Privacy Policy

This Privacy Policy (“Policy”) explains how [Legal Entity Name] (“LoreBook”, “we”, “us”, or “our”) collects, uses, stores, and shares personal data when you use LoreBook at lorebook.ai and app.lorebook.ai (the “Service”).

This Policy works together with our Terms of Service. Capitalized terms not defined here have the meanings in the Terms.

1. Scope

This Policy applies to personal data LoreBook collects in providing the Service. It does not cover data collected independently by third-party services you connect to LoreBook (for example AI model providers or social login providers), which are governed by their own privacy policies. LoreBook does not currently offer separate enterprise or business-to-business deployments; if that changes, a separate notice may apply to those customers.

LoreBook is operated from Israel. This Policy is written to meet GDPR and UK GDPR transparency requirements for users in the European Economic Area and United Kingdom, as well as other applicable laws. GDPR and UK GDPR apply when we process personal data of individuals in the EEA or UK (for example customers, waitlist signups, or visitors), regardless of where our company is registered.

2. Information we collect

Account information

When you sign in or register, we receive your email address and basic profile information from your login method (for example Google, Facebook, email and password, magic link, or passkey). Your account is identified by email. If you register a passkey, we store credential metadata needed to authenticate you.

Creative content

We store the content you create in the Service, including story prose, chapters, brainstorm chat messages, Codex entries, timeline events, project settings, and related metadata. This content is scoped to your account and is not published as a public feed or community gallery.

Settings and API keys

If you connect your own AI provider API key (“BYOK”), we store it encrypted to make AI requests on your behalf. We also store preferences such as model, provider, and assistant personality.

Usage and technical data

We log information needed to operate and secure the Service, including:

  • Token usage per AI feature (for included-AI allowances).
  • HTTP request metadata (method, path, status, latency).
  • LLM request metadata for support and debugging; creative prompt and response bodies are redacted in logs where configured.
  • Support messages you send through in-app Help chat.
  • Device and browser technical data sent with requests (for example IP address and user agent) via our hosting and security providers.

Payment information

You may buy optional LoreBook credit packs through our payment partner Paddle (merchant of record). Paddle collects and processes payment card and billing details on checkout; LoreBook does not store your full card number on our servers. We receive purchase confirmations (for example transaction identifiers and the email you use at checkout) so we can add credits to your account. Credits are an internal currency with no cash value and are not refundable except where required by law or stated at purchase.

3. How we use information

We use personal data to:

  • Provide, maintain, and improve the Service.
  • Authenticate you and enforce invite access, rate limits, and account status.
  • Process AI requests (including sending relevant project context to AI providers to generate outputs).
  • Respond to support requests and send transactional emails (for example invitations, sign-in links, password resets, and support replies).
  • Monitor abuse, secure the Service, and comply with law.

We may aggregate and de-identify data for analytics and service improvement. We do not sell your personal data.

4. Legal basis (GDPR / UK GDPR)

If you are in the European Economic Area or United Kingdom, we process personal data on the following bases:

  • Contract: to provide the Service you request (account, storage of your creative work, AI features, support).
  • Legitimate interests: to operate, secure, and improve the Service, prevent fraud and abuse, and enforce our Terms — balanced against your rights.
  • Consent: where required by law (for example, if we introduce non-essential cookies or optional marketing communications in the future).
  • Legal obligation: where we must retain or disclose data to comply with applicable law.

5. How we share information

We do not sell your personal information and do not share it with advertisers. We share information only as follows:

  • AI providers: When you use AI features, we transmit prompts and relevant project context to providers such as OpenAI, Anthropic, OpenRouter, or Requesty (directly for BYOK, or via our gateways for included AI), subject to those providers’ policies.
  • Login providers: Google and Facebook (if you choose those sign-in methods) process authentication according to their policies.
  • Infrastructure and communications: Service providers that host, secure, back up, or deliver the Service — including Hetzner (hosting), Cloudflare (CDN and security), Resend (email delivery), and Paddle (credit-pack checkout and payment processing) — process data on our behalf under contractual obligations.
  • Legal and safety: We may disclose information if required by law, to protect rights and safety, or to respond to valid legal process. We anonymize or minimize data where possible.

6. Where we store data and international transfers

Primary customer data is stored in EEA data centers in Finland (Hetzner). Encrypted database backups are stored in Cloudflare R2 in the European Union.

LoreBook is operated from Israel. Authorized personnel may access data from Israel to provide support, maintain infrastructure, and operate the Service. When you use AI features, your inputs may be processed in the United States or other countries where our AI and CDN providers operate.

Where personal data is transferred outside the EEA or United Kingdom, we rely on appropriate safeguards — including Israel’s adequacy recognition where applicable and Standard Contractual Clauses where required — to protect your data.

7. Cookies and similar technologies

LoreBook uses strictly necessary cookies (including from Cloudflare) and browser storage for sign-in and preferences. We do not use analytics or marketing cookies today. For full details, including a table of cookies and storage keys, see our Cookie Policy.

8. Retention

General rule

We keep your data only as long as needed to provide the Service, meet legal obligations, or resolve disputes. We do not archive or sell deleted creative content.

Retention schedule

The table below summarizes how long we retain major categories of data. After account deletion, see Section 11 for what is removed from live systems, what may persist, and backup timing.

Data type Retention period
Account and profile information While your account is active. If you have not signed in for 12 consecutive months, we may delete your account and associated data (dormant purge). Operator admin accounts are exempt.
Creative content (story prose, chapters, Codex, brainstorm chat, timeline, project settings) While your account is active; removed when you delete your account, when an administrator purges your creative data, or when a dormant account is deleted.
Encrypted API keys and preferences Same as account and profile information.
AI data stored in LoreBook Stored with your creative content. LoreBook does not use your content to train generalized AI models (see Section 12). When you use AI features, data sent to third-party providers is governed by their policies.
Token-usage records May persist after account deletion for cost tracking and abuse prevention.
Operational logs (HTTP metadata, redacted LLM logs) Rolling retention on production hosts (typically a few days of rotated log files). Per-user debug logs may survive account deletion until an administrator purges them.
Encrypted database backups (Cloudflare R2, EU) Approximately 30 days on a rolling schedule (30-minute snapshots for the first 3 days, then one snapshot per day through day 30).
Erasure compliance log Hashed account identifier and timestamps only (no personal data), approximately two years.
Authentication credentials (separate auth database) Sign-in sessions end immediately on account deletion; credential rows may persist until our backup cycle completes.
Support messages (in-app Help chat) While your account is active; deleted when your account is deleted.
Invites and waitlist records Until removed, approved, or your account is deleted.
Cookies and browser local storage Auth token until sign-out or account deletion; theme and language until you clear site data; Cloudflare security cookies as needed for the Service to function.
Transactional email records Retained as needed for delivery, troubleshooting, and legal compliance.
Payment data Card and billing details are processed by Paddle; we retain purchase records (transaction references and credit grants) in our account ledger for as long as your account exists, plus operational logs as described above.
Marketing data Not collected today.

User controls

You may delete your data at any time — see Section 11 (Delete account, waitlist Remove my email, or email [email protected]). Administrators may purge creative data separately from deleting an account. See our Terms for account lifecycle details.

Deletion assurance

When you delete your account (or when a dormant account is removed), we delete matching records from our live database promptly — we do not rely on long-lived “deleted” flags to hide data from the Service. Residual copies may remain briefly in encrypted backups (up to approximately 30 days) and in operational or token-usage records as described above. See Section 11 for the full deletion workflow.

Legal holds

If required by subpoena, investigation, or applicable law, certain data (for example login records or transaction logs) may be kept longer, but only for the minimum period necessary, isolated from ordinary Service use, and protected consistent with our Security Policy.

Anonymization

For some analytics and service improvement, we use aggregated or de-identified data that cannot reasonably be traced back to you. These datasets may be retained for trend analysis.

Policy updates and compliance review

We update retention schedules as needed for new features or legal requirements and notify users through this Policy (see Section 15). Retention schedules are reviewed periodically (at least annually).

9. Security

We protect your data using TLS in transit, encryption of API keys and creative content at rest (when encryption keys are configured in production), access controls on production systems, rate limiting, and redacted LLM logs.

For full details, see our Security Policy.

No method of transmission or storage is completely secure. If a data breach affecting your personal data occurs, we will notify affected users and relevant authorities within 72 hours where required by applicable law.

10. Your rights

Depending on where you live, you may have rights to access, correct, or delete your data; restrict or object to processing; receive a portable copy of your data; and withdraw consent where processing is based on consent.

You can exercise these rights by contacting us at [email protected], or by using in-app deletion: Delete account on the Account page in the app, or Remove my email while on the waitlist. We will respond within the timeframe required by applicable law.

If you are in the European Economic Area or United Kingdom, you may lodge a complaint with your local supervisory authority (for example the ICO in the UK or CNIL in France) if you are unsatisfied with our response.

If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information we collect and the right to request deletion. We do not sell or share personal information for cross-context behavioral advertising. Contact [email protected] to exercise these rights.

11. Account deletion

Your right to delete

You may delete your account and personal data at any time. To delete:

  • Open Account in the app and choose Delete account, or
  • While on the waitlist, choose Remove my email, or
  • Email [email protected] from the address on your account.

Dormant accounts

If you have not signed in for 12 consecutive months, we may automatically delete your account and associated personal data using the same process described below (including erasure logging and confirmation email). Signing in before that period resets the clock. Operator admin accounts are exempt. See Section 8 for the full retention schedule.

What happens when you delete

When you request deletion, we follow this process:

  1. We verify your identity (sign-in for in-app requests, or email verification for written requests).
  2. If no legal hold applies (for example, an active fraud investigation), we remove your data from our live systems promptly — not on a delayed schedule.
  3. We remove your profile, creative content (story prose, chapters, brainstorm chat, Codex entries, timeline events), project settings, encrypted API keys, support messages, and invite record from our primary database. Active sign-in sessions are ended.
  4. We send a confirmation email when deletion from live systems is complete.
  5. We record a compliance entry in an erasure log (a hashed account identifier and timestamps only — no personal data) as proof of deletion.
  6. Residual copies in encrypted database backups are purged on our rolling backup schedule (up to approximately 30 days; see Backups below).

Consequences

Deleted accounts lose all access to the Service. You cannot sign in or recover your projects, chapters, or Codex after deletion. Your content is not published to others through LoreBook; deletion ensures it is no longer available to you or through your account.

What may remain

We may retain the following even after account deletion:

  • Token-usage records and operational logs (including redacted LLM debug logs) for cost tracking, abuse prevention, and security — as described in Section 8.
  • Encrypted backup snapshots for up to approximately 30 days before they are deleted per our backup schedule.
  • Anonymized or aggregated data that cannot reasonably be traced back to you.
  • Records required by law (for example, during litigation, tax, or fraud investigation) for a limited time, isolated from ordinary Service use.
  • Erasure compliance log entries (hashed identifiers and timestamps only) for up to two years, then purged.

Sign-in credentials (for example passkeys or email-password records) may persist in our separate authentication database until removed through our backup cycle or a follow-up erasure step. Sessions are ended immediately on deletion.

If a legal hold applies, we retain the minimum data necessary until the hold ends, without using it for ordinary Service operations.

Backups

Database backups are encrypted and stored in Cloudflare R2 in the European Union. Restoration requires restricted access. We take backups every 30 minutes and retain them on a rolling schedule: all 30-minute snapshots for the first 3 days, then one snapshot per day through day 30, after which backups are deleted. After you delete your account, we do not restore your data from backups for ordinary operations; remaining copies expire per this schedule.

Third-party services

When you used AI features, your prompts and project context may have been transmitted to AI providers (OpenAI, Anthropic, OpenRouter, Requesty, or your own provider under BYOK). Those providers handle data under their own policies. LoreBook does not train generalized models on your content (see Section 12). We use infrastructure providers (Hetzner hosting, Cloudflare CDN and backups) and Resend for email delivery; we instruct subprocessors to delete or stop processing your data when we delete your account, subject to their retention rules.

Cross-border requests

Users in the European Economic Area, United Kingdom, California, and elsewhere may use the same in-app deletion options or contact [email protected]. If we cannot verify your identity or match your request to an account, we will explain why and let you resubmit.

If deletion seems incomplete

If you believe your data was not deleted properly, contact [email protected].

12. AI features and model training

We do not use your Inputs or Outputs to train generalized AI models for LoreBook. When you use AI features, your inputs and relevant project context are sent to third-party model providers (or your own provider when using BYOK) solely to generate outputs for you, subject to those providers’ policies. LoreBook does not currently offer an opt-in setting for model training because we do not train on your content.

13. Automated decisions

We do not perform high-stakes automated decision-making about you (such as decisions with legal or similarly significant effects). We may use automated checks for fraud prevention, abuse detection, and rate limiting. These affect access to features but do not produce legal or similarly significant outcomes about you.

14. Children

The Service is not directed to children under 13 (United States) or 16 (EEA/UK). We do not knowingly collect personal information from children below the applicable minimum age. If we learn that we have collected such information without appropriate consent, we will delete the account and associated data promptly. Parents or guardians who believe a child has provided us data may contact [email protected].

15. Changes

We may update this Policy from time to time. We will post the current version at lorebook.ai/privacy and update the “Last updated” date. Material changes may be communicated by email or in the app before they take effect where required by law.

16. Contact

Privacy questions and requests: [email protected]
Registered office: [Registered Address, Israel]