Information you choose to provide
Social Loom processes screenshots, supported images, text, URLs and other material you deliberately save or share with it. The service also processes generated summaries, titles, tags, extracted text, search representations, questions, answers and source references. Questions are sent to AI for answering; the backend stores a request fingerprint rather than the plain-text question. Answers use a short-lived cache, not a permanent conversation history. Content can contain personal information about you or other people; only submit material you have the right to use.
Accounts, purchases and service records
Apple or Google sign-in is handled through Supabase Auth. We receive the authentication identity and available account profile information, such as an email address. Authentication sessions are stored using the platforms' protected storage. RevenueCat and the relevant app store process purchase and entitlement information, including app account identifiers, product and transaction references, purchase dates and subscription status. Social Loom does not receive your full payment card number. Our backend keeps usage, processing, storage, entitlement and operational records needed to run and protect the service.
Why information is processed
We use this information to save and sync your collection, create AI-assisted results and search indexes, answer your questions, manage purchases and usage, provide support, prevent abuse and carry out deletion requests. Depending on your location and the processing involved, the legal basis may be providing the service you request, our legitimate interests in operating and securing it, complying with legal obligations, or consent where required. We do not sell your collection or use it for targeted advertising.
Cloud AI and your original material
Cloud AI processing sends relevant original text, images, URLs or selected source excerpts to OpenAI through our backend. Search also uses derived embeddings. Original material and AI-derived results are stored separately. API requests set store:false; this is not a promise of zero provider retention. OpenAI states that API data is not used to train its models by default, unless a customer opts in, and that abuse-monitoring logs may be retained for up to 30 days or longer in the circumstances described by OpenAI. We do not promise zero retention, end-to-end encryption, entirely on-device AI, or that AI results are always accurate.
Service providers and international processing
Cloudflare operates the business backend, databases, original-file storage, queues and search infrastructure. Supabase provides authentication; OpenAI provides AI processing and embeddings; RevenueCat helps verify purchases and subscriptions. Apple and Google provide sign-in and store services. Vercel hosts this website. These providers may process information in countries other than yours under their own applicable terms and safeguards. We share information needed for their service, and may disclose information when legally required or necessary to protect users and the service. Provider policy links appear below.
Retention, storage limits and deletion
Saved collection content remains associated with your account until you delete it, delete the account, or a disclosed storage rule applies. Answer caches expire after 24 hours; successful usage records remain separate from that cache. If cloud original-file usage exceeds your active capacity, a 30-day grace period starts. If the account remains over capacity, the newest uploaded original files are removed first until usage fits. Text, AI knowledge and search indexes are retained by this capacity process; existing local copies may remain available. Renewing or buying capacity does not recover physically removed files. Account deletion removes account content, AI results, indexes, purchase projections and usage records from the active Social Loom service and deletes the authentication account after cleanup. Offline devices clear old account data after they reconnect and confirm deletion. Provider security logs, backups or records they must retain can follow their own retention schedules; deletion does not cancel store subscriptions or erase stores' legally required transaction records.
Device access and local data
The app receives content you select through system sharing, photo selection or supported import flows. It uses network access for sign-in, sync, cloud processing and purchases. It does not require continuous access to your entire photo library, contacts, microphone or precise location for these functions. Local content and pending uploads can remain on your device until removed by the app or by you. Signing out is different from deleting an account. You can export available original files through supported app controls; this is not a complete account-data export tool.
This website and support messages
This website does not install advertising pixels or optional analytics scripts, and it has no newsletter or waitlist form. Hosting and delivery providers may process request information such as IP address, browser details, requested URL and security logs. Language is selected through the page URL. The separate account verification service temporarily uses session storage for its sign-in handoff. If you email support, your message and address are used to respond and resolve the request; your email provider also processes that message.
Your choices and rights
You can remove saved material, export available originals and request account deletion using the app or the website's account entry. Depending on your location, you may have rights to access, correct, erase or receive personal data, restrict or object to processing, withdraw consent where applicable, or complain to a data protection authority. Contact kcr0976@gmail.com to make a request. We may need to verify your identity before acting. We do not knowingly design the service for children who cannot legally consent to its use; if you believe a child has provided personal information without appropriate permission, please contact us.
Security and policy changes
We use authenticated access, account ownership checks, protected session storage and encrypted network connections to help protect information. No system is completely secure. Please avoid saving passwords, authentication codes or sensitive material you do not want processed by the listed services. We update this policy when the service or data practices change and revise the date above. Material changes will be communicated through an appropriate service or website notice.