Legal

Privacy Policy

Last updated: February 2026

Effective Date: February 21, 2026 — LockLoom version 1.5.x+

Summary

LockLoom collects no data. Period.

No personal information, no usage analytics, no crash reports, no telemetry, no advertising identifiers, and no device fingerprints are collected, transmitted, or stored by LockLoom or LockLoom LLC. We have no servers. We have no accounts. We have no backend infrastructure.

1. Information We Collect

None.

LockLoom operates on a zero-backend architecture. All data processing occurs exclusively on your device. Specifically:

2. Information Stored on Your Device

LockLoom stores the following information exclusively on your device in encrypted local storage. This data never leaves your device to our servers (because we have no servers):

Data TypePurposeStorage
App protection policiesPer-app security configurationDevice-encrypted SharedPreferences
Biometric enrollment statusMFA authentication chainAndroid Keystore
Emergency contact numbersDistress SOS dispatchEncrypted local database
Distress PIN / codewordsCovert SOS triggeringSalted hash (no plaintext)
Cloak icon selectionApp disguise preferenceSharedPreferences
Network cloak settingsRadio toggle preferencesDevice-encrypted storage
Vault contentsUser's encrypted filesML-KEM-1024 / XChaCha20

3. Distress Alerts & Data Flow

When a distress code is triggered, LockLoom sends alerts directly from your device to your configured emergency contacts. The data flow is:

Your Device → Your Emergency Contacts

LockLoom LLC is not involved in this transmission. We do not see, store, relay, or have access to:

4. Third-Party Services

Google Play Billing

Your one-time purchase is processed by Google Play. Google's privacy policy governs this transaction. LockLoom receives only a purchase verification token — we do not receive your payment details, Google account email, or any personal information from Google.

Gmail API (Optional)

If you choose to use Gmail for distress email dispatch, you authenticate directly with Google via OAuth2. LockLoom receives a scoped access token stored only on your device. We never see your Gmail credentials, email content, or contact list.

5. Data Sharing

We cannot share what we do not have.

LockLoom LLC does not share, sell, rent, or disclose any user data to any third party — because we possess no user data. This includes:

6. Law Enforcement Requests

If we receive a lawful request for user data, our response is simple: we have no user data to provide. Our zero-backend architecture means we genuinely cannot comply with data production requests because the data does not exist on our infrastructure.

7. Children's Privacy

LockLoom is a security application designed for adults. We do not knowingly market to or collect information from children under 13. Since we collect no data from any user of any age, there is no children's data to protect — but we want to be explicit about our intended audience.

8. Data Retention

Zero days. We retain no user data because we collect no user data. If you uninstall LockLoom, all locally-stored configuration is removed with the app.

9. Your Rights

Under GDPR, CCPA, and similar privacy regulations, you have the right to access, correct, delete, and port your data. Since we hold no data about you, these rights are automatically satisfied. There is nothing to access, correct, delete, or port.

10. Changes to This Policy

If we update this privacy policy, the changes will be posted on this page with an updated effective date. Our core commitment — zero data collection — will never change. If we ever need to collect data (we don't anticipate this), we will obtain explicit consent first.

11. Contact

If you have questions about this privacy policy or LockLoom's data practices:

© 2025-2026 LockLoom LLC. All rights reserved.