Privacy Policy — LoomProof Keys
Last updated: June 25, 2026 · Effective immediately
The bottom line: We hash your API keys in your browser. We never see plaintext. We never share your data. We never sell anything.
What LoomProof Keys Does
LoomProof Keys is an API key monitoring and anomaly-detection service. You register keys (OpenAI, Anthropic, Stripe, etc.) and we watch them 24/7. If a key leaks to GitHub, gets used from a new country, or shows abnormal call patterns, we alert you.
How We Handle Your Keys
We never store plaintext API keys. Ever.
When you register a key, your browser computes a SHA-256 hash of the key locally before sending it to our servers. We only ever store the hash. The plaintext key exists only in your browser session — it never reaches our backend.
What We Collect
- Account data: Your email address (for account access, billing, and critical alerts)
- Key hashes: SHA-256 hashes of API keys you register (we never see the original keys)
- Key metadata: The service the key belongs to (OpenAI, Anthropic, Stripe, etc.), the first/last 4 characters of the key for display, registration date
- Usage telemetry: Aggregated event counts per key per hour (for anomaly detection). No request bodies.
- Payment data: Handled entirely by Stripe. We do not store your credit card.
What We Do NOT Collect
- Plaintext API keys (technically impossible — we never see them)
- Request/response bodies from your API calls
- Your customers' data or end-user information
- Behavioral tracking for advertising purposes
- Anything we wouldn't want collected about ourselves
How Anomaly Detection Works
When a key is exercised in the wild (i.e., the actual API provider sees a request with that key), the provider can send us a webhook or event signal. We compare the request metadata (region, call volume, time of day) against a per-key baseline. Anomalies trigger an alert to your account email.
We do not see the request content — only metadata (region, service, timestamp, call count). The actual data flowing through your APIs stays with your API provider.
Data Storage & Retention
- Account data: retained until you delete your account
- Key hashes + metadata: retained until you remove the key
- Alert history: retained 90 days
- Usage telemetry: aggregated hourly, retained 30 days for baseline modeling
Data Sharing
We do not sell, share, or license your data to third parties. The only exceptions:
- Stripe — processes your payments under Stripe's Privacy Policy
- Email providers — deliver alert emails to your account address
- Legal compulsion — if required by valid legal process (we've never received one)
Your Rights
- Access your account data on request
- Delete your account and all associated data at any time (Settings → Delete Account)
- Export your alert history and key metadata
- Opt out of aggregated usage analytics (impacts anomaly detection quality)
Security Practices
- SHA-256 key hashing happens client-side, not server-side
- TLS 1.3+ for all connections
- PostgreSQL with at-rest encryption
- JWT with short-lived access tokens
- SOC 2 Type 1 in progress (expected Q4 2026)
Changes to This Policy
Material changes will be announced by email 30 days before they take effect. Non-material changes (typo fixes, clarifications) will be posted with an updated effective date.
Contact
Privacy inquiries: privacy@signalloomai.com
Signal Loom AI™ — AIM Elemental Health Solutions, Inc.
Mailing address: 300 E Bottle Bay Road, Sagle, ID 83860
Website: signalloomai.com