Loomy is a private, local-first journal. Your entries, photos, voice notes, location history, and health readings are stored on your device — we do not keep a copy of your journal on a server.
This is a summary; the full policy below controls.
This policy explains how the Loomy mobile app handles information. It does not cover third-party services you connect to Loomy (such as a wearable service or your device platform), which are governed by their own privacy policies.
Loomy keeps your content locally in an on-device database and file storage. This includes, depending on how you use the app:
We do not transmit this on-device data to us. Some of it is sent to third-party processors only in the specific situations described in Sections 3–5.
When you use an AI feature, Loomy sends the content that feature needs to a third-party AI provider, which processes it and returns a result. Requests are relayed through our own service, which does not store your content.
| When you… | What is sent for processing |
|---|---|
| Loom (or Reloom) a day | The day's journal text, a compact digest of that day's metrics, place/timeline context, and — if you've opted into photo access — up to a few photos you attached or picked that day |
| Transcribe a voice note | The audio recording for that clip |
| Generate an album cover | A short text prompt derived from the day's summary, and — if opted in — one photo to redraw in the app's art style |
| Generate a health report | A de-identified statistical digest (averages, correlations, symptom counts) — not your raw entries |
| Automatic Journaling drafts a day's timeline (opt-in, background) | A digest of that day's location stays, health-device metrics, and photo capture times/places — never your written journal entries or a photo image itself. See §3a. |
The provider processes this data on our behalf, solely to return the result, under its own terms. We do not use your content to train any model. If you never use AI features, no journal content leaves your device through this path.
AI output can be wrong or incomplete and is not professional, medical, or mental-health advice (see the Terms of Service).
Automatic Journaling is off by default. Turning it on in Settings — after an explicit confirmation screen that explains what it does — lets Loomy draft a short timeline for a small rolling window of recent days (roughly the last week) automatically, in the background, without you tapping anything. Turning it on does not reach back through your whole history; older days are unaffected unless you Loom them yourself.
What it reads: your background location (to derive named stays and trips — never a raw coordinate trace), metrics from any health device you've connected, and, if you've also allowed photo access, the capture time and matched place of a few photos from that day — never the photo image itself.
What it sends: a compact digest built from the above to one or more AI providers (such as Google Gemini, OpenAI, Anthropic, or similar services), without your name, email, or account details attached. It never sends your written journal entries or a photo image itself.
What it writes: a short preview timeline, stored on your device, that you can read in the Timeline tab or ignore — Automatic Journaling never creates a journal entry on its own; only your own writing, or your own tap on Loom, does that. Looming a day replaces the preview with the real chronicle.
Turning it off: available anytime in Settings → Auto Journaling. Turning it off stops the background location tracking and the background previews; previews already written stay on your device until you delete them (Reset All Data, or by overwriting a day with Loom).
If something goes wrong, Loomy lets you send us a report — from the error screen itself, or anytime from Settings → Report a problem. By default, this is not an automatic, always-on crash-reporting service: nothing is sent without you reviewing it and tapping Send, unless you separately turn on the optional automatic setting described below.
What's included: the error message and, where available, its technical stack trace; basic device and app info (platform, app version); a short rolling log of recent in-app events used to help us reproduce the issue (for example, which screen or feature was active) — this log is limited to short, structured entries and cannot contain your journal text; and, if you choose to add one, a short note in your own words describing what you were doing.
What's never included, even here: your journal entries, photos, voice recordings, precise location, or health metric values.
Reports are stored so we can investigate and fix the underlying issue, and are periodically deleted once they're no longer needed.
Sending reports automatically (optional, off by default): Settings → Privacy & Security has a separate toggle, "Send crash reports automatically," behind its own explicit confirmation screen. Turning it on lets Loomy send a report — with no per-incident review, no tap required — for errors you'd otherwise never see or get a chance to report yourself, such as a background task failing silently. An automatic report contains the same information described above, minus the free-text note (there's no prompt to write one when it happens automatically) — still never your journal content. Reports you send yourself always stay fully manual and reviewed, regardless of this setting. Turn it off anytime in Settings.
If you grant location permission, Loomy logs your location in the background to build your daily “footprint” and timeline. This processing happens on your device — your raw coordinate trace is never uploaded to us or to a routing service. When you use an AI feature that draws on location — Loom/Reloom, or, if you enable it, Automatic Journaling's background drafts — a summarized version (named stays and trip segments, never the raw trace) is sent for processing, as described in Section 3 and Section 3a. Separately, three narrow exceptions send limited location data to third parties so those features work:
You can decline or later revoke location permission in your device settings; those features degrade gracefully.
We have no advertising, analytics, or attribution SDKs in the app, and we do not sell or rent your information to anyone. We also don't use a third-party crash-reporting SDK — Loomy's own optional, user-initiated way to report a problem is described in Section 3b, and it never sends anything without you choosing to.
If you ask for an invitation on our website, we store the email address you give us, the optional note you write, and the language you were reading the site in. That is the only personal data we collect on a server, and we use it for exactly one purpose: to send you an invitation code. We do not add you to a newsletter, we do not use it for advertising, and we do not share or sell it.
Your journal is not connected to this in any way — signing up to the waitlist does not create an account, and no journal content ever reaches our servers.
Write to us at the address in Section 13 and we will delete your waitlist entry.
Because your data lives on your device, you control retention:
Your data stays on your device. Wearable tokens are stored in the OS secure keystore, and optional App Lock adds a biometric/passcode gate. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
Loomy is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has used Loomy, contact us and we will help.
Some processors above may process data in the United States or other countries. By using AI or connected features you understand that the relevant data may be processed in those locations.
Because Loomy is local-first, you already hold your data directly: you can access and export it, correct it by editing, and delete it — all from within the app, without contacting us. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; contact us to exercise them.
We may update this policy. Material changes will be reflected by a new effective date and, where appropriate, an in-app notice.
Questions or requests: hello@loomyjournal.com.