Privacy Policy
Last updated: July 7, 2026.
What we collect
When you request access or sign in, we collect the email address you provide, sign-in metadata needed to operate the beta, and basic server logs used for security and troubleshooting.
We use a third-party bot-protection service to help prevent automated abuse. It may receive browser and network signals needed to perform the check.
If you use a hosted Loom Cloud store, we store the memory content, facts, task evidence, store names, usage labels, and configuration details you or your agents add to that store.
How we use it
We use signup information to review beta access, contact you about your account, operate hosted stores, troubleshoot service issues, and prevent abuse.
We do not use your hosted memory content for anything other than providing the service to you. That means: storing the facts you save, answering your agents' queries, coordinating task state, and returning the context your connected tools request. The one exception is debugging: if you report an issue or the service errors, we may inspect the relevant data to diagnose and fix the problem. We do not read, analyze, sell, or use your hosted memory content for advertising, marketing, analytics, product improvement, or training any model.
Hosted-store access and encryption
Hosted stores are encrypted at rest and in transit. They are not end-to-end encrypted. Loom Cloud needs server-side access to hosted store content so the service can answer your agents' queries and operate shared memory features.
If your organization needs a strict zero-trust boundary where the service operator cannot access memory content, use a self-hosted deployment.
Retention and deletion
- Pending access requests and the operational request/audit log are kept for at most 30 days.
- Provisioning status files are removed after 1 hour.
- At trial expiry, a hosted store is locked. Its live encrypted volume is deleted after a 7-day deletion grace period.
A verified erasure request removes hosted-store content, account records, matching request-log entries, and matching queued or processing web requests. Normal web access is not written to an application access log; system journal entries cannot be selectively rewritten and expire under the host journal policy.
Encrypted image backups are not edited in place. Up to two weekly local rotations can retain deleted ciphertext temporarily; off-host ciphertext copies remain until the storage provider's configured lifecycle removes them. Erasure does not attempt to rewrite those encrypted images.
Sharing
We do not sell your data, and we do not share your hosted memory content with third parties except the infrastructure providers strictly necessary to run the hosted service (e.g. hosting/storage), who have no independent right to use it. We may disclose account information (not hosted memory content) when required to comply with law, protect the service, or prevent abuse.
Contact
Questions or deletion requests can be sent to info@loomcloud.ai.