ReportLoom — Insight. Analysis. Advantage. Get started
Legal

Privacy Policy

Effective date: April 1, 2026 · Last updated: April 1, 2026

1. Introduction & Scope

LoomTech Ventures LLC, a California limited liability company ("we," "us," or "our"), doing business as ReportLoom, operates the website and platform at reportloom.com (the "Service"). This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you visit our website, create an account, purchase report credits, generate reports, or otherwise interact with the Service.

This policy applies to all users of the Service, including visitors who browse without creating an account. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices as described here, please do not use the Service.

We are committed to transparency. Where industry-specific regulations apply to you (such as GDPR, CCPA, or others), we have included specific disclosures in the relevant sections below.

2. Data Controller

For the purposes of applicable data protection laws (including the CCPA and GDPR), the data controller responsible for your personal data is:

LoomTech Ventures LLC (doing business as ReportLoom)

A California limited liability company

Contact: reportloom.com/contact

If you have any questions about how we handle your data, or if you wish to exercise any of your rights, you can reach us using the contact details above.

3. Information We Collect

We collect several categories of information depending on how you interact with the Service:

3.1 Account Data

When you register for an account, we collect your name, email address, and the password you create. Your password is cryptographically hashed before storage and is never stored in plain text. This information is necessary to create your account, authenticate you, and communicate with you about the Service.

3.2 Company Profiles

When you create company profiles for report generation, we store the business information you provide, including company name, website URL, company description, industry classification, and details about competitors you identify. This data is provided entirely by you and is used solely to generate your requested reports.

3.3 Generated Reports

When you use a credit to generate a report, the resulting PDF file is stored on our servers and made available to you for download. Reports contain AI-generated analysis based on publicly available information about the companies you specified. Report files are retained for 6 months from generation, after which they are permanently deleted.

3.4 Usage & Log Data

We automatically collect certain technical and usage information when you access the Service, including:

  • IP address and approximate geographic location derived from it
  • Browser type, version, and language preferences
  • Operating system and device type
  • Pages visited, features used, and actions taken within the Service
  • Report generation requests, timestamps, and completion status
  • Referring URL and how you arrived at the Service
  • Error logs and performance data

This data helps us operate, maintain, and improve the Service, diagnose technical issues, and detect abuse.

3.5 Cookies

We use a small number of strictly necessary cookies to make the Service work (such as keeping you signed in and recording your cookie preferences). If you consent, we also use Google Analytics and first-touch marketing-attribution cookies to understand how the Service is used and which campaigns drive sign-ups. You can accept, reject, or change your choice at any time using the cookie banner or the "Cookie settings" link in our footer. See Section 9 for full details.

3.6 Payment Data

When you purchase report credits, your payment is processed by a third-party payment provider. We receive a transaction confirmation, the amount paid, and a transaction identifier from the payment provider. We do not receive, process, or store your full credit card number, CVV, or other sensitive payment card details. The payment provider handles your financial information under their own privacy policy and PCI-DSS compliance obligations.

4. Legal Basis for Processing

We process your personal data under the following legal bases, depending on the context:

  • Performance of a contract: Processing your account data, company profiles, and payment information is necessary to provide the Service you have purchased, including generating and delivering reports.
  • Legitimate interests: We process usage and log data to maintain the security of the Service, prevent fraud, diagnose technical problems, and improve the user experience. We have assessed that these interests do not override your fundamental rights and freedoms.
  • Consent: Where we send you optional communications (such as product updates or feature announcements), we do so with your consent. You may withdraw consent at any time by using the unsubscribe mechanism in those communications or by contacting us.
  • Legal obligation: We may process and retain certain data where required to comply with applicable laws, regulations, or legal processes.

5. How We Use Your Information

We use the information we collect for the following specific purposes:

  • Account creation and authentication: To register your account, verify your email, authenticate login sessions, and enable password resets.
  • Report generation and delivery: To process the company profile data you provide, send it to our AI processing pipeline, generate your report, store the resulting PDF, and make it available for download.
  • Order fulfillment: To process credit purchases, issue transaction confirmations, and maintain records of your purchases and credit balance.
  • Service communications: To send you essential transactional emails, including email verification, password resets, report completion notifications, report expiry warnings (14 days before deletion), and policy update notifications.
  • Security and abuse prevention: To monitor for unauthorized access, detect and prevent fraudulent activity, enforce our Terms of Service, and protect the integrity of the Service.
  • Service maintenance and improvement: To identify and fix bugs, monitor performance, understand usage patterns, and improve the reliability and functionality of the Service.
  • Legal compliance: To comply with applicable laws, respond to lawful requests from public authorities, and establish, exercise, or defend legal claims.

We do not use your data for automated decision-making that produces legal effects concerning you. Report generation is initiated by you and produces informational output, not decisions about you personally.

6. AI Processing Disclosure

ReportLoom uses artificial intelligence models provided by Anthropic (the "AI Provider") to generate business intelligence reports. This section explains what that means for your data.

6.1 What Data Is Sent to Anthropic

When you generate a report, the following information from your company profile is sent to Anthropic's Claude API for processing:

  • The target company name, website URL, and description you provided
  • Competitor names, URLs, and descriptions you identified
  • Industry and sector classifications

We do not send your personal account information (name, email, password) to Anthropic. Only the business-related data necessary for report generation is transmitted.

6.2 How Anthropic Handles This Data

Anthropic processes the data we send through their API under their commercial API terms. According to Anthropic's policies, data sent through their API is not used to train their AI models. Anthropic may retain API inputs and outputs for a limited period for trust and safety purposes, as described in their own privacy documentation. We encourage you to review Anthropic's privacy policy for full details.

6.3 AI-Generated Content

The reports produced by the AI are based on publicly available information, including company websites, online reviews, press coverage, regulatory filings, and similar public sources. The AI synthesizes this information into a structured report. The output may contain estimates, inferences, and analysis that have not been independently verified. Reports represent a point-in-time snapshot and should not be treated as professional advice.

7. Third-Party Services

We work with a limited number of third-party service providers to operate the Service. Each provider receives only the data necessary for their specific function:

  • Anthropic (AI processing): Receives company profile data to generate reports via their Claude API. See Section 6 for full details.
  • Payment processor: Processes your payment when you purchase credits. Receives your payment card details directly. We receive only transaction confirmations and identifiers. We do not store your payment card information.
  • Cloud hosting infrastructure (AWS): Our application, database, and file storage are hosted on cloud infrastructure. Your data is stored and processed on these servers, which provide encryption at rest and in transit.
  • Email delivery service: We use a transactional email provider to send account-related emails (verification, password resets, report notifications, policy updates). This provider receives your email address and the content of the email being sent.

We require all third-party providers to handle your data in accordance with applicable data protection laws and in a manner consistent with this Privacy Policy.

8. Data Sharing

We do not sell, rent, or trade your personal information to third parties. We only share your data in the following limited circumstances:

  • Service providers: As described in Section 7, we share data with third-party providers who help us operate the Service. These providers are contractually restricted to using your data only for the purposes we specify.
  • Legal requirements: We may disclose your information if required to do so by law, or in response to valid legal process (such as a subpoena, court order, or government request).
  • Protection of rights: We may disclose information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our Terms of Service, suspected fraud, threats to safety, or illegal activities.
  • Business transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We would notify you via email before your data becomes subject to a different privacy policy.

Outside of these specific scenarios, we do not share your personal data with any third party.

9. Cookies

We use cookies in two categories: strictly necessary cookies that make the Service work, and analytics cookies that help us understand how the Service is used. Strictly necessary cookies are set automatically. Analytics cookies are only set if you grant consent through our cookie banner.

You can accept, reject, or change your choice at any time using the cookie banner shown on your first visit, or by clicking Cookie settings in the footer of any page.

Strictly necessary cookies

These cookies are required for the Service to function. They are exempt from the consent requirement under GDPR (Recital 30) and the ePrivacy Directive (Art. 5(3)) because the Service cannot operate without them.

Cookie Purpose Duration Set by
rl_auth Authenticates your session after login. HttpOnly, Secure, SameSite=Strict. Session ReportLoom (first-party)
rl_consent Records your cookie preferences so we don't show the banner on every visit. SameSite=Lax. 12 months ReportLoom (first-party)
rl.intent If you click "Buy" before you're signed in, remembers which product you wanted so we can route you back to it after sign-up. Equivalent to a shopping-cart cookie. 1 hour ReportLoom (first-party)

Analytics cookies (consent required)

These cookies are only set after you click Accept all or enable Analytics in the cookie preferences. They help us understand how visitors find and use the Service, so we can improve it.

Cookie Purpose Duration Set by
_ga Google Analytics: distinguishes unique visitors. 2 years Google (third-party)
_ga_* Google Analytics 4: maintains session state for the GA4 property. 2 years Google (third-party)
rl.referral First-touch marketing attribution: records which campaign or referral source brought you to the site, so we can credit it if you later sign up. 30 days ReportLoom (first-party)

Google Analytics is provided by Google LLC and processes pseudonymous identifiers, IP addresses, and page-view metadata on Google's servers (which may include the United States). Google acts as our data processor under Article 28 of the GDPR. See Google's privacy policy for details on how Google handles this data.

If you do not consent to analytics cookies (or you later revoke consent), none of the cookies listed above will be set, no data will be sent to Google Analytics, and our server-side first-touch attribution endpoint will not be called.

10. Data Retention

We retain different categories of data for different periods, based on the purpose for which they were collected:

Data Category Retention Period Details
Account data Duration of account Retained while your account is active. Upon account deletion, personal data is anonymized (name and email removed) and the account is soft-deleted. Anonymization occurs promptly after your deletion request.
Company profiles Duration of account Retained while your account is active. Deleted when you remove the profile or delete your account.
Generated reports (PDF files) 6 months Report files are permanently deleted 6 months after generation. You will receive an email notification 14 days before deletion. We recommend downloading and storing your reports locally before expiry.
Activity & security logs 12 months Server logs, access logs, and error logs are retained for 12 months for security monitoring and incident investigation, then automatically purged.
Anonymized order data Indefinite Transaction records with personal identifiers removed are retained indefinitely for accounting, tax compliance, and aggregate business analytics. This data cannot be linked back to you.

When data reaches the end of its retention period, it is permanently deleted or irreversibly anonymized. We do not retain personal data longer than necessary for the purposes described above.

11. International Data Transfers

Your data may be processed and stored in the United States and the European Union, depending on the infrastructure and third-party services involved. Specifically:

  • Our hosting infrastructure and database servers may be located in the United States or the European Union.
  • Anthropic's AI processing infrastructure is based in the United States.
  • Our email delivery and payment processing providers may operate in multiple jurisdictions.

Where personal data is transferred outside the European Economic Area (EEA) or the United Kingdom, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or reliance on an adequacy decision. If you are located in the EEA or UK, your data will only be transferred to countries or organizations that provide an adequate level of protection or where appropriate safeguards have been implemented.

12. Data Security

We implement technical and organizational measures designed to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption at rest: Your data is stored in a Neon Postgres database with encryption at rest enabled.
  • Encryption in transit: All connections between your browser and our servers use TLS/SSL encryption. Internal service-to-service communication is also encrypted.
  • Password security: Passwords are cryptographically hashed using industry-standard algorithms before storage. We never store or log plain-text passwords.
  • Secure authentication: Session tokens are delivered via HttpOnly, Secure, SameSite=Strict cookies to prevent cross-site scripting and cross-site request forgery attacks.
  • Access controls: Access to production systems and customer data is restricted to authorized personnel on a need-to-know basis.
  • Secure file storage: Generated report files are stored in private cloud storage with access controlled via time-limited pre-signed URLs, ensuring that only authenticated account holders can download their own reports.

While we take reasonable precautions to protect your data, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your information, but we are committed to promptly addressing any security incidents and notifying affected users in accordance with applicable law.

13. Your Rights

Depending on where you are located, you may have specific rights regarding your personal data under applicable privacy laws. We respect these rights regardless of your location to the greatest extent practical.

13.1 Rights Under the GDPR (EEA & UK Residents)

If you are located in the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation:

  • Right of access (Article 15): You can request a copy of the personal data we hold about you, along with information about how it is processed.
  • Right to rectification (Article 16): You can request correction of inaccurate or incomplete personal data. You can also update much of your data directly through your account settings.
  • Right to erasure (Article 17): You can request deletion of your personal data. You can initiate this directly through the account deletion feature in your account settings, which soft-deletes your account, anonymizes your personal information, and removes your report files.
  • Right to restriction of processing (Article 18): You can request that we restrict the processing of your data in certain circumstances, such as when you contest the accuracy of your data.
  • Right to data portability (Article 20): You can request your personal data in a structured, commonly used, machine-readable format for transfer to another service.
  • Right to object (Article 21): You can object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
  • Right to withdraw consent (Article 7): Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

13.2 Rights Under the CCPA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to know: You can request disclosure of the categories and specific pieces of personal information we have collected, the sources of collection, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to delete: You can request deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to opt out of sale: We do not sell your personal information. No opt-out is necessary, but we affirm this right.
  • Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights. You will not receive different pricing or a different level of service for making a rights request.

13.3 Rights Under Other Frameworks

If you are located in a jurisdiction with its own data protection laws (such as Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, or others), you may have similar rights to those described above. We will honor reasonable requests to access, correct, or delete your personal data regardless of your location. Please contact us if you have questions about how your local laws apply.

14. How to Exercise Your Rights

You can exercise your data rights in the following ways:

  • Self-service: You can update your profile information, download your reports, and delete your account directly through your account settings within the Service.
  • Contact us: For any rights request you cannot fulfill through the Service directly, submit a request via our contact form with the subject line "Data Rights Request."

We will acknowledge your request as soon as reasonably practicable and aim to provide a substantive response within 30 days. If your request is complex or we receive a high volume of requests, we may extend this period by an additional 30 days and will notify you of the extension. We may need to verify your identity before processing your request to protect your data from unauthorized access. Verification is typically completed by confirming details associated with your account.

All rights requests are handled free of charge. If a request is manifestly unfounded or excessive (particularly if repetitive), we reserve the right to charge a reasonable fee or decline the request, but we will explain our reasoning.

15. Children's Privacy

The Service is designed for business professionals and is not directed at individuals under the age of 16. We do not knowingly collect personal data from anyone under 16 years of age. If we become aware that we have inadvertently collected personal data from a child under 16, we will take immediate steps to delete that information and terminate the associated account. If you believe that a child under 16 has provided us with personal data, please contact us at our contact form so we can take appropriate action.

16. Do Not Track Signals

Some web browsers transmit "Do Not Track" (DNT) signals to websites. There is currently no industry-wide standard for how websites should respond to DNT signals, so we do not alter our data-collection practices based on DNT. Our cookie banner is the authoritative mechanism for opting in to or out of analytics cookies: if you do not click "Accept all" or enable Analytics in the preferences panel, no analytics cookies are set and no data is sent to Google Analytics, regardless of any DNT signal sent by your browser.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we do, we will update the "Last updated" date at the top of this page.

For material changes that significantly affect how we collect, use, or share your personal data, we will notify you by email (sent to the address associated with your account) at least 14 days before the changes take effect. Material changes include introducing new categories of data collection, sharing data with new categories of third parties, or significantly changing the purposes for which we process your data.

We encourage you to review this policy periodically. Your continued use of the Service after any changes take effect constitutes your acceptance of the revised policy.

18. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy, our data practices, or how we handle your personal information, please contact us:

LoomTech Ventures LLC (doing business as ReportLoom)

Contact: reportloom.com/contact

We aim to resolve all complaints and inquiries promptly. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.