← Looci

Privacy Policy

Last updated 17 August 2026

This explains what Looci collects, why, who else touches it, and how to get rid of it.

Looci is in free beta and is run by an individual, not a company. Everything below describes the service as it works today. When it changes, this page changes with it, and the date above moves.

1. Who is responsible

Looci is operated by Luka Spalević, an individual based in Montenegro. No company has been registered yet; when one is, this section will name it and this policy will be reissued under it.

For anything in this document, including requests to see or delete your data, write to loociinfo@gmail.com.

2. What Looci collects

Because you made an account

Because you saved something

Kept on your own device, not on a server

What Looci does not do

3. Why Looci is allowed to hold it

WhatWhy it is lawful
Account detailsContract — without them there is no account to give you.
Saves, extracted content, notesContract — this is the service you asked for.
Security and abuse logsLegitimate interest — keeping the service standing up.
Emails about the serviceContract for essential notices; consent for anything else.

4. Who else touches your data

Looci is built on other people's infrastructure. These are the only processors involved, and each is bound by its own agreement:

ProcessorWhat it doesWhat it sees
SupabaseDatabase and authenticationYour account and everything you save
VercelHosting and content deliveryStandard request logs, including IP address
GoogleSign-in, only if you choose itThat you signed in to Looci

Some of these operate servers outside Montenegro and outside the EEA. Where data is transferred, it relies on those providers' standard contractual clauses.

Artificial intelligence

Looci contains features that would send the content of a save to a third-party AI provider in order to categorise or describe it. These features are switched off in the public build. While that remains true, nothing you save is sent to any AI provider. If that changes, this page will say so before it happens, naming the provider.

5. How long it is kept

6. Your rights

If you are in the EU or the EEA, the GDPR gives you the right to access your data, correct it, delete it, export it, object to processing, and complain to your national data protection authority. Looci extends every one of these rights to all users, wherever they are, because operating two standards would be worse than operating one.

Email loociinfo@gmail.com and you will get a reply within 30 days. There is no charge.

7. Security

Traffic runs over HTTPS. Database access is restricted per user with row-level security, so one account cannot read another's rows. Passwords are hashed by the authentication provider and never stored in readable form.

Honest limit: Looci is a beta run by one person. It is built carefully, but no service can promise it will never be breached. Do not store anything in Looci whose exposure would seriously harm you.

8. Children

Looci is not intended for anyone under 16, and accounts are not knowingly created for them. If you believe a child has made an account, write to us and it will be removed.

9. Changes

When this policy changes, the date at the top changes. If a change materially affects what happens to your data, account holders will be emailed before it takes effect.

10. Contact

loociinfo@gmail.com