102 Total
24 High severity
59 Medium severity
19 Low severity

Key Facts

When does Atlassian remain liable under the EU-U.S. DPF Principles?
Atlassian remains liable under the EU-U.S. DPF Principles if its agent processes personal information in a manner inconsistent with those Principles, unless Atlassian proves it is not responsible for the event giving rise to damage.
Are third-party service policies and procedures controlled by Loom?
Loom states that third-party service policies and procedures are not controlled by Loom, and that its privacy policy does not cover how third-party services use your information.
Is Loom responsible for the privacy or security practices of its customers?
Loom states it is not responsible for the privacy or security practices of its customers, which may differ from those described in Loom's privacy policy.
May Loom disclose information about users to government authorities or law enforcement?
Loom may disclose information about users to government authorities, law enforcement, or industry peers if Loom believes sharing is reasonably necessary to comply with any applicable law, regulation, legal process, or enforceable governmental request.
When may Loom disclose information?
Loom may disclose information about users to government authorities, law enforcement, or industry peers if Loom believes sharing is reasonably necessary to comply with any applicable law, regulation, legal process, or enforceable governmental request.
Where does Loom collect and process personal information?
Loom collects and processes personal information about individuals in the EEA or UK only where it has legal bases for doing so under applicable data protection laws.
What account information does Loom make accessible to an organization's administrator?
Loom makes certain account information—including name, profile picture, contact info, content, and past account use—accessible to an organization's administrator when a user registers or accesses the Services using an email address with a domain owned by that employer or organization.
When does Loom make account information accessible?
Loom makes certain account information—including name, profile picture, contact info, content, and past account use—accessible to an organization's administrator when a user registers or accesses the Services using an email address with a domain owned by that employer or organization.
What age is Loom's Services not intended for?
Loom's Services are not intended for use by anyone under the age of 16, and Loom will take steps to delete personal information if it becomes aware a child under 16 has provided it.
What will Loom do if it becomes aware a child under 16 has provided personal information?
Loom's Services are not intended for use by anyone under the age of 16, and Loom will take steps to delete personal information if it becomes aware a child under 16 has provided it.
Stay ahead of the changes
Track Loom and get the diff the day its terms change.
Summary

Loom's Privacy Policy explains what information Loom collects about you, how it uses that information—including to train AI models and show you targeted ads—and when it may share it with others, such as law enforcement. If you use Loom with a work email address, your employer's administrator can access your account information, content, and usage history. Loom is not responsible for how its customers or connected third-party services handle your data, so those interactions fall outside the protections this policy provides.

Analysis

Loom's Privacy Policy establishes how Loom collects, uses, shares, and retains personal information in connection with its Services. It sets out behavioral and account data collection practices, including use of user information for AI and machine learning model development, training, and fine-tuning. The policy defines data-sharing conditions—including disclosures to law enforcement based on Loom's own reasonable-necessity determination—and delineates the boundaries of Loom's responsibility, expressly excluding liability for the privacy and security practices of its customers and connected third-party services. EEA and UK users are afforded a legal-basis requirement for all collection and processing, and users in eligible jurisdictions may opt out of targeted advertising via a 'Manage Preferences' link. The policy further establishes that when a user registers with an employer-owned email domain, certain account information becomes accessible to that organization's administrator.

What this means for you

Loom automatically collects detailed records of how you use its Services and applies that data to targeted advertising and AI model training, both of which are secondary uses beyond basic service delivery. If you sign up or log in with an employer-owned email domain, your name, profile picture, contact information, content, and past usage become accessible to your organization's administrator—a consequence that may not be obvious at sign-up. Loom's policy does not extend to how its customers or connected third-party services handle your data, so those parties' practices are governed solely by their own policies. Where local law applies, you can opt out of targeted advertising by clicking the 'Manage Preferences' link and following the instructions Loom provides.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

102 provisions
12 featured
17 clause types
24 high severity
Restricted or Prohibited Content/Industries 1 1 high
Targeting and Audience Restrictions 1 1 high
Disclosure and Transparency Requirements 1
Platform Discretion 1
Stay ahead of the changes

Monitoring

Loom has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Atlassian Liable for Agent Onward Transfer Violations and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:18 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000565
Version ID CA-V-001257
SHA-256 065111cefdcb43fb98af94e05eac5a4f3ea251c3de569497bcc23b06b5e2755c
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans