September 3, 2026

Privacy Policy

Effective date: September 1, 2026
Operator: Draper Security LLC. AdvisoryLoom is a brand and product operated by Draper Security LLC.

A feature-matched privacy notice for WordPress accounts, device-local personalization, first-party analytics, Stripe, Turnstile, AI processing, and user rights.

1. Who we are

This Privacy Policy explains how Draper Security LLC collects, uses, discloses, and protects personal information when operating AdvisoryLoom. AdvisoryLoom is a brand and product of Draper Security LLC.

Controller/operator contact: Draper Security LLC, 2746 Kirby Road, Draper, VA 24324; support@advisoryloom.com.

2. Information we collect

Information you provide may include:

  1. account information such as email address, username, display name, password credentials processed by WordPress, avatar or profile settings, and email-verification status;
  2. communications, support requests, correction requests, billing questions, and privacy requests;
  3. subscription selections and records associated with Stripe customer, subscription, price, billing-period, and payment-status identifiers;
  4. optional context you type when requesting an AI briefing, after you acknowledge the provider-transmission notice; and
  5. preferences or consents you choose to save.

Information collected automatically may include:

  1. security and access information such as IP address, request time, requested resource, browser or device information, authentication events, and rate-limit signals processed by WordPress, the hosting environment, security services, or server logs;
  2. limited first-party product analytics using random pseudonymous browser and session identifiers; and
  3. cookies, local storage, session storage, IndexedDB records, and similar browser storage described below.

We also process public cybersecurity content and metadata from publishers, vendors, government sources, vulnerability databases, and other external sources. That information ordinarily concerns publications and products rather than AdvisoryLoom users.

3. Device-local personalization

AdvisoryLoom is designed so Saved and Recent items, Watchlists, Intelligence Profiles, reading preferences, local matching results, and current AI briefing history can remain in an encrypted browser vault on the user’s device. The vault uses browser cryptography and IndexedDB. Its device key is not exportable.

The WordPress server publishes a generic intelligence feed and does not accept current personalization writes. Legacy server personalization data, if any, is made available only to its owner for migration and is purged after successful migration or the configured migration window.

Device-local data may be lost if you clear browser data, lose the device, use a different browser profile, or the browser evicts storage. AdvisoryLoom provides an optional encrypted backup. Draper Security LLC cannot recover a forgotten backup passphrase or a lost device-local key.

4. Product analytics

AdvisoryLoom may collect a limited set of first-party usage events: session start, app open, app installation, and sign-up or sign-in page view. These events use salted pseudonymous identifiers that are not derived from or linked to a WordPress account.

The product-analytics collector is designed not to store article activity, publisher clicks, searches, categories, Saved/Recent activity, Watchlists, Intelligence Profiles, local match results, AI history, IP addresses, browser user agents, full URLs, passwords, or tokens. This limitation applies to the product-analytics table; ordinary hosting and security logs may separately process IP addresses and request metadata.

When enabled, browser Do Not Track and Global Privacy Control signals are respected, and a device-level analytics opt-out is available in the AdvisoryLoom account panel.

5. AI Intelligence Advisor

The AI Advisor is optional. When you request a briefing and affirm the transmission notice, AdvisoryLoom sends the selected released Intelligence Object, related public-source evidence, and any optional user context you entered to the configured AI provider, currently OpenAI when that provider is enabled. The request also includes technical instructions needed to generate and validate the response.

Private Watchlists, Intelligence Profiles, Saved/Recent activity, and local matching data are not automatically sent to the AI provider. The generated briefing history is stored in the encrypted device vault. AdvisoryLoom may retain bounded operational records such as account ID, selected object ID, request outcome, model identifier, timestamp, and token estimate for security, limits, cost control, and troubleshooting; these records are not intended to contain the full local briefing history.

Do not enter secrets or sensitive personal, confidential, regulated, or incident-response data into optional AI context. The AI provider processes transmitted information under its applicable business terms and privacy commitments.

6. How we use information

  1. provide, personalize on-device, maintain, and improve AdvisoryLoom;
  2. create and authenticate accounts, verify email, reset passwords, and protect account access;
  3. process subscriptions, reconcile Stripe events, provide paid entitlements, and address billing disputes;
  4. generate an AI briefing only when requested and acknowledged;
  5. measure limited aggregate product use and improve usability;
  6. detect abuse, enforce rate limits, investigate security events, and protect users and the service;
  7. respond to support, correction, legal, and privacy requests;
  8. comply with law, preserve legal claims, enforce agreements, and prevent fraud; and
  9. communicate service, security, policy, and billing notices and, where consent is obtained, optional product communications.

7. Cookies and browser storage

AdvisoryLoom and WordPress may use strictly necessary cookies for authentication, session security, preferences, and account functions. Cloudflare Turnstile may use browser signals or storage to distinguish legitimate requests from abuse. Stripe uses its own cookies and technologies on hosted checkout and customer-portal pages.

AdvisoryLoom uses localStorage and sessionStorage for items such as pseudonymous analytics identifiers, analytics opt-out status, session state, return-after-sign-in routing, and installation state. It uses IndexedDB for the encrypted private vault. A private search term is designed to stay in the browser and be matched against a generic content feed.

Blocking necessary cookies or browser storage may prevent sign-in, the private vault, Turnstile, checkout, or other features from working. AdvisoryLoom does not currently use personal information for third-party targeted advertising.

8. How we disclose information

We may disclose information to:

  1. service providers that host, secure, email, maintain, or support the service;
  2. Stripe for checkout, recurring billing, receipts, fraud prevention, and customer-portal functions;
  3. Cloudflare for Turnstile anti-abuse verification when enabled;
  4. OpenAI or another configured AI provider only for an explicitly requested AI operation;
  5. professional advisers, auditors, insurers, and financing or transaction participants subject to appropriate confidentiality obligations;
  6. government authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate fraud or abuse, or respond to lawful process; and
  7. a successor in connection with a merger, financing, reorganization, sale, or transfer, subject to applicable law.

Draper Security LLC does not sell personal information for money and does not use personal information for third-party targeted advertising as of the effective date.

9. Retention

We retain personal information only as long as reasonably needed for the purposes described above, including to provide an account, maintain security, complete billing and tax records, resolve disputes, and meet legal obligations.

  1. Account data is generally retained while the account is active and for a limited period afterward when needed for security, legal, backup, or accounting purposes.
  2. Product analytics default to a 180-day retention setting; administrators can configure 30, 90, 180, or 365 days, after which scheduled cleanup removes older events.
  3. Short-lived aggregate presence signals expire after approximately five minutes and are designed not to store names, email addresses, IP addresses, user agents, or Stripe identifiers.
  4. Device-local vault data remains until the user clears it, clears browser storage, the browser removes it, or the device or browser profile is lost.
  5. Billing, dispute, security, and legal records may be retained longer when reasonably necessary or required by law.

10. Your choices and rights

  1. Access and export: use the account-data download control and the encrypted device-backup feature.
  2. Correction: update available account settings or contact support.
  3. Deletion: use the account-deletion control. Clear the private vault on each device or browser separately because device-local data may not be visible to the server.
  4. Analytics: use the device-level opt-out; supported Do Not Track and Global Privacy Control signals are respected when enabled.
  5. Email: change available preferences or use the unsubscribe method in optional marketing messages. Essential account, billing, security, and legal notices may still be sent.
  6. AI: do not request a briefing if you do not want the disclosed evidence and optional context transmitted to the configured provider.

Depending on where you live and whether a privacy law applies to Draper Security LLC, you may have rights to confirm processing, access, correct, delete, obtain a portable copy, opt out of certain processing, and appeal a decision. Submit a request to support@advisoryloom.com with the subject “Privacy Request.” We may verify identity before acting. If we deny an applicable request, you may appeal by replying with the subject “Privacy Appeal.” We will not unlawfully discriminate against you for exercising a privacy right.

11. Security

We use administrative, technical, and organizational safeguards intended to protect information, including access controls, secure authentication, rate limiting, anti-abuse verification, encryption in transit, and device-local encryption for designated personalization data. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

12. Children

AdvisoryLoom is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. Paid accounts are intended for adults who can enter a contract. If you believe a child provided personal information, contact support@advisoryloom.com so we can investigate and take appropriate action.

13. International users

AdvisoryLoom is operated from the United States. If you use it from another country, information may be processed in the United States and other locations where service providers operate. Applicable data-protection rights may vary by jurisdiction.

14. Third-party links

AdvisoryLoom links to third-party publishers, vendors, authorities, and service providers. Their privacy practices are governed by their own notices. Review those notices before providing information to them.

15. Changes to this Policy

We may update this Policy as the service or law changes. We will post the revised version with a new effective date and provide additional notice when required or when a change materially affects how personal information is handled.

16. Contact

Draper Security LLC
AdvisoryLoom
2746 Kirby Road
Draper, VA 24324
Email: support@advisoryloom.com