Privacy Policy
Last updated: September 10, 2026
This document is an informational template and does not constitute legal advice. Consult a qualified attorney for legal matters specific to your jurisdiction.
1. Who we are
LoomInn is a platform for builders to work in public — share posts, collaborate on projects, and join communities. This policy applies to the LoomInn website, web app, and any related services (the "Service").
For privacy questions or data requests, contact us at privacy@loominn.com.
2. Information we collect
- Account data — email, username, display name, and a one-way hash of your password. We never see your password in plain text.
- Profile data — anything you add to your profile: bio, avatar, location, links, skills, interests.
- Content you create — posts, comments, project data, chat messages, notes, tasks, files you upload, votes, and bookmarks.
- Usage data — pages you visit, posts you view, features you use, search terms. This powers the personalized feed algorithm and helps us improve the product.
- Device and connection data — browser, operating system, IP address, approximate location, and session info. We retain this for security, fraud prevention, and basic analytics.
- Communications — when you email us, we keep the message and your email address to follow up.
3. How we use your data
- To operate the Service — deliver your feed, route notifications, sync your projects, host your uploads.
- To personalize the Service — the feed algorithm uses your interests, follows, and engagement to rank content.
- To secure your account — detect unusual activity and prevent abuse.
- To communicate — transactional emails (password resets, invitations, mentions) and, only if you opt in, digests.
- To improve LoomInn — aggregated, anonymous usage metrics (e.g. how often a feature is used).
- To comply with legal obligations, enforce our Terms, or respond to valid legal requests.
4. Third-party processors
We use the following trusted services to operate LoomInn. Each is under contract with appropriate data-processing terms.
- Supabase (database): primary PostgreSQL storage for all application data. Hosted in the region closest to our production environment.
- Cloudinary (media): stores and serves images, avatars, and file uploads. Only what you upload is sent to Cloudinary.
- Redis (cache / real-time): holds short-lived session, presence, and rate-limit data; powers WebSocket delivery.
- Email delivery provider: sends transactional emails (password reset, verification, invitations). Only your email address and the email content are shared.
We do not run third-party advertising networks, session recording, or behavioral fingerprinting.
5. Data storage and security
- All traffic between your browser and LoomInn is encrypted in transit with TLS.
- Sensitive secrets (password hashes, API keys, refresh tokens) are stored encrypted at rest.
- Authentication uses httpOnly, sameSite cookies that cannot be read from JavaScript. Sessions refresh silently; access tokens live 15 minutes, refresh tokens live up to 7 days.
- Access to production data is limited to a small number of engineers, gated by device posture and logged.
- We back up the database daily with point-in-time recovery. Backups are encrypted and retained for 30 days.
No system is perfectly secure. If we discover a breach that affects your data, we will notify you as required by applicable law.
6. Your rights and controls
- Access — view all data we hold about you via your profile and settings.
- Correction — update your profile, interests, and privacy preferences in Settings.
- Profile visibility— make your profile searchable or not, allow/block direct messages, require approval for new followers, in Settings → Privacy.
- Blocking — block any user to hide their content and prevent them from interacting with you.
- Export— we'll provide an export of your content on request. Email us from your registered address.
- Deletion— delete your account from Settings → Danger zone. We remove personal data within 30 days, except where retention is required by law.
- GDPR / CCPA-equivalent rights— if you live in a jurisdiction that grants additional rights (right to portability, right to object, right to restriction), email us and we'll honor them.
7. Cookies and local storage
We use only the cookies and storage needed to run the Service:
- Authentication cookies — httpOnly
auth-tokenandrefresh-tokenissued by our backend when you sign in. - UI preferences — theme, sidebar state, post-draft autosave stored in
localStorageon your device. - Session ID — a random per-browser-tab identifier in
sessionStorageused to dedupe post views for the feed algorithm.
We do not set third-party tracking cookies. If we add analytics in the future, we will update this section and, where required, obtain consent.
8. Children
LoomInn is not intended for people under 13. We do not knowingly collect personal data from minors under 13. If you believe a minor has created an account, email privacy@loominn.com and we will remove it promptly.
9. Data retention
We keep your data for as long as your account is active. If you delete your account, we remove personal data within 30 days. Anonymized usage statistics, audit logs, and content you posted publicly (which other users may have interacted with) may persist in aggregated form. Backups age out on a 30-day rolling window.
10. International transfers
LoomInn may process data outside your country of residence, including in the United States and the European Union, via our hosting providers. Where required by law, we rely on standard-contractual-clause-equivalent mechanisms with our processors to protect that transfer.
11. Changes to this policy
We may update this policy from time to time. For material changes we will notify you by email or in-app notice at least 15 days before the change takes effect. Continued use of the Service after a change means you accept the updated policy.
12. Governing law
This policy is governed by the laws of the jurisdiction where LoomInn is incorporated, without regard to its conflict-of-laws rules. If you are covered by the GDPR (EU/EEA), the UK GDPR, or similar regional data-protection law, nothing in this policy waives your statutory rights under those laws.
13. Contact
Questions or requests about your data? Email privacy@loominn.com. For general support, write hello@loominn.com.