This document lists every device permission the Loop Rewards app requests on Android and iOS, exactly what each one is used for, and what happens if you decline it. It is a companion to our full Privacy Policy, which covers how we handle the data these permissions give us access to.
We only request a permission the first time a feature that actually needs it is used — for example, we ask for Camera access when you first tap “Record a Sale,” not automatically when you install or open the app. You can grant or revoke any of these at any time from your device Settings.
Permissions We Request
Camera
Android & iOS
- Used for
- Taking a photo of a paper sales receipt when you log a sale ("Record a Sale").
- Data captured
- The receipt photo you take. Nothing else on your camera is accessed.
- If declined
- You can still log a sale by attaching an existing photo from your gallery instead (see “Photos / Media” below); otherwise you won’t be able to submit a receipt.
Photos / Media Library
Android (legacy devices) & iOS
- Used for
- Letting you pick an existing receipt photo from your gallery as an alternative to taking a new one. On Android 13+, this uses the system Photo Picker, which doesn’t require a broad gallery permission at all — the older, permission-gated picker only applies on earlier Android versions.
- Data captured
- Only the single image you select is shared with the app; we don’t get a list of your other photos.
- If declined
- You can still log a sale by taking a new photo with the Camera permission above.
Location (While Using the App)
Android & iOS
- Used for
- Confirming that a logged sale was submitted from an in-store location, as an anti-fraud check when a receipt is reviewed.
- Data captured
- Your device’s location at the moment you submit a sale. We only request “When In Use” access — the app never requests or uses background/“Always” location, and does not track your location outside of that moment.
- If declined
- You can still log a sale; the submission simply won’t include a location signal for review.
Notifications
Android 13+ & iOS
- Used for
- Alerting you when a sale is approved/rejected, a badge is earned, a referral is confirmed, or Loop posts a program announcement.
- Data captured
- A device push token (via Firebase Cloud Messaging) is generated and stored against your account so we know where to deliver a notification.
- If declined
- The app works normally; you just won’t receive push alerts and will need to check the app itself for status updates.
Internet / Network Access
Android & iOS
- Used for
- Every feature of the app — logging in, recording sales, viewing points/badges/rewards, and receiving program content — requires a connection to our backend.
- Data captured
- Standard network traffic between the app and our servers, always sent over an encrypted (HTTPS) connection.
- If declined
- Not applicable — this is a basic platform capability, not a permission you are prompted for or can deny individually.
What We Don’t Access
The app does not request or use your contacts, microphone, call/SMS logs, calendar, or browsing activity in other apps. If a future update adds a new permission, this page will be updated before that update ships.
Quick Reference
| Permission | Android manifest entry | iOS usage description key | Feature |
| Camera | android.permission.CAMERA | NSCameraUsageDescription | Record a Sale |
| Photos / Media | android.permission.READ_EXTERNAL_STORAGE (API 32 and below only) | NSPhotoLibraryUsageDescription, NSPhotoLibraryAddUsageDescription | Record a Sale (gallery upload) |
| Location | android.permission.ACCESS_FINE_LOCATION, android.permission.ACCESS_COARSE_LOCATION | NSLocationWhenInUseUsageDescription | Record a Sale (fraud check) |
| Notifications | android.permission.POST_NOTIFICATIONS | (system prompt, no usage-description key) | Push alerts |
| Internet | android.permission.INTERNET | (not applicable on iOS) | All features |