haloop.ai
How it works Meet Lumo FAQ What's New
ENID
Download
How it works Meet Lumo FAQ What's New Download
Privacy

Your contacts. Your data. Your call.

Plain English. Last updated 17 August 2026.

1. Who we are

This notice describes how Haloop Pte. Ltd. (“Haloop”, “we”, “us”) handles personal data when you use the Haloop mobile app, our site at haloop.ai, or interact with us directly.

Haloop Pte. Ltd.
UEN: 202620083C
23-02 152 Beach Road
Singapore 189721

We are a Singapore-incorporated company. We process personal data under the Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU/UK GDPR.

2. What we collect

Information you give us

  • Account information — name, email, phone number, profile photo when you sign up.
  • Contacts you add — names, phone numbers, email, photos, birthdays, notes, conversation history, tags and preferences you record about people in your network.
  • Messages and drafts — the messages Lumo helps you draft and any conversation history you choose to save.
  • Form responses — waitlist signups, contact form messages, beta feedback.

Information we collect automatically

  • Device and usage data — device model, OS version, app version, crash logs, feature usage, IP address.
  • Location — only when you actively use “near you” features. We ask permission first; you can revoke it anytime in device settings.
  • Cookies and similar — see Section 11.

Information from third parties

  • Sign-in providers — if you sign in with Google or Apple, we receive your email and basic profile per your authorization.
  • Google Calendar integration — if you choose to connect Google Calendar, we receive your Google account email, the OAuth permissions you grant, OAuth access and refresh tokens, and results for Calendar events Haloop creates or manages at your request, such as event identifiers and Calendar or Google Meet links.

3. Why we collect it

We use your personal data only for purposes you’d reasonably expect:

  • Provide the service — sign you in, store your contacts, send you reminders, draft messages.
  • Personalize the experience — surface relevant cultural moments, suggest the right language for a draft.
  • Communicate with you — beta invites, service announcements, replies to your support requests.
  • Improve the product — diagnose crashes, understand which features matter, make Lumo better at his job.
  • Security and fraud prevention — detect abuse, comply with legal obligations.

We do not use your personal data, your contacts, or your conversations to train general-purpose AI models for anyone else.

The purposes above do not expand how we use data obtained through the Google Calendar integration. Except when needed for security or required by law, that data is used only as described in Section 4 and never for beta invitations, marketing, general product analytics, profiling, or training AI models.

4. Google API Services user data

Connecting Google Calendar is optional. Haloop uses information received from Google APIs only to provide or improve the user-facing Google Calendar and Google Meet features that you choose to use.

  • Access and use — when you explicitly ask Haloop to add a meeting to Google Calendar or create a Google Meet link, Haloop can create an event in your primary calendar, add the attendee email addresses you selected, create a Meet conference, update or delete an event previously created through Haloop, and show you its Calendar and Meet links.
  • No access to unrelated events — Haloop does not list, import, scan, or analyse existing Google Calendar events that are unrelated to events created through Haloop.
  • Storage — we store your Google account email, granted OAuth scopes, and encrypted OAuth access and refresh tokens. For events created through Haloop, we also store the Google event identifier and Calendar or Meet links in the related Haloop activity so we can display and manage that event.
  • Sharing — we do not transfer Google Calendar event data, OAuth credentials, Google event identifiers, or Calendar and Meet links to OpenAI, PostHog, advertising platforms, data brokers, or information resellers. Our infrastructure and database providers may process this data only as necessary to securely host and operate the integration on our behalf and under contractual confidentiality obligations.
  • Human access — Haloop personnel do not read data obtained through the Google Calendar integration unless you give affirmative permission for a specific support request, access is necessary to investigate abuse or a security issue, or access is required by law.
  • Prohibited uses — we do not use data obtained through the Google Calendar integration for advertising, retargeting, marketing, user profiling, credit or lending decisions, sale, or training general-purpose AI models.
  • Retention and control — OAuth credentials are kept while your Google Calendar integration is connected. Disconnecting Google Calendar in Haloop deletes the stored OAuth credentials from our active systems and stops future access. Disconnecting does not delete events already created in Google Calendar; you can manage those events directly in Google Calendar.

Haloop’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. About the contacts you upload

When you add someone to Haloop, you are sharing their personal data with us. You must have a reasonable basis to do so — typically your personal or family relationship with that person, or their consent.

We handle uploaded contacts on your behalf. We treat that information as confidential, do not sell or share it for marketing, and delete it when you delete the contact or close your account.

6. Who we share it with

We do not sell, rent, broker, or syndicate your personal data. Ever.

We do work with carefully chosen service providers (“data intermediaries” under PDPA) who process data on our behalf under written contracts:

ProviderPurposeRegion
Google Cloud / Firebase / Google CalendarAuthentication, app infrastructure, Calendar and Meet featuresSingapore / global Google infrastructure
SupabaseDatabase hostingSingapore
CloudflareCDN, image storage, anti-abuseGlobal (configured for Asia-Pacific)
OpenAIDrafting messages, language understandingUnited States
ResendTransactional email (invites, notifications)United States
PostHogPrivacy-respecting product analyticsUnited States

We require each provider to maintain protections at least equivalent to PDPA standards.

We may also disclose personal data when required by law, court order, or a valid request from a competent authority.

7. International transfers

Most of your data stays in Singapore. Some processing (drafting via OpenAI, transactional email via Resend, analytics via PostHog) happens in the United States. We rely on standard contractual safeguards to ensure protections travel with the data.

8. How long we keep it

DataRetention
Account, contacts, messagesWhile your account is active, plus up to 30 days after deletion to allow recovery
Google OAuth credentialsWhile the Google Calendar integration is connected; deleted from active systems when you disconnect
Google event identifiers and Calendar or Meet linksWhile the related Haloop activity is retained
Crash logs and aggregated usageUp to 12 months, then anonymised
Marketing site signups (waitlist, contact form)Until you ask us to delete, or 24 months of inactivity
BackupsRolling 30-day window, then overwritten

When you delete your account, all personal data is removed from active systems within 30 days and from backups within the rolling backup window above.

9. How we protect it

  • All data encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Database row-level security — users can only access their own data.
  • Strict role-based access for staff, audited regularly.
  • Hosted in Singapore data centres with industry-standard physical security.
  • Independent security review before public launch.

No system is perfectly secure. If we ever experience a breach affecting your personal data, we will notify you and the PDPC promptly, as required by law.

10. Your rights and choices

Under PDPA you have the right to:

  • Access the personal data we hold about you.
  • Correct anything that’s inaccurate.
  • Withdraw consent for any specific use (note: this may limit what Haloop can do for you).
  • Delete your account and personal data — in-app, no email required.

To exercise any of these, email support@haloop.ai. We’ll respond within 30 days.

If you’re in the EU/UK and GDPR applies to you, you additionally have the right to data portability and to lodge a complaint with your national supervisory authority.

If you’re in Singapore and we don’t resolve a concern to your satisfaction, you may contact the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.

11. Cookies and analytics

The marketing site uses minimal cookies for essential function (language preference) and PostHog for privacy-respecting analytics (page views, no cross-site tracking, no ad-network sharing). We don’t run ad-network trackers.

The Haloop mobile app does not use cookies. It does collect crash and performance diagnostics, which you can opt out of in app settings.

12. Children

Haloop is intended for users 13 years and older. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us personal data, email support@haloop.ai and we will delete it.

13. Changes to this notice

We’ll update this notice as Haloop evolves or as laws change. Material changes will be announced in-app or by email. The “Last updated” date at the top always reflects the most recent revision.

14. Contact us

Data Protection Officer
Haloop Pte. Ltd.
Email: support@haloop.ai
Post: 23-02 152 Beach Road, Singapore 189721

haloop.ai — never out of the loop
ENID
Lumo's Origin What's New Privacy Terms Contact
Made with care in Singapore. © 2026 Haloop Pte. Ltd. · UEN 202620083C · All rights reserved. ·

Cookies

We use a few cookies to understand how people use haloop.ai so we can make Lumo more useful. Only essentials (like form security) run by default — you choose the rest.

Cookie preferences

You're in control. Pick what's OK with you. You can change this any time from the footer.

Necessary

Required for the site to work — e.g. Cloudflare Turnstile on the signup form to keep bots out.

Analytics

PostHog and Google Analytics help us see what's working and what isn't. We never sell this data.