Skip to content
Loot AI← Back

Privacy Policy

Deutsch · Français

Last updated: August 3, 2026

This Privacy Policy explains what personal data We collect when You use Loot AI, why We collect it, where it goes, how long We keep it, and the rights You have over it.

At a Glance

  • Who We are. Loot AI is operated by Brunology OÜ, Saarvahtra pst 15, 10915 Tallinn, Estonia (registry code 17205261) — the data controller.
  • What We collect. Your sign-in name and email (or Apple relay address), the item photos You scan, Your scan history, subscription status, optional feedback and creator-referral entries, and technical server logs.
  • What We don't do. No advertising identifiers, no cross-app tracking, no ad networks, no selling of Your data, and no biometric processing.
  • Where data goes. Data is stored in the EU (Frankfurt, Germany). Some of Our processors are in the United States (backend hosting, website hosting, AI item identification, paywall management, Apple, Google); those transfers rely on the EU-U.S. Data Privacy Framework or Standard Contractual Clauses.
  • How long. Uploaded item photos are processed in memory and are not stored on Our servers; transient copies at Our AI vision provider are gone within 30 days at most. Your account and scan history are deleted within 30 days of account deletion, which You can do in the app.
  • Your rights. Access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a data protection authority. Contact: lootai-support@brunology.tech.

The rest of this Policy is the full version of the summary above. "We", "Us", and "Our" refer to Brunology OÜ; "You" refers to the person using the Service; the "Application" is the Loot AI mobile app; a "Scan" is photographing a secondhand item so the Application can identify it and estimate a resale value from comparable marketplace listings; "Service Providers" are companies that process data on Our behalf (data processors under the GDPR).

Who We Are

The data controller is Brunology OÜ, Saarvahtra pst 15, Tallinn, Harju county, 10915, Estonia (registry code 17205261). We are established in Estonia (EEA). We have not appointed a Data Protection Officer, as We are not required to under Article 37 GDPR, and as an EEA-established controller We are not required to designate an Article 27 representative. For any privacy question, contact lootai-support@brunology.tech.

What We Collect

We obtain Your data from You directly and from Your chosen sign-in provider (Apple or Google), which supplies Your name, email or relay address, and Your user ID.

  • Account data. When You create an account with Sign in with Apple or Sign in with Google, We receive Your name (or the name You choose to share; Apple provides it only on first sign-in, so We store it), Your email address — or, with Apple's "Hide My Email", an Apple-generated relay address that forwards to Your real inbox and that We cannot resolve to Your real email — and a stable Apple or Google user ID. We never receive Your provider password or payment card details, and We request no additional Google permissions (no access to Your Gmail, Calendar, Contacts, or Drive).
  • Item images. Photos of secondhand items You capture or select for a Scan. Images are uploaded to Our servers so an AI vision model can identify the item (brand, category, model or variant where discernible, condition). Photos may incidentally include people or surroundings if You put them in frame; We do not use images to identify, profile, or track any person, do not perform facial recognition, and do not extract biometric identifiers. Photos may contain embedded EXIF metadata (such as GPS coordinates and capture time); We do not use this metadata. Our AI vision Service Provider is contractually prohibited from using Your images to train or improve its models.
  • Scan results. The identified item, the estimated price statistics and confidence indicator, and Your scan history, linked to Your account.
  • Subscription data. Your subscription status (active, trial, expired), plan type, and a subscriber identifier used to determine Your access. We never receive Your payment card details.
  • Creator attribution (optional). If You enter the name of a creator who referred You during onboarding, We store it as typed, with Your app/device identifier, region, and platform, solely to attribute Your install and any subscription to that creator for Our own marketing measurement. Leaving it empty stores nothing.
  • Feedback (optional). If You use "Send us a message" in the app, We receive Your message, an optional contact email (or Your account email if signed in), and basic app context (app/device identifier, app version, platform, region), used solely to respond to You and improve the Service.
  • Server logs and diagnostics. Our backend keeps standard request logs (IP address, timestamps, app version, platform) and records diagnostic information when a Scan fails, for security, troubleshooting, and product improvement. We use first-party, EU-hosted product analytics and crash and error reporting to understand how the Application is used and to keep it stable, and You can turn analytics off at any time in Settings under Privacy (see "Analytics and Crash Reporting" below).

We do not process special categories of data (Article 9 GDPR).

Device identifiers. The Application does not use web cookies, does not use the advertising identifier (IDFA/AAID), and does not request App Tracking Transparency permission, because We do not track You across other companies' apps or websites. Our paywall Service Provider's SDK uses an app-scoped identifier to display the correct paywall and determine Your entitlement; it does not receive Your scan images or valuations. For users in Germany, where §25 TDDDG requires consent to store or read information on Your device, We rely on the strict-necessity exemption for the identifiers essential to run the Application and operate the paywall, and for crash and error reporting as a stable service You asked for. For product analytics We rely on Our legitimate interest (Art. 6(1)(f) GDPR) in understanding and improving the Application, We keep it first-party and IP-free, and You can object at any time by turning analytics off in Settings under Privacy.

Notifications. If You enable them, trial-reminder notifications are scheduled locally on Your device. No push token or notification data is sent to Us or to any server.

Camera and photo library. Camera access is used solely so You can photograph items to scan; photo-library access is optional and used only when You choose an existing photo. We never access the camera in the background. You can revoke both permissions in Your device settings at any time; without camera access the Scan feature is unavailable, but the rest of the Application still works.

How Scans Work

When You scan an item, Your photo(s) are uploaded to Our backend and analyzed by an AI vision model to identify the item. Our backend then retrieves comparable public marketplace listings — live eBay listings (asking prices) via eBay's official API — and computes estimated price statistics from them. You see the identification, the price statistics, a confidence indicator, and the comparable listings themselves. In this valuation read-path We send eBay only non-personal item search attributes, never Your account data or images; if You open a listing, You interact with eBay directly under its own privacy policy.

How We Use and Share Your Data

We use Personal Data to provide and maintain the Service: to operate Your account, deliver the Scan and valuation features and Your scan history, verify Your subscription entitlement and operate the paywall, respond to Your requests and feedback, send account-related email where needed, secure and troubleshoot the Service, and improve it. If You opt in, We may send You marketing email; We do not send marketing email by default, every such email has an unsubscribe link, and You can withdraw consent at any time (for users in Germany, We rely on the opt-in requirement of §7 UWG).

We share Personal Data only: with the Service Providers listed below, who process it under contract on Our instructions; in connection with a merger, acquisition, or asset sale (with prior notice before Your data becomes subject to a different privacy policy); where required by law or valid requests of public authorities, or where necessary to enforce Our rights, prevent wrongdoing, or protect users; and otherwise only with Your consent. We do not share Your Personal Data with advertising networks and We do not sell it.

Analytics and Crash Reporting

We use PostHog to measure how the app is used, hosted in the European Union (Frankfurt), so that We can improve Loot AI. We use Sentry to receive crash and error reports so that We can keep the app stable, also hosted in the European Union. Both run as Our processors under a data processing agreement. We do not collect Your IP address for analytics, We do not use advertising identifiers, and We do not track You across other apps or websites. Our legal basis is Our legitimate interest in understanding and improving Our product and in keeping it stable and secure. You can object at any time and turn analytics off in Settings under Privacy. Turning analytics off stops usage analytics from Your device. Purchase and subscription events are still processed to provide the Service and to keep accurate sales records (Art. 6(1)(b) and (f) GDPR). Where local rules require it, We treat crash and error reporting as strictly necessary to provide a stable service You asked for.

Legal Bases and Retention by Processing Activity

For users in the EEA, the table below summarizes each processing activity, the data involved, Our legal basis under Article 6(1) GDPR, and retention:

Processing activity Data categories Legal basis (Art. 6(1) GDPR) Retention
Account creation & authentication (Sign in with Apple/Google) Name, email or Apple relay address, provider user ID (b) Performance of a contract Life of account + up to 30 days after deletion
Running scans: image upload & AI item identification Item images, identified item attributes (b) Performance of a contract Images not retained by Us (processed in memory); transient provider copies ≤30 days
Valuation (price statistics & comparable listings) Identified item, public marketplace comps, scan results (b) Performance of a contract Scan history kept while account active; deleted ≤30 days after account deletion
Marketplace data fetching (live eBay listings via eBay's official API) Item search attributes only (no user personal data) (b) Performance of a contract Not user-identifying
Subscription & entitlement management (paywall provider + App Store/Play) Subscription status, plan, entitlement, subscriber ID (b) Performance of a contract Duration of subscription; minimal records per legal/accounting needs
Post-deletion erasure-integrity record App-generated device identifier and deletion date only (f) Legitimate interests (ensuring an erasure cannot be undone by later store notifications); giving effect to Art. 17 Kept indefinitely; contains no name, email, scan, or payment data
Creator attribution (optional referral name entered in onboarding) Creator name as typed, app/device identifier, region, platform, subscription-event log (f) Legitimate interests (marketing measurement); provided voluntarily Deleted on account deletion or verified request; at most 24 months
In-app feedback ("Send us a message") Message text, optional contact email, app/device identifier, app version, platform, region (f) Legitimate interests (responding to feedback, improving the Service); provided voluntarily Deleted on verified request; at most 24 months
Email delivery (account notices, support replies, waitlist launch email) via Google LLC (Gmail) Email or relay address, message content (b) Performance of a contract / (f) Legitimate interests (responding to You) As needed to deliver and evidence delivery
Server logs & scan diagnostics IP address, timestamps, app version, platform, failure diagnostics (f) Legitimate interests Up to 24 months (see balancing statement below)
Product analytics (PostHog) App usage and interaction events, an app-generated analytics identifier (no IP address) (f) Legitimate interests (understanding and improving the Application) Up to 25 months
Crash and error diagnostics (Sentry) Crash and error reports, technical device and app state (no account identity) (f) Legitimate interests (keeping the Application stable and secure); strictly necessary where local rules require Up to 90 days
Marketing communications (if any) Email (a) Consent Until withdrawn

Legitimate-interests balancing (server logs, product analytics, and crash reporting). We have a legitimate interest in understanding how the Application performs and is used, fixing failures, improving the product, and securing the Service. We consider this interest is not overridden by Your interests or rights because the data is pseudonymized (keyed to an internal or app-generated identifier, not Your email), Our product analytics is first-party, EU-hosted, and collected without Your IP address, crash and error reports carry no account identity, none of it is used for advertising or cross-app tracking, and You can object at any time by turning analytics off in Settings under Privacy or by contacting lootai-support@brunology.tech.

Required versus optional. The data needed to operate Your account and deliver the Scan, valuation, and subscription features — Your sign-in name and email (or relay address), Your entitlement status, and, for a real scan, the photo You submit — is required; without it We cannot provide that part of the Service. Optional, with no effect on the core Service: photo-library access, notifications, creator attribution, feedback, and marketing email.

Automated Processing of Scans

Scan results (identification, estimated price range, confidence indicator) are produced by automated processing without a human reviewing each result. In plain terms: an AI vision model identifies the item from Your photo(s); price statistics are then computed from comparable live marketplace listings; the confidence indicator reflects the amount and quality of comparable data found. These outputs are estimates to support Your own decision — the Application deliberately makes no buy or skip recommendation, and the results are not financial, investment, or professional advice; actual resale outcomes may differ materially.

The valuation of a secondhand item produces no legal or similarly significant effect on You, so the prohibition and mandatory human-review right of Article 22(1) GDPR do not apply. Nonetheless, You may always contact Us at lootai-support@brunology.tech to ask how a result was produced, request human review of a result You believe is wrong, or express Your point of view; We respond within one month. When You run a Scan, You are interacting with an AI-powered system (disclosed at the point of scan); We deploy an AI model provided by a third-party model provider.

Retention

We keep Personal Data only as long as needed for the purposes above (the table lists the period per activity), then delete or anonymize it. Key periods: uploaded item images not retained by Us (in-memory processing; transient provider copies ≤30 days); account data and scan history for the life of the account plus up to 30 days after deletion; server logs up to 24 months; after an account deletion, a minimal erasure-integrity record (the app-generated device identifier and deletion date, nothing else) is kept indefinitely so that later store notifications cannot recreate the deleted data; records that constitute accounting source documents as long as Estonian and EU accounting and tax rules require (generally up to 7 years). Residual copies may persist in encrypted backups for up to 30 days before being purged and are not restored except for security, disaster recovery, or legal compliance. We may retain specific data longer only where the law requires it or where it is necessary to establish, exercise, or defend legal claims.

International Transfers

We are established in Estonia and store account and scan data in the EU (Frankfurt, Germany). Several of Our Service Providers process data in the United States; each is listed below with the safeguard used. For transfers outside the EEA/UK to countries without an adequacy decision, We rely on the EU-U.S. Data Privacy Framework (for certified providers), the European Commission's Standard Contractual Clauses (2021) — with the UK Addendum or IDTA where applicable — and supplementary measures such as encryption in transit and at rest, access controls, data minimisation, and pseudonymization, supported by transfer impact assessments. You can request further information about these safeguards, including copies of the relevant contractual protections (redacted where necessary), via lootai-support@brunology.tech.

Your Rights (GDPR)

If You are in the EEA/UK, You have the right to:

  • Access the Personal Data We hold about You and receive a copy.
  • Correct incomplete or inaccurate data.
  • Delete Your data, including uploaded images and scan history (see "Deleting Your Data" below).
  • Restrict processing in certain circumstances (for example while We verify accuracy or assess an objection).
  • Object to processing based on legitimate interests, and to any direct marketing.
  • Portability: receive Your account data and scan history in a structured, commonly used, machine-readable format (for example a JSON export).
  • Withdraw consent at any time where processing is based on consent, without affecting prior processing.

To exercise any right, contact lootai-support@brunology.tech; where possible You can also act directly in Your account settings. We may ask You to verify Your identity. We respond within one month, extendable by two further months where necessary in accordance with applicable law.

You also have the right to complain to a data protection authority. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia (aki.ee, info@aki.ee). If You are in another EEA state (for example Germany or France), You may also complain to the authority of Your country of residence.

Deleting Your Data

You can delete Your account and associated data directly in the Application (Profile → Delete account). This removes Your account data and scan history, subject to the retention exceptions above. See also the dedicated deletion page at loot-ai.app/delete-account. You can also contact Us to request access, correction, or deletion.

Security

We implement technical and organizational measures appropriate to the risk of Our processing, including encryption in transit (TLS) and at rest, role-based access controls and least privilege, pseudonymization of scan records by internal user identifier, authentication on backend endpoints, and data-processing agreements with Our Service Providers requiring equivalent safeguards. In the event of a personal data breach likely to result in a risk to Your rights and freedoms, We will notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of it, and affected users without undue delay where the risk is high (Articles 33–34 GDPR). No method of transmission or storage is 100% secure, and We cannot guarantee absolute security.

Service Providers

We use a small, stable set of Service Providers (processors). Where We add or substitute one, We will reflect it in an updated version of this Policy and, where required by law, notify You in advance. You can request the current named list of Our processors and the applicable transfer mechanisms at any time via lootai-support@brunology.tech.

Service Provider Role Location Transfer safeguard
Database hosting provider Storage of account and scan data EU (Frankfurt, Germany) Within the EEA; DPA with SCCs covering any management-plane access
Backend hosting provider Application backend (image processing in transit, scan computation) United States EU Standard Contractual Clauses (2021) + supplementary measures
AI vision model provider Item identification from uploaded images; contractually prohibited from using Your images to train or improve its models United States EU Standard Contractual Clauses (2021); contracted through the provider's EU entity
Paywall & subscription management provider Receives subscription status, app-interaction events, and, if You provide one, the creator name You typed in normalized form (lowercased and trimmed); does not receive scan images or valuations United States EU Standard Contractual Clauses (2021)
PostHog (product analytics) First-party product analytics: app usage and interaction events; no IP address collected; does not receive scan images or valuations EU (Frankfurt, Germany) Within the EEA; DPA in place; no new third-country transfer
Sentry (crash and error reporting) Crash and error diagnostics to keep the Application stable; identity-free, not linked to Your account EU region Within the EEA; DPA in place; no new third-country transfer
Website hosting provider Hosting of the loot-ai.app website and waitlist signup (processes website request data such as IP address and browser information) United States EU-U.S. Data Privacy Framework and/or SCCs
Apple Inc. Sign in with Apple, App Store in-app payments, app distribution United States EU Standard Contractual Clauses (2021)
Google LLC Sign in with Google, Google Play in-app payments, app distribution, email delivery (Gmail) for account notices, support replies, and the waitlist launch email United States EU-U.S. Data Privacy Framework

eBay is not a processor of Your personal data. We read comparable-listing data from eBay through its official API to compute valuations; the search attributes We send contain no personal data. If You open a comparable listing, You leave the Application and deal with eBay directly as an independent controller under its own privacy policy.

Payments

All purchases are made through and processed by Apple (App Store) or Google (Google Play) as the merchant of record. We never receive or store Your payment card details; We receive only Your subscription and entitlement status and aggregated payout reports. Subscriptions auto-renew and may include a free trial; manage or cancel any time in Your device's App Store or Google Play subscription settings. See Apple's privacy policy and Google's privacy policy.

Website Waitlist (loot-ai.app)

If You join the pre-launch waitlist, We store Your email address, the exact consent notice shown to You with a timestamp (as proof of consent), and — for abuse prevention and rate limiting — a truncated, hashed form of Your IP address, Your browser's user-agent string, and basic locale/source information, stored with Our database hosting provider in the EU. Our website and the signup request itself are served by Our website hosting provider in the United States, which processes the request data (including Your IP address and browser user-agent) to deliver the page and Your submission; that transfer relies on the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses. We use this solely to send You a single launch announcement, delivered via Our email provider Google LLC (Gmail, United States, EU-U.S. Data Privacy Framework). Every launch email contains an unsubscribe link. We rely on Your consent (Art. 6(1)(a) GDPR; §7 UWG in Germany) for the launch email, and on Our legitimate interest (Art. 6(1)(f) GDPR) in preventing abuse for the hashed IP and user-agent data. We delete or anonymize waitlist data once the launch notification has been sent or upon request to lootai-support@brunology.tech. If You unsubscribe, We delete the abuse-prevention data and keep only Your address marked as unsubscribed, together with Your consent record (the consent notice with its timestamps), so that We do not contact You again and can prove the consent that existed while We mailed You.

App Store and Google Play Disclosures

The practices in this Policy are reflected in Our Apple App Store privacy ("nutrition label") and Google Play Data Safety declarations. In summary: the data We collect — name, email address, user identifier, item photos, scan activity, subscription status, an optionally provided creator name, feedback, and product-analytics events — is linked to Your account or device identifier and used for app functionality, account management, subscription, analytics, and security; crash and error diagnostics are collected without account identity and are not linked to You. We do not use Your data to track You across other companies' apps or websites, do not collect biometric data, and do not use precise location (including location metadata embedded in images). Payment card data is collected by Apple or Google, not Us. If You notice an inconsistency between this Policy and a store declaration, tell Us at lootai-support@brunology.tech.

United States and California Residents

We do not sell or share personal information within the meaning of the California Consumer Privacy Act (CCPA/CPRA), and We have not done so in the preceding twelve months; there is accordingly nothing to opt out of. We do not disclose personal information to third parties for their own direct-marketing purposes. California residents may request access to, correction of, or deletion of their personal information at lootai-support@brunology.tech; We verify Your identity and respond within one month. Our Service does not respond to "Do Not Track" browser signals.

Children's Privacy

The Service is not directed at anyone under 16, and You must be at least 16 to use it (or older where Your country requires it). We do not knowingly collect Personal Data from anyone under 16, and We do not knowingly create accounts for them; if You believe a child has provided Us data, contact Us and We will delete it promptly.

Links to Other Websites

The Service may link to third-party sites (for example, eBay listings). We have no control over and assume no responsibility for their content or privacy practices; review their policies.

Changes to this Privacy Policy

We may update this Policy from time to time. We will post the new version on this page, update the "Last updated" date, and — for material changes — notify You by email and/or a prominent notice in the Service before the change becomes effective.

Contact Us

For any question about this Privacy Policy or Your data: lootai-support@brunology.tech