How Looms protects your data

Support CenterSecurity & Privacy
Updated May 30, 2026· 1 min read

Your account is protected with secure, token-based authentication, and your records are stored with encryption at rest.

How authentication works

Looms uses a session-based authentication system. When you sign in, a cryptographically secure token is issued and stored. Each request to the server is authenticated against that token. Sessions expire after 30 days of inactivity.

Good security habits

  • Use a strong, unique password — a password manager makes this easy
  • Sign out on shared or public devices after each session
  • Only share documents via Looms share links, not by forwarding files directly
  • Review your active sessions in Settings and revoke any you don't recognise

Data retention

Your records and health data are stored for as long as your account is active. If you delete your account, your data is permanently removed within 30 days. You can request a full export of your data at any time from Settings.

Was this article helpful?