Washington privacy
Washington Consumer Health Data Privacy Policy
Effective July 16, 2026 · Last updated July 20, 2026
This policy contains the disclosures required by the Washington My Health My Data Act for consumer health data that Loommi, Inc. may process about a Washington consumer. It applies to the Loommi website, Store, device, companion application, account, AI conversation, accessibility, recognition, safety, cloud, support, and related services that Loommi makes available.
Some described features are planned and may not be available. Describing a planned category is not a statement that Loommi currently collects it and is not consent. Before collecting a new category of consumer health data or using it for an additional purpose, Loommi will disclose the category and purpose and obtain affirmative consent unless the processing is necessary to provide a product or service the consumer requested as permitted by Washington law.
1. Loommi contact
Loommi, Inc. 14 Tews Ct Newport, RI 02840, USA Telephone: (781) 718-2161 support@loommi.ai — subject “Privacy request”
2. Categories Loommi may collect and their purposes
Washington defines consumer health data broadly. Depending on the feature a consumer or parent enables, Loommi may collect:
| Category | Collection and use purpose |
|---|---|
| Optional accessibility or support information | To apply a parent-selected communication, hearing, speech, mobility, sensory, learning, or other accessibility setting to the child profile or device. |
| Health-related conversation content | To respond to the activated request on the device or through an optional cloud feature the user selects. |
| Suicide, self-harm, eating-disorder, abuse, violence, crisis, or other safety signal | To choose a protective response, interrupt harmful output, present 988 or 911 guidance, and measure the safety system without continuous human monitoring. |
| Mental- or physical-health inference | Only when needed for the user-requested safety or accessibility function; not to diagnose, advertise, determine eligibility, or build a commercial health profile. |
| Voice recording, face image, voiceprint, face-geometry template, or recognition result capable of identifying a person | To enroll and recognize a person for the optional household recognition feature after the separate person-specific biometric permission. |
| Health-related memory or parent summary | To show the information to the authorized user who enabled the feature and permit access, correction, and deletion. |
| Consent, withdrawal, and deletion information | To apply the consumer's choices and demonstrate compliance. |
| Device and security information associated with a health-data feature | To authenticate the household, protect the data, operate the requested feature, diagnose a reported failure, and execute deletion. |
Loommi does not collect consumer health data to advertise, sell data, train a general-purpose AI model, make an insurance, credit, employment, education, housing, health-care, or other legal or similarly significant decision, or infer an unrelated sensitive trait.
3. Sources
Loommi may receive consumer health data:
- directly from the consumer;
- from a parent or legal guardian who enters optional information for their own child;
- from an activated voice or camera interaction after the applicable notice and permission;
- from on-device automated safety or recognition processing;
- from a paired device or application executing the user's setting; and
- from a contracted processor acting under Loommi's instructions for the enabled feature.
Loommi does not buy consumer health data from a data broker. For recognition kept only on one household robot, the owner may record another adult household member's choice only after that adult receives the notice, agrees, and asks the owner to record it. This local choice does not permit online health-data or biometric processing. Another competent adult must complete an online adult flow themself. A household owner cannot act for an unrelated child.
4. Categories collected
The categories Loommi may collect are the categories in Section 2. A specific feature collects only the categories its in-context notice identifies. Local processing is still treated conservatively as collection for this policy even when the information does not reach Loommi's cloud.
An optional accessibility field is not required for an unrelated core function. Optional recognition, cloud conversation, memory, backup, and support upload remain off until the eligible person enables them.
5. Categories shared
Loommi does not currently share consumer health data with a third party or affiliate as “sharing” is defined by the Washington My Health My Data Act. Loommi has no affiliate with access to consumer health data.
Loommi may use a processor under a binding contract to provide the requested service. Processing under Loommi's instructions for the disclosed purpose is not treated as third-party sharing under the Act. Depending on the enabled feature, those processors may be:
- Cloudflare, for restricted API delivery, network protection, and security;
- Supabase, for restricted account, consent, profile, and optional cloud storage; and
- a cloud AI, support, or verification processor that Loommi specifically identifies before any consumer health data is sent.
Loommi will not add a processor that uses consumer health data inconsistently with this policy. If Loommi proposes a disclosure that is “sharing” under the Act, it will identify the category and recipient and obtain a separate consent for sharing before the disclosure. Collection consent is not sharing consent.
6. Collection and sharing consent
Before consent-based collection, Loommi's request states the categories, specific purposes and uses, recipient categories, and how to withdraw. The consumer takes an unambiguous affirmative action. The request is separate from general Terms and is not combined with an authorization to sell.
Loommi relies on the requested-product-or-service basis only to the extent the processing is actually necessary to provide the product or service the consumer requested. Optional personalization, memory, recognition, analytics, model improvement, and unrelated secondary uses are not treated as necessary merely because they could be useful.
7. Sale
Loommi does not sell consumer health data and does not offer it for sale. It does not condition a product or service on an authorization to sell. If this commitment ever changes, Washington law requires a separate, signed, time- limited authorization containing the statutory disclosures; a general update to this policy would not provide that authorization.
8. Washington rights
A Washington consumer may ask Loommi to:
- confirm whether Loommi is collecting, sharing, or selling their consumer health data;
- provide access to that data;
- provide a list of all third parties and affiliates with whom the data was shared or sold and an active contact method for each;
- withdraw consent from future collection or sharing; and
- delete the consumer health data.
Loommi currently has no sale, third-party sharing, or affiliate recipient to list. A processor used under Loommi's instructions is identified in Section 5 and in the applicable feature notice.
Submit a request through the application's Privacy Center when available or email support@loommi.ai with the subject “Privacy request.” A consumer does not need to create a new account, though Loommi may require use of an existing account or request additional information when commercially reasonable efforts cannot authenticate the person or their authority for a child. If Loommi cannot authenticate a request after commercially reasonable efforts, it is not required to act on the request and may ask for the additional information reasonably necessary to authenticate it.
Loommi provides up to two responses per year without charge. For a request Loommi can authenticate, it acts without undue delay and in all cases within 45 days after receiving the request. Loommi promptly takes steps to authenticate a request, but authentication does not extend the 45-day period. If reasonably necessary because of the complexity or number of requests, Loommi may take one additional 45-day period after notifying the consumer within the initial 45-day period of the extension and the reason. If Loommi declines a request, it explains the decision and appeal method.
Appeal by replying to the decision or emailing the same address with the subject “Privacy appeal.” Loommi decides an appeal within 45 days after receiving it and provides the online mechanism for contacting the Washington Attorney General if the appeal is denied.
Loommi does not unlawfully discriminate because a consumer exercises a right. Withdrawing an optional permission may stop only the feature that requires the information; unrelated features remain available.
9. Deletion
After receiving a deletion request, Loommi promptly takes steps to authenticate it. For a request Loommi can authenticate, Loommi deletes the consumer health data from active records and notifies each processor, contractor, affiliate, or third party that received it. Each recipient must honor the request as required by law.
Loommi completes active-system deletion and recipient notification without undue delay and no later than 45 days after receiving the request, and sooner when an immediate feature control is available. Authentication does not extend that active-system deadline. Isolated backup deletion completes within 90 days and in all events no later than six months after authentication. Deleted data is not restored to active use.
An offline device cannot receive a remote command. The consumer may use local deletion or factory reset immediately; otherwise Loommi marks device deletion pending and completes it when the device reconnects. If a broken device cannot be reset, Loommi uses restricted service intake and erases or destroys accessible information.
10. Security
Access is limited to personnel and processors for whom it is necessary to provide the requested and consented purpose. Loommi uses safeguards appropriate to the volume and nature of the data, including minimization, role-based access, adult authentication, encryption in transit, encryption at rest where cloud data is stored, device credentials, logging, provider restrictions, retention and deletion controls, security testing, and incident response. No system is completely secure.
11. Geofencing
Loommi does not use a geofence around an in-person health-care facility to identify or track a consumer seeking care, collect consumer health data, or send a health-related message or advertisement.
12. Changes
Before collecting an additional category or using consumer health data for an additional purpose, Loommi will update this policy and obtain affirmative consent before that collection or use. Before third-party sharing, Loommi will obtain a separate sharing consent. A policy update is not retroactive consent.