Legal
Privacy
Last updated 1 September 2026
This describes what happens to an image you upload. It is written to be accurate rather than comforting; where something is a risk, it says so.
There is no account
LoopIt has no sign-up, no password and no email address for you. To show you your own past analyses, your browser generates a random token and keeps it in local storage. Only a SHA-256 hash of it is stored on the server, so reading the database does not yield a working credential.
Clearing your browser data destroys that token and, with it, your ability to list your own uploads. Individual results remain reachable at their own links.
What is stored
- The image, for thirty days, then deleted automatically.
- Any context you typed, alongside the result.
- The analysis — candidate coordinates, confidence scores and the evidence cited. Kept after the image is deleted, so the confidence model can be measured and improved.
- A hash of your browser token, to scope your list of uploads to you.
- Coarse request data — IP-derived rate-limiting counters, held in memory and not written to disk.
The image itself is not published, listed or indexed. There is no public gallery and no endpoint that returns other people’s uploads.
Who your image is sent to
Analysis requires third parties. Your image, or data derived from it, is sent to:
- OpenRouter, which routes it to Google’s Gemini model for visual reasoning. The image is transmitted in full.
- Mapillary (Meta) — coordinates only, to fetch street-level photographs for comparison. Your image is not sent.
- OpenStreetMap Nominatim — text read from the image, to resolve place names.
- CARTO and OpenStreetMap — map tiles, requested by your browser.
- Akash (compute) and Vercel (website hosting).
Each has its own terms and retention. We use paid API tiers where available, which generally excludes your image from being used to train those providers’ models — but that is their undertaking, not ours, and you should read theirs if it matters to you.
Photographs of people
Photographs frequently contain people who never agreed to be uploaded. Two things follow.
Where an image appears to have identifiable people as its main subject, LoopIt deliberately reduces the precision of the location it reports. This is a mitigation, not a solution.
If an image of you has been uploaded, write to hello@loopit.fun and it will be deleted. You do not need an account, and you do not need to prove anything.
Sharing a result
A result link contains 128 bits of randomness and cannot be guessed or enumerated. It is not secret in any other sense: anyone you send it to can open it, and so can anyone they forward it to. Sharing the link shares the photograph.
Your rights
You can ask what is held about you, ask for it to be corrected, or ask for it to be deleted, by writing to hello@loopit.fun. Because there are no accounts, identifying which records are yours may require the result link.
If you are in the UK or EU and are unhappy with how a request was handled, you can complain to your data protection authority.
Cookies
None. No analytics, no advertising, no third-party trackers. The browser token described above is local storage, not a cookie, and is never sent anywhere except to LoopIt’s own API.
Changes
If what we do with your data changes, this page changes and the date at the top moves.
Questions about any of this: hello@loopit.fun