If you notice something suspicious — an unfamiliar device signed into your account, a record you didn't upload, a message you didn't send — act quickly. Here's what to do. If you haven't already enabled two-step verification, do so now via setting up two-step verification, and review managing active sessions to see all devices currently signed in.
Immediate steps
- Go to Settings > Security > Active Sessions
- Sign out all other sessions — this immediately ends all other active logins
- Change your password straight away — use a strong, unique password not used elsewhere
- If you use the same password on other services, change those too
- Enable two-step verification if it isn't already on
- Review your recent activity in Settings > Security > Activity Log — look for logins from unfamiliar devices or locations
How to report to Looms
- In the app: go to Settings > Help and Support > Report a security issue
- By email: security@looms.app
- Describe what you saw, when you noticed it, and what device/browser you were using
- Include screenshots if possible — these help the investigation
- The security team will respond within 24 hours and may ask you to verify your identity
If you believe a data breach occurred
A breach means someone who shouldn't have access saw, copied or altered your health data. If you believe this happened, contact the Looms security team immediately. Looms is required by UAE and applicable data protection regulations to notify affected users and relevant authorities in the event of a confirmed breach.
Responsible disclosure for security researchers
If you've discovered a potential vulnerability in Looms — a bug that could allow unauthorised access, data leakage or other security issues — please report it to security@looms.app before disclosing it publicly. Include a clear description and, where possible, steps to reproduce. We aim to respond within 48 hours and will work with you to resolve the issue responsibly.