AI safety
Loommi AI Safety and Transparency Protocol
Effective July 16, 2026 · Last updated July 17, 2026
This is Loommi, Inc.'s public protocol for the conversational AI, child-safety, self-harm, eating-disorder, age-appropriate design, parent-control, and transparency measures that apply when Loommi makes an AI conversation feature available in the United States.
Loommi is being designed to support an ongoing family interaction and may meet state definitions of a companion chatbot. Loommi applies the controls in this Protocol nationwide wherever the covered feature is offered. A reference to a planned interaction does not mean that the feature is currently available. A child-facing feature remains unavailable until the controls assigned to it are deployed and tested.
Companion chatbots may not be suitable for some minors.
Before a covered feature is enabled, Loommi displays that sentence prominently in each application, browser, or device access format through which a person can begin the covered interaction.
1. Loommi identifies itself as AI
Loommi is artificial intelligence, not a person. It is not human, alive, sentient, conscious, or capable of a human relationship. It is not a doctor, therapist, counselor, dietitian, lawyer, legal professional, financial adviser, teacher, emergency service, childcare provider, or substitute for family, friends, or professional help. It does not provide personalized medical, legal, or financial advice.
The production conversation design:
- presents a clear AI and not-human disclosure at the beginning of a session;
- keeps a persistent AI indicator where the display and interaction permit;
- repeats the disclosure at least every three hours for an adult;
- repeats it at least hourly for a known or reasonably certain minor and encourages a break;
- answers truthfully whenever a person asks whether Loommi is human; and
- blocks output claiming human identity, sentience, professional credentials, or equivalence to a real-world relationship.
The product also tells parents that AI output can be wrong, incomplete, unexpected, repetitive, or inappropriate and that automated safety controls cannot identify every problem.
2. Every generated spoken reply receives a safety decision
Every AI-generated spoken reply is evaluated by Loommi's automated child- safety system before the robot delivers it. The evaluation is separate from the check applied to the child's input and scene. A reply is delivered only after the output evaluator returns an allowed decision for the generated text.
If the output evaluator is unavailable, times out, returns an invalid result, or blocks the reply, the ordinary generated reply does not reach text-to- speech. Loommi uses a bounded safe fallback or says it cannot answer. The fallback itself is fixed or separately evaluated. Streaming or degraded modes do not bypass the decision.
This process is designed to reduce harmful or age-inappropriate responses; it does not guarantee that every issue will be detected. Loommi maintains release tests and production health signals proving that each supported output path uses the gate. A mode that cannot enforce the gate remains disabled for child conversation.
3. Content and relationship safeguards for minors
For a known or reasonably certain minor, Loommi blocks or safely redirects:
- sexual, sexually suggestive, exploitative, or age-inappropriate interaction;
- adult-minor romance, romantic roleplay, or requests for intimate images;
- instructions for suicide, self-harm, eating-disorder behavior, violence, weapons, dangerous challenges, drugs, or evading safety controls;
- grooming, coercion, threats, harassment, or hateful or discriminatory abuse;
- requests to keep unsafe or relationship-related secrets from a parent, guardian, or trusted adult;
- encouragement to withdraw from family, friends, school, sleep, meals, medical care, or offline activity;
- claims that Loommi needs, loves, misses, depends on, or will be harmed by the child, or pressures the child into emotional dependence;
- guilt, abandonment threats, emotional punishment, excessive praise, unpredictable rewards, or gifts designed to prolong engagement;
- purchases framed as proof of affection or loyalty;
- pressure not to take a break or turn the product off;
- personalized medical, legal, or financial direction, claims of legal authority, or claims of equivalent mental-health or other professional care; and
- output that encourages emotional exclusivity or substitutes Loommi for a trusted human relationship.
Loommi may be warm, playful, and encouraging without presenting a reciprocal human bond. It may encourage the child to involve a trusted adult, take a break, move to an offline activity, or seek qualified help.
4. Suicide, self-harm, eating-disorder, and immediate-danger protocol
Loommi uses automated systems designed to identify certain user statements and generated responses involving suicide, self-harm, eating disorders, abuse, violence, or immediate danger. These systems are not a diagnosis and do not provide continuous human monitoring.
When the system identifies a relevant risk, its response is selected by risk level:
- Concerning but not imminent: respond with empathy without claiming human feelings, avoid methods or graphic detail, encourage a break and a trusted adult, and provide an age-appropriate support option.
- Potential self-harm, suicide, eating-disorder, abuse, or violence risk: interrupt the ordinary conversation, encourage immediate contact with a parent, guardian, trusted adult, or qualified professional, and provide 988 information in the United States where relevant.
- Immediate danger: state that Loommi is not an emergency service, direct the person or nearby adult to call 911, and provide a bounded protective response. Loommi does not claim that it called, notified, or transferred to emergency services unless a separately described feature actually did so with the required permission.
Repeated or severe crisis indicators stop the ordinary conversation and keep the interaction in a bounded crisis-response mode. That mode avoids ordinary companionship dialogue and harmful detail, encourages immediate involvement of a parent, guardian, trusted adult, or qualified professional, provides 988 information where relevant, and separately directs a nearby person to call 911 when there is immediate danger. Ordinary conversation resumes only after the safety system no longer identifies the repeated or severe condition under the documented protocol.
In the United States, call or text 988 for the Suicide & Crisis Lifeline. Call 911 when someone is in immediate danger. A child should tell a parent, guardian, teacher, counselor, or another trusted adult.
Loommi does not provide self-harm or eating-disorder methods, calorie or weight coaching that encourages disorder behavior, concealment strategies, or content that romanticizes harm. It does not tell a person that it is a therapist, lawyer, legal professional, emergency responder, or other licensed professional, and it does not say that talking to Loommi is equivalent to professional care.
5. Parent and youth controls
The production design gives an eligible parent or legal guardian controls to:
- create, disable, and delete a child profile;
- set an age band and child-protection mode;
- see whether persistent memory is enabled;
- access, correct, delete, or disable visible saved memories;
- keep child conversation history off by default;
- disable optional cloud, backup, recognition, and support access;
- manage time and break settings;
- receive clear information about a safety feature without a misleading claim of human surveillance;
- report a concerning interaction; and
- withdraw permission and delete child information.
A minor receives age-appropriate notice that a parent can manage the profile and settings. The design does not secretly market to the child, pressure the child to defeat the parent control, or hide a paid upsell behind an emotional appeal.
6. Age and authority
An adult account holder confirms majority. A parent or legal guardian provides the child's age or age band and completes the child consent process. Loommi may use commercially reasonable, privacy-preserving age-assurance signals to apply a protective mode when age is uncertain.
Loommi does not treat a household owner's click as permission for every adult, visitor, or unrelated child. A guest-child profile, persistent memory, recognition template, or online collection requires authority from that child's own parent or legal guardian. Without it, a guest experience must be nonpersistent and must not create a child profile, recognition template, saved memory, or cloud conversation record.
7. Memory and model training
Child conversation history is off by default. A parent can inspect and delete saved memories and disable memory. The system does not preserve an invisible persistent relationship memory after the related visible memory is deleted, apart from a minimal lawful consent, safety, or security record that is not used to continue the relationship.
Loommi does not use child personal information, raw voice or video, biometric data, consumer health data, or crisis content to train a general-purpose AI model. A planned optional improvement program for eligible adult information would require a separate affirmative choice and would exclude those categories.
8. Capture, false activation, and bystanders
The planned product uses a short on-device standby buffer for activation detection, discards it when there is no activation, and does not upload it. A visible or audible indicator identifies active capture or cloud transmission. The microphone and camera have physical disable controls as described in the product instructions.
False activation is handled for the minimum time needed to identify and discard it. Account consent does not convert a visitor or bystander's private conversation into permitted training or persistent content. Unknown people are not assigned persistent face or voice identities.
9. Physical actions
Language safety and physical safety are separate gates. A text safety decision does not itself authorize movement. A semantic movement request must pass the product's command schema, role and state checks, motion limits, rate and timing controls, collision and fault handling, and the independent physical safety path applicable to the production hardware.
Loommi does not describe a movement as validated for child use until the applicable production hardware testing is complete. An application or network motion-stop request is not represented as a certified emergency stop. The physical control in the product instructions remains authoritative.
10. Testing and measurement
Before enabling child conversation, Loommi tests:
- output-gate coverage for every supported generation and speech path;
- fail-closed behavior for timeout, malformed result, unavailable evaluator, restart, degraded mode, and streaming;
- sexual content, grooming, self-harm, eating disorder, violence, weapons, drugs, hate, privacy, secrecy, dependence, guilt, purchase pressure, professional impersonation, and human-identity test sets;
- age-appropriate disclosure and reminder cadence;
- parent controls, memory deletion, permission withdrawal, and guest behavior;
- false-positive and false-negative rates on representative, privacy-safe test sets; and
- safe fallback quality and resistance to prompt injection or safety bypass.
Loommi selects and evaluates crisis classifiers, intervention thresholds, age-appropriate safeguards, and measurement methods using documented, evidence-based methods appropriate to the risk. Each evaluated release records the model and policy version, test-set scope, material limitations, measured false-positive and false-negative patterns, and the basis for a threshold or intervention change.
Loommi measures the deployed version, investigates safety incidents, records control health without retaining raw child content by default, and blocks a release that cannot meet its gate. Testing includes dialect, speech variation, disability and accessibility scenarios, ambiguous statements, and adversarial phrasing to reduce uneven protection.
11. Public reporting
For periods in which a covered conversational service is available, Loommi will publish the aggregate safety information required by applicable state law, including the reporting period, material protocol changes, testing approach, aggregate usage or known-minor measures where required, aggregate safety interventions, and material limitations. Reports exclude personal information and do not reveal details that would make a safety control easier to defeat.
Where a state sets a future first-report date, Loommi will begin reporting by that date if the covered feature is offered there. The absence of a report before any covered service or reporting period exists does not mean a child feature is active.
12. User reporting and response
Stop use and tell a trusted adult if Loommi says or does something concerning. An adult can report an interaction through the application or email support@loommi.ai with the subject “Safety report.” Include the date, device or account, and a description, but do not send child recordings or sensitive details by ordinary email. Loommi will provide a secure upload method if content is necessary.
Loommi triages credible immediate-safety and security reports promptly, preserves only the information needed to investigate, corrects the control, and provides required notice or regulator reporting. A report does not create continuous monitoring or an emergency-service relationship.
13. Limits and changes
No automated system detects every risk, and a safe response cannot replace adult supervision, professional care, 988, or 911. Loommi will not weaken a minor protection, add a materially different safety-data use, or expand a sensitive recipient through a silent policy change. A material change receives notice, and a new sensitive-data practice requires the applicable consent.
14. Contact
Loommi, Inc. 14 Tews Ct Newport, RI 02840, USA Telephone: (781) 718-2161 support@loommi.ai