Privacy Policy

Legal

Privacy Policy

What data we handle, why, how AI uses it, and your rights.

Introduction

Welcome to Loomworld. We know how much your personal information and your work mean to you — your trust is the precondition for this product existing. Taiyuan Daxigan Culture Media Co., Ltd. ("we", "us") sets out in this policy how, in providing the Product, we collect, store, use, disclose and protect your personal information and project content, and how you can manage them.

Please read this policy carefully, especially the clauses in bold. If you do not agree with any part of it, stop registering or using the Product immediately. By confirming this policy through registration, login or actual use, you agree to the processing described here.

In summary:

  • What we collect to make the product work, and why
  • How your project content is stored, synced and processed by AI
  • How we share, transfer and disclose information
  • How and where we store and protect it
  • What rights you have and how to exercise them
  • Minor protection, policy updates and how to reach us

Two commitments matter especially for this product: we do not process your data for advertising or targeted marketing, and apart from what is necessary to complete the AI tasks you start, we do not use your script text to train or improve any machine-learning model.

1. Definitions and Scope

1.1 Loomworld means the AI-native screenwriting product developed and operated by Taiyuan Daxigan Culture Media Co., Ltd., including the official websites (loomworld.ai, loomworld.cn), the Browser client, the Desktop client, and future service forms.

1.2 Personal information means various kinds of information recorded electronically or otherwise relating to an identified or identifiable natural person, excluding information after anonymisation.

1.3 Project content means the project data you create — script text, character, location, prop and setting material, timelines and image assets. It is your creative work.

1.4 This policy applies to all product and services we provide in our official forms. It does not apply to services a third party provides to you directly (such as a payment channel or a model provider's own service), which are governed by the terms they present to you.

2. How We Collect and Use Personal Information

To deliver product functions we divide the information we collect into what is necessary for core functionality and what is optional for additional functionality. Refusing to provide necessary information means the corresponding function cannot be used; refusing optional information does not affect core functions.

2.1 Account registration and login

  • The Global edition collects and uses your email address for registration, password login, and password setup and recovery. Identity methods do not cross over between markets: when email delivery is unavailable, the Global flows fail explicitly rather than falling back to a mobile number.
  • Registration and recovery require a code sent by our email delivery service. The specific provider is as stated in the provider list and product prompts in force at the time; this policy does not name suppliers that are not yet configured.
  • Your account's market is held server-side as the single source of truth and re-validated against the request host; Global and CN accounts, identity methods and entry points are not interchangeable, and cross-entry access is refused. Your password is stored only as a salted, irreversible hash, so we cannot recover it in plaintext.
  • If you enable two-factor authentication we store your TOTP configuration. Session credentials are stored per client: on the Browser only in an HttpOnly, Secure, SameSite cookie on the API domain; on Desktop in your operating system's credential store.
  • An optional invitation code and the resulting invitee relationship are used for referral attribution. When the invited account completes its first genuine paid order, the referrer receives a one-off Credit grant.
  • We keep device summaries and session records (sign-in time, device type and the like) for account security. You can review and revoke individual or all other sessions from the account centre.

2.2 Storage and sync of project content

  • Projects on ordinary free accounts stay on your device: Browser uses IndexedDB in your current browser and Desktop uses a local project folder. Signing in alone does not upload a project.
  • Cloud sync requires an active subscription or a recorded legacy Global entitlement. When you enable sync for a selected project, its cloud version is stored in our master database within your account, and your device keeps a complete local copy for offline editing. The account centre shows legacy access separately; it is not a purchased subscription.
  • While sync access is valid, local edits upload on reconnect. Concurrent multi-device edits preserve your un-uploaded changes as a "conflict copy" before refreshing from the cloud. After subscription expiry, cloud writes pause while local editing, saving and export continue; existing cloud projects remain available to read, export and delete. Renewal checks both versions before resuming sync.
  • Large assets such as images are stored content-addressed and deduplicated (identical content shares a stored asset within each project). Deduplication is based on content alone and involves no additional analysis about you.
  • You may export your project as a complete local copy at any time, including all text and image assets.

2.3 AI task processing

  • AI functions (multi-turn writing assistant, one-shot generation skills, background archive maintenance) process your project data in the cloud. Writing-assistant and maintenance tasks are served by a cloud agent that reads the cloud project store directly; one-shot skills have your device extract the needed data, with prompt templates applied server-side before the model is called.
  • The project content necessary to complete a task is sent with the request to the model provider. The providers we currently connect to are all based in mainland China (for example DeepSeek and MiniMax), so your project content is not transmitted to a model provider located outside mainland China.
  • AI never modifies your project directly: every write it proposes comes back as a proposal and takes effect only when you confirm it.
  • We do not give providers data unrelated to completing your task, and we do not use your script text to train or improve any model.

2.4 Credits, orders and billing

  • To provide per-use AI billing and its accounting records we keep your Credit ledger history, reservations and settlements, and AI call measurements (call time, task type, Credits consumed, provider brand). Order records are kept only once actual paid orders exist.
  • Global uses Creem; the CN desktop website uses Alipay. After you confirm a purchase, we provide the relevant channel with order IDs, product identifiers, amounts and other order information needed to complete payment. We receive payment results, transaction identifiers and refund status to reconcile the ledger. The channel directly collects information needed for its checkout under its own privacy notice. We neither handle nor store card details or other sensitive payment credentials, and do not send your writing or project files to payment channels.

2.5 Logs and security

  • We keep the structured logs and alerts needed to operate the service (error codes, request latency, task status). Logs do not contain project text or a full project graph, are used only for fault isolation and security, and are retained on a minimum-necessary basis.
  • Runtime statistics (such as active project counts) use behavioural metadata only and do not read or measure your creative content.

2.6 Support and disputes

When you contact us to ask, complain, request a refund, or exercise a personal-information right, we need the account information necessary to verify who you are and handle the request, and we keep the correspondence and handling record for the necessary period.

2.7 Other rules

  • We do not use your personal information for targeted delivery or precision marketing.
  • What personal information you choose to include in a project or conversation is your decision. Do not store sensitive personal information unrelated to the writing — biometrics, financial accounts, precise movement data — because a leak of those would seriously harm the people concerned.
  • Where the law permits processing without your consent (performing legal obligations, protecting life and health in an emergency, and the like), that legal basis applies.
  • If we discontinue a product or service we will stop collecting personal information for it, announce it to you, and delete or anonymise the related information.

3. Cookies and Local Storage

  • Session cookies: held only in HttpOnly, Secure, SameSite cookies on the API domain, to maintain login state and guard against unauthorised access. They contain no project content.
  • Local project storage: Browser IndexedDB holds complete local projects and is the storage location for free local mode. With cloud sync enabled it also supports offline editing and faster loading. Desktop uses the local project folder you choose.
  • We do not use cookies or similar technology for advertising, behavioural tracking or cross-site profiling. You may clear cookies and site data at any time. Doing so requires you to sign in again and removes Browser-local projects and un-uploaded edits. Successfully synced cloud versions are unaffected; signing in again cannot restore work that existed only on this device, so export a project pack first.

4. Sharing, Transfer and Disclosure

4.1 Sharing

Apart from the following, which are necessary to deliver the service, we do not sell, rent or share your project content or account data with third parties:

RecipientWhat they receivePurpose
Model providers based in mainland China (e.g. DeepSeek, MiniMax)The project content necessary to complete an AI taskProviding AI generation capability
CloudflareNetwork transport-layer information (no plaintext storage of content)TLS encryption and edge delivery over the public internet
Email delivery service (name as published at the time)Your email addressCodes for Global registration, login and recovery
Creem (Global), Alipay (CN desktop website)Order IDs, product identifiers, amounts, and payment or refund resultsProcessed when you confirm a purchase or request a refund; excludes writing, project files and card credentials

Each recipient touches only the data required to perform its function. If the provider list changes we will update this policy. We will not use your project text for any purpose outside this scope.

4.2 Transfer

We will not transfer your personal information. If a transfer becomes necessary through merger, division, acquisition or bankruptcy, we will require the recipient to keep being bound by this policy, and will seek your fresh consent if the recipient changes the purposes or means of processing.

4.3 Disclosure

We will not disclose your personal information publicly except as required by law or by a competent judicial or administrative authority. Where disclosure is legally compelled we keep it to the minimum necessary scope and means.

5. Where and How We Store and Protect Information

5.1 Storage location

Personal information and project data collected and generated in the course of our operations within mainland China are stored on servers we self-host within mainland China; transmission over the public internet is encrypted with TLS. At present we do not transfer or store your personal information or project content outside mainland China. Should a cross-border transfer become necessary in future, we will disclose the purpose of the export, the recipients and the categories of information as the law requires, and obtain your separate consent in advance.

5.2 Retention

  • We keep information only for the shortest period necessary for the purposes in this policy, save where a longer mandatory retention applies (such as statutory retention for financial and order records).
  • Deleted data may persist in existing backup copies until the current backup rotation ends, and is then cleared. Backups are used for disaster recovery only.

5.3 Security measures

  • Project data is strictly isolated per account; no interface can read another account's projects.
  • Passwords are stored as irreversible hashes; managed AI nodes use separate credentials and short-lived task tokens scoped per task.
  • Payment and Credit ledgers are authoritative only on the server; client input is never trusted.
  • We maintain data classification, access control, audit and backup-and-restore mechanisms, and keep improving technical and organisational measures.
  • On a personal-information security incident we will activate our response plan, take remedial action, and notify you of the incident type, cause, likely harm, remedial measures and contact details as the law requires; where individual notice is impracticable we will announce it instead.

6. Your Rights

  • Access and correction: account details can be viewed and changed in the Product; project content can be viewed and edited directly in the editor.
  • Data portability: you may export a complete project package (all text and image assets) at any time, and may request a copy of the personal information we hold about your account through our published channel; we respond within 15 days after verifying your identity.
  • Erasure: you can delete project content yourself in the Product; deletion of your account and all cloud data runs through the deletion flow below.
  • Withdrawal of consent and sign-out: you may revoke device sessions and perform a strict online sign-out at any time. Withdrawal does not affect processing already carried out on the basis of your consent before withdrawal.
  • Account deletion: you may apply from the account centre. A cooling-off period applies, revocable by you. After it ends and session termination is confirmed, your cloud projects (with all image assets) and account data are cascade-deleted. Local caches on your devices and copies you exported are unaffected and you can delete them yourself. This cascade deletion is on our pre-launch acceptance checklist; until it is confirmed by a live drill, the deletion commitment in this clause takes effect on that acceptance passing.
  • Response time: we answer requests made under this policy within 15 days. For requests that are repeated, excessive or beyond reasonable limits we may charge a reasonable cost or refuse. Where the law does not permit us to respond (state security, criminal investigation, another person's major lawful rights, trade secrets and the like) we will say so.

7. Minors

The Product is not available to minors at this stage and we do not collect minors' personal information. Until minor-protection capability (age prompts, guardian consent flows) is deployed and verified, guardians should not allow minors to register for or use the Product. If we find we have mistakenly collected a minor's personal information we will delete or anonymise it promptly. A guardian who finds a minor registered or paid by impersonating an adult may contact us through the published channel and we will handle it lawfully once verified (payment rules are in the Refund Policy).

8. Changes to This Policy

When product behaviour or the law changes we update this policy and mark its version date, and we will flag material changes prominently in the Product. Without your consent we will not diminish the rights this policy gives you. Material changes include: a substantive change in purposes or information types; a change in the main recipients under sharing, transfer or disclosure; a change in your rights or how you exercise them; and a change in the responsible contact and channel.

9. Contact

We maintain a personal-information contact channel. For questions, comments or complaints about this policy, about the processing of your personal information, or about exercising a right under it, contact us through the channel published on the official website's Contact page (loomworld.ai); we reply within 15 days. The published email address is as stated on the website.

Disputes arising from this policy should be settled by friendly negotiation; failing that, either party may bring suit before the competent court at the Operator's place of business. The formation, effect, interpretation of and disputes under this policy are governed by the laws of mainland China.