Security
This page describes how ScriptLoom is built to protect your scripts, session notes and treatment plans. It is maintained by Jura.
Who operates this app
ScriptLoom is operated by Joe Mickleburgh t/a Jura. For security questions, email trust@jura.network.
Account-only access
The library, courses and every script inside them are only available after you sign in. There is no public or anonymous view of any script, course, note or homework item. Every data request is checked against your authenticated session.
No client or patient data
ScriptLoom is not designed to hold information about your clients or patients. We do not collect, store or process client names, contact details, dates of birth, medical records, case notes or any other identifying information about the people you work with.
The only data we store is your sign-in identity (the email and provider name from Google or Apple) and the content you freely choose to create: your scripts, session notes, homework, courses and personal settings.
Row-level isolation
Each script, course and course step belongs to a single account. The database uses Row Level Security so that a query can only return rows owned by the currently signed-in user. Even if two users are on the app at the same time, they cannot read each other's content.
Where data is stored and transmitted
ScriptLoom runs on Lovable Cloud infrastructure. Data is stored in a managed backend database and transmitted between your browser and the service over HTTPS.
We do not run our own servers or self-host the database. Infrastructure maintenance, patching and availability are handled by the Lovable Cloud platform.
Payments
Supporter memberships and one-off supporter contributions are processed by Paddle, our merchant of record. Card and bank details are entered on Paddle's secure checkout and are never sent to or stored by ScriptLoom.
Payment events (such as a membership starting, renewing or being cancelled) reach the app through signed webhooks. Every event's signature is verified before anything is recorded, and the only data stored is your membership status and billing period dates.
AI-generated summaries
The only AI feature is the summary button in the script editor. When you press it, the script title and body are sent to an AI service through the Lovable AI Gateway, which returns a short one-line summary. The request is tied to your account but is not used to train models or retained for model improvement.
Nothing is sent unless you press the button, and the summary is only stored if you save the script. You can edit or clear it at any time.
Data deletion
Your scripts, courses, sessions, notes and homework are kept until you delete your account. You can delete individual scripts and courses from the library and course planner at any time.
To request deletion of all account data, email trust@jura.network.
Report a concern
If you notice unexpected access, a bug that exposes data, or anything else that affects the security of your account, contact us at trust@jura.network.
We will investigate and respond as quickly as possible. We do not offer bug bounties, but we treat every report seriously.