LorebraidInteractive story companion
Terms Return to Lorebraid

Your data

Privacy
Policy

How Lorebraid handles the identity, story, memory, billing, and visual data that keeps your worlds persistent.

Effective July 31, 2026
Contents
  1. Scope and controller
  2. Information collected
  3. How information is used
  4. AI processing
  5. Providers and disclosures
  6. Administrative Content Access
  7. Cookies and local storage
  8. Merge, export, and shutdown
  9. Retention, deletion, and recovery
  10. Security and transfers
  11. Your rights
  12. Adult service
  13. Changes and contact

Plain-language summary: Lorebraid stores the account, story, allowance, and billing information needed to preserve your progress and purchases. Bounded story context is sent to OpenAI to generate and review text or images. Stripe controls payment transactions. Purpose-authorized Lorebraid administrators can access private content when necessary, and every such access is privately audited.

Section 01

Scope and controller

This Privacy Policy applies to the Lorebraid reader platform at lorebraid.com, including account authentication, adult eligibility, Journeys and story saves, story metadata and memories, generated media, generation allowance, billing operations, account support, and private exports.

Lorebraid, operated by the owner of lorebraid.com, is the controller of personal information handled for the service except where a provider such as Stripe acts in its own disclosed role. “Lorebraid,” “we,” “us,” and “our” refer to that service operator. Questions and privacy requests may be sent to [email protected].

Section 02

Information we collect

Account and authentication information

  • Name, email address, verification state, profile image, immutable account identifier, account role, and account status.
  • Password or Google sign-in method, provider-specific identity, encrypted OAuth tokens where needed, password hashes handled by the authentication system, session identifiers, and security timestamps.
  • Adult-attestation policy version, wording version, and confirmation time. Lorebraid does not collect your date of birth or request an identity document by default.
  • Account Merge authentication results and timestamps, preview and confirmation records, selected surviving account and renewal, identity attachments, and merge audit state.

Story and creative content

  • Your prompts, Storyteller responses, Suggested Moves, story transcripts, authored story material, scene information, saved progress, Journeys, and Book Playthroughs.
  • Backend story state such as foundations, memories, goals, relationships, skills, inventory, schedule, scene headers, progression, disputed facts, and provenance-linked correction history.
  • Character descriptions and portraits, private reference images, generated images, image prompts, quality and safety review results, variants, and gallery associations.
  • Adult-content eligibility decisions, Story intensity preferences, accepted Sensitive Content Contracts, and related safety decisions. Private mature content is processed like other account-scoped Story content and is not made public merely because it is stored.

Allowance, payment, and account-lifecycle information

  • Subscription Quota, grants, Merge Allowance, Top-up Lots, reservations, Usage Charges, expiry, consumption, adjustment, refund, dispute, freeze, and Settlement Deficit history.
  • Versioned Plan Offer, immutable Billing Identity, Stripe Checkout, customer, Subscription, invoice, PaymentIntent, charge, refund, and dispute identifiers and statuses; original amount and currency; paid periods; renewal and payment-attention state; and provider event evidence.
  • Account Deletion previews, acknowledgement, recovery deadline, cancellation and session-revocation progress, verified recovery, expiry, and retained redacted audit evidence.
  • Service Shutdown notices, renewal cancellation, refund reconciliation, private export, delivery status, and related incident records.

Lorebraid does not receive or store full payment-card details. Stripe collects payment credentials and may associate a Link identity under its own policies.

Technical and communication information

  • IP address, request time, browser and device information, referring information, error details, provider-call usage and latency, security events, and access logs produced by Lorebraid and its infrastructure providers.
  • Essential browser-held state, including theme and interface preferences, in-progress character-creation drafts, stable generation request identifiers, checkout return state, and private story actions paused for insufficient generation allowance.
  • Messages sent to Lorebraid and transactional-email delivery information.

We receive this information from you, connected identity providers, Stripe, the application and its infrastructure, and authorized administrators acting under an allowed purpose.

Section 03

How information is used

We use personal information to:

  • Create and secure accounts, authenticate sign-ins, confirm adult eligibility, prevent unauthorized identity attachment, and perform explicit Account Merge.
  • Load, continue, synchronize, export, preserve, and recover Journeys, private media, story state, and galleries.
  • Generate contextual Story text and images, review generation safety and quality, maintain continuity, enforce adult-content contracts, and display progression.
  • Quote, reserve, settle, and explain generation allowance; present Plan Offers; preserve checkout state; and reconcile authoritative payments, renewals, refunds, disputes, and Service Shutdown obligations.
  • Deliver verification, recovery, password, billing, safety, shutdown, and other service-related messages.
  • Provide reader support, diagnose quality and cost incidents, prevent abuse and fraud, protect readers and infrastructure, maintain audits, and comply with law.

Where applicable, these uses rely on performance of our agreement with you, legitimate interests in operating and securing Lorebraid, consent for an optional connection, and legal obligations. Lorebraid does not sell personal information, share it for cross-context behavioral advertising, or use Google account information for advertising.

Section 04

AI processing

To continue a Story, Lorebraid sends your current action and a bounded selection of relevant Story context to OpenAI. That context may include recent conversation, Story foundations, active goals, selected memories, character relationships, status, safety constraints, and other continuity information. The complete long-term archive is not intentionally sent with every request.

For image generation and review, Lorebraid may send the requested scene description, visual canon, character descriptions, relevant reference portraits, and safety constraints. Generated text, images, prompts, review outcomes, provider usage, and latency may be saved to the account’s Story, gallery, and private Usage Ledger.

Lorebraid does not intentionally include your account email, adult-attestation evidence, payment identifiers, or Google identity in an AI prompt unless you place that information in Story content yourself. Lorebraid does not use your content to train a public Lorebraid model. OpenAI processes submitted material under its applicable service terms, privacy commitments, and Lorebraid account settings.

Section 05

Providers and disclosures

We disclose information only as needed to operate, protect, transact for, or lawfully support the service. Current provider categories include:

CloudflareSecure traffic delivery, proxying, abuse protection, and edge request metadata.
VercelApplication hosting, request delivery, operational logs, and private Blob storage for account-scoped saves and generated media.
NeonPostgreSQL storage for accounts, sessions, allowance, billing state, administrator audits, and lifecycle records.
OpenAIAI text generation, image generation, and generated-content review using the prompts and bounded context described above.
Stripe Managed Payments and LinkMerchant-of-record checkout, payment credentials, payment authorization, tax, receipts, Subscription renewal, refunds, disputes, and transaction support. Stripe is the authoritative source for transaction outcomes and handles information under its own applicable privacy terms.
ResendDelivery of verification, recovery, password, billing, safety, and service-related transactional emails. Administrator alerts use identifiers and secure review links where practical instead of private Story prose or media.
GoogleOptional identity authentication and the profile information you authorize Google to return.

A Link payer email may differ from the Lorebraid account email and is not authority to merge accounts, change ownership, or reroute a purchase. Lorebraid accepts only verified Stripe events as payment authority.

We may also disclose information to professional advisers under confidentiality, during a legitimate business reorganization, to protect rights or safety, or when reasonably required by law, court order, or valid legal process. Private Story content is not disclosed publicly unless you deliberately publish or share it through a feature that says it will do so.

Section 06

Administrative Content Access

Authorized Lorebraid administrators can access identity records, connected providers, Story progress and transcripts, backend state and memories, generation prompts, private and mature generated images, allowance, Billing Identity, charge and dispute records, provider usage, and audit history only when reasonably necessary for service operation, safety review, reader support, abuse investigation, legal compliance, or quality and cost incident diagnosis.

Administrative Content Access is restricted to verified privileged accounts, requires a recent authenticated session, and requires selection of an allowed purpose before private content is returned or allowance is adjusted. The private audit records the actual administrator identity, purpose, resource scope, action, time, and support context where required. Those actual-identity audit entries remain private for security and accountability.

Reader-facing history and notifications attribute an administrative action only to Admin, not to the administrator’s personal name or email. Allowance adjustments are append-only; reductions can use only currently available value and produce a durable notice. Mature images that already comply with Lorebraid rules render normally in the secured administrator console and are not made public by that access. Administrative access is not used for advertising or to publish a private Story.

Section 07

Cookies and local storage

Lorebraid uses essential authentication cookies to maintain secure sessions and prevent request forgery. Browser storage may remember theme and interface preferences, in-progress character-creation drafts, owner-scoped generation requests, checkout return state, and the exact text and Story, Playthrough, and Turn identifiers of an action paused for insufficient allowance.

A paused action is kept so reload or checkout return can restore it without generating or charging automatically. It is removed after that action succeeds or you replace and cancel it. Browser-held information remains readable to other people or software with access to the same browser profile, so use a private device or profile for private Story content.

Lorebraid does not currently operate third-party advertising cookies or behavioral advertising trackers. Google, Stripe, and Link may use their own cookies when you interact with their domains or embedded services; their policies govern that processing.

Section 08

Account Merge, export, and Service Shutdown

An Account Merge processes recent authentication proofs for both accounts, a digest-bound consequence preview, explicit selections, financial-lot provenance, identity attachments, and an irreversible audit record. Email equality alone is not merge authority. The surviving account keeps all Journeys while billing and allowance records retain the identities needed to prevent duplicate fulfillment and support refunds, disputes, security, and audit.

An authenticated private account export may include account information, Journeys, Story content and state, generated-media references, allowance balances and history, and Reader-safe billing state. It excludes secrets, other readers’ data, private administrator identity, and internal provider credentials.

During Service Shutdown, Lorebraid processes notice delivery, renewal cancellation, original-value paid refunds, and export availability until the published deadlines. Related transaction, delivery, incident, and audit evidence may be retained as described below even after Story content is deleted.

Section 09

Retention, Account Deletion, and recovery

While an account is active, Lorebraid generally keeps its identity, sessions, Journeys, Story saves, backend state, conversations, private media, allowance, and billing state so the service can continue across sessions. Provider usage, security events, email delivery, billing evidence, and administrator audits are kept as reasonably needed for operations, accountability, fraud prevention, disputes, security, and legal obligations.

Account Deletion is requested through Account settings after a complete consequence preview, recent authentication, acknowledgement, and exact confirmation. Lorebraid immediately starts renewal cancellation and session revocation and freezes the account, content, and balances for a 30-day recovery window. A verified recovery link used before the deadline restores Journeys, content, and remaining balances, but never restarts the cancelled Subscription.

After the 30-day recovery deadline, Lorebraid permanently removes account content, private media, credentials, and remaining allowance from active service storage. It retains only limited redacted evidence required for billing, security, fraud prevention, disputes, legal compliance, and deletion audit. Protected infrastructure backups and cached copies may expire on their normal schedules and are not restored to active use except for disaster recovery or legal necessity.

Section 10

Security and international transfers

Lorebraid uses account-scoped private storage, encrypted transport, encrypted OAuth-token storage, hashed passwords, origin checks, same-origin private media, non-public administrator routes, recent-session requirements for sensitive administration, rate limiting, immutable billing identities, idempotent provider events, and audit logging. No online service can guarantee absolute security. Protect your credentials and report suspected compromise promptly.

Providers may process information in the United States, European Economic Area, or other countries where they or their subprocessors operate. Where required, transfers rely on provider contractual safeguards, adequacy mechanisms, or other lawful transfer tools.

Section 11

Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information, withdraw consent, and appeal or complain about how a request is handled. EEA and UK users may complain to their local data-protection supervisory authority.

Use the authenticated export and Account Deletion controls where available, or contact [email protected]. We may request reasonable verification and may decline or limit a request where law permits, including to protect another person, security, transaction integrity, or records that must be retained. Lorebraid will not discriminate against you for exercising applicable privacy rights.

Section 12

Adult service

Lorebraid is intended for adults and is not directed to children. Authentication and these public legal pages remain available before eligibility is confirmed, but a person who is not at least 18 years old, or the age of legal majority where they live if higher, cannot create a character, enter or resume a Story, generate content, or purchase a product.

Lorebraid may process lawful mature fictional Story content under the account-scoped and Administrative Content Access rules above. It prohibits romantic or sexual content involving minors, including fictional, fantasy, age-regressed, or age-ambiguous depictions. If you believe a child provided information, contact us so we can investigate and delete it where appropriate.

Section 13

Changes and contact

We may update this policy when the service, providers, or legal requirements change. We will update the effective date and may announce material changes through the service or by email. Continued use after an update is subject to the revised policy, without limiting rights that require separate consent.

Privacy and account requests

Email: [email protected]
Service: https://lorebraid.com

© 2026 Lorebraid. Where every choice becomes braided into the lore.
Terms of ServiceReturn to Lorebraid