What Loom stores, who can read it, how credentials work, and how to protect and report.
~/.loom/stores.toml holds the connection details for your stores, including keys. Treat it as a credential file:
loom setup or loom login write it rather than assembling it by hand.Setup writes it atomically and restricts it to your user (mode 0600 on Linux and macOS). On Windows setup removes inherited permissions and grants full control to your user only, before any secret is written. A stores.toml written by a Loom older than v0.672 can still carry read access inherited from its folder (another local account or group; one was seen on a v0.660 install). Check it with icacls %USERPROFILE%\.loom\stores.toml: a file written by v0.672 or later shows exactly one entry, your user with (F), and none marked (I). Re-run loom login to rewrite an older file, or remove inherited entries yourself. Not verified on Windows: that icacls shows one full-control entry for your user and no inherited entries on v0.672 or later; only code and a regression test confirm it.
Setup does not restrict the ~/.loom directory itself. On a default Linux install it is group-writable (mode 0775) and only stores.toml is 0600. On a shared machine, run:
chmod 700 ~/.loomEmail codes, sign-in links and enrollment grants are short-lived. Codes last 10 minutes and are single-use. Enter them only at the hidden prompt, and confirm you started the request yourself before following any sign-in link.
loom logout needs the section name; the bare command fails with missing a required argument: 'section':
loom logout --params '{"section":"<name>"}'This removes that section from ~/.loom/stores.toml. The result's server_status: "removed" refers to the local section only; nothing is revoked on the server. If you log out of the section that default points to, stores.toml loses its default line and loom list_stores fails with `must set top-level default = "<store>" until you run loom login` again, which writes it back.
| Data | Where | Notes |
|---|---|---|
| Facts, relations, rules you save | The store on the server | One store per section in stores.toml. |
| Connection credentials | ~/.loom/stores.toml | Your computer only. |
| Embedding model files | ~/.loom/cache/fastembed on your computer | Downloaded on first save; no facts in it. |
| Model download cache | ~/.cache/huggingface/ on your computer | Created on first save (download logs and staging); no facts in it. |
| Embedding runtime device id | ~/.cache/Microsoft/DeveloperTools/.onnxruntime/ | Created by the embedding runtime. |
| Plugin update check cache | ~/.loom/plugin-update-check.json | Exists only when a Claude Code or Codex plugin is installed. Holds the marketplace's latest commit and version. |
Do not save passwords, tokens or other secrets as facts.
save on a computer downloads the embedding model (Qdrant/bge-small-en-v1.5-onnx-Q) from huggingface.co and its CDN hosts. After that, embeddings are computed on your computer, and later saves and queries contact only your store gateway.mobile.events.data.microsoft.com on that first run and writes a device id under ~/.cache/Microsoft/DeveloperTools/.onnxruntime/./loom-plugins.git. No memory data is sent. Set LOOM_PLUGIN_SKIP_REMOTE=1 to disable the check.loom setup contacts only the server it signs in to (--base, or the single origin recorded in stores.toml, or LOOM_WEB_BASE, or https://loomcloud.ai) and installs plugins from that same server. The loom command installer is fetched from loomcloud.ai (or from LOOM_CLI_BOOTSTRAP_URL), because a private server does not serve it.The connection between your computer and the server is encrypted and the server authenticates itself to your client. A store's endpoint and server public key are bearer connection material: anyone holding a valid store key and endpoint can connect, which is why the file must stay private.
Do not open a public issue for a vulnerability or credential exposure. Email info@loomcloud.ai with a short description and a reproduction that contains no live keys or personal data.