Privacy notice
Updated September 8, 2026 · About Steward Cloud
Steward Cloud is the hosted workspace service from LoomX. Contact its operator at wangbinxin001@gmail.com with privacy questions or requests to access or delete your account and workspace data.
Account and sign-in data
We store your verified email address, internal account identifier, workspace memberships and sign-in sessions. Email/password accounts store a password hash, not the original password. Verification links and session identifiers are stored as hashes. Temporary verification and OAuth state records expire and are periodically removed.
Google sign-in requests only OpenID identity and email information. GitHub sign-in requests verified email information and uses your stable GitHub user identifier. These sign-in methods do not request access to your email contents or GitHub repositories. Provider tokens are used during sign-in and are not retained in our database. Connecting cloud providers inside a workspace is a separate action with separate credentials and permissions.
Workspace data and service operation
We store the connections, cloud resource metadata, configuration and activity records needed for the workspace features you choose to use. Cloud-provider credentials are encrypted with a workspace-specific key. Your authorized workspace members can access information according to their roles; running the service also requires operator access to its infrastructure. Separate workspaces have separate database roles, databases and application processes, but share hosting infrastructure.
Account and workspace information is hosted using Alibaba Cloud infrastructure in Singapore. Our email delivery provider processes recipient addresses and verification messages when sending registration emails. Google and GitHub process sign-in requests under their own privacy policies. Network requests necessarily involve connection information such as IP addresses. Essential cookies maintain sign-in and protect OAuth flows.
Retention and requests
Account and workspace records remain stored until removed through the available administration process. Contact the operator to request access or deletion; we may need to verify account ownership before acting. The configured database backups are retained for seven days, so previously backed-up data can remain until those backups expire. Do not submit secrets or passwords in a privacy request.