← LoreLynx

Privacy Policy

Last updated: September 2026

What we collect

We collect your email address (for authentication), the display name you choose, and the creative content you save to your projects. If you sign in with Google, Google sends us the email address, name, and profile picture link on your Google account; we use the email and name for your account and never display the picture. We do not collect payment card details: if you buy a paid plan, Stripe handles those, as described under Payments below. We do collect anonymized usage and performance analytics, described in the next section.

Analytics and performance

We use Vercel Analytics and Vercel Speed Insights to understand aggregate usage (page views, referrers, device and browser type) and real-user performance. Both are anonymized and do not track you across sites. Error monitoring via GlitchTip is described in the Error tracking section below.

How we use it

Your data is used solely to provide the LoreLynx service. Syncing your projects across devices and authenticating your account. We do not sell data or run ads. Your creative content is only shared with a third party when you explicitly use AI features, as described below.

Sharing and collaboration

Projects are private to your account unless you share them. If you invite someone to a project by email, they can see that project's content: editors can also change it, readers can only read it. Team members see your display name and the shared project, never your email address or your other projects. You can change a member's role or remove them at any time, and members can leave on their own. Read-only share links show prose and chapter structure only. Publishing to the book feed shares that book with all signed-in readers, under the pen name you choose. If you also publish a World page for a book, only the codex entries you pick are shown, and each entry reveals nothing beyond the chapters you have released. Anything you publish can be read, quoted, and reported by other readers; unpublishing removes it from the feed.

Payments

Paid plans are processed by Stripe. When you subscribe, Stripe collects your card details and billing address on its own checkout page; they never pass through our servers. Stripe shares with us only what we need to run your plan: which plan you bought, whether it is active, and a customer reference. Stripe keeps transaction records for as long as financial regulations require, under its own privacy policy at stripe.com/privacy. Deleting your account ends any active subscription.

AI providers

If you use AI features, your lore and prompts are sent to the AI provider you configured. With a local provider (LM Studio or Ollama), all data stays on your machine. With a cloud provider (OpenAI, Anthropic, OpenRouter, Mistral, or Google Gemini), your request content is sent to that provider and is subject to its privacy policy. Cloud requests are relayed through our servers to the provider you chose; LoreLynx never stores AI request content.

Local storage

LoreLynx stores settings and some project state in your browser's local storage for performance. This data stays on your device. AI API keys (if provided) are encrypted (AES-GCM) and stored in your browser's IndexedDB. When you make a cloud AI request, your key travels with that request so we can relay it to the provider you chose; keys are never stored or logged on our servers.

Data retention & deletion

Deleted projects stay in Recently deleted until you delete them forever. Scene version history keeps the newest 50 versions of each scene; older versions beyond that are pruned after 30 days. You can delete your account at any time from Settings. This permanently removes your projects, published books, uploaded images, and account data from our servers. Local storage data can be cleared from your browser settings at any time.

Error tracking

We use GlitchTip, an error-monitoring service, to learn about crashes and failed requests. When an error occurs, the report may include a stack trace, your browser and operating system version, the path of the page where it happened, and the last few pages and requests before it (paths and status codes only). Reports travel through our own servers to GlitchTip. Before anything leaves your browser we drop request bodies, cookies, auth headers, console output, and anything after a question mark or hash in a URL, so GlitchTip never receives your creative content, API keys, AI prompts, or sign-in tokens. There is no session recording. You can review GlitchTip's privacy policy at glitchtip.com.

Infrastructure

LoreLynx is hosted on Vercel and uses Supabase for database and authentication. Both providers have their own privacy and security practices. Authentication emails are sent via Supabase's email service.

Contact

Questions about your data, or a request to export or delete it? Email support@lorelynx.app, or use Send Feedback in the app's Settings.