Security Policy
This Security Policy (“Policy”) describes how [Legal Entity Name] (“LoreBook”, “we”, “us”, or “our”) protects the LoreBook writing studio at lorebook.ai and app.lorebook.ai (the “Service”).
This Policy complements our Privacy Policy, which explains what personal data we collect and how we use it. For privacy questions or data requests, contact [email protected].
1. Data protection
We employ security measures appropriate to a private writing studio that stores your stories, Codex, and account settings:
- Encryption in transit. All traffic between your browser and LoreBook is protected with HTTPS/TLS. TLS is terminated at our CDN and security provider (Cloudflare) before traffic reaches our production servers.
- Encryption at rest. When encryption keys are configured in production, we encrypt your BYOK API keys and internal provider keys using AES-256-GCM. Creative content (story prose, chapters, brainstorm chat, Codex entries, and related project data) is encrypted at rest with per-user keys using the same standard.
- Infrastructure. Production systems run on Hetzner infrastructure in Finland (EEA), reachable only through a Cloudflare Tunnel. Encrypted database backups are stored off-site on Cloudflare R2 in the European Union. Our internal auth service is not exposed directly to the public internet.
- Access controls. Access to production servers and databases is limited to essential personnel. Production access uses restricted SSH and the principle of least privilege — team members receive only the access their role requires.
2. Authentication and account security
LoreBook supports sign-in via Google, Facebook, email and password, magic link, or passkeys (WebAuthn). Account credentials are managed in a dedicated authentication service, separate from your creative content database.
- Invite-only access. The Service is currently offered on an invite-only basis. Unapproved accounts cannot access the writing studio.
- Passkeys. You can register passkeys for phishing-resistant sign-in and manage them from your Account page in the app.
- BYOK. If you connect your own AI provider API key, we store it encrypted and use it only to make AI requests on your behalf. When you use BYOK, requests are sent to your chosen provider under that provider’s terms.
- Rate limiting. AI features are rate-limited in the app (30 requests per minute per user). Authentication endpoints are also protected by edge rate limits through Cloudflare.
3. Team practices
Our team is expected to follow security and confidentiality practices appropriate to handling user data. We limit access to personal data and creative content to the minimum needed for each person’s role. When someone leaves the team, their access to production systems is revoked promptly.
4. Incident response
We maintain an incident response process. If we detect or reasonably suspect a breach or compromise affecting personal data, we will investigate, contain the incident, and take steps to prevent recurrence.
Where required by applicable law (including the GDPR), we will notify affected users and relevant supervisory authorities within 72 hours of becoming aware of a personal data breach. If you believe your LoreBook account has been compromised, contact [email protected] promptly.
5. Third parties and subprocessors
We rely on reputable infrastructure and service providers to operate LoreBook. Key subprocessors include:
- Hetzner — server hosting (Finland, EEA).
- Cloudflare — CDN, TLS, tunnel, security, and EU R2 backups.
- Resend — transactional email delivery.
- AI providers — OpenRouter, Requesty, and (when you use BYOK) your chosen provider such as OpenAI or Anthropic.
We require appropriate safeguards from vendors that process data on our behalf, including data processing agreements where applicable. For more detail on subprocessors and international transfers, see Section 8 of our Privacy Policy.
6. Your responsibilities
You are responsible for protecting access to your account:
- Keep your sign-in methods secure. If you use a passkey, protect the device and screen lock that guards it.
- Do not share your account or API keys with others.
- Be cautious of phishing or malware on your device. LoreBook is not responsible for compromises that result from stolen credentials, phishing, or malware outside our systems.
- When using BYOK, review what you send to third-party AI providers and their privacy practices.
7. Continual improvement
We review our security controls periodically and when our architecture, threats, or legal requirements change. As LoreBook grows, we aim to strengthen protections in line with the sensitivity of the data we store and the risks we face.
Appendix A — Technical safeguards
In addition to encryption and access controls, we use technical measures including:
-
Security headers and a Content Security Policy on the web app
(for example,
X-Frame-Options,X-Content-Type-Options, and CSP). - Request body size limits on API endpoints.
- Cloudflare WAF rate limiting on authentication routes to reduce brute-force and abuse attempts.
- CORS restrictions limiting which origins can call our API with authenticated requests.
Appendix B — Data breach notification
Under the GDPR (Articles 33–34), if a personal data breach is likely to result in a risk to individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, including the nature of the breach, categories of data affected, and mitigation steps. Where the breach is likely to result in a high risk to individuals, we will also inform affected users directly.
Under California law, we will provide notice of a security breach involving personal information “as soon as practicable,” as required by applicable statutes.
Appendix C — Encryption details
- API keys and provider secrets — encrypted with AES-256-GCM in production.
- Creative content — encrypted with per-user content encryption keys (AES-256-GCM) in production.
- Account passwords — stored and hashed by our dedicated authentication service using industry-standard password hashing. LoreBook does not store plaintext passwords.
- Backups — database backups may contain encrypted application-layer data. Backups are stored off-site on Cloudflare R2 in the European Union.
Appendix D — Backups and recovery
We run automated SQLite database backups approximately every 30 minutes to Cloudflare R2 off-site storage in the European Union. Backup retention follows a rolling schedule: full snapshots for the first few days, then one backup per day for up to approximately 30 days, after which older backups are deleted.
Recovery from backup is a manual process performed by our team. We do not publish formal Recovery Time Objective (RTO) or Recovery Point Objective (RPO) targets, but our backup frequency is designed to limit data loss to roughly the interval between scheduled backups.
Residual copies in encrypted backups may persist for up to approximately 30 days after account deletion, as described in our Privacy Policy.
Appendix E — Logging and audit records
We maintain operational logs to run and secure the Service:
- HTTP logs — request metadata (method, path, status, latency). Request bodies are not logged.
- LLM logs — metadata for AI requests; creative prompt and response bodies are redacted.
- Erasure compliance log — when you delete your account, we record a hashed account identifier and timestamps (no personal data) as proof of deletion, retained for approximately two years.
These logs support operations, abuse prevention, and compliance. They are not a complete immutable audit trail of every administrative action. For the full data retention schedule (including backups, creative content, and account lifecycle), see Section 8 of our Privacy Policy.
Appendix F — Privacy by design
LoreBook is built as a private writing studio — your projects, Codex, and chats are scoped to your account and are not published to a public community feed. We collect only what we need to operate the Service.
LoreBook does not train machine learning models on your creative content. When you use AI features, your text is sent to third-party AI providers to generate responses; those providers are governed by their own policies.
For significant changes to how we process personal data, we assess privacy impact as appropriate before launch.
Contact
Security questions and incident reports:
[email protected]
Registered office: [Registered Address, Israel]
Related documents: Privacy Policy · Terms of Service · Content Policy