How Loreline handles your personal data.
Last updated: 4 September 2026 · Beta, provided free of charge.
1. Overview
This Privacy Policy explains what personal data Loreline ("we", "us", the "Service") collects, how we use it, who we share it with, and the choices you have. It applies to spectators and signed-in members alike.
Loreline is currently a free, non-commercial beta operated on an informal basis, not yet by an incorporated legal entity. We aim to collect only what is needed to run the Service. This policy should be read alongside our Terms & Conditions.
2. Data we collect
Depending on how you use the Service, we may process:
- Account data: we store your email address and a unique account identifier. If you sign in with Google we receive your email address from Google; we do not request offline access to your Google account and do not store Google refresh tokens. If you sign in with an emailed code, you give us the email address directly and we send a one-time code to it.
- Profile data: a display name and username you choose, shown publicly on your profile if set.
- Content you contribute: photos, videos, audio, titles, descriptions, and the lorelines you create or interact with, stored in our media storage and database.
- Embedded-media metadata: when you add media from third-party platforms (YouTube, TikTok, Instagram, X), we store references and public metadata, not the media itself.
- Curator applications: if you apply to curate someone else’s loreline, we store your written pitch and the pitch video you upload, together with your account identifier. This is shown to the owner of the loreline you applied to, so they can decide on your application.
- Location and capture data from media. Where a photo or video contains EXIF metadata, we may extract its GPS coordinates and capture date. To protect your privacy, we coarsen the coordinates to roughly town/neighbourhood level (about a 1 km grid) before storing them. We do not retain the original street-level precision. Capture date may be shown on the scene; the coarsened location is stored with the scene and is not shown publicly unless you choose to include it.
- Usage and analytics data. Loreline views, watch time, completion, save/unsave actions, device type (mobile/desktop), and, for embedded players, the host site the player is shown on. A per-browser session identifier is stored in your browser’s local storage. We do not store IP addresses in our analytics database.
- Preferences stored locally in your browser: theme, sound, last-selected loreline, and dismissed notices.
3. How we use your data
- To authenticate you and maintain your session, including sending a one-time code to your email address when you sign in that way.
- To provide, operate, and improve the Service, including displaying your content within the lorelines it belongs to.
- To pass a curator application, with its pitch, to the owner of the loreline you applied to, and to notify you both of the outcome.
- To produce aggregate analytics (such as view counts and watch time) for loreline owners.
- To screen content for safety and legal compliance (see "Content moderation" below).
- To protect the Service against abuse, including rate limiting.
- To respond to your requests and to copyright or content notices.
4. Content moderation
When a loreline is submitted to be made public, its text (title, description, and a sample of scene titles and descriptions) is sent to OpenAI’s content-moderation service to screen for unsafe or unlawful content. Only text is sent; we do not send your images or video for screening. Content that is flagged stays private until an admin reviews it. Private lorelines are never sent for moderation.
If the screening service is unavailable when you publish, we record that the submission went out unscreened rather than blocking you, and it remains subject to review and to reports from anyone who sees it.
Separately, theme generation (a creator/operator feature) sends your design prompt and any reference image URL you provide to Anthropic to generate a theme. Anthropic is not used for content moderation.
5. Location data and reverse geocoding
If a photo or video you upload contains GPS coordinates in its EXIF metadata, we first coarsen those coordinates to roughly town/neighbourhood level, then send the coarsened coordinates to the OpenStreetMap Nominatim service to translate them into a human-readable place name (town, region or country, not a street address). The coarsened coordinates and place name are stored with your scene. When you search for a location manually, the search text is sent through our server to Komoot Photon, which uses OpenStreetMap data. You can avoid EXIF processing by removing location metadata from files before uploading.
6. Cookies, consent, and local storage
We use cookies that are strictly necessary to keep you signed in (set by our self-hosted authentication service). These are secure, same-site cookies and are not used for advertising.
Non-essential analytics (content views, playback time and scene engagement, using a random browser identifier renewed each UTC day) are off by default and only run after you opt in via our cookie banner. If you reject, or before you choose, none of these run. You can change your choice at any time using the “Manage cookies” link in the site footer.
This applies to embedded players too. When a loreline is embedded on someone else’s website we cannot show you our cookie banner there, so an embedded player records nothing unless you have already accepted analytics on loreline.live itself. If you have not, viewing an embed is not counted at all.
We also store some essential preferences (theme, sound, last-selected loreline, dismissed notices) in your browser’s local storage; these never leave your device.
7. Who we share data with
We do not sell your personal data. We share data only with service providers ("subprocessors") who help us run the Service, each acting on our behalf:
- Supabase: database and legacy media storage (hosts core data, but not authentication).
- Google: sign-in (we receive your email) and the YouTube Data API, which receives the video identifier when you add a YouTube link so we can read its public title and duration.
- Resend: delivers our sign-in emails. When you request a one-time code, Resend processes your email address in order to send it. It is used only for these transactional emails, never for marketing.
- OpenAI: AI content moderation (screening public submissions).
- Anthropic: AI theme generation (creator/operator feature only).
- OpenStreetMap (Nominatim): reverse-geocoding of EXIF GPS coordinates.
- Komoot Photon (OpenStreetMap data): location suggestions based on the search text you type.
- Meta (Facebook): when you add an Instagram embed, we request public embed metadata from Meta’s oEmbed endpoint; we do not send Meta your account data.
- Upstash: rate-limiting counters (keyed by account or request identifiers; no profile data).
- Search engines (IndexNow): when a loreline or segment is approved and made public, we notify the IndexNow service, which shares the new public URL with participating search engines (including Bing, Yandex and Seznam) so it can be indexed. Only the public address is sent, never your account data.
- Third-party embed platforms (YouTube, TikTok, Instagram, X): their embedded players load directly in your browser and are governed by their own privacy policies; we do not send them your account data. Embedded YouTube players may in turn connect to Google’s advertising domains (e.g. doubleclick.net) under Google’s own policies.
8. International transfers
Our service providers may process data in countries outside your own, including the United States. Where this happens, we rely on the providers’ own safeguards for international transfers. Because Loreline is an early-stage beta, we have not yet executed formal data-processing agreements with every provider; we will do so as the Service matures.
9. Data retention
We keep your data only as long as we need it for the purposes described in this policy:
- Account and profile data: kept while your account exists. When you delete your account, this data is erased immediately (see "Your rights" below).
- Content (lorelines, scenes, segments, uploaded media): kept while it remains on the Service. Content you delete is removed from the database, and we delete the underlying uploaded files from media storage. If a file cannot be removed at that moment, our system records that the erasure was incomplete so it can be swept up; write to us if you want confirmation that your files are gone. Residual copies may persist in encrypted backups for up to 30 days before being overwritten.
- Analytics records: retained for up to 24 months to provide historical view and watch-time statistics to loreline owners, then deleted or aggregated into non-identifying totals. When you delete your account, any account identifier on your past analytics rows is removed so the remaining records can no longer be linked back to you.
- Rate-limiting counters: transient, expiring automatically within minutes to hours.
- Operational error logs: the application retains short-lived server logs used to diagnose errors. These may contain technical identifiers such as a session or loreline identifier; they are not a marketing or profiling store.
- When you delete your account, deletion cascades across our database to remove your profile, lorelines, scenes, media metadata, saved items, watch progress, notifications, and the shares you created.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can manage much of your content directly: edit or delete lorelines and scenes, set content to private, and hide scenes.
You can exercise the core rights yourself from your profile, under “Privacy & data”:
- Export my data: download a machine-readable (JSON) copy of your profile, lorelines, scenes, media metadata, saves, and the shares you created.
- Delete my account: permanently and immediately erase your account and associated personal data. This is irreversible.
10a. Contacting us about your rights
For any right not covered by the self-serve tools above, or if you cannot access your account, contact us at [email protected] and we will action your request manually.
If you appear in a scene, or a photo of yours was published here, you do not need an account to ask us to take it down: use the report form at /report and choose "Privacy / remove me". It reaches the same place.
11. Children
The Service is not directed to children. When you sign in, you confirm that you are at least 16 years old (or the higher age of digital consent in your country). We do not knowingly collect personal data from children below that age. If you believe a child has provided us personal data, contact us and we will remove it.
12. Changes to this policy
We may update this policy as the Service develops. Material changes take effect when posted at this page. Your continued use of the Service after changes are posted constitutes acceptance.
13. Contact
For privacy questions or to exercise your rights, contact us at [email protected].
This document is a plain-language privacy notice for a beta service and is not legal advice. It should be reviewed by a qualified professional before Loreline begins monetising or operates under a legal entity.