1. Why and on what basis we process data
The Lorerium operator processes personal information to create accounts, verify Google sign-in, provide globally unique nicknames, protect sessions, record policy acknowledgements, answer support requests, and secure the service.
Processing is based on entering into and performing the service agreement, providing features you request, legitimate security interests, and obligations under applicable law. If a future activity requires separate consent, we will first explain its purpose and data fields and ask for that consent.
2. Information handled by Lorerium Cloud
We process the minimum information below in a D1 database to operate Google sign-in and Lorerium accounts.
We do not request your Google name or profile photo. OAuth access tokens, ID tokens, refresh tokens, and authorization codes are not stored after sign-in verification. The server stores only a SHA-256 hash of a session token, never the session token itself.
- The stable Google account identifier (sub) and verified email address
- The nickname you choose and a case-insensitive uniqueness key
- The Terms and Privacy Policy versions acknowledged and the acknowledgement time
- Session hash, issue time, and expiry time
3. Information kept only on your computer
Chats, character images, wiki content, search indexes, SQLite data, and the app-specific Codex profile stay on your computer by default and are not uploaded to Lorerium Cloud.
You manage local backups and device security. Deleting your cloud account does not automatically delete local data; use the app's data controls or your operating system's app-data removal process to remove it separately.
4. Website and cookies
lorerium.com is a static product site with download links. The Lorerium operator does not add first-party analytics, advertising trackers, or marketing cookies.
Cloudflare, which delivers the site and API, may process standard network request information such as IP address, request time, and user agent in its own infrastructure for delivery and security. Lorerium does not add that information to a user profile or D1 account record.
5. Service providers and separate services
Google provides account sign-in and email verification. Support email is also handled through Google's email service. When you use ChatGPT/Codex features, the necessary inputs and outputs are processed by OpenAI through your separate ChatGPT account; this is separate from your Lorerium Cloud account and Google sign-in.
Cloudflare, Inc. provides Workers, D1, R2, DNS, security, and static asset delivery. Each provider handles information under its own terms and privacy policy.
6. International processing and transfers
Cloudflare, Inc. (United States) may process service requests through global infrastructure, including worldwide edge locations and the United States. Transfers occur through encrypted network connections when you use the site, API, or sign-in. Account identifiers, verified email, nickname, policy acknowledgement, session hash and timestamps, and standard network request information may be processed for delivery, security, and storage.
Google sign-in and support email, and OpenAI's processing of ChatGPT/Codex use, may also rely on each provider's global infrastructure. You can stop future processing by deleting your account or not using the relevant feature, but refusing Cloudflare processing means we cannot provide Lorerium Cloud accounts and online features.
7. Retention and deletion
Active account information is kept until you delete the account or the service ends. Sign-in sessions are valid for 30 days, and expired sessions are removed opportunistically during authentication. Support email is kept only as long as needed to resolve the request and handle related disputes.
Completing in-app account deletion removes identities, email, nickname, policy acknowledgements, and all sessions from active D1 data. Cloudflare D1 Time Travel recovery history may retain pre-deletion data for up to 30 days before it expires from recovery history. If law requires separate retention, only the required information is isolated for the required period.
8. Your rights and how to exercise them
You can change your nickname and delete your Lorerium Cloud account in the app. You may also email support to request access, correction, deletion, restriction of processing, or withdrawal of a policy acknowledgement where applicable.
We may request the minimum information needed to verify identity. We will respond within the period required by applicable law and explain the outcome or any lawful limitation. A legal representative may exercise rights with appropriate evidence of authority.
9. Account deletion and local data
After you complete the confirmation flow in Lorerium account settings, the cloud account and server sessions are disabled and active data is deleted. If you cannot use the app, email support to request deletion.
Deleting a Lorerium account does not sign out of or close your separate ChatGPT/Codex account, and it does not delete stories, images, or wiki content stored on your computer. You remain responsible for managing that local data.
10. Security measures
Lorerium uses encrypted transport, least-privilege service bindings, server-side session hashing, expiry times, exclusion of sensitive authentication values from logs, and separation of access boundaries.
Lorerium sessions and minimal account cache stored by the desktop app are encrypted using operating-system secure storage. No system can guarantee perfect security, but we review safeguards as risks change.
11. Users under 14
You must be at least 14 to create a Lorerium Cloud account. We do not offer a parental-consent flow for younger users.
If we learn that an account belongs to someone under 14, we will suspend its online functions and delete associated cloud personal information. A guardian may request deletion through the support email.
12. Changes to this policy
If purposes, data fields, providers, or user rights change materially, we will provide notice in the website or app before the change takes effect. Editorial changes and contact updates will also be reflected in this page's version and effective date.
13. Privacy contact
Lorerium 운영자 is responsible for privacy and user requests. Send questions, complaints, rights requests, or security reports to kseokhun91@gmail.com.
You may also contact the relevant Korean privacy authorities for remedies concerning an infringement of your rights.