current version of the app shows no ads. Nothing asks for tracking permission and no advertising identifier is read. If we introduce ads later, they would be served by Google AdMob to people on the free plan, iOS would first ask whether LOQI may track you across other companies' apps and websites, and saying no would still leave you with ads, just not personalised ones.
  • Product analytics. We use PostHog to see where people get stuck. This is off by default. It only runs if you switch it on yourself under Settings, Help Improve LOQI, it is linked to your account id, and you can switch it off again at any time.
  • Crash reporting. We use Sentry to be told when the app crashes. It collects the technical details of the crash, not the contents of your pins.

12. Children's privacy

LOQI is not intended for children under 16. We do not knowingly collect data from anyone under 16.

13. Security

  • Passwords are hashed via Supabase Auth.
  • Access to your data is protected with Row Level Security, so you only see your own data and what is shared with you. Photos are stored as separate files with a long, unguessable address. We never publish those addresses, but anyone who receives one can open that photo.
  • API keys are kept server-side and never shipped in the app.
  • Data is stored within the EU (Supabase, AWS eu-west-1).

14. Changes

If we make material changes to this policy, we will update the "Last updated" date above and, where appropriate, notify you.

15. Contact

Questions about your privacy? Email privacy@loqimaps.com.