Longhorn Loop

Privacy Policy

Last updated 18 August 2026

Longhorn Loop is a campus events app for students at The University of Texas at Austin, built by Longhorn Developers, a student organization. This policy explains what we collect, why, and what you can do about it. It is written to be read, not to be skimmed past.

Who this app is for

Longhorn Loop is restricted to people with a UT Austin email address — utexas.edu, my.utexas.edu or eid.utexas.edu. We verify this by emailing a one-time code to that address at sign-up. If you cannot receive that code, you cannot create an account.

The app is not directed to children under 13, and we do not knowingly collect information from them.

What we collect

Data Why
UT email address To verify you are a UT student and to sign you in. It is your account identifier.
Name, year, major, interests, profile photo Shown on your profile and used to recommend events. All optional except your name.
Events you save, RSVP to, or create To build your feed, send reminders you asked for, and show your activity.
Follows and blocks To show you the right people's activity, and to hide people you have blocked.
Notification preference To know whether to remind you about events you saved. You choose this at sign-up.

We do not collect your location in the background, your contacts, your browsing outside the app, or any advertising identifier. We do not use third-party advertising or analytics SDKs.

Where it goes

Your data is stored in Cloudflare D1 and Cloudflare R2 (for images), hosted in the United States. Verification-code emails are sent through Resend, which processes your email address solely to deliver that message.

We do not sell your data, and we do not share it with advertisers or data brokers. Ever.

What other people can see

Your profile — name, photo, year, major, interests — is visible to other signed-in Longhorn Loop users. Events you create and organizations you belong to are visible too. Your email address is not shown to other users.

Blocking someone hides you from them and them from you, in both directions.

Your choices

Deletion is permanent. We keep no shadow copy of a deleted account beyond routine backups, which age out.

Security

Sign-in codes are stored hashed, never in plain text, and expire after ten minutes. Session tokens are held in your device's secure keychain. All traffic to our servers is encrypted in transit.

We are a student team, not a security company. We have designed this carefully, but if you find a problem we would genuinely rather hear about it than not — see below.

Changes

If this policy changes in a way that affects what we collect or who sees it, we will say so in the app rather than quietly updating this page.

Contact

Questions, data requests, or security reports: privacy@longhorndevelopers.org