Your account is protected with secure, token-based authentication, and your records are stored with encryption at rest.
How authentication works
Looms uses a session-based authentication system. When you sign in, a cryptographically secure token is issued and stored. Each request to the server is authenticated against that token. Sessions expire after 30 days of inactivity.
Good security habits
- Use a strong, unique password — a password manager makes this easy
- Sign out on shared or public devices after each session
- Only share documents via Looms share links, not by forwarding files directly
- Review your active sessions in Settings and revoke any you don't recognise
Data retention
Your records and health data are stored for as long as your account is active. If you delete your account, your data is permanently removed within 30 days. You can request a full export of your data at any time from Settings.