Children's privacy
Loommi Children's Privacy Notice
Effective July 16, 2026 · Last updated July 21, 2026
This Notice explains how Loommi, Inc. handles personal information from children, including children under 13, when Loommi makes its family robot, companion application, child profiles, AI conversations, memory, recognition, cloud, and related features available in the United States.
Loommi is designed for household use with an adult in charge. A parent or legal guardian must create and manage a child profile. A reference to a planned child feature does not mean that it is currently available or that the related information is currently collected. Loommi will present a direct notice describing the actual feature and obtain verifiable parental consent before online collection from a child begins.
Accepting general Terms or this Notice is not advance consent to a future child-information practice.
1. Operator and contact
Loommi, Inc. 14 Tews Ct Newport, RI 02840, USA Telephone: (781) 718-2161 support@loommi.ai — subject “Child privacy request”
Loommi, Inc. is the operator of the Loommi services. The providers that may process child information under Loommi's instructions for an enabled feature are identified below and in the feature's direct notice.
2. Before Loommi collects from a child
Loommi provides the child's parent or legal guardian with a direct notice that states:
- the child information the feature will collect;
- why it is needed and how it will be used;
- whether it stays on the device or leaves the home;
- each provider or recipient and why it receives the information;
- how long the information is kept;
- whether the feature is optional and what happens if permission is declined or withdrawn;
- how to access, correct, export, or delete the information; and
- the parent-verification method.
Loommi obtains verifiable parental consent before online collection. When disclosure to another party is not integral to the feature the parent requested, Loommi presents a separate choice for that disclosure. A parent may permit the core feature and decline the optional disclosure where the law requires that choice.
Unless and until Loommi obtains the required verifiable parental consent, Loommi will not collect, use, or disclose the child's personal information through the Family app or another Loommi online service. If Loommi collects a parent's name or online contact information solely to provide this direct notice or seek consent, Loommi deletes that information if consent is not obtained within a reasonable time.
Loommi's online method combines several steps. The adult signs in to an authenticated adult account, reads the direct notice, and separately confirms that they are at least 18, are the child's parent or legal guardian, and own or are authorized to use the card details they provide. Stripe processes those details in a hosted setup flow. Stripe or the card issuer may require authentication or other checks. The setup is not a purchase, and Loommi does not charge or capture any amount. Successful Stripe processing does not independently prove the adult's age, relationship to the child, or ownership of the card or payment account. Before granting permission, Loommi confirms the completed setup result directly with Stripe. Permission cannot activate unless the initiating adult account then has a currently confirmed email address; as part of the same activation, Loommi schedules a confirmation message for that exact address. If it cannot do both, it cancels the entire activation. Loommi does not create a Stripe customer profile for the setup, attach or reuse the card, or keep Stripe's reusable card identifier.
After activation, Loommi starts the delivery process for that confirmation. If a temporary delivery-system problem occurs, Loommi keeps trying instead of silently dropping the required message. Cloudflare may present the same pending message more than once for processing. This supports retries; it does not guarantee that the email provider accepts the message or that the message reaches the inbox.
Loommi keeps a separate database copy of the confirmed adult email address until Resend accepts the send request and Loommi records Resend's random message reference. Loommi sets a fixed cleanup deadline 30 days after permission is activated and this delivery obligation is created. Cloudflare accepting a delivery instruction for processing is not enough to remove this copy, and a staff retry cannot restart or extend the 30-day period. After Resend accepts the request and Loommi records the random reference, Loommi removes its separate database copy of the adult email address. During the final ten minutes before the deadline, Loommi stops new send attempts and its cleanup processes try to remove any address still waiting. A database outage or an unusually long database transaction could delay the physical removal. Loommi monitors for that condition, treats a delay as a retention incident, and removes the address as soon as database service permits. The delay does not extend the deadline or authorize another send. Loommi then keeps only a fixed unresolved result and the relevant times. It does not mark the message sent or delivered, and it does not reverse permission that was already recorded.
The dedicated Cloudflare delivery queue does not store the adult email address or confirmation text. A waiting copy contains only a random request identifier, which of the two online-permission flows applies, and the fixed message version. It expires within 14 days. After repeated failures, the same limited copy may remain in a separate, restricted failed-message area for up to 14 more days so authorized Loommi staff can safely retry or resolve it; after that it expires.
Immediately before a send, the Cloudflare-hosted service checks the current private database record under a two-minute authorization. It receives the confirmed adult address and creates the fixed message only when that send is still allowed. An already accepted or expired copy gets no address and is discarded without contacting Resend.
Once Resend accepts the send request, its standard service keeps the sent-email delivery data, including the adult email address and fixed message, for 30 days. If an address permanently rejects the message or the recipient reports it as spam, Resend may keep the adult address on a blocked-delivery list until it is removed so the service does not keep repeating a failed delivery. The confirmation is a plain-text account message, contains no child name or child content, and is not used for marketing.
Resend may send Loommi a signed notice that the message was delayed, delivered to the receiving mail server, failed, bounced, blocked, or reported as spam. Loommi uses a fixed category with no account, adult, household, or child identifier to separate these notices from other email. For each accepted send, it keeps only the random reference Resend assigns to the message, the result, and the time with the final verification record, not the adult address or message text. During the original 30-day period, if delivery fails or remains unresolved, authorized support staff may start another send after at least 24 hours. Loommi uses the initiating adult's current confirmed account email; staff cannot supply a different address or extend the deadline. Loommi does not automatically resend a message reported as spam. A small record containing only random references, result type, and times is used to handle notices that arrive more than once or before the send record is ready, and it expires within 30 days. A “delivered” notice does not prove that the adult opened or read the message.
The message explains how to stop online child use, withdraw permission, and report a request the adult does not recognize. To withdraw core online child permission, stop the child's online use and disconnect the robot, then open Settings → Privacy Center → Your data rights in the Loommi Family app to delete the child profile or request account deletion. An adult may also email support@loommi.ai with the subject “Child privacy request.”
Stripe or the card issuer may display a $0 verification or a small temporary authorization. Loommi cannot promise that display and does not rely on it or on the bank or card issuer sending a notice. The confirmation email described above comes from Loommi, not the bank or card issuer. Loommi uses the authenticated adult account, the adult's confirmations, successful Stripe-hosted setup processing, Loommi's direct confirmation of the result, the requirement for a confirmed email when permission turns on, and the confirmation message scheduled for that address together as its parent-verification method.
Successful Stripe setup processing is one element of Loommi's combined method; it does not prove age, relationship, ownership, or authorized use of the card or payment account, and it does not allow an account holder to claim authority over another parent's child. If Loommi offers a different permitted verification method, the direct notice will identify it and explain the information and provider involved.
3. Child information an enabled feature may handle
The direct notice selects from these categories and states the exact fields:
- profile: nickname or name, age or age band, language, time zone, confirmed interests, routines, and parent-selected settings;
- account relationship: child profile identifier, household and device association, parent permission and withdrawal records;
- voice and conversation: activated audio, on-device transcript, prompt, AI response, text-to-speech output, conversation context, visible history, summary, and saved memory;
- camera and scene: an image, video frame, face, object, or compact scene signal needed for a parent-enabled visual feature;
- recognition: a raw enrollment sample, face or voice template, matching result, permission status, and deletion date;
- accessibility and consumer health: an optional parent-entered accessibility need, health-related conversation, or safety signal, subject to a separate consumer-health notice and consent where required;
- safety: an automated classification involving self-harm, suicide, eating disorders, abuse, violence, or immediate danger and the protective response selected;
- device and internal operations: device identifier, software version, consent state, routing label, latency, error, security signal, and compact machine-health information needed to operate and protect the service; and
- support content: a log, screenshot, recording, or other item an adult intentionally submits for a specific support matter.
Loommi does not require a child to provide more personal information than is reasonably necessary for the requested activity. Optional interests, accessibility details, memory, recognition, backup, cloud processing, analytics, and improvement programs are not conditions of unrelated core use.
Loommi may use a persistent identifier without separate parental consent only where the law permits it to support the service's internal operations, such as authentication, security, fraud prevention, maintaining settings, network communications, or legal and safety compliance. Loommi does not use that internal-operations exception for behavioral advertising, to contact a child, or to build an unrelated child profile. If Loommi plans to use the identifier for another purpose or combines it with other child personal information, Loommi will provide direct notice and obtain the required consent first.
Loommi's production design constrains internal-operations identifiers through field allowlists, purpose-bound services, role-based access, separation from child-content and advertising datasets, provider contracts that prohibit independent use, security logging, and deletion or rotation when the identifier is no longer needed for the stated operation. A provider may process an identifier only for the operation Loommi assigned to it.
4. Local and cloud processing
The planned default keeps a short activation buffer, activated raw media, transcripts, AI conversation processing, and recognition templates on the device. The standby buffer lasts only a few seconds, is discarded when there is no activation, and is not uploaded.
Raw child audio, images, video, and transcripts do not leave the device by default. A cloud feature remains off until the parent sees what segment and context will be sent, the provider, the purpose, retention, and deletion control, then provides the required permission. A visible or audible indicator identifies active capture or transmission in the production design.
Machine-health communication is limited to non-content operational fields. It is not a path for raw child media, conversation text, child name, or biometric template.
A feature is “local-only” under this Notice only when child personal information stays on the household device and is not transmitted to Loommi or another online service. Calling a feature local-only does not change its legal status if it sends a persistent identifier, content, profile field, or other child personal information online. Any such transmission must follow the direct-notice and consent rules in this Notice.
5. How Loommi uses child information
Depending on the enabled feature, Loommi uses child information only to:
- provide the requested AI interaction, routine, memory, personalization, recognition, backup, accessibility, or parent insight;
- authenticate the child's household and apply the parent's settings;
- generate and evaluate an AI response before delivery;
- detect certain safety signals and provide a protective response or crisis resource;
- maintain security, prevent abuse, and deliver critical firmware or safety changes;
- diagnose a specific issue after an adult authorizes support access or an upload; and
- comply with a deletion request, safety duty, recall, or legal obligation.
Loommi does not use child information for targeted advertising, cross-context behavioral advertising, sale, data brokering, credit or eligibility decisions, or general-purpose AI-model training. Loommi does not ask a child to make a purchase or begin a subscription.
6. Providers and disclosures
Providers receive only what is needed for the enabled function and act under contractual purpose, security, retention, and deletion restrictions.
| Provider | Child-related role when enabled |
|---|---|
| Cloudflare | Restricted API and parent-confirmation delivery, network protection, and service security. |
| Supabase | Adult authentication and restricted household, child-profile, consent, and optional cloud records. |
| Stripe | Stripe-hosted card-details setup processing used as one part of parent verification. Stripe receives the card and billing details directly and returns a limited setup result; Stripe or the card issuer may require authentication or other checks. Loommi sends no child information, captures no charge, creates no Stripe customer for the setup, and does not retain a reusable card identifier. Successful processing does not independently prove age, relationship, or ownership of the card or payment account. |
| Expo, Apple APNs, and Google FCM | Minimal push token and routing text for a notification the parent enables. |
| Apple App Attest and Google Play Integrity | Application-integrity signal used to protect a high-risk parent action. |
| A named optional cloud processor | Only after the direct notice names the provider and the parent enables the particular cloud feature. |
Shopify, Resend, carriers, and fulfillment providers process adult Store or communication information and are not intended to receive child conversation content. Loommi may disclose child information when a parent directs it, when valid legal process requires it, or when narrowly necessary to protect a child or another person from an immediate and credible threat. Loommi evaluates and limits such a disclosure.
Loommi does not sell child personal information or disclose it for targeted advertising, data brokering, or a provider's independent use. Loommi discloses child personal information only as described in this Notice. It does not permit a provider to retain child content for its own advertising or model training. Loommi does not provide a public child profile, chat room, message board, or other feature where a child can publicly post personal information. If Loommi plans a feature that permits public disclosure, it will remain off until a direct notice describes the feature and Loommi obtains the permission required by law.
7. Recognition, guests, and bystanders
Recognition remains off until the child being enrolled has a separate notice and permission from that child's own parent or legal guardian. A device owner cannot provide biometric permission for an unrelated child. Unknown people are not assigned persistent voice or face templates.
A guest-child feature that creates a profile or sends personal information online requires permission from that guest child's own parent or legal guardian. Without it, the product must use a nonpersistent mode that does not create a child profile, recognition template, saved memory, or cloud conversation record.
Account-holder consent does not cover a bystander's false activation. Loommi's design uses an activation boundary, capture indicators, physical mute and camera controls, prompt discard of false activations, and no unknown-person template to reduce unintended collection.
8. Parent rights and controls
A verified parent or legal guardian may:
- confirm whether Loommi has collected the child's personal information;
- access the child's profile, permission state, visible memories, and other information available to Loommi;
- correct inaccurate profile or memory information;
- obtain a portable copy of eligible information;
- delete one item, a feature category, a recognition template, the child profile, or the child's account-linked information;
- stop further collection or use;
- withdraw one optional permission without disabling unrelated features; and
- withdraw core online child permission.
Withdrawing permission for an optional feature stops that feature's future collection and use. Withdrawing core online child permission stops further online collection and cloud child processing and begins deletion of the child's account-linked information. A local-only function that sends no child information to Loommi may remain available after the parent clears cloud information and local data, if the product can provide that function without the withdrawn processing. Loommi will state the exact effect before the parent confirms withdrawal.
Use the application's Privacy Center or email support@loommi.ai with the subject “Child privacy request.” Loommi may authenticate the adult and their authority for the child. Loommi ordinarily completes an authenticated request within 45 days, and sooner where an immediate feature control is available.
9. Deletion by layer
Deleting a child profile removes the child's active cloud profile, visible memories, related cloud content, optional backup, and recognition data, and queues deletion for processors. Loommi retains only minimal consent, transaction, safety, security, or legal evidence that law permits and does not use it to continue the child's experience.
An offline robot cannot receive a remote command. The parent can delete locally or factory-reset it immediately; otherwise the queued deletion executes when it reconnects. The same limitation applies to a powered-off phone. Isolated recovery backups are overwritten within 90 days and deleted information is not restored to active use.
For a broken device that cannot be reset, contact Loommi before service or return. Loommi routes it through restricted intake and erases or destroys accessible child information.
10. Retention
The detailed Privacy Notice schedule applies. In summary:
| Information | Purpose and business need | Deletion rule |
|---|---|---|
| Standby activation audio | Detect the household's activation phrase without continuously recording a conversation. | Lasts only a few seconds and is discarded when there is no activation. |
| Local activated raw media | Complete the interaction requested by the household. | Deleted after the requested operation unless the parent separately enables a feature that requires a stated retention period. |
| Optional cloud raw media | Complete the particular parent-enabled cloud operation. | Deleted from active systems within 24 hours. |
| Child history | Let the parent review recent activity when the parent turns history on. | Off by default; if enabled, rolls off within 30 days unless the parent affirmatively saves an item. |
| Saved memory | Provide the specific continuity or personalization the parent enabled. | Deleted on item deletion, feature disable, profile deletion, or 12 months of inactivity, whichever occurs first. |
| Raw biometric enrollment sample | Create the separately permitted local recognition template. | Deleted immediately after template creation. |
| Recognition template | Recognize the particular person for the separately permitted purpose. | Deleted at the earliest of disable, withdrawal, purpose completion, profile deletion, or 365 days without recognition use. |
| Identifiable safety signal or device diagnostic | Deliver a protective response, investigate a specific incident, secure the service, or repair a device problem. | Retained no more than 30 days unless a documented incident, security, safety, or legal need requires longer retention. |
| Adult-authorized support upload | Diagnose and resolve the support matter for which the adult supplied it. | Deleted within 90 days after closure unless the adult requests earlier deletion or a documented warranty, safety, security, or legal need requires longer retention. |
| Consent and verification records | Show the parent's choice, prevent reuse for another request, document withdrawal, resolve disputes, and meet legal recordkeeping duties. | Minimum consent records are retained for five years after consent ends. A limited final Stripe setup record is retained for seven years after the result, then becomes eligible for deletion, unless law requires a different period. It does not contain the full card number, reusable card identifier, or address-line result. An unfinished request expires within 14 days and grants no permission. |
| Parent-verification confirmation delivery | Send the required fixed confirmation to the initiating adult account and recover a temporary delivery failure. | Loommi keeps its separate copy of the confirmed adult email while the confirmation is waiting. Loommi removes the copy after Resend accepts the request and Loommi records the random reference Resend assigns to the message, and it sets a fixed cleanup deadline 30 days after permission is activated and the delivery obligation is created. Staff cannot extend that deadline or choose a different address. During the final ten minutes, Loommi stops new send attempts and its cleanup processes try to delete any remaining address. A database outage or unusually long database transaction can delay physical deletion; Loommi monitors for that retention incident and deletes the address as soon as database service permits. The delay cannot extend the deadline or authorize another send. Loommi keeps only a fixed unresolved result and times without claiming delivery or reversing permission. Loommi does not automatically resend a message reported as spam. Cloudflare's Queue and restricted failed-message area may hold only an address-free random request identifier, flow, and message version for up to 14 days in each area. Immediately before an allowed send, the Cloudflare-hosted service briefly handles the confirmed adult address and fixed message while passing them to Resend; expired or already accepted copies receive no address. After each Resend acceptance, Loommi deletes its separate address copy and keeps only the random message reference, result, and times for that send with the final verification record for up to seven years. A small record containing only random references, result type, and times is used to handle repeated or early notices and expires within 30 days. Resend keeps its sent-email delivery data for 30 days and may keep an address that permanently rejected the message or reported it as spam on a blocked-delivery list until it is removed. |
| Isolated recovery backup | Restore service after a technical failure without restoring information the parent deleted to active use. | Overwritten within 90 days; deleted information is not restored to active use. |
Loommi has a written child-data retention and security program. It does not retain child information indefinitely merely because it could improve a product. Loommi keeps each category only for the disclosed purpose and documented business need, then deletes or de-identifies it under the rule above.
11. Security
Loommi applies safeguards appropriate to child information, including minimization, role-based parent access, multifactor authentication for sensitive adult actions, encryption in transit, encryption at rest where cloud information is stored, device credentials, consent enforcement, provider restrictions, event logging, deletion controls, security testing, updates, and incident response. No system is completely secure.
12. Changes
Loommi will not use a general policy update to authorize a materially different child-information practice. Before collecting a new category, adding a materially different use, or making a nonintegral disclosure, Loommi will provide a new direct notice and obtain the permission required. If a parent does not agree, the new optional feature remains off.
13. Contact and complaints
Contact Loommi at the address in Section 1. A parent may also submit a concern to the Federal Trade Commission or their state attorney general.