Legal
Privacy Policy
Last updated: 22 July 2026
1. Controller
The controller for personal data processed in connection with Loreon is Synapti AS, org. nr. 934 968 514, Alundamveien 54D, 0957 Oslo, Norway. Contact: support@loreon.ink.
2. What we process
- Account data — your name, email address, and passkey public keys. We never see or store passwords.
- Your content — the manuscripts, story-bible entries, outlines, and related material you create in the Service.
- Usage and billing records — metadata about agent runs (model used, token counts, credit cost), your credit balance, and credit transactions.
- Technical logs — IP address and user-agent data used for security and abuse prevention. Ordinary request logs are short-lived; entries that become part of a staff-action audit record are kept as described in Retention below.
- Staff-action audit records — when our staff act on an account through the staff admin area (for example granting credits or assisting with support), we record who did what, when, and to which account, together with a minimized form of the staff member's IP address and browser. These records are kept for 15 months.
- Payment data — payments are handled by Paddle as merchant of record. We receive transaction identifiers, amounts, and status; we never receive your full payment-card details.
3. Why we process it
- Providing the Service (contract) — operating your account, storing your content, running the agents you invoke, and accounting for credits.
- Billing and bookkeeping (contract and legal obligation) — recording purchases and credit movements.
- Security and abuse prevention (legitimate interests) — protecting the Service and its users.
We do not run advertising, we do not sell personal data, and we use no third-party analytics or tracking on loreon.ink or app.loreon.ink.
4. AI processing
When you direct an agent to work on your material, the relevant content is sent through our infrastructure to our AI provider, Anthropic, to generate the requested output. Under our agreements, content submitted via the API is not used to train their models. We do not use your content to train AI models.
5. Processors and transfers
We use a small set of processors under data-processing agreements:
- Cloudflare — hosting, storage, and network infrastructure.
- Anthropic — AI model inference.
- Paddle — payment processing, as merchant of record.
Where processing takes place outside the EEA, transfers are protected by recognised safeguards such as the EU Standard Contractual Clauses or an adequacy decision (including the EU–US Data Privacy Framework where applicable).
6. Cookies
We use only strictly necessary cookies: the session cookie that keeps you signed in, and — on staff-only admin paths — a staff-access cookie that authenticates our own staff. There are no analytics, advertising, or third-party cookies.
7. Retention
You can delete your account at any time from your account settings. Deletion is immediate: your projects and their contents, your sign-in, passkeys, and preferences are permanently removed, and any unspent credits are forfeited.
- Account data — for as long as your account exists; removed when you delete it.
- Your content — until you delete it or delete your account, after which it is removed from production systems within a reasonable period.
- Billing records — retained as required by Norwegian bookkeeping law (generally five years). After you delete your account we keep these only in de-identified form: the records remain for our bookkeeping obligations but no longer identify you.
- A one-way hash of your email address — kept after account deletion so that registering again with the same email does not receive a second welcome-credit bonus. It is a fraud-prevention measure (a legitimate interest) and cannot be reversed to your email.
- Technical logs — ordinary request logs are short-lived; entries incorporated into a staff-action audit record are kept as described in the next bullet.
- Staff-action audit records — kept for 15 months from the action; the tamper-evident export archives are deleted automatically after at most 461 days.
8. Your rights
Under the GDPR you can request access to, rectification or erasure of your personal data, restriction of processing, data portability, and you can object to processing based on legitimate interests. Write to support@loreon.ink and we will respond without undue delay. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or your local EEA supervisory authority.
9. Security
All traffic is encrypted in transit. Sign-in uses phishing-resistant passkeys — no passwords are stored. Your projects are isolated per tenant, and internal access follows least-privilege principles.
10. Changes
We will post updates to this policy here and give notice of material changes by email or in the app.