Privacy Policy
Last updated: 6 July 2026
Who we are
Loom ("we", "us", "our") is a service operated by Loom Presence LTD, a company being incorporated in the United Kingdom. Loom Presence LTD is the data controller for the personal data described in this policy.
You can reach us at contact@loompresence.co.uk for any privacy question, data-subject request, or complaint.
Who Loom is for
Loom is currently intended for adults aged 18 and over. If you are under 18, please do not create an account. We may extend Loom to younger audiences in the future, and if we do, we will publish a separate policy and additional safeguards before that happens.
What data we collect
- Account data — your email address, authentication identifier, and (if you sign in with Google) the basic profile fields Google returns.
- Content you create — daily anchors, memory-vault entries, awe moments, creative-sandbox writing, threads and replies, and any media you upload to the vault.
- Circle & thread data — the circles you join, your display name in each circle, and the content you choose to share with them.
- Vault passcode — stored only as a salted hash. We cannot recover or read your passcode.
- Technical data — basic logs (IP address, browser, timestamps) needed to run the service, prevent abuse, and diagnose errors.
- Voice input — if you use dictation, the audio is sent to our AI provider for transcription and is not retained beyond that request.
How we use your data
- To provide the Loom service and the features you use.
- To authenticate you and keep your account secure.
- To generate AI responses (poems, stories, letters, transcriptions) when you explicitly request them.
- To communicate essential service messages, including inactivity warnings.
- To detect, prevent and address abuse or security incidents.
- To comply with legal obligations.
We do not sell your personal data. We do not use your private content (vault entries, anchors, creations) to train AI models.
Legal bases (UK GDPR)
- Contract — to deliver the service you signed up for.
- Legitimate interests — to keep Loom secure, prevent abuse, and improve reliability.
- Consent — for optional features such as marketing emails (if we ever introduce them) and non-essential cookies.
- Legal obligation — where we must retain or disclose data by law.
AI processing
Loom uses the Lovable AI Gateway to generate text, transcribe voice input, and power creative features. When you use these features, the relevant input (your prompt, dictated audio, or the text you asked to work with) is sent to Lovable AI and, through it, to underlying model providers such as Google. These providers act as our processors and are contractually bound to handle the data only to fulfil the request. Your data is not used to train their models.
Subprocessors
- Supabase — database, authentication and file storage (EU region where possible).
- Lovable — hosting, AI gateway, and platform infrastructure.
- Google — Google Sign-In and underlying AI models accessed via the Lovable AI Gateway.
- Email delivery — a transactional email provider for account and inactivity notices (to be confirmed at launch).
Data retention
- Active accounts — we keep your content for as long as your account is active.
- Account deletion — when you delete your account, your data is removed from active systems within 30 days. Encrypted backups may persist for a short additional period before being overwritten in the normal backup rotation.
- Inactivity — if you do not sign in for 2 years, we will delete your account and content. Before doing so, we will send warning emails at 6, 12 and 18 months of inactivity so you can sign in and keep your data.
- Legal or safety records — limited data may be retained longer where required to comply with legal obligations or resolve disputes.
Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to processing of your personal data, and to data portability. You can exercise most of these directly in the app (edit your profile, delete entries, delete your account) or by emailing us. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).
Security
We use industry-standard measures: encryption in transit, encrypted storage, row-level access controls, hashed passcodes, and least-privilege access to systems. No service can guarantee absolute security, but we work to protect your data and will notify you and the relevant authorities of any breach as required by law.
International transfers
Some of our subprocessors are based outside the UK/EEA. Where personal data is transferred internationally, we rely on adequacy decisions or Standard Contractual Clauses to ensure equivalent protection.
Cookies
Loom uses cookies and similar storage that are strictly necessary to keep you signed in and to run the service. If we ever introduce analytics or advertising cookies, we will ask for your consent first.
Changes to this policy
We may update this policy as Loom grows. If changes are material, we will notify you in-app or by email before they take effect.
Contact
Loom Presence LTD · contact@loompresence.co.uk