Legal and privacy
Privacy Policy
This notice explains the information Credential Loom handles, why it is needed, and how access to a professional-owned portfolio is controlled.
Last updated October 7, 2026
1. Scope and product boundary
Credential Loom helps licensed professionals organize continuing education, licenses, renewal dates, certificates, and related administrative information. It is not a clinical system. Do not submit patient records, diagnoses, treatment information, clinical notes, or other patient or clinical information.
This notice applies to Credential Loom websites, applications, support channels, and related services.
2. Information collected
- Account and profile information: name, email, verification state, authentication provider, sessions, account recovery, and multifactor-authentication events.
- Professional records: professions, jurisdictions, license types and numbers, issue and expiration dates, CE activities, credits, categories, notes, reminders, and reports.
- Documents and imports: certificates, transcripts, images, spreadsheet data, metadata, file hashes, processing states, proposed extracted fields, confidence indicators, and review decisions.
- Organization information: workspaces, departments, invitations, memberships, seat assignments, administrator roles, and portfolio permissions.
- Billing information: Stripe customer, subscription, invoice, plan, and entitlement identifiers and states. Stripe collects payment-card details; Credential Loom does not store full card numbers.
- Communications and operations: support requests, feedback, transactional delivery states, IP address, user agent, timestamps, rate-limit events, audit records, job states, and sanitized error codes.
3. How information is used
Credential Loom uses information to:
- create and secure accounts and professional portfolios;
- provide license, CE, document, reminder, reporting, import, and organization tools;
- enforce ownership, explicit organization permissions, plan limits, and security controls;
- provide subscriptions, cancellation, support, and essential transactional messages;
- investigate abuse, recover from failures, maintain audit trails, and respond to access, correction, export, and deletion requests; and
- understand product usage through minimized first-party records and, when analytics is enabled, privacy-limited PostHog product events. Credential Loom does not use those events for behavioral advertising.
Credential Loom does not currently sell professional portfolio data or use certificate contents for targeted advertising.
4. Documents and imports
When real uploads are enabled after the launch gates pass, supported files enter private quarantine and undergo size, extension, MIME, magic-byte, and duplicate-hash validation. A private ClamAV scanner must return a clean result before evidence can be promoted. Infected, unavailable, timed-out, or invalid scan results fail closed.
Credential Loom may create editable extraction proposals from a document. A proposal may be incomplete or wrong and requires user review. Uploading or importing a record does not verify a provider, credit, requirement, board report, or board acceptance. Guided APA, CE Broker, and CME Passport imports use files the user obtains; they are not automatic provider synchronization or partnerships.
5. Professional ownership and organization access
A professional owns the personal portfolio associated with their account. Organization membership, an invitation, an administrator role, or an employer-funded seat does not automatically disclose CE, license, or document information.
Organization access requires explicit, granular permission from the professional. Permissions may expire or be revoked and are audited. Leaving an organization removes its future access without deleting or transferring the professional's canonical CE history.
6. Service providers and subprocessors
Credential Loom currently relies on:
- Railway for application hosting and private workers;
- Supabase for PostgreSQL, authentication, and private object storage;
- Google as an optional authentication provider;
- Stripe for subscription billing and hosted payment interfaces;
- Resend for transactional email and delivery events;
- Namecheap Private Email for the monitored support mailbox;
- PostHog, when enabled, for pseudonymous, allowlisted product events with session replay disabled;
- private ClamAV infrastructure for malware scanning; and
- Backblaze B2 for encrypted, private, independent certificate-object backups.
Credential Loom does not receive Google passwords or store complete payment-card numbers. No document is sent to an external AI processor unless that provider, disclosure, consent, and feature are separately approved and enabled.
7. Retention and deletion
Active account and portfolio records are retained while the account is active and until an eligible, verified deletion request is completed. The proposed document recovery period is 30 days after soft deletion, while terminal quarantine and failed-import files are proposed for cleanup after 7 days. Import previews and staged rows have a 30-day review window. Eligible active-system account deletion has a 30-day operational target after identity, ownership, shared-record, and hold review. Destructive production purge remains disabled until its final synthetic acceptance and secure configuration are complete.
Database backups and independent object backups are protected separately. Deletion from active systems may not immediately remove protected backup copies; restored data remains subject to outstanding deletion instructions. A narrowly scoped legal, security, tax, or dispute hold may delay deletion and must be authorized and audited. See the authenticated deletion workflow or contact support to make a request.
8. Security practices
Credential Loom uses managed authentication, server-side authorization, PostgreSQL row-level security, private object storage, short-lived signed download links, encryption in transit, environment-separated secrets, signed webhooks, rate limits, audit events, malware scanning, and independent backup verification. No system is risk-free.
These safeguards are not a claim of HIPAA compliance, SOC 2 certification, accreditation, licensing-board approval, or another external certification.
9. Choices and requests
Subject to identity verification and applicable law, users may request access, correction, export, deactivation, or deletion through account settings or the secure support workflow. Users can manage ordinary notification preferences, while Credential Loom may still send essential account, security, legal, and billing messages.
10. Contact and changes
Privacy questions and requests should use the public contact form or the authenticated support workflow. Do not email passwords, authentication codes, patient information, or certificate contents.
Material changes will be dated and communicated as appropriate. The owner approved this pre-launch version for deployment on October 7, 2026. It has not been certified or approved by an attorney.