Private beta · Invited friends aged 18+
Privacy notice
6 October 2026
On this page
Who runs LORE
Romeo Landry operates LORE privately, without a company. Contact: app.lore@gmx.ch Use this address for support, access, correction, deletion, data-export requests or privacy questions. The current invited testing round is for friends aged 18 or older. LORE does not ask for a date of birth or identity document for this round. The operator is temporarily in New York, United States, and may access service data there for administration, support and security. Administration is planned to continue from Switzerland after his return. This notice will be updated when that changes.
Data and purposes
We process your email address and account credentials through Supabase Auth to create and protect your account. We store your profile name, optional profile photo, Circle memberships and roles, invitations, voice clips, written stories, photos, optional places and dates, comments and reactions to provide the features you use. A name can be a nickname. Optional notification tokens, preferences and delivery status support activity notifications. Operational information such as connection metadata, timestamps, quotas, reports and deletion jobs supports security, moderation and cleanup.
Who can see stories
Shared stories are available to the members of their Circle. The operator and authorised service personnel can technically access service data for administration, support, security or moderation. Circles have access controls; LORE does not provide end-to-end encryption. An active invitation can disclose a limited preview including the Circle name, inviter and expiry before a person signs in. A valid invitation can be used to join inside the app. Share invitation links only with the intended people. Members can copy or save what they can see.
Services, countries and safeguards
Supabase provides authentication, database, media storage and server functions. The configured primary project region is eu-central-2 (Switzerland). This is not a promise that every log, support operation or provider service stays in Switzerland. Supabase Pte. Ltd and its service providers process authentication, database, media and operational information. Primary project storage is Zurich, Switzerland; Supabase also identifies the United States and Singapore for international processing. Its published DPA incorporates Standard Contractual Clauses with Swiss adaptations. Resend (Plus Five Five, Inc., United States) processes the recipient email address, authentication-email content and delivery information for registration and account access, using US storage and US subprocessors including AWS. Its published DPA contains Swiss-adapted Standard Contractual Clauses. Expo (650 Industries, Inc., United States) and Apple process optional push tokens, a generic notification and the Lore identifier used to open the story; photos and recordings are not included in these notification payloads. Expo's policy names the Swiss-US Data Privacy Framework and contractual safeguards. Apple identifies Ireland and the United States for relevant international processing and describes Standard Contractual Clauses for Swiss data. GMX / 1&1 Mail & Media processes support correspondence; GMX describes storage of email traffic in Germany. The new public invitation, email-confirmation and notice pages at uselore.ch are prepared for Infomaniak Network SA, Switzerland. Infomaniak states that hosted customer data stays in its own Swiss infrastructure and publishes a DPA as part of its service terms. During the transition, older invitation and email-confirmation links continue to use OpenAI Sites on Cloudflare. Hosting can process connection information including IP address, time, requested page and device/browser information for delivery and security. Cloudflare describes US and EEA storage and international operations, with Swiss-US Data Privacy Framework and contractual safeguards. The project-specific full hosting country list and contractual coverage still need confirmation; the provider review is not marked complete.
Registration emails and support
Registration and other configured account-access emails are sent through Supabase using Resend SMTP. Resend receives the recipient address, email message (including its authentication link), and delivery metadata. Lore voice recordings and shared photos are not placed in those emails by the LORE app. Support emails sent to app.lore@gmx.ch are received through GMX and can be read by the operator. Send only information necessary for your request; never send your password. Support correspondence is retained as needed to handle the request, related disputes or applicable legal duties.
Local drafts and saved photos
Unshared drafts and retained recordings/photos stay in app storage on your device. Preparing a share can upload draft media privately before the story is saved; uploaded draft files may remain until account or Circle deletion. Local caches, account state and a previous-state recovery copy are stored in the app sandbox. Sessions use iOS Keychain storage through SecureStore. Signing out preserves unshared drafts for your next sign-in on the same device. Save photo copies the selected shared file to your device photo library, with add-only permission requested on iOS. Copies in Apple Photos remain outside LORE and are not erased by account or Circle deletion. Your device and cloud-photo settings govern any further synchronisation.
Optional permissions and notifications
Microphone access is used for recording. Photo access is used for selecting images and saving a selected shared photo. Location is used only when you choose a place; the app does not collect background location. A shared place can contain precise coordinates. iOS maps and address lookup use Apple system services, which can receive map areas, search/address information and optional location. Push notifications, if enabled, use Expo and Apple. The notification contains a generic activity message and a Lore identifier, rather than story text, photos or recordings. You can decline or revoke these permissions in device Settings.
Retention and deletion
Account and shared-content data is retained while the account or content exists. In your profile, account deletion is confirmed with your password. It removes the account, profile, authored stories, comments, reactions, uploads and notification registration. Contributions attached to a deleted authored story are removed with it; other members' independent content remains. Media reused in another story is removed too. Circles with no other member are deleted. A Circle admin can delete the Circle and its shared content for every member. Cleanup retries failed file deletions and displays a pending state while work remains. Local account data is removed on the initiating device; other devices remove it when they next connect and verify the session. Supabase's Free plan publishes one day of accessible API/database logs and one hour of accessible Auth audit logs. These dashboard access windows are not a guarantee that all internal logs or recovery copies are erased within those periods. Resend publishes 30 days for email and log data and seven days for backups. Expo states that notification payloads are deleted after forwarding to Apple, while push tokens remain in its service; its general privacy policy uses purpose-based retention. Infomaniak publishes at least seven days of web access/error log retention; this is a minimum, not a verified maximum for this Starter account. Apple and the legacy website hosting providers use their own retention criteria. Exact project-specific website-log retention and some provider-internal recovery periods have not been confirmed. Account deletion does not remotely erase downloaded files, screenshots, saved photos or independent recipient copies. It also does not automatically remove separate support emails or every provider's security record.
Tracking and website visits
The LORE app code has no advertising SDK, advertising identifier use, cross-app tracking or analytics integration. The invitation, confirmation and notice pages contain no analytics integration or cookie-setting code. This statement concerns the LORE code; hosting providers and the operating system can process security, delivery or diagnostic information under their own terms and settings. The invitation page sends its invitation token to Supabase to retrieve the limited preview. The email-confirmation page reads the confirmation result locally and removes the callback fragment/query from the address bar; its script does not store or forward the login token. This does not guarantee that no network or browser system retains connection information.
Your rights
Contact app.lore@gmx.ch to request information about your personal data and its recipients, correction, deletion or, where applicable, a portable copy. We may need to verify your identity and protect other members' information when answering. Swiss data protection law is the basis of this notice; mandatory protections applicable to a particular user remain in force. You may contact the Swiss Federal Data Protection and Information Commissioner (EDÖB).
Version and current review
Notice dated 2026-10-06. This published preparation draft describes the current implementation and information checked so far. The project-specific hosting country list, contractual coverage and some internal retention details are still under review. It is not a declaration that external distribution is ready. We will update the notice when the operator's access location, providers or processing changes.
Provider information
Provider statements are sources for this notice, not proof that every project-specific setting or contract has been verified.
- Supabase DPA
- Supabase international processing
- Supabase subprocessors
- Supabase log access windows
- Resend retention & contracts
- Resend DPA
- Resend subprocessors
- Expo privacy
- Expo notification handling
- Apple privacy
- Apple Maps
- GMX email storage
- Infomaniak hosting commitments
- Infomaniak DPA
- Infomaniak web log retention
- Legacy Cloudflare hosting privacy
- OpenAI privacy
- Swiss privacy information duties