lookloom.ai
Legal
Back

Lookloom legal

Privacy Policy

This Policy explains how Lookloom handles account data, uploaded images, references, prompts, AI-generated images, sharing, and community activity.

Effective date: August 19, 2026

Image privacy at a glance. Images you upload and Outputs you create are private by default. They become accessible to others only when you choose a sharing link or image-pack visibility, or when you submit an Output to Discover and Lookloom approves it.

1. Who controls your information

Ruhuy, Inc. operates Lookloom and is responsible for the personal information described in this Policy. “Lookloom,” “we,” “us,” and “our” refer to that operator.

Privacy contact: privacy@lookloom.ai
Registered office: 131 Continental Drive, Suite 305, Newark, DE 19713, United States

Lookloom is not currently offered in the European Union, the European Economic Area, or the United Kingdom. We use country information supplied by our hosting and security infrastructure to prevent access from those locations. The regional-unavailability response does not load the Lookloom application, account features, or first-party product analytics. Our infrastructure providers may still process the request and produce aggregated traffic and security measurements.

2. Information we collect

CategoryExamples
Account and identityName, email address, authentication provider, account identifiers, verification status, profile image, role, and account dates.
Authentication and securityPassword credential records, session tokens, IP address, user agent, rate-limit records, login and reset activity, human-verification challenge results, and security logs. We do not display your password to our staff.
Images and AI inputsUploaded images, close-up regions, reference images, Quick Edits, custom prompts and instructions, generation requests, and Outputs.
Profile and preferencesDisplay name, avatar, language, dark-mode and font-size preferences, credit balance, and credit ledger.
Activity and community dataEditing sessions, favorites, follows, downloads requested through the Service, sharing links, image-pack visibility, Discover submissions, titles, moderation status, and published posts.
Feedback and communicationsProfile feedback, generation ratings and selected issue topics, feedback messages, language and app version, administrator replies, email-delivery status, password-reset messages, support requests, commercial-license requests, rights complaints, and other correspondence.
Technical dataRequest timestamps, error and queue status, device and browser information available in requests, cookies, local storage, and operational logs.
First-party product analyticsA random anonymous visitor ID, first-seen country and language, UTM source/medium/campaign, referrer hostname, and a limited set of product events such as landing, source selection, whether an edit was configured through Quick Edit or Prompt, the number of selected Quick Edits and selection-limit encounters, Generate clicks, pricing, paywall, payment-option selection, checkout start, and generation-result actions such as download, share, favorite, publish, redo, deletion, or continuing from an image. We do not put the selected edit, prompt text, image contents, full URLs, full user-agent strings, or raw IP addresses in product analytics.
Website traffic and performance analyticsAggregated visits, page views, URL paths, referrer hostnames, country, device type, browser, operating system, navigation type, page-load timing, and Core Web Vitals. This analytics does not receive Lookloom's custom product events or URL query strings and does not use cookies, local storage, or fingerprinting to identify individual visitors.

We receive information directly from you, automatically from your browser and use of the Service, and from an identity provider if you choose a third-party sign-in option.

3. How we use information

We use information to:

  • create and secure accounts, authenticate users, and provide password recovery;
  • store images, run editing sessions, process AI generation requests, deliver downloads, and maintain history;
  • operate sharing links, image packs, Discover, remixing, attribution, and other community features;
  • manage credits, verify legitimate trial use, prevent duplicate or abusive requests, diagnose failures, and protect the Service;
  • personalize language and display preferences;
  • measure website traffic and performance, acquisition, trial activation, creation success, plan use, and service economics so we can improve product quality and pricing;
  • review feedback, understand generation-result behavior as separate raw signals, improve the Service, and reply to feedback through your registered email address;
  • review shared material and Discover submissions and address moderation or rights issues;
  • respond to support, privacy, commercial-license, legal, and rights requests;
  • comply with law and enforce our Terms.

Depending on where you live, these activities rely on performance of our contract with you, our legitimate interests in operating and securing the Service, consent where required, and compliance with legal obligations.

4. Uploaded and generated images

MaterialDefault visibilityWhen others can access it
Uploaded imagesPrivate to the uploader.Only when the uploader activates an image link, includes the image in a shared or public image pack, or otherwise selects an available sharing option.
References, prompts, and editing historyPrivate.They are processed to create requested Outputs but are not included in ordinary image or Output sharing links.
OutputsPrivate to the user who creates them.When the user creates an Output link, includes the original in that link, or submits the Output to Discover and it is approved.

The ability to download an image does not change its ownership, privacy classification, or permitted-use license. See our Terms & Conditions.

5. AI processing

When you request an AI edit or virtual try-on, Lookloom sends the relevant uploaded or generated image, selected references or regions, prompts and instructions, and related technical request data to an AI processing service provider so it can generate an Output. The provider may perform limited processing or retention for service operation, caching, security, or abuse prevention as governed by applicable contracts, configurations, and service terms.

Lookloom does not authorize any third-party service provider to use private uploaded images or private Outputs to train or fine-tune its general-purpose models. Lookloom also does not use private uploaded images or private Outputs to train its own models unless we first provide a separate explanation and obtain any consent required by law.

6. Service providers and other disclosures

We disclose information only as reasonably necessary to operate the Service or as described here:

  • Infrastructure, database, file-storage, analytics, and security providers process account, media, request, and technical data to host, deliver, measure, back up, and protect the Service.
  • Bot-detection and human-verification providers process limited request, browser, device, network, and challenge-result data to distinguish legitimate trial use from automated abuse.
  • Identity and account providers process sign-in and account information when you use their authentication option.
  • AI processing providers process images, references, prompts, instructions, and technical request data to create requested Outputs.
  • Email and communications providers process contact and message-delivery information for account and service communications.
  • Moderators and authorized operators may review shared material and investigate safety, support, privacy, or rights issues.
  • Legal and safety recipients may receive information when reasonably necessary to comply with law, protect rights and safety, prevent fraud, or respond to valid legal process.
  • Transaction counterparties may receive relevant information during a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate safeguards.

We do not currently sell personal information or use images for targeted advertising. We do not authorize service providers to use private uploaded images or private Outputs for their own advertising or to train or fine-tune general-purpose models.

7. Cookies and local storage

Lookloom uses cookies and similar storage to keep you signed in, protect authentication requests, maintain application state, support security and human-verification checks, and measure the product using a first-party anonymous visitor identifier. The first-party product-analytics cookie is HttpOnly, uses SameSite=Lax, and lasts up to 180 days. The app may store a recent editing-session identifier locally so you can resume your work. Our website traffic analytics does not use cookies, local storage, or other client-side identifiers. We do not currently use behavioral advertising cookies or third-party analytics cookies. If that changes, we will update this Policy and provide any choices required by law.

8. Shared and public content

Link sharing is separate from Discover. An Output-only link exposes the selected Output and limited creator and image information without exposing the original image. If you activate an original-image link or an Output + Original link, recipients can view and create from the original, forward the authorized link, and include the original in links for their derivative Outputs. Sharing does not expose prompts, reference images, intermediate generations, branches, or session identifiers.

A shared image pack is available to anyone with its link; a public image pack is visible more broadly and may be featured in Discover. Shared and public images may be reviewed, restricted, or removed. If you submit an Output to Discover and it is approved, the image, chosen title, display name, available source attribution, and related engagement become public and may be accessed by anyone with the link. Discover may recommend the approved Look to you, your followers, your audience, or the attributed source creator's followers and audience. If a moderator also selects Publish to Discover, the Look may be shown in everyone's Discover. Discover recommendation eligibility does not control direct access to an approved Look. Public content may be copied by others despite our Terms, so do not share or publish information you want to keep private.

Anyone who receives or forwards an active sharing link can use it under our Terms. Forwarding the Lookloom link does not require separate attribution because the sharing page carries the available source information. The Terms explain when attribution is required for an original image reposted outside its Lookloom sharing page.

Revoking original-image access disables links that depend on that permission, including descendant links, and stops future access and new creation from the original. It does not retroactively delete recipients' existing sessions or Outputs, and Outputs lawfully created before revocation may continue to be used and shared under our Terms. Changing an image pack to private, deleting it, or losing access, approval, or its active image may likewise disable dependent links. We may also block shared material for moderation or safety reasons.

Deleting an editing session makes that session unavailable but does not necessarily delete generated images, favorites, publication records, approved Discover posts, moderation records, or independent Output-only links. Standard and other non-personal session deletion revokes Output-only and Output + Original links for that session's Outputs. Deleting a session carrying your own Personal Upload authority revokes the original link and every dependent Output + Original link, including descendant links, while independent Output-only links remain available.

9. Retention and deletion

We retain account information and private content while your account is active and for as long as reasonably needed to provide the Service, maintain generation history and credits, resolve disputes, enforce agreements, secure the Service, and meet legal obligations. Feedback submissions and administrator replies are retained while the submitting account exists and are deleted when that account is deleted. Raw first-party product events are kept for up to 180 days and are deleted with their account link when an account is deleted. Aggregated website analytics are available to us for up to six months. Security, rate-limit, moderation, transaction, aggregated or de-identified analytics, and legal records may be kept longer where necessary.

You may request deletion using the privacy contact above. Deletion from active systems may take a reasonable period and does not necessarily remove lawful backups, de-identified records, content another user independently provided, or public content and license records that must be retained to protect users and rights holders. We will explain material limitations where required by law.

10. Security and international processing

We use access controls, private-by-default media permissions, secure transport, managed storage protections, rate limiting, and operational safeguards designed to protect information. No system is completely secure, and we cannot guarantee absolute security.

Service providers may process information in countries other than your own. Where required, we use contractual or other recognized safeguards for international transfers. Contact us for information relevant to your location.

11. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent without affecting earlier lawful processing. You may update available profile settings in the app or contact us. You may also complain to your local data-protection authority.

We may verify your identity before completing a request. Some rights are subject to legal exceptions, the rights of others, and records we must retain. Where applicable law requires information about actual recipients rather than recipient categories, you may request it using the privacy contact above.

12. Children and legal capacity

Lookloom is not directed to a child who cannot lawfully consent to the processing required for the Service. Where parent or guardian consent is required, the responsible adult must authorize the account and use. If you believe a child has provided information without required authorization, contact us so we can investigate and take appropriate action.

13. Changes and contact

We may update this Policy as the Service, provider categories, or law changes. We will post the revised Policy with a new effective date and provide reasonable additional notice for material changes.

Questions or requests: privacy@lookloom.ai
Operator: Ruhuy, Inc.
Registered office: 131 Continental Drive, Suite 305, Newark, DE 19713, United States

© 2026 Lookloom