Privacy Policy
Last updated: February 23, 2026
I collect what I need to make Lorewright work and nothing else. I don't sell your data and I don't track you around the web.
What I collect (and don't)
Your email for login. Your campaign content so the app works (only you can see it). Usage data (token counts, costs) for billing and transparency.
No analytics. No fingerprinting. No tracking scripts. No payment card details — Polar handles that. I do not use your content to train AI models.
Third-party services
| Service | What it does | What it sees |
|---|---|---|
| Supabase | Auth & database | Email, campaign content, usage data |
| OpenRouter | AI models | Campaign context (no personal info) |
| Polar | Payments | Email & payment details |
| Fly.io | Hosting | Server logs |
Storage, retention & your rights
Data lives in Supabase (US), isolated per user with row-level security. Everything's encrypted in transit. Delete your account and it's all wiped within 30 days. You can export your campaigns anytime from Settings. Only cookie is the session token for auth.
For GDPR/CCPA requests or questions, use the contact form. I'll notify you of any changes to this policy by email or in the app.