Sign up and log in
Email and password, what codes are for, where sessions live on each device, and account deletion’s cooling-off period.
How you sign in, and from where
Day to day, email plus password is enough—no code every time. Web users sign in from the entrance on loomworld.ai; the desktop app asks for the same credentials once, then the system credential store keeps you signed in across restarts.
Signing in changes two things: what your account can show (credits, task history, devices, deletion) and access to the cloud project library. Signed out, the software is still usable—the editor and the reference modules work, projects live on this device, and cloud sync and AI are skipped quietly.
Sign up: password first, mailbox second
- Email and password“Password must be 10–128 characters long.” No strength lecture, but treat it like the account your manuscripts hang from.
- The 6-digit codeA registration code arrives by email and the app tells you to check the newest message. Codes expire, so never reach for an older mail.
- Invitation code (optional)During public sign-up the invitation code is optional and changes no capability. Filling one in only records a referral.
An account with no password is a normal state: early beta or partner accounts set one via “Forgot Password / Set Initial Password”, which verifies identity with an email code.
Changing or recovering a password
Reset and first-time setup share one chain: email → 6-digit code → new password, with the same 10–128 character rule. The code does not distinguish “forgot” from “never set”, which is why the entry is named “Forgot Password / Set Initial Password”.
Where the session lives, and on how many devices
- Browser: the session rides on an HttpOnly cookie only the API can read. Tokens are never written to localStorage, IndexedDB, or your project files.
- Desktop: the access token stays in runtime memory and the refresh token in the system credential store, so a restart restores sign-in.
- Account → Devices and security lists the current device plus other active sessions with their last activity; revoke them one by one or all at once.
- If the local secure store is unavailable, the app says this session is memory-only and offers “Retry saving” or “Sign out strictly” rather than pretending it persisted.
Signing out, deleting the account, the cooling-off period
Signing out only leaves the account; project files and cloud data stay put. Deleting an account is another matter: applying in Account → Danger zone starts a cooling-off period you can withdraw from. During processing you cannot top up or start new agent tasks, while orders, ledger entries, and history remain readable. Once the cooling-off period ends and deletion is confirmed, that account’s creative-result notifications on this machine are cleared.
Limits and troubleshooting
- “Verification code incorrect or expired”: use the 6-digit code from the latest email; older ones are dead.
- Codes sent too fast: wait, then resend—clicking repeatedly only extends the wait.
- “Invalid invitation code. Please check and retry; you can also register without a code.”: leave it empty and continue.
- No mail: check junk first, then the address spelling.
- Signed out, AI entrances do not quietly switch to a local model, and cloud sync is skipped. A browser-local project depends on that browser’s storage—clearing site data or changing browsers will not carry it. Export a pack.
What else Account holds: Settings and project data; where data lives: Cloud version and local cache.