loozy Privacy Policy
This is a courtesy translation. If there is any discrepancy, the Portuguese (Portugal) version prevails.
In short
loozy helps you find a toilet. To use it you need to create an account, with your name, a username and your email. We don't store your location, we don't track you across apps, and we don't sell data to anyone. You can tell us your sex and age range — it's optional, it helps us understand, in aggregate numbers, who uses the app, and it's never public. We only send you news by email if you ask for it, and you can change your mind at any time. You can delete everything inside the app, whenever you want.
This summary doesn't replace the text below, but it doesn't contradict it.
1. Who we are
(To be completed: name of the entity, tax number, address and contact of the data controller.)
- Privacy matters: privacidade@loozygo.com
- General support: ola@loozygo.com
- Supervisory authorities: CNPD (Portugal) and ANPD (Brazil)
2. You need an account to use loozy
Since 8 September 2026 the app asks you to create an account before showing the map. The account is free and only becomes active after you confirm your email with the code we send you. If you don't want to create an account, you can't use the app — and we collect nothing from you.
3. Which data we process, and why
When you use the map
- Your location, to show what's nearest. The app asks our server for the toilets within a radius around your position (or, if you don't grant location access, around the centre of Lisbon). The server answers and does not store that request in the database: there is no history of where you've been. Like any request, it may appear, with the IP address, in the server's technical logs for up to 30 days. Legal basis: consent, given through the system's location permission, which you can withdraw at any time.
When you create an account — required
- Name — so we know who we're talking to and the account belongs to a real person. Never shown to other people. Legal basis: performance of the contract.
- Username — the public name that signs what you contribute. You choose it and it doesn't have to relate to your name. Legal basis: performance of the contract.
- Email — to sign in and recover access. When you create the account, and when you ask to reset your password, we send a 6-digit code to that email; we only store an encrypted version of the code, valid for 10 minutes. Emails are sent through Microsoft Azure's email service (Azure Communication Services), with data in the European Union, and have no open or click tracking. Legal basis: performance of the contract.
- Password — stored only as a cryptographic hash (scrypt). We never have access to the password itself.
- Your contributions — toilets, reviews, reports, photos and favourites.
- Your acceptance of these documents — we store the date and the version of the Terms and of this Policy you accepted when creating the account. Legal basis: legal obligation to demonstrate consent (GDPR art. 7(1)).
When you create an account — optional, and only if you want
- Sex (female, male, other) and age range (for example 25–34). They serve one purpose: understanding, in aggregate numbers, who uses the app — how many people per age range, what proportion of each sex — to decide where to improve. They are never shown to anyone, never used to treat you differently, and never sold or shared. You can skip them ("prefer not to say"), and you can delete the answers in your profile at any time. Legal basis: consent (GDPR art. 6(1)(a) / LGPD art. 7-I), which is not a condition for using the app.
- Receiving news by email — only if you tick the option, which comes unticked. It's for sending you loozy news: new features, new areas on the map, partners. We never hand your email to third parties for advertising. You can untick it in your profile whenever you want and every email tells you how. Legal basis: consent (and Law no. 41/2004 in Portugal for commercial communications).
Always
- Minimal technical data for the app to work: the IP address at the time of the request, used only to stop brute-force attempts and bulk requests (an in-memory count on the server, for minutes, never written to the database), and the server's error logs.
4. What we DON'T do
- We don't keep a history of your location.
- We don't use analytics SDKs, advertising or advertising identifiers. The only statistics we produce are aggregate counts from the data you gave us in your account (section 3), with no individual profiles.
- We don't track you across apps or websites.
- We don't sell or rent personal data, nor hand your email or account data to partners. If one day we want to share something with a partner, we ask you first, separately, and you can say no.
- We make no automated decisions with legal effects on you.
4-A. Crash reports
(This section only applies when crash reporting is enabled. Today it is off — the integration exists in the code but sends nothing without configuration. Delete this section if the decision is not to enable it.)
When something breaks in the app or on the server, a technical report is sent to Sentry so we can understand what happened: the error itself, the device model, the OS version and the app version.
The report does not include your email, your passwords, your session keys, nor the addresses the app requested — which is why it doesn't include your location either, which travelled in those addresses. Legal basis: legitimate interest in keeping the service running.
5. When data leaves your phone to third parties
The base map. To draw the map, the app uses Google Maps on Android and Apple Maps on iOS. As in any app with a map, those services receive from your device the map area you're looking at and your IP address, under Google's and Apple's privacy policies. We receive and store none of it.
Walking directions. Only when you ask for them: then the coordinates of
where you are and where you want to go are sent to Project OSRM
(router.project-osrm.org), a public routing service of the OpenStreetMap
ecosystem, which returns the route.
You learn about this when you create your account, in the box you accept at sign-up, and here. The app doesn't ask again each time: asking for directions is asking for this computation. If you don't want your position to leave your phone, don't use directions — the map and everything else work without them. If the service doesn't answer, the app shows you the straight line, with the compass.
We don't store that request. We don't control what OSRM does with it. Everything else in the app works without directions.
6. Where the data lives
On Microsoft Azure servers, currently in the brazilsouth (Brazil) region.
For people in the European Union this is a transfer outside the EU to a country without an adequacy decision from the European Commission. The transfer relies on the standard contractual clauses of the data processing agreement with Microsoft. (To be confirmed and documented before publication. Moving the hosting to a European region is under evaluation.)
7. How long we keep it
- Your account and what you contributed: as long as you have an account. When you delete it, we delete it (see section 9).
- Never-confirmed accounts: if you create an account and don't confirm the email within 7 days, we delete it completely — it never had a session, so it never contributed anything.
- Sessions: access keys last 15 minutes and refresh keys 30 days; the record of each refresh key is deleted 30 days after it expires.
- Codes sent by email: valid for 10 minutes; the record is deleted 24 hours after expiry.
- Server technical logs: 30 days.
8. Your rights
You have the right to access, correct, delete, object to processing, request restriction, withdraw consent and receive your data in a portable format.
The most important part is already inside the app:
- See — Profile shows everything we have about you.
- Correct — Profile → Edit profile.
- Delete — Profile → Account settings → Delete account.
For the rest, write to privacidade@loozygo.com. We reply within 1 month (GDPR) and within 15 days for confirmation and access requests under the LGPD.
If you believe we mishandled your data, you can complain to the CNPD (Portugal) or the ANPD (Brazil).
9. What happens when you delete your account
Deleted: the account, the email, the name, the reviews and comments, the reports you sent, the photos, the favourites and every open session.
Kept: the toilets you added stay on the map, but with no link to you — the author field is cleared and the record stops being personal data.
We do it this way for a simple reason: deleting a public toilet from the map doesn't protect your privacy and harms everyone who relies on it.
There is no way to recover anything after you confirm.
10. Security
All communication is encrypted in transit (TLS 1.2 or higher) and data is encrypted at rest. Passwords are stored with scrypt. Session keys live in the operating system's vault (Keychain on iOS, Keystore on Android). Access to data is controlled at the database level itself, with per-operation rules.
If you discover a vulnerability, write to security@loozygo.com.
In the event of a data breach that puts you at risk, we notify the authority within 72 hours and inform you when the risk is high.
11. Minimum age
loozy is intended for people aged 13 or over. We don't collect the date of birth — asking for your age would mean collecting more data to protect data. If you know of an account belonging to someone younger, tell us and we delete it.
12. Third-party data on the map
Most toilets come from OpenStreetMap, under the ODbL licence. They are not personal data and don't come from you.
13. Changes to this policy
If we change something important, we let you know inside the app before the change takes effect. The date at the top always says which version is in force.