Privacy
Loommi Privacy Notice
Effective July 16, 2026 · Last updated July 21, 2026
This Notice explains how Loommi, Inc. (Loommi, we, us, or our) handles personal information through the loommi.ai website and Store, adult waitlist, Loommi devices and embedded software, companion applications, adult accounts, household and child-profile features, artificial-intelligence experiences, optional cloud, memory, recognition and backup features, subscriptions, firmware, telemetry, and support services that Loommi makes available in the United States.
It also explains the boundaries Loommi has set for features it plans to offer. A reference to a planned feature does not mean that the feature is currently available or that Loommi currently collects the related information. Before a planned feature begins collecting a new category of sensitive information or using information for a materially different purpose, Loommi will provide an in-context notice and obtain any permission required by law. Accepting this Notice is not consent to future processing of children's personal information, biometric information, consumer health data, or another category that requires affirmative consent.
Loommi offers its consumer product and services only in the 50 U.S. states and the District of Columbia. U.S. territories and possessions are not included, and Loommi does not offer the product or services internationally.
1. Loommi and contact information
Loommi, Inc. is the operator and controller responsible for the practices in this Notice.
Loommi, Inc. 14 Tews Ct Newport, RI 02840, USA Telephone: (781) 718-2161 support@loommi.ai
Use the subject “Privacy request” for a privacy right or concern. See Contact Information and Legal Notices for other requests.
2. Privacy choices built into the planned product
Loommi's planned family product follows these boundaries:
- a short standby audio buffer is processed on the device to detect an activation and is discarded if no activation occurs;
- raw child audio, images, video, and conversation transcripts do not leave the device by default;
- optional cloud, backup, support-upload, recognition, memory, and diagnostic features remain off until an eligible adult enables them through the applicable controls;
- a feature screen identifies what will leave the device, why, who receives it, and how to turn the feature off;
- physical capture-disable controls and capture indicators operate independently of an ordinary application setting in the production design;
- Loommi does not sell personal information, use it for cross-context behavioral advertising, or use child information, raw voice or video, biometrics, or consumer health data to train a general-purpose AI model; and
- a parent can manage a child's profile, permissions, memories, recognition, exports, and deletion from the application's Privacy Center when those features are available.
These are product commitments, not a claim that every planned control has already shipped. A feature that depends on one of these controls will remain unavailable until the control is deployed for that feature.
3. Information Loommi handles
Not every category applies to every person. Local-only use and optional features materially reduce what reaches Loommi.
3.1 Website, Store, waitlist, and communications
Loommi may handle:
- ordinary network request information, including IP address, browser and device headers, requested page, time, and security signals;
- first-party Store session and cart identifiers;
- an adult waitlist subscriber's email address, optional first name, confirmation and unsubscribe state, consent wording version, source page, email-delivery attempt and provider-message identifiers, template version, delivery, bounce, complaint or suppression state, and associated timestamps;
- a protected confirmation-token fingerprint while a signup is pending;
- catalog, cart, customer-account, checkout, order, tax, shipping, refund, return, warranty, and fraud-prevention information when commerce is available; and
- messages, requests, and attachments that a person intentionally sends to Loommi.
The adult waitlist does not ask for child information. Do not send passwords, full payment-card numbers, government identification, child recordings, biometric samples, or health details through ordinary email.
The signup choice asks the subscriber to confirm that they are an adult living in one of the 50 U.S. states or the District of Columbia and that they agree to receive Loommi updates by email. Loommi records the version of that wording with the signup.
The waitlist normalizes the submitted email address. Its lead record does not store the raw network address, browser description, raw confirmation token, or a child-data field. Cloudflare still processes ordinary request information at the network edge to deliver and protect the service. An empty field that an ordinary visitor does not fill in is used only to reject automated spam.
After submission, Loommi asks Resend to send a confirmation message. The adult joins the update list only after opening the link and completing that confirmation. This double opt-in is separate from a child consent, cookie choice, account, order, or product reservation. Resend returns a message identifier and sends Loommi signed lifecycle notices about sending, delivery, delay, failure, bounce, complaint or provider suppression. Loommi stores the bounded identifiers, status and timestamps needed to reconcile those notices, not the provider's raw notice, diagnostic message, subject or message body. A permanent bounce, spam complaint or provider suppression removes the address from the active update list; a temporary or undetermined bounce does not.
3.2 Adult account and household
When accounts are made available, Loommi may handle an adult's email address, display name, locale, age or majority confirmation, authentication subject, multifactor enrollment and security state, session metadata, account status, notification and marketing choices, last activity, and household role.
A household record can connect an owner, co-guardian, caregiver, paired device, and child profile. Role-based permissions determine which adult can change consent, export or delete data, transfer a device, or invite another adult. Loommi records permission and high-risk account events to protect the household and demonstrate choices.
3.3 Device, network, firmware, and security
Loommi may handle a device identifier, product model, serial and component identifiers, certificate fingerprint and validity, lifecycle and pairing state, account or household association, firmware and software version, configuration hash, update channel, last connection time, coarse network information, truncated IP address where configured, online state, security events, and consent state.
This information supports provisioning, pairing, authentication, firmware and security updates, fraud prevention, recalls, warranty service, device transfer, and fleet reliability. Device-registry records are not intended to contain raw child audio, images, video, transcripts, or recognition templates.
3.4 Child profile and family settings
After a direct parent notice and verifiable parental consent, Loommi may handle a child profile's nickname or name, age or age band, language, time zone, interests the parent confirms, routines, household relationships, parent-controlled settings, permission state, and profile identifier.
If Loommi offers a field for accessibility or support needs, that field may reveal health or disability information. It will be optional, visible to the parent, limited to the selected purpose, and subject to the separate Washington or Nevada consumer-health notice and consent where applicable. Loommi will not require optional health information to use an unrelated core feature.
3.5 Voice, camera, conversation, and AI output
Depending on the mode an adult enables, the device may process:
- a short standby audio buffer used only for on-device activation detection;
- activated raw audio;
- on-device speech recognition, transcript fragments, prompts, AI responses, and text-to-speech output;
- camera frames or scene signals needed for an enabled visual interaction;
- speaker or face matching signals for optional recognition;
- conversation context, summaries, saved memories, interests, and routines; and
- automated safety classifications and response-safety decisions.
Local mode keeps raw media, transcripts, and conversation processing on the device except for a specifically disclosed function such as a support upload, an account control, or an optional cloud feature. If optional cloud conversation processing is offered, the feature screen will identify the activated segment and context sent, the processor, retention, and deletion control before transmission begins.
A capture indicator identifies an active microphone or camera state in the production design. The microphone and camera can be physically disabled as described in the product instructions. A false activation is treated as activated audio only for the minimum time needed to identify and discard it; it is not a reason to retain a bystander's conversation.
3.6 Memories, summaries, and parent insights
If enabled, Loommi may create a child-visible or parent-visible summary, confirmed interest, routine state, saved preference, or memory. A proposed interest is not added to a profile until an authorized adult confirms it. Loommi does not use a mood, safety, or other inference to decide eligibility, price, education, employment, credit, insurance, housing, health care, or another legal or similarly significant matter.
Child conversation history is off by default. When memory is available, the parent controls whether it is enabled and can access, correct, or delete saved items. Loommi does not maintain a hidden persistent child memory after the related visible memory has been deleted, except for a minimal legally permitted security or consent record that is not used as memory.
3.7 Recognition and biometrics
Optional voice or face recognition may process a short enrollment sample and convert it into a mathematical voice or face template used to recognize the enrolled person. Recognition remains off until Loommi records a separate choice for that one person. For recognition kept only on one household robot, the owner may confirm themself. The owner may confirm another adult who lives in the household only after that adult agrees and asks the owner to record the choice. The owner may confirm a child who lives in the household only when the owner is the child's parent or legal guardian and is authorized to decide. This is Loommi's local product rule; it is not a claim that the owner signed another adult's Illinois written release.
A non-household adult must open and accept their own private form served by the robot over the home network. For a non-household child, that child's own parent or legal guardian must accept the form. Optional online recognition storage is a separate, stricter choice: another competent adult must complete the online adult flow themself, and the household owner cannot complete it for that adult or for an unrelated child.
Loommi does not use recognition data to infer emotion, health, race, ethnicity, or another sensitive trait; create a persistent identity for an unknown person; advertise; or sell or profit from biometric data. The Biometric Privacy and Retention Policy controls this feature.
3.8 Consumer health data and safety signals
An optional accessibility field, a health-related conversation, and an automated signal about suicide, self-harm, eating disorders, abuse, violence, or physical or mental health can be consumer health data in some states. Loommi processes such information only for the user-requested accessibility or safety function, with separate consent where required. It is not used for advertising, eligibility decisions, or general-purpose model training.
Washington and Nevada residents should read the separate Washington Consumer Health Data Privacy Policy and Nevada Consumer Health Data Privacy Policy.
3.9 Machine telemetry and support
Loommi separates operational machine information from family content. Planned fleet-health information includes version, uptime, routing label, latency, confidence, temperature or power state, error code, crash signal, component health, audio-quality summary, and whether a control succeeded. It is designed not to include raw audio, raw images or video, conversation text, child name, or biometric template.
Product analytics and third-party analytics are off by default for child use. A diagnostic escalation occurs only after an adult requests help and authorizes a time-limited support path. The support screen will show the payload categories, duration, recipient, and revocation control. A user may separately choose to upload a log, screenshot, recording, or other content for one support matter. Loommi does not describe a support payload as “hardware only” unless its enforced schema makes that statement true.
3.10 Backup and recovery
If encrypted cloud backup is offered, the adult enables it separately. The feature can back up only the categories shown in its screen. When encryption uses a key held only by the household, Loommi cannot read the protected content or recover a lost key. The active design uses a device-generated recovery code as the encryption key. The application displays that code once and does not retain it. "Displayed once" does not mean the code becomes cryptographically single-use: a copy saved by the household can restore the encrypted backup again, and Loommi cannot invalidate that offline copy.
Stopping future backups and deleting an existing backup are separate actions. The application will provide both controls. A restore can place information back onto a device only after household authentication and the applicable consent checks.
3.11 Payment, subscription, parental verification, and service records
Shopify and configured payment providers process payment-card information at checkout. Loommi may receive transaction status, tokenized payment reference, payment brand and last four digits, billing and shipping contact, tax and fraud signals, order, refund, and subscription state. Loommi does not ask you to send a full card number to Loommi by email.
Loommi's online parent-verification flow combines several steps. The adult signs in to an authenticated adult account, reads the direct notice, and separately confirms that they are at least 18, are the child's parent or legal guardian, and own or are authorized to use the card details they provide. Stripe processes those details in a hosted setup flow. Stripe or the card issuer may require authentication or other checks. The setup is not a purchase, and Loommi does not charge or capture any amount. Successful Stripe processing does not independently prove the adult's age, relationship to the child, or ownership of the card or payment account. Before granting permission, Loommi confirms the completed setup result directly with Stripe. Permission cannot activate unless the initiating adult account then has a currently confirmed email address. During activation, Loommi also schedules a confirmation message for that exact address. If it cannot both activate permission and schedule the message, it cancels the entire activation.
After activation, Loommi starts the delivery process for that confirmation. Loommi keeps a separate database copy of the confirmed adult email address until Resend accepts the send request and Loommi records Resend's random message reference. Loommi sets a fixed cleanup deadline 30 days after permission is activated and the delivery obligation is created. Cloudflare accepting a delivery instruction for processing is not enough to remove this copy. During that 30-day period, if a waiting Cloudflare instruction expires or Loommi cannot record Resend's acceptance, Loommi may try the same fixed message again instead of silently dropping it. A staff retry cannot restart or extend the 30-day period.
After Resend accepts the request and Loommi records the random reference, Loommi removes the separate database copy of the adult email address. During the final ten minutes before the fixed deadline, Loommi stops admitting new send attempts and its minute cleanup processes try to remove any address still waiting. A database outage or an unusually long database transaction could delay the physical removal. Loommi monitors for those conditions, treats a delay as a retention incident, and removes the address as soon as database service permits. The original deadline still stops automatic and staff retry; a delay does not extend the deadline or authorize another send. Loommi then keeps only the fact that the confirmation remained unresolved, a fixed reason, and the relevant times with the limited verification record. That outcome does not say the message was sent or delivered, and it does not reverse permission that was already recorded.
The dedicated Cloudflare delivery queue does not store the adult email address or message text. A waiting copy contains only a random request identifier, which of the two online-permission flows applies, and the fixed message version. It expires within 14 days. If repeated attempts fail, the same limited copy may move to a separate, restricted failed-message area for up to 14 more days so authorized Loommi staff can safely retry or resolve it; after that it expires. Acceptance for processing does not mean that Resend accepted the message or that it reached the inbox. Cloudflare may present the same pending instruction more than once for processing. That supports retries; it is not a guarantee of provider acceptance or inbox delivery.
Immediately before a send, the Cloudflare-hosted service checks the current database status under a two-minute authorization, obtains the confirmed adult address only for an allowed send, and creates the fixed message for Resend. A copy tied to a completed, already accepted, or expired confirmation gets no address and is discarded without contacting Resend.
Once Resend accepts the send request, its standard service keeps the sent-email delivery data, including the adult email address and fixed message, for 30 days. If an address permanently rejects the message or the recipient reports it as spam, Resend may keep the adult address on a blocked-delivery list until it is removed so the service does not keep repeating a failed delivery. The confirmation is a plain-text account message, contains no child name or child content, and is not used for marketing.
Resend may send Loommi a signed notice that the message was delayed, delivered to the receiving mail server, failed, bounced, blocked, or reported as spam. Loommi accepts these notices for this confirmation only when they carry a fixed category that contains no account, adult, household, or child identifier. For each send Resend accepts, Loommi keeps the random reference Resend assigns to the message, the result, and the time as part of the limited final parent-verification record described below. Those records do not contain the adult email address or message text. During the original 30-day period, if delivery fails or remains unresolved, authorized support staff may start another send after at least 24 hours. Loommi then uses the initiating adult's current confirmed account email; staff cannot supply a different address or extend the original deadline. Loommi does not automatically resend a message reported as spam. If Loommi later offers an adult a self-service reissue after the original period, it will require the initiating adult to be signed in, use that adult account's then current confirmed email, and create a separate delivery record with a new deadline; support staff will not be able to reopen the old record or choose the address. Loommi also keeps a small record containing only random event and message references, the result type, and times for up to 30 days so it can correctly handle notices that arrive more than once or before the send record is ready. A “delivered” notice means the receiving mail server accepted the message; it does not prove that the adult opened or read it.
The message explains how to stop online child use, withdraw permission, and report a request the adult does not recognize. To withdraw core online child permission, stop the child's online use and disconnect the robot, then open Settings → Privacy Center → Your data rights in the Loommi Family app to delete the child profile or request account deletion. An adult may also email support@loommi.ai with the subject “Child privacy request.”
Stripe or the card issuer may display a $0 verification or a small temporary authorization. Loommi cannot promise that display and does not rely on it or on the bank or card issuer sending a notice. The confirmation email described above comes from Loommi, not the bank or card issuer. Loommi uses the authenticated adult account, the adult's confirmations, successful Stripe-hosted setup processing, Loommi's direct confirmation of the result, the requirement for a confirmed email when permission turns on, and the confirmation message scheduled for that address together as its parent-verification method. Successful Stripe processing by itself does not prove the adult's exact age, relationship to the child, or ownership or authorized use of the card or payment account.
Stripe receives the full card details and billing address directly. Loommi does not receive or store the full card number, inspect or store any billing name, email address, or street address Stripe returns, create a Stripe customer profile for the setup, attach the card to an account, or reuse it. Loommi discards Stripe's reusable card identifier. A limited record may include random and Stripe references, card brand and last four digits, any card-security and postal-code results Stripe provides, the adult's confirmations, notice and consent versions, relevant times, selected location, network address, and the final result. Card-security and postal-code results may be unavailable, unchecked, or null; Loommi rejects an explicit failure but does not treat an absent or unchecked result as proof of adult status or ownership of the card or payment account. The record does not include the full card number, reusable card identifier, or address-line result.
If Loommi offers a different age or parent-verification method, the direct notice will identify the method and provider, explain the information used, and state how the verification artifact and result are retained or deleted.
4. Where information comes from
Loommi receives information:
- directly from an adult, parent, child after consent, household member, or support requester;
- automatically from a browser, application, device, firmware, network, or enabled sensor;
- from an adult account holder who creates a lawful child or household relationship;
- from Shopify, Stripe, an application store, a carrier, or another processor used for a transaction or requested service;
- from a paired device during an authenticated account or recovery action; and
- from an optional integration that an adult chooses and can disconnect.
Loommi does not buy family profiles from data brokers.
5. Why Loommi uses information
Loommi uses the applicable categories to:
- provide the website, Store, waitlist, account, device, application, AI interaction, memory, recognition, backup, subscription, and support feature the person requests;
- obtain and record parental, biometric, health-data, and other permissions;
- personalize an enabled household experience under parent controls;
- process orders, payments, taxes, shipping, returns, refunds, warranty, and recalls;
- authenticate adults and devices, prevent fraud and abuse, secure systems, investigate incidents, and deliver updates;
- run automated response-safety controls and provide crisis resources without claiming continuous human monitoring;
- measure machine reliability with content-excluding telemetry;
- respond to rights requests and communications;
- enforce the Terms and protect people, Loommi, and the services; and
- meet accounting, warranty, safety, legal-process, and other legal duties.
Loommi does not use child information, raw voice or video, biometric data, or consumer health data to train a general-purpose AI model. An optional improvement program for other eligible adult information would require a separate affirmative choice and would exclude those categories.
6. Processors, service providers, and independent providers
Loommi uses processors and service providers that act under contractual confidentiality, security, deletion, and purpose restrictions. Some commerce, payment, application-store, network, and delivery providers may independently control limited transaction, device, fraud, security, or legally required information under their own privacy notices. Loommi treats a disclosure as excluded from “sale,” “sharing,” or targeted advertising only when the disclosure and applicable contract satisfy the statutory requirements for that exclusion. Loommi does not authorize a provider to use child content, raw family media, biometric data, or consumer health data for the provider's advertising or general-purpose model training.
Depending on the feature, planned and current providers include:
| Provider | Role and information |
|---|---|
| Shopify | Store hosting, catalog, cart, customer account, checkout, order, and commerce operations. |
| Cloudflare | Website and API hosting, network delivery, abuse prevention, service security, and temporary parent-confirmation delivery and retry. |
| Supabase | Account authentication and restricted cloud database services. |
| Resend | Requested confirmation, account, transaction, and update email. |
| Stripe | Stripe-hosted card-details setup processing used as one part of adult parent verification. Stripe receives card and billing details directly and returns a limited setup result; Stripe or the card issuer may require authentication or other checks. Loommi sends no child information, creates no Stripe customer for the setup, captures no charge, and does not retain a reusable card identifier. Successful processing does not independently prove age, relationship, or ownership of the card or payment account. |
| Expo, Apple APNs, and Google FCM | Delivery of notifications chosen for a device, using a push token and minimal routing content. |
| Apple App Attest and Google Play Integrity | Application and device-integrity signals used to protect high-risk actions. |
| Carriers, fulfillment, repair, and warranty providers | Address, order, device, and service information needed to deliver or service a product. |
If Loommi offers optional cloud AI or media processing through another provider, Loommi will identify that provider in the applicable notice before family content is sent. No unnamed provider receives a blanket right under this Notice to retain family content or use it for its own model training.
Loommi may also provide limited information:
- when you direct Loommi to do so through an integration or feature;
- to comply with valid legal process or protect a person from an immediate, credible threat, after evaluating the scope and lawfulness of the request;
- to investigate fraud, abuse, or a security incident; or
- in a merger, financing, reorganization, bankruptcy, or sale of relevant assets, if the recipient assumes the applicable obligations and Loommi gives notice of a materially incompatible change before using information that way.
Loommi does not sell personal information, share it for cross-context behavioral advertising, or process it for targeted advertising. Loommi does not disclose personal information to third parties for their own direct marketing. See Do Not Sell or Share My Personal Information.
7. Retention
Loommi uses the following operating schedule when the related category is collected. A shorter period applies when law, a feature screen, or a deletion request requires it. A narrow record may be retained longer when reasonably necessary for tax, accounting, warranty, recall, security, fraud, legal process, or dispute obligations; it is restricted to that purpose.
| Category | Operating schedule |
|---|---|
| Standby activation buffer | A few seconds; discarded when no activation occurs; not uploaded. |
| Activated raw media processed locally | Deleted after the requested response or operation completes, unless the adult intentionally saves or uploads it. |
| Activated raw media sent for optional cloud processing | Deleted from active systems within 24 hours after the response; processors may not retain it or train on it. |
| Child conversation history | Off by default; if enabled, a visible rolling history of no more than 30 days unless an item is affirmatively saved. |
| Saved memories and preferences | While the profile is active and memory remains enabled; deleted on request, feature disable, profile deletion, or 12 months of account inactivity. |
| Raw biometric enrollment sample | Deleted immediately after the template is created. |
| Biometric template | Deleted on disable, withdrawal, profile or account deletion, device transfer or reset, purpose completion, the fixed permission term ending no later than 365 days after permission, or 365 days without a recognition interaction, whichever occurs first. |
| Identifiable safety classification | Up to 30 days unless needed for a user-requested escalation, incident, or legal obligation; aggregate reporting excludes personal information. |
| Identifiable diagnostics and telemetry | Up to 30 days. |
| Deidentified reliability aggregate | Up to 12 months under no-reidentification controls. |
| Support upload | Up to 90 days after the matter closes unless the user requests earlier deletion or a documented warranty, safety, security, or legal need requires a limited record. |
| Unconfirmed waitlist record and its delivery metadata | 30 days after the last submission. |
| Confirmed waitlist record and its delivery metadata | 24 months after confirmation, or 30 days after unsubscribe or delivery suppression. |
| Waitlist confirmation link and cookie | Link expires after 7 days; protected cookie lasts no more than 10 minutes and clears after use. |
| Order, tax, payment, refund, warranty, and accounting record | Seven years, limited to the transaction information needed for legal and accounting purposes. |
| Final parent-verification record | Seven years after the attempt reaches a final result. The limited record described in Section 3.11 does not contain the full card number, reusable card identifier, or address-line result. |
| Parent-verification confirmation delivery | Loommi keeps a separate database copy of the confirmed adult account email while the confirmation is waiting. Loommi removes the copy after Resend accepts the send request and Loommi records the random reference Resend assigns to the message, and it sets a fixed cleanup deadline 30 days after permission is activated and the delivery obligation is created. A staff retry cannot extend that deadline. During the 30-day period, a safe retry uses only the initiating adult's current confirmed account email; staff cannot choose a different address. Loommi does not automatically resend a message reported as spam. During the final ten minutes, Loommi stops new send attempts and its cleanup processes try to remove any remaining address. A database outage or unusually long database transaction can delay physical removal; Loommi monitors for that retention incident and removes the address as soon as database service permits. The delay cannot extend the deadline or authorize another send. Loommi then keeps only a fixed unresolved-delivery reason and times; it does not mark the message delivered or reverse permission that was already recorded. Cloudflare's Queue and restricted failed-message area may hold an address-free copy containing only a random request identifier, the applicable flow, and fixed message version for up to 14 days in each area. Immediately before an allowed send, the Cloudflare-hosted service briefly handles the confirmed adult address and fixed message while passing them to Resend. It checks the current database status first and receives no address for a copy whose deadline ended or whose send was already accepted. After each Resend acceptance, Loommi deletes its separate email-address copy and retains only the random message reference, the delivery result, and the times for that send with the final parent-verification record for up to seven years. A separate small record containing only random references, result type, and times is used to handle repeated or early notices and expires within 30 days. Resend's standard service keeps its sent-email delivery data for 30 days and may keep an address that permanently rejected the message or reported it as spam on a blocked-delivery list until it is removed. |
| Unfinished parent-verification request | No more than 14 days after the request begins. An individual Stripe-hosted page expires after two hours; an expired page grants no permission. When the request expires, Loommi deletes its temporary setup information and keeps the online child feature off. |
| Consent and withdrawal evidence | Cloud consent and withdrawal evidence: up to five years after permission ends when needed to demonstrate the choice. A robot's detailed local recognition-permission record is deleted no later than 365 days after permission ends, apart from a random nonidentifying record used only to ensure that required cleanup is not repeated or lost. Neither record contains a recognition template. |
| Active-system privacy deletion | Within 45 days after receipt where applicable law uses receipt, including Washington consumer-health and California requests; within 30 days after authentication for Nevada consumer-health deletion; and otherwise within the applicable verified-request period. Loommi authenticates promptly and does not use authentication to extend a receipt-based deadline. |
| Isolated recovery backup | Overwritten within 90 days and not restored to active use after deletion. A Washington consumer-health backup deletion will occur no later than six months after authentication. |
An offline device cannot receive a remote deletion command. A deletion request is queued for the paired device and completes when it reconnects; the adult can complete it immediately through the local deletion or factory-reset control. A powered-off phone likewise updates when it next connects or its local application data is removed. Loommi explains these layers in the deletion confirmation.
8. Children
Loommi is designed for families and may be used by children, including children under 13. A parent or legal guardian must create and manage a child profile. Before online collection from a child, Loommi provides a direct notice and obtains verifiable parental consent. Optional disclosure that is not integral to the requested service uses a separate parental choice.
Loommi does not condition participation on a child providing more information than reasonably necessary for the requested activity. A household owner cannot consent for another parent's child. The Children's Privacy Notice provides the complete child-data notice and parent rights.
9. Your choices and rights
All U.S. residents may ask Loommi to confirm whether it processes their personal information; access it; correct it; delete it; obtain a portable copy; obtain recipient information where applicable; withdraw consent; and opt out of sale, cross-context behavioral advertising, targeted advertising, and profiling that produces legal or similarly significant effects.
Loommi does not engage in those sale, advertising, or significant-effect profiling practices. Exercising a choice will not reduce unrelated service.
Use the application's Privacy Center when available or email support@loommi.ai with the subject “Privacy request.” You do not need to create a new account. Loommi will authenticate the request in proportion to its sensitivity, ordinarily respond within 45 days, and provide notice if one additional 45-day period is reasonably needed. If Loommi denies a request, the response explains why and how to appeal. An appeal may be submitted through the same channel and will be decided within 45 days.
Loommi recognizes Global Privacy Control and another legally required universal opt-out signal as a request to opt out of sale, sharing, and targeted advertising for the browser or device that sends it. Where Loommi can reliably associate the signal with an account, it applies the choice to the account. Because Loommi does not engage in those practices, the signal does not change current service behavior.
See U.S. State Privacy Rights for authorized agents, state-specific details, and California disclosures.
10. Cookies and network storage
Loommi's current Store code uses only first-party functional storage:
| Name | Purpose | Duration |
|---|---|---|
| `session` | Maintains Store session and Shopify cart state. It is first-party, `HttpOnly`, and `SameSite=Lax`. | Browser session. |
| `__Host-loommi_waitlist_confirm` | Holds only a protected fingerprint while an adult completes waitlist confirmation. It is `Secure`, `HttpOnly`, and `SameSite=Strict`. | Up to 10 minutes; cleared after confirmation. |
The current Store source does not intentionally deploy advertising pixels or third-party audience analytics. Shopify-hosted account and checkout pages may use additional functional cookies described in Shopify's notices. Before Loommi adds a nonessential analytics or advertising technology, it will update this inventory and provide any required preference control.
11. Security
Loommi maintains administrative, technical, and physical safeguards designed for the nature and sensitivity of the information processed. Planned and current controls include data minimization, role-based access, multifactor authentication for sensitive adult actions, encryption in transit, encryption at rest where cloud information is stored, device credentials, restricted service accounts, event logging, provider controls, vulnerability and update processes, retention automation, and incident response.
For the current waitlist, the database is limited to the stated lead fields, bounded non-content delivery records and signed-event identifiers. The raw confirmation token and raw email-provider notices stay out of that database, direct database access is restricted to the service credential, and the short confirmation cookie is protected as described in Section 10.
No system is completely secure. Contact Loommi promptly with a suspected account, device, privacy, or security issue. A good-faith vulnerability report may be sent with the subject “Security report.”
12. Changes to this Notice
Loommi may update this Notice as the services and law change. The effective date identifies the current version. Loommi will provide account holders at least 30 days' direct notice of a materially adverse change when practicable. Before using information for a materially new or incompatible purpose, collecting a new category of sensitive information, or disclosing sensitive information to a new recipient, Loommi will provide additional notice and obtain consent where required.
Loommi does not use a Notice update to retroactively authorize processing that required consent when the information was collected.
13. Accessibility and complaints
Email support@loommi.ai with the subject “Accessibility request” for this Notice in a reasonable alternate format.
If you are dissatisfied with Loommi's response, you may contact your state attorney general or the Federal Trade Commission. Loommi will identify any additional state authority in a rights-appeal decision where applicable.