Recognition privacy
Loommi Biometric Privacy and Retention Policy
Effective July 16, 2026 · Last updated July 20, 2026
This public policy governs any optional Loommi face or voice recognition feature that Loommi, Inc. makes available in the United States. It provides a nationwide baseline and is intended to satisfy the public retention-and- destruction policy requirements that apply to biometric identifiers and biometric information, including face geometry and voiceprints.
Recognition is a planned optional feature. A reference here does not mean that it is currently available or that Loommi currently possesses a person's biometric data. Recognition remains off until Loommi records the separate, person-specific choice described below. The rule differs for a choice kept only on one household robot and a choice that permits online storage. This policy is not the person's notice or permission form.
1. Contact
Loommi, Inc. 14 Tews Ct Newport, RI 02840, USA Telephone: (781) 718-2161 support@loommi.ai — subject “Biometric request”
2. What the feature processes
For a person who affirmatively enrolls, the feature may process:
- a short voice sample or face image used for enrollment;
- a mathematical voice or face template derived from that sample;
- the enrolled person's profile identifier and selected modality;
- the date, purpose, permission version, and recorded choice;
- a local recognition match or nonmatch and last interaction date; and
- deletion, withdrawal, device-transfer, and reset state.
Loommi treats a voiceprint, face-geometry template, and information derived from either for identity as biometric information even where a particular state definition is narrower.
Loommi does not create a persistent biometric template for an unknown person. Raw media used only to determine that an unknown person is present is not assigned a stable identity or retained as a recognition profile.
3. Purpose
Loommi uses an enrolled template only to recognize that person for the household feature described at enrollment—for example, to select the correct profile, preference, greeting, or parent-confirmed memory.
Loommi does not use biometric data to:
- infer emotion, mental or physical health, race, ethnicity, disability, sexuality, or another sensitive trait;
- advertise or build a cross-service profile;
- make a credit, insurance, employment, housing, education, health-care, or other legal or similarly significant decision;
- train a general-purpose AI model;
- identify an unknown visitor; or
- sell, lease, trade, or otherwise profit from biometric data.
4. Notice and person-specific permission
Before the first enrollment capture, Loommi tells the person, the minor's own parent or legal guardian, or an adult's legally authorized representative acting within documented authority in writing that:
- a biometric identifier or biometric information will be collected or stored;
- the exact purpose of collection and use;
- whether the template remains on the device or uses an optional cloud path;
- the period for which it will be collected, stored, and used;
- the recipient and processor, if any;
- how to refuse, withdraw, and delete; and
- ordinary robot use remains available without recognition.
For recognition kept only on one household robot, the owner may record their own choice. The owner may record the choice of another competent adult who lives in the household only after that adult receives the notice, agrees, and asks the owner to record it. This is Loommi's local product rule; it is not a claim that the owner signed another adult's Illinois written release.
A competent adult who does not live in the household must open and accept their own private form served by the robot over the home network. An optional online-recognition or backup feature is a separate, stricter choice: another competent adult must complete the online adult flow themself, even if that adult lives in the household. The owner cannot complete that online flow for the other adult.
A legally authorized representative for an adult, including a court-appointed guardian, may act only to the extent of documented legal authority and only through a Loommi flow that verifies that authority. If Loommi cannot verify the authority or does not offer that flow, recognition remains off. For a minor, the choice must come from that minor's own parent or legal guardian after any required parent-verification step. A device owner cannot enroll an unrelated child.
The permission record identifies its text version, person, modality, device or household, purpose, date, fixed permission term, expiration, and acceptance event. Loommi provides a retainable copy. Device-local permission ends 365 days after acceptance. An optional cloud permission, if offered, lasts for the specific term selected in its separate flow and never more than 365 days. Permission is never indefinite. Expiration disables recognition and requires a new notice and choice before any later enrollment capture.
5. Local and optional cloud modes
The planned default creates and stores the recognition template on the device. Local recognition does not transmit the template to Loommi merely because the device is connected for updates or machine health. The detailed local choice, notice snapshot, choice evidence, and deletion state also remain on that robot; they are not copied to the cloud merely to prove local permission.
An optional cloud-recognition or encrypted-backup feature, if offered, remains off until a separate screen identifies the template or related data that will leave the device, the processor, purpose, retention, security, deletion, and effect of refusal. Enabling local recognition is not permission for cloud processing. A material change from local to cloud requires a new notice and permission before transmission. Optional cloud authorization evidence is a separate restricted record identifying the person, modality, purpose, term, notice version, authority, and choice. It is not a biometric template and does not turn a local permission record into cloud permission.
6. Retention and permanent destruction
Loommi applies the earliest applicable event:
| Information | Destruction rule |
|---|---|
| Raw voice or face enrollment sample | Permanently deleted immediately after a usable template is created, or immediately after an unsuccessful enrollment is abandoned. |
| Recognition template | Permanently deleted when recognition is disabled, permission expires or is withdrawn, the related profile or account is deleted, the device is transferred or factory-reset, the original purpose is satisfied, or 365 days pass without a recognition interaction, whichever occurs first. |
| Optional cloud or backup copy | Deleted on the same trigger from active systems and processors; isolated recovery copies are overwritten within 90 days and are not restored to active use. |
| Device-local permission and destruction evidence | The detailed ended-choice record remains only on the robot and is deleted no later than 365 days after permission ends, and sooner when a child-profile deletion or other law requires it. A random, non-identifying anti-replay or deletion-job reference may remain only as long as needed to finish and prove pending native cleanup. |
| Optional cloud permission and destruction evidence | The minimum non-template proof is retained in Loommi's restricted systems for seven years after permission ends to demonstrate the choice, authority, withdrawal, and deletion. It cannot be used for recognition and does not contain the face or voice template. |
This schedule is shorter than an outside three-year limit. Loommi will not keep a template until that outside limit when an earlier event above occurs. A law that requires faster destruction controls.
At least annually, Loommi reviews whether storage of each biometric identifier remains necessary, adequate, and relevant to the express purpose stated in the person-specific notice and permission record. If Loommi determines that an identifier no longer meets those requirements, Loommi permanently deletes it at the earliest reasonably feasible date and no later than 45 days after the determination. Loommi may take one additional period of no more than 45 days only when reasonably necessary because of the complexity or number of deletion operations, and documents the reason.
An offline device cannot receive a remote deletion command. The adult can use the device's local deletion or factory-reset control immediately. Otherwise, Loommi queues the command and it executes when the device reconnects. The application identifies pending device deletion rather than claiming it is complete.
7. Disclosure
Loommi does not disclose or otherwise disseminate biometric information unless:
- the subject, the minor's parent or legal guardian, or an adult's legally authorized representative acting within documented authority consents to the specific disclosure;
- disclosure to a contracted processor is necessary for the separately enabled feature and consistent with its notice;
- disclosure completes a transaction the subject requested; or
- a valid warrant, subpoena, or law requires it.
A processor must use the information only under Loommi's written instructions, protect it, assist with deletion, and must not retain it, sell it, advertise with it, or train its own model on it. Loommi does not disclose biometrics to a data broker, advertiser, or another household merely because accounts share a device.
8. Security
Loommi uses a reasonable standard of care and protects biometric information at least as strongly as other confidential and sensitive information. Planned controls include on-device storage by default, encryption in transit for an enabled cloud path, encryption at rest, keys and credentials separated from templates where practicable, role-based access, no raw sample in telemetry, permission enforcement before capture, logging of enrollment and deletion, processor restrictions, and security testing.
No system is completely secure. A suspected compromise triggers containment, investigation, deletion or credential rotation where appropriate, and legally required notice.
9. Device service, loss, transfer, and reset
Before return, repair, resale, or transfer, the owner must unlink and reset the device. Reset permanently deletes local templates. If damage prevents reset, contact Loommi before shipment; the device enters restricted intake and Loommi erases or destroys accessible biometric information before ordinary service or reuse.
A replacement does not copy a template unless the person separately enabled an eligible encrypted backup and completes authenticated restore and consent checks. A lost or stolen device can be remotely queued for unlink and deletion, but Loommi will accurately identify the deletion as pending until the device connects. Physical security and local encryption remain important while it is offline.
10. Rights
The biometric subject, a minor's parent or legal guardian, or an adult's legally authorized representative acting within documented authority may:
- confirm whether Loommi has a biometric identifier for the person and obtain the enrollment status and applicable policy;
- obtain the source from which the identifier was collected, the express purpose for collection and processing, and the data associated with it;
- obtain a copy of the notice and recorded permission;
- obtain the identity or category of each recipient and the purpose of the disclosure;
- correct inaccurate profile or permission metadata and, because a mathematical template cannot be edited directly, delete and re-enroll to correct the template;
- disable recognition or withdraw permission; and
- delete the template.
Refusal or withdrawal does not disable ordinary robot use or cause a penalty.
Use the application's recognition settings or email support@loommi.ai with the subject “Biometric request.” Loommi may authenticate the requester and their authority. A competent adult subject must ordinarily act for their own template; a representative may act only within verified legal authority.
11. Changes
Loommi will not expand a biometric purpose, modality, recipient, or cloud use through a general policy change. It will provide a new specific notice and obtain a new person-specific permission, including a signed electronic release where required, before the materially different processing begins. If permission is not given, the new processing remains off.
Nonwaivable rights under Illinois, Texas, Colorado, Washington, and any other applicable law remain in effect.