Skip to policy
loam
  • Product
  • Call Loam
  • Evidence
  • Team
  • Security
  • Pricing
  • Get started
Login
Product Call Loam Evidence Team Security Pricing Get started Login

Privacy Policy

Privacy Policy.

Last updated: August 31, 2026

This policy explains what Loam collects, why it is used, how it is protected, which providers process it, how long it is retained, and how it is removed. For the line-by-line technical inventory, see Security.

No trackers. This website makes no third-party requests, sets no cookies, and runs no analytics. Fonts and scripts are served from our own servers — nothing you do here is reported to anyone else.

On this page

  1. Who we are
  2. What we collect
  3. How we use it
  4. How it's protected
  5. Service providers & sub-processors
  6. How long we keep it
  7. Your choices & rights
  8. Where your data lives
  9. Children
  10. Changes to this policy
  11. Contact us

1. Who we are

Toast2IT LLC, a Florida limited liability company (Florida document L21000139665), operates Loam and is the data controller where applicable (“Loam,” “we,” or “us”). This policy covers loam.team, the Loam service and API, and the Loam VS Code extension — including our legacy domain docpro.cloud, which still serves existing installations. Loam is built on Anthropic's Claude and is not affiliated with Anthropic.


2. What we collect

Loam stores session records in its database and some generated media as server files. The main categories are:

  • Account basics — your email, name, and phone number. Your phone is used for sign-in verification and for the team's voice calls.
  • Session content — the transcripts of your work with the team, and the documents, code, and audio produced in those sessions.
  • Team memory & project context — the preferences, decisions, and project details the team records so it can recall them later.
  • Calls — conversation transcripts (stored for memory synthesis), and, for calls that connect, audio recordings where fetched. Authorized Loam administrators can access cross-account call logs and transcripts for service operation and support; organizational customer-admin access is not shipped today.
  • Public contact submissions — the name, email, optional company, inquiry category, message, and request metadata you submit through the Contact form. The form sends that material through Mailjet to Loam’s contact mailbox; it is not added to product memory by the form.
  • Credentials you connect — API keys, connected-service tokens (such as GitHub), and any cloud-provisioning credentials you provide. These are encrypted (see below).
  • Technical logs — standard web-server and security logs (such as IP address and request metadata) used to operate and protect the service.

We do not sell your data, use it for advertising, or use your content to train Loam-owned models.

By default, Loam does not scan or upload your source code. Your code is only read when you paste it, attach it, start a workflow that needs it, or turn on Workspace Indexing (which is off by default).


3. How we use it

  • To provide the service — run your sessions, remember your work across them, produce code and documents, and (when you ask) provision infrastructure.
  • To reach you — the team's voice calls, meeting invites, and follow-ups, and sign-in verification codes, all sent to the phone or email on your account.
  • To keep it secure — detect and prevent abuse, debug problems, and protect the platform and your account.

4. How it's protected

  • Encrypted at rest. Your credentials, conversation content, team memory, and project context are field-encrypted at rest with Fernet (AES-based) symmetric encryption. The encryption key is held outside the database, and rotating it is a supported operation.
  • Passwords hashed, never stored. Passwords are hashed with bcrypt and a per-password salt. We cannot read your password and never store it in the clear.
  • Encrypted in transit. All traffic to Loam is served over TLS (HTTPS).
  • Isolated per account. Your data is scoped to your account with strict per-account isolation.

Where the line sits, honestly. Two categories are kept in plaintext, and we'd rather tell you exactly where than imply more than we do:

  • Recall metadata — display names, the phone number we match a return call against, and the keyword tags and short summaries the memory index searches. Encrypting these would break search and recall, so they stay queryable behind strict per-account isolation.
  • Call transcripts — stored as plaintext (not field-encrypted like session content) so the team can synthesize them into memory.
  • Reception work orders and delivered reports — the text of a work order, its intake record, and the delivered report files are stored without field encryption. The context attached to an order and the body of an email request are encrypted.

The Security page carries the full data table — each data type, whether it's stored, whether it's encrypted at rest, whether it stays searchable, and how you delete it.


5. Service providers & sub-processors

Loam relies on a small set of service providers to operate. When a task needs model reasoning, your content is sent to the AI provider that performs it — it is not sold, used for ads, or used to train Loam-owned models.

  • Anthropic (Claude) — performs the core AI work.
  • Google (Gemini) — performs server-side image generation when that feature is enabled.
  • Amazon Web Services — hosts the platform and stores media assets.
  • Cloudflare — provides edge delivery, DNS, and request security for public properties and supported infrastructure workflows.
  • Communications providers — Twilio (telephony), ElevenLabs (voice synthesis), ClickSend (SMS/MMS), and Mailjet (email and public contact-form delivery).

A current, itemized sub-processor list is available to enterprise customers on request via Contact.


6. How long we keep it

  • Session content, team memory, and project context — kept until you delete them or delete your account.
  • Call audio recordings — cleared automatically about 30 days after the call; the status becomes “expired.”
  • Full call records (including transcripts) — do not currently auto-expire; removed when you delete your account or when an authorized Loam administrator runs the cleanup control.
  • Produced audio (such as Morning Read and Studio audio) — stored as server files. Account deletion removes the related database records; file removal requires Loam-operated cleanup.
  • Reception work orders — removed from the live database when you delete your account. Delivered report files stay on Loam’s server until Loam removes them; contact us to request removal. A short intake record of each request, including your words, is kept after account deletion as an audit record, and so are notes recorded when older open orders were closed out.
  • Public contact submissions — delivered to Loam’s contact mailbox through Mailjet. No product-controlled automatic retention schedule is defined for mailbox copies today; contact us to request deletion.
  • Backups. Deletion removes data from our live systems immediately, but disaster-recovery snapshots may still contain deleted data until those snapshots expire. Current backup retention window: 7 days.

7. Your choices & rights

Database deletion is in your hands. From your account you can delete a single team member's memory, an individual project, or the live database records tied to your account — confirmed behind a phone code where required. The account transaction removes memories, sessions, projects, settings, stored credentials, and the user record. Server-stored generated audio requires Loam-operated file cleanup; infrastructure teardown follows the applicable plan or order.

Honest limits. A one-click data export isn't built yet. If you need a copy of your data, contact us and we'll help.

Depending on where you live, you may have additional rights — to access, correct, port, or delete your personal data, or to object to certain processing. To make a request, contact us using the details in the Contact section below; we'll verify your identity and respond within the timeframe the applicable law requires.


8. Where your data lives

Loam is hosted on Amazon Web Services in the United States. If you access Loam from outside the United States, your information will be processed in the U.S. and in the regions where our service providers operate.


9. Children

Loam is a professional development tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we'll delete it.


10. Changes to this policy

If we change how we handle your data, we'll update this page and the “Last updated” date above. Material changes will be communicated through the platform.


11. Contact us

Questions about this policy, or a request about your data? Email info@loam.team, use the Contact page, or write to Toast2IT LLC, 4121 Shadow Creek Circle, Oviedo, Florida 32765, United States. For the technical detail behind everything here, see Security.

Loam — AI software delivery.
© 2024–2026 Loam. All rights reserved.
Product Call Loam Evidence Team Security Get started Pricing Compare For IT For Leaders Story Research Glossary Releases Contact Privacy Terms

Loam is an independent product built on Anthropic’s Claude. It is not affiliated with or endorsed by Anthropic. Carl, Diana, Anthony, Abish, and Meg are AI working contexts with synthesized imagery and voices, not human employees.