Privacy Policy — LoomProof Keys

Last updated: June 25, 2026 · Effective immediately

The bottom line: We hash your API keys in your browser. We never see plaintext. We never share your data. We never sell anything.

What LoomProof Keys Does

LoomProof Keys is an API key monitoring and anomaly-detection service. You register keys (OpenAI, Anthropic, Stripe, etc.) and we watch them 24/7. If a key leaks to GitHub, gets used from a new country, or shows abnormal call patterns, we alert you.

How We Handle Your Keys

We never store plaintext API keys. Ever.

When you register a key, your browser computes a SHA-256 hash of the key locally before sending it to our servers. We only ever store the hash. The plaintext key exists only in your browser session — it never reaches our backend.

What We Collect

What We Do NOT Collect

How Anomaly Detection Works

When a key is exercised in the wild (i.e., the actual API provider sees a request with that key), the provider can send us a webhook or event signal. We compare the request metadata (region, call volume, time of day) against a per-key baseline. Anomalies trigger an alert to your account email.

We do not see the request content — only metadata (region, service, timestamp, call count). The actual data flowing through your APIs stays with your API provider.

Data Storage & Retention

Data Sharing

We do not sell, share, or license your data to third parties. The only exceptions:

Your Rights

Security Practices

Changes to This Policy

Material changes will be announced by email 30 days before they take effect. Non-material changes (typo fixes, clarifications) will be posted with an updated effective date.

Contact

Privacy inquiries: privacy@signalloomai.com

Signal Loom AI™ — AIM Elemental Health Solutions, Inc.

Mailing address: 300 E Bottle Bay Road, Sagle, ID 83860

Website: signalloomai.com