Loppos
Value an image0My route
HomeMapMy routeGuides & articlesFAQAbout usBusiness
Menu
HomeMapMy routeGuides & articlesFAQAbout usBusiness
Language
App privacy

App Privacy Policy

Last updated 19 July 2026 · For the Loppos mobile app

1. Who is responsible2. What we process3. Why we process it, and on what legal basis4. AI appraisal5. Automated image moderation6. Translation7. Location8. Statistics — and how to switch it off9. Reporting, blocking and moderation10. Who else processes your data11. Transfers outside the EU/EEA12. How long we keep it13. Automated decisions14. Security15. Your rights16. Complaints17. Age18. Changes

This policy explains what personal data the Loppos app processes, why, on what legal basis, who else sees it and how long we keep it. The loppos.com website has its own separate policy.

1. Who is responsible

The data controller is:

Michelangelo AB
Tröinge Hällinge 102
311 38 Falkenberg, Sweden
Company registration number 559588-9386
Email: support@loppos.com

Write to that address for anything in this policy, including all of the rights described in section 12.

2. What we process

CategoryWhat it is
AccountEmail address and password (stored hashed by our authentication provider), or the identity token from Sign in with Apple / Google. Plus your internal user ID.
ProfileUsername, display name, bio, avatar image, city, country, language, seller status, subscription tier, referral code, and your Instagram/Facebook handle if you add one. Also your privacy settings.
Content you createListings (title, description, price, photos), finds/scans (photo, the AI result, tags), boards, reviews (rating, free text, one photo), check-ins, favourites and who you follow.
MessagesThe text of direct messages between you and other users, and the thread they belong to. Messages are text only — no attachments. Also any email you send to support.
LocationPrecise coordinates from your device, only while you use the app and only if you grant permission. Coordinates are stored with each check-in (latitude, longitude, accuracy, country, region), and your last known position is stored on your profile row so the map can open where you are.
Usage dataEvent name, screen name, event properties, session ID, platform, app version, your user ID when signed in, and anon_id — a random identifier generated on your device and stored in the app. It is not an advertising ID and not a system device ID, and it disappears when you uninstall the app.
Push tokenThe push token issued by Expo for your device, plus the platform, if you allow notifications.
PurchasesSubscription and entitlement status. Payment is handled entirely by Apple or Google — we never receive your card details.
Business claimsIf you claim or register a shop: contact name, email, phone, company registration number, street address, postal code, city, country, website, social handles, shop description, opening hours and shop images.
Safety dataReports you submit (what was reported, the reason, and your user ID), your block list, and moderation decisions taken on your content.
Deletion requestsA hashed confirmation token and the relevant timestamps.

3. Why we process it, and on what legal basis

PurposeLegal basis (GDPR art. 6)
Create and secure your account; deliver the app's core features (listings, finds, boards, reviews, check-ins, messages); send service emails such as sign-in, confirmation and deletion linksPerformance of a contract, art. 6(1)(b)
Produce an AI appraisal from the photo you scanPerformance of a contract, art. 6(1)(b) — this is the service you asked for
Enrich an appraisal with external image recognition (OCR, logo and visual product matching) to make it more accurateLegitimate interest, art. 6(1)(f). Our interest is giving you a usable valuation rather than a guess; the data used is the photo you deliberately submitted for that exact purpose, so the impact on you is minimal.
Automated screening of uploaded images for adult or violent content, and handling of reports, blocks and moderationLegitimate interest, art. 6(1)(f). Our interest — and yours — is a marketplace free of offensive material. This is also what app store rules require of us. Only the image and the resulting verdict are processed.
Show you markets, shops and finds near you; let you check inYour consent to location access, art. 6(1)(a), which you can withdraw at any time in your device settings
Translate reviews, listings and appraisals into your languageLegitimate interest, art. 6(1)(f) — making content readable across four markets. Applies only to text already published in the app.
Send push notificationsYour consent to notifications, art. 6(1)(a)
Product statistics to understand and improve the appLegitimate interest, art. 6(1)(f). We use no advertising or attribution SDKs and share nothing with third parties, so the intrusion is low — and you can switch it off entirely (section 8).
Manage subscriptions and purchasesPerformance of a contract, art. 6(1)(b)
Handle business claims and verify shopsSteps taken at your request prior to a contract, art. 6(1)(b), and our legitimate interest in verifying that a shop is claimed by its real owner, art. 6(1)(f)
Keep records of moderation decisionsLegitimate interest and accountability, art. 6(1)(f) and art. 5(2)
Comply with accounting and other statutory dutiesLegal obligation, art. 6(1)(c)

Where we rely on legitimate interest, you have the right to object — see section 12.

4. AI appraisal

When you scan an item, the photo leaves our servers and is sent to external AI providers so they can identify the object and estimate a value. Depending on configuration, the following may receive the photo:

  • Anthropic (Claude) and/or Google (Gemini) — the model that writes the actual appraisal.
  • Google Cloud Vision — optional image recognition: text on the object (OCR), logos, and similar images on the web.
  • SerpApi (Google Lens) — optional visual product matching. To do this we place a temporary copy of the photo in our storage and generate a link that is valid for 300 seconds; the temporary copy is deleted immediately after the lookup.

Your appraisal photo itself is stored in your account in a private store that is not publicly reachable. When the app needs to display it, it generates a temporary link valid for one hour.

To avoid asking the same question twice, we cache the recognition results (not the image) under a hash of the image. A cached result is reused for at most 24 hours and the cache entry is deleted after 30 days.

Please do not scan photos containing other people, documents or sensitive information you do not want sent to these providers.

5. Automated image moderation

Every image you upload — profile picture, shop logo and cover, shop and place photos, listing photos, review photos and business-claim images — is sent to Google Cloud Vision SafeSearch before it is published, so we can detect adult or violent material. The upload runs through our own server, which screens the image and then stores it; the app cannot bypass this.

There are two outcomes:

  • Rejected — for profile pictures, shop logos and covers, shop, place and claim photos, the image is never stored and you get an error message.
  • Flagged — for listing photos, review photos and finds, the image is stored but hidden and sent to our moderation queue, where a person reviews it before it is either published or removed.

Only the image and the resulting verdict are processed; we keep a record of the verdict so we can measure and correct the thresholds. If you believe your image was wrongly rejected or hidden, write to support@loppos.com and a person will look at it.

6. Translation

Loppos runs in Swedish, Danish, English and German. When content needs to be shown in another language, the text of a review, a listing or an appraisal is sent to Anthropic or Google (Gemini) for translation. No images are sent for translation.

7. Location

Location is only ever read while the app is open and in use — there is no background location tracking. You can decline; the location-based features will simply not work. Note that when you check in, the coordinates are saved as part of that check-in, and your most recent position is saved on your profile so the map opens in the right place. Your own check-ins are only readable by you; check-in activity may be shown publicly as being at a given place.

When you search for an address or a town, that text is sent to OpenStreetMap Nominatim or, via our server, to Google's geocoding service. Map tiles are loaded directly from CARTO (and OpenStreetMap on the web), which means those providers see your IP address and which part of the map you are looking at. If you tap "navigate", the destination is handed to Apple Maps, Google Maps or Waze — after that, their own privacy policies apply.

8. Statistics — and how to switch it off

We record basic in-app events (which screens are opened, which key actions are taken) to understand how the app is used. To be precise about what this is and is not:

  • The data goes to our own database only. No third party receives it.
  • The app contains no advertising, attribution or third-party analytics SDKs, and no crash-reporting SDK.
  • We do not track you across other companies' apps or websites, we do not build advertising profiles, and we do not sell data.
  • The data is pseudonymous, not anonymous — your user ID is attached while you are signed in.

You can turn statistics off completely under Settings in the app. The switch works on both iOS and Android and takes effect immediately.

9. Reporting, blocking and moderation

You can report content and block other users. A report records what was reported, the reason you gave and your user ID, and it goes to a moderation queue where a person decides. Administrators can hide content and suspend accounts. Every administrative action is written to an internal audit log. A small number of authorised staff can access user data, including private content, where it is necessary for moderation and support.

10. Who else processes your data

We use the following providers. They process data on our instructions only and may not use it for their own purposes.

ProviderWhat they processEstablished
SupabaseHosting, database, authentication and image storage — all of your data passes through hereUSA
AnthropicAI appraisal of scan photos; translation of textUSA
Google (Gemini, Cloud Vision, Geocoding, Places)AI appraisal, image recognition, SafeSearch moderation, translation, address and place lookupsUSA
SerpApiVisual product matching via Google Lens (temporary link to the scan photo)USA
ResendSending emails: sign-in, welcome, deletion confirmation, shop approvalUSA
RevenueCatSubscription management; receives your user ID and purchase statusUSA
Apple / GoogleApp distribution and all payment processingUSA
ExpoPush notification delivery (onward to Apple APNs / Google FCM)USA
CARTO and OpenStreetMapMap tiles and address search; they receive your IP address and map requests directly from your deviceUSA / Europe
MetaInstagram oEmbed, used only to fetch public posts a seller has explicitly chosen to featureUSA

We do not sell your personal data, and we do not share it for advertising.

Instagram content

Sellers can choose to feature their own public Instagram posts inside the app. A seller connects their public username, gives explicit consent and submits a link to one of their own public posts; we then retrieve it through Instagram's official oEmbed service and store the public username, caption, thumbnail and permalink. We do not scrape, and we do not access private accounts or other people's content. If a post is removed or made private on Instagram, we remove it from Loppos.

11. Transfers outside the EU/EEA

Your account, your content and your images are stored in Supabase's EU region — that data does not leave the EU/EEA at rest. As the table above shows, several of the providers we send data to are established in the United States, so those transfers do leave the EU/EEA. For those transfers we rely on the European Commission's standard contractual clauses and, where the provider is certified, the EU–US Data Privacy Framework. You can ask us which safeguard applies to a specific provider by writing to support@loppos.com.

12. How long we keep it

DataRetention
Account, profile and the content you createFor as long as your account exists
A deleted accountHidden immediately, then permanently deleted after a 30-day grace period. The deletion job runs every night at 03:17 UTC.
The deletion confirmation link24 hours
Your imagesWith your account. On permanent deletion they are removed from all six of our storage areas — scans, avatars, shops, listings, reviews and Instagram thumbnails.
Recognition cache (external results, no images)Reused for at most 24 hours; deleted after 30 days
Temporary copy sent for visual matchingLink valid 300 seconds; the copy is deleted right after the lookup
Temporary links to your private scan photos1 hour
Business claim submissionsDeleted in full when you delete your account
Usage events24 months. Flea markets are strongly seasonal, so product analysis only becomes meaningful year over year; two years gives us one full year to compare against. When you delete your account, your user ID and device identifier are stripped from these records straight away, leaving statistics that cannot be traced back to you.
Moderation records and the administrative audit logKept for accountability; no fixed limit at present

How deletion actually works

You start deletion in the app under Settings → Delete account. We email you a confirmation link, valid for 24 hours. Once you click it, your profile is hidden immediately and your account is locked. After 30 days — during which you can contact us to regret it — an automated job permanently deletes your account, your images in all six storage areas, and your business claim submissions, and strips the identifiers from your usage events.

13. Automated decisions

Two things in Loppos are automated, and we want to be straight about both.

The AI appraisal is an estimate for guidance only. It has no legal effect on you, it does not decide anything about you as a person, and it is not a decision within the meaning of GDPR art. 22.

Image moderation automatically rejects or hides images. In our assessment this is not an art. 22 decision either, because it produces no legal or similarly significant effect on you. But it is automated and it can be wrong, so a human being reviews every flagged image, and you can always contact support@loppos.com to have a rejection reviewed by a person.

14. Security

Data is protected by row-level access control in the database, so each user can only reach their own records. Scan photos and Instagram thumbnails are held in private storage that is not publicly reachable and can only be opened through short-lived, signed links. Images that belong to public content — listings, shops, reviews and avatars — are publicly readable by design, because that content is public. Uploads run through our own server so they can be screened before storage. Passwords are stored hashed by our authentication provider, and we never see your payment details.

15. Your rights

Under the GDPR you have the right to:

  • Access — get a copy of the data we hold about you.
  • Rectification — have inaccurate data corrected. Most profile fields you can edit yourself in the app.
  • Erasure — have your data deleted. Use Settings → Delete account, or write to us.
  • Restriction — have processing limited while a dispute is resolved.
  • Objection — object to processing based on legitimate interest, including our product statistics. For statistics you can act immediately with the switch in Settings.
  • Data portability — receive the data you provided in a machine-readable format.
  • Withdraw consent — turn off location or notifications in your device settings at any time. Withdrawal does not affect processing that already took place.

To exercise any of these, write to support@loppos.com. We reply within one month.

16. Complaints

If you think we handle your data unlawfully, please tell us first — but you always have the right to complain to a supervisory authority. Ours is the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, imy.se. You may also complain to the authority in the country where you live or work: in Denmark that is Datatilsynet, and in Germany the competent state data protection authority.

17. Age

Loppos has a minimum age of 16. The app has free-text messaging, location features and physical meeting places, and although some countries permit a lower age under GDPR art. 8, we apply 16 across all our markets. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will remove it.

18. Changes

We may update this policy. The "last updated" date at the top always reflects the current version. If we make a significant change we will tell you in the app.

Loppos

Loppos news

New guides, find tips and flea-market news — straight to your inbox. No noise, just the best.

Thanks for subscribing.

Discover

Finds near youAntique shops & flea marketsGuides & articlesValue a find

Loppos

About usFAQFor shopsMy routeDownload the app
© 2026 Loppos · Rare findsPrivacy PolicyTerms of UseDelete accountContact
The Loppos app

Coming soon

The Loppos app is coming soon to the App Store and Google Play.