LEGAL
Privacy Policy
Effective October 3, 2026
1. Who we are
Loomora Fitness is operated by Loomora (“we,” “us”), based in Indonesia. We respect your privacy and collect only what we need to make the app work for you.
2. What we collect
Account data — email, name, password (stored as a one-way bcrypt hash), and a Google account identifier if you sign in with Google. Google tokens are used to verify sign-in.
Workout data — exercises, sets, reps, weights, routines, body weight, daily check-ins, and personal records you log in the app.
Device & usage — timing of key events (workout_started, set_logged, session_finished). We do not collect your contacts, photos, location, or microphone data.
3. Why we use it
- To provide the core training & tracking features
- To sync your data across devices
- To send transactional emails (password reset, weekly recap)
- To understand app usage and improve the product
We do not sell your data. We do not show ads. We do not share your workout data with third-party advertisers.
4. Where it lives
Your workout data is stored locally on your device and synchronised to our API. The API uses ArangoDB for account and workout records and Redis for caching and background jobs. Email is delivered via Resend.
5. Service providers we share with
- Resend — sends transactional emails; receives your email address and the email content.
- Google Sign-In — authenticates you when you choose to sign in with Google.
- Vercel — hosts our website and processes requests made to the website.
Each provider operates under their own privacy policy and processes data only as needed to deliver their part of the Service.
6. Your rights
You can:
- Access your workout history and profile in the app
- Correct any data through the app
- Request deletion of your account and associated data through our account deletion page
- Contact support about your email preferences
- Request a copy of all data we hold about you by emailing hello@heyloomora.com
7. Security
Our production API uses HTTPS for data in transit. Passwords are hashed with bcrypt. Authentication uses access and refresh tokens. We follow industry-standard practices to keep your data safe, but no system is impenetrable; report suspected vulnerabilities to hello@heyloomora.com.
8. Children
The Service is not intended for users under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us and we will delete it.
9. International transfers
If you are outside Indonesia, your data may be processed on servers in Indonesia or other regions where our service providers operate. Contact us for information about the providers used to process your data.
10. Retention
Account and workout data are kept while your account is active. To request deletion, contact us through the account deletion page. We verify account ownership and confirm the scope and processing timeframe. If any data must be retained for a legal or security reason, we explain that retention when handling your request.
11. Changes
We may update this policy. The effective date above identifies the latest version.
12. Contact
Privacy questions or requests: hello@heyloomora.com.