loupe
Privacy Policy
Last updated 2026-08-05 · Version 0.1 (DRAFT)
Draft for review
This document is a working draft prepared to be reviewed by a qualified lawyer. It is not legal advice, and some details (marked with brackets) still need to be finalised before publishing.
This is a draft prepared for review by a qualified lawyer. It is not legal advice.
Loupe ("Loupe", "we", "us", "our"), operated by Loupeco Pty Ltd, ABN 20 701 804 926, of [REGISTERED ADDRESS], provides a private ledger that helps you catalogue the designer handbags you own, track an ongoing market-value estimate for each piece, and keep documentation so you are better prepared for insurance and appraisal.
This Privacy Policy explains what personal information we collect, how we use and protect it, and the choices and rights you have. We handle personal information in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where it applies to you, the EU General Data Protection Regulation (GDPR) and the UK GDPR. Loupe launches in Australia and is built to serve users in multiple regions.
By using Loupe you agree to this Policy. If you do not agree, please do not use Loupe.
1. Who is responsible for your information
Loupeco Pty Ltd is the entity responsible for your personal information (the "data controller" under GDPR). Our contact details for privacy matters are in section 15.
2. The information we collect
We collect only what we need to run Loupe. This includes:
Account and identity information, your name, email address, password credentials (managed by our authentication provider; we do not store your raw password), country, and preferred currency.
Collection and piece information, details you add or that our tools extract about your pieces: brand, model, materials, hardware, colour, size, year, condition, purchase price and currency, purchase date, purchase location, and your own notes.
Documents and images you upload, photographs of your pieces, and documents such as receipts, invoices, appraisals, and certificates. These may themselves contain personal information (for example, your name, a store, a card's last four digits, or a purchase date). Please avoid uploading more sensitive information than you need to.
Valuation and usage data, the estimates, confidence levels, comparable-sales counts, and value history we generate for your pieces, and records of how you use Loupe (for example, features used and reports exported).
Billing information, if you subscribe to a paid plan, our payments provider (Stripe) processes your payment details. We receive limited information such as your subscription status, plan, and billing country. We do not store full card numbers.
Technical and analytics information, device and browser type, IP address, approximate location derived from IP, pages viewed, and similar diagnostic data, collected through cookies and similar technologies (see our Cookie Policy) and error-monitoring tools. Non-essential analytics and marketing cookies are only used with your consent.
Communications, messages you send us (for example, support requests) and, if you interact with the in-app concierge, the questions you ask it.
We do not intentionally collect "sensitive information" (as defined by the Privacy Act) or GDPR "special category data". Please do not upload health, biometric, or similar sensitive documents into Loupe.
3. How we collect it
We collect information directly from you when you create an account, add pieces, upload documents, subscribe, or contact us. We also collect information automatically through cookies and diagnostic tools when you use the service, and we generate information (such as valuation estimates) from what you provide. We may receive limited information from our providers (for example, subscription status from Stripe).
4. Why we use it, and our lawful basis
We use personal information to:
- create and run your account and provide the core ledger, valuation, documentation, and export features;
- produce market-value estimates and value history for your pieces;
- extract details from photos and receipts using AI-assisted tools (see section 7);
- operate the in-app concierge so it can answer questions about your own collection;
- process subscriptions and payments and prevent payment fraud;
- secure the service, prevent abuse, debug, and keep records for audit;
- communicate with you about service, security, and (with consent where required) marketing; and
- comply with legal obligations and enforce our Terms.
Where the GDPR applies, our lawful bases are: performance of a contract with you (running the service you sign up for); our legitimate interests (securing and improving the service, preventing abuse, balanced against your rights); your consent (for non-essential cookies, analytics, and marketing, which you can withdraw at any time); and legal obligation (for example, retaining certain records). Under the Australian Privacy Act, we collect and use personal information for these related purposes and as reasonably expected by you.
5. Automated processing and automated decisions
Loupe relies on automated processing to deliver its core features, in particular, generating valuation estimates and extracting attributes from your photos and receipts using AI-assisted tools. These processes are decision-support and informational: they produce estimates and suggestions that you review and can edit, and they do not make legal or similarly significant decisions about you without human involvement.
In line with the transparency requirements introduced by Australia's privacy reforms (the automated decision-making disclosure obligations under APP 1, and the GDPR's rules on automated decisions), we want to be clear about this:
- valuation estimates and extracted attributes are produced automatically and are estimates, not certified appraisals (see the Valuation Disclaimer);
- every estimate is shown with a confidence level and the number of comparable sales it is based on;
- you can review, correct, and override any automatically extracted or estimated value; and
- we do not use these tools to make decisions that produce legal effects concerning you or similarly significantly affect you in a solely automated way.
If you are in the EU/UK and believe an automated process has significantly affected you, you can ask for human review, contact us using section 15.
6. When we share it (recipients and sub-processors)
We do not sell your personal information, and we do not share it for third-party advertising. We share it only with service providers ("sub-processors") who help us run Loupe, under contracts that require them to protect it and use it only on our instructions. Our current sub-processors, including Supabase (database, authentication, storage), Anthropic (AI processing), Stripe (payments), Vercel (hosting), and our email provider, are listed, with their purpose and location, on our Sub-processor List.
We may also disclose information where we are required or permitted by law, to protect our rights or the safety of others, or as part of a business transfer (such as a merger or acquisition), in which case we will require the recipient to honour this Policy.
7. AI processing of your images, receipts, and questions
Some Loupe features send your content to a third-party AI provider (currently Anthropic) for processing:
- photos and receipts are processed to extract attributes (brand, model, materials, price, date, and so on); and
- concierge questions are processed so the concierge can answer questions about your own collection.
We take specific steps to protect you here:
- No training on your data. We use our AI provider under commercial/enterprise terms and configure our integration so that your content is not used to train the provider's models beyond what is necessary to return a result to us, and not for the provider's own model development.
- PII minimisation. We minimise the personal information included in prompts and logs, avoid sending identifiers we don't need, and treat text found in your documents as untrusted data rather than instructions.
- Server-side only. All AI calls are made from our servers, never directly from your browser, so your credentials and keys are never exposed.
- Retention. AI processing is transient; we retain only the structured result we need (and, where useful for auditing and quality, a limited record of the model version and response), subject to section 9.
The AI provider's own handling is described on our Sub-processor List.
8. Cross-border disclosure
Loupe's primary data store for pieces, documents, and account data is hosted in Australia (Sydney region). However, some of our providers process information overseas, for example, AI processing, payments, hosting edge functions, error monitoring, and email may involve providers in the United States or elsewhere. This means your personal information may be disclosed to, and stored or processed in, countries outside your own.
Before disclosing personal information overseas, we take reasonable steps to ensure recipients handle it consistently with the APPs, and, where the GDPR applies, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision. The location of each provider is shown on our Sub-processor List. By using Loupe you acknowledge these overseas disclosures.
9. How long we keep it (retention)
We keep personal information only for as long as we need it:
- while your account is active, we keep your pieces, documents, valuations, and account data so the service works;
- after you delete a piece or document, we remove it from active systems promptly and purge it from encrypted backups within our backup-rotation window (currently up to 30 days);
- after you close your account, we delete or de-identify your personal information within 30 days, except where we must keep limited records longer to meet legal, tax, accounting, or fraud-prevention obligations (for example, transaction records), or to resolve disputes and enforce agreements; and
- analytics and diagnostic data is kept for a limited period consistent with our Cookie Policy.
10. Your privacy rights and choices
Subject to the Privacy Act, the GDPR/UK GDPR (where they apply to you), and some legal exceptions, you can:
- access the personal information we hold about you and get a copy (data export);
- correct information that is inaccurate or out of date;
- delete your account and associated personal information;
- object to or restrict certain processing, and withdraw consent for analytics and marketing at any time;
- port your data by exporting it in a machine-readable format; and
- complain to us and to a regulator (see section 15).
You can exercise the main rights yourself in the app: Settings → Privacy provides one-click Export my data and Delete my account. For any other request, contact us using section 15. We will respond within the timeframes required by law (generally within 30 days; we may verify your identity first, and complex requests may take longer, in which case we will tell you). We do not charge for reasonable requests.
11. Marketing
We will only send you marketing messages where we are permitted to, and every marketing email has an easy unsubscribe. You can opt out of marketing at any time without affecting service and security messages we need to send you. Marketing and analytics cookies are used only with your consent, see the Cookie Policy.
12. Security
We take the security of your information seriously. Measures include encryption in transit (HTTPS/TLS) and at rest, strict per-user access controls enforced at the database level (row-level security, so you only ever access your own data), private storage with time-limited signed links for your photos and documents, server-side-only handling of secrets and AI/payment calls, access logging, and rate limiting. No system is perfectly secure, but we work to protect your information and to detect and respond to incidents.
Data breaches. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme, and (where the GDPR applies) the relevant supervisory authority, within the required timeframes.
13. Children
Loupe is intended for adults and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
14. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you (for example, by email or an in-app notice) before they take effect where required. The "last updated" date at the top shows the current version.
15. Contact us and complaints
For any privacy question or to exercise a right, contact our Privacy Officer:
- Email: privacy@loupe.example (placeholder)
- Post: [REGISTERED ADDRESS]
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. If you are in the EU/UK, you may also complain to your local data protection authority. [If we offer services to EU/UK users, our Article 27 representative is [EU/UK REPRESENTATIVE].]
Draft placeholders to complete before publishing: legal entity name, ABN, registered address, contact email/domain, EU/UK Article 27 representative (if applicable), backup-window and retention periods confirmed by counsel, and confirmation of the automated decision-making disclosure required from 10 December 2026. Flagged for review by a qualified Australian privacy lawyer (Privacy Act/APPs) and a GDPR/UK GDPR adviser.
