Privacy Policy
Effective 2026-07-01
1. Who we are
LoreWire is a publishing tool operated by Traffic.Club IT GmbH. The site is reachable at lorewire.com. This policy explains what data the service collects, why, and how to control it. Questions go to contact@lorewire.com.
The data controller responsible for your personal data is Traffic.Club IT GmbH, Kaiserstraße 170-174, 66386 St. Ingbert, Germany. Its full company details, including the commercial register entry and VAT number, are on our Imprint page.
2. Data we collect
We collect the following categories of data, depending on how you use LoreWire.
Account data
- Your email address, and a salted, hashed password if you set one.
- How you sign in. You can use an email and password, a one-time email sign-in link, or a Google, Microsoft, or Reddit account. When you sign in with one of those providers we store the account identifier they return and the email tied to it, so we recognize you next time. We never receive or store your password for those providers.
- A display name and profile picture, if you set one or a sign-in provider supplies it.
- A session cookie that keeps you signed in. The cookie holds only an opaque session identifier, not personal data.
Reader activity
- Stories you save, like, or mark as favorite categories; the stories you have recently viewed; and how far you read or watched, so your list and your place are still here next time.
- Your answers to the optional engagement polls. A signed-in vote is linked to your account; an anonymous vote is linked only to a random cookie on your device.
- A random identifier stored on your device (the
lw_anoncookie) that ties this device's activity together before you sign in. Choosing Reject in the cookie banner clears it.
Content you create
- Stories, articles, scripts, captions, and rendered video and audio files you generate inside LoreWire.
- Settings you save (preferred voices, default privacy, hashtag sets, scheduling defaults).
Connected social accounts
- When you connect a YouTube channel, a Meta-managed Facebook Page or Instagram Business account, or a TikTok account, LoreWire stores the OAuth access token, refresh token, and a display name returned by the platform.
- Tokens are encrypted at rest with AES-256-GCM. They never appear in our logs or in any response sent back to the browser.
- We use these tokens only to publish content you explicitly asked us to publish, and to read back basic post status (views, watch time) when you have that feature turned on.
Technical data
- Application logs that record what happened during a request (e.g. "publish to YouTube succeeded in 9.2 s"). Logs do not contain access tokens, refresh tokens, or password hashes.
- IP address at the edge for abuse prevention. We do not retain it beyond standard hosting log retention windows.
- When you vote in a poll, a one-way hash of your IP address and browser user-agent, used only to rate-limit voting and stop abuse. It cannot be reversed back to your IP address.
3. Analytics and what we do not do
If you press Accept on the cookie banner, LoreWire loads three measurement tools so we can see how the site is being used and catch errors that happen in your browser.
- Google Analytics 4 records aggregated page views and basic events (which page, what referred you, screen size). We turn on IP anonymization and we do not enable Google Signals, ad personalization, or remarketing.
- Vercel Analytics and Speed Insights record aggregated page views and page load timing. Vercel does not use the data to track you across other sites.
- Sentryrecords errors and the stack trace that produced them, so we can fix bugs. We disable Sentry's default personal-data collection (no IP, no user agent), and we never attach your account to an error report.
If you press Reject, none of these tools load. We also clear anything LoreWire saved on this device.
LoreWire never loads third-party advertising scripts, retargeting pixels, or marketing automation tags. There is no Facebook Pixel and no advertising tag of any kind. The cookies LoreWire sets directly are first-party and functional, listed in the Cookies section below.
4. How we use your data
- To let you sign in and use LoreWire.
- To show you stories, remember the list and reading position you save, and run the optional polls you choose to answer.
- To render and publish the content you create on the platforms you have connected.
- To show you the status of past publishes (succeeded, failed, pending) and metrics you opted into.
- To diagnose failures when something breaks. Engineers read logs; logs never contain credentials.
5. Legal bases and automated decisions
Because Traffic.Club IT GmbH is established in the European Union, our processing of personal data is governed by the EU General Data Protection Regulation (GDPR). We rely on the following legal bases.
- Performance of a contract (Art. 6(1)(b)): creating and running your account, showing you stories and remembering the list and reading position you save, rendering the content you create, and publishing to the accounts you connect when you ask us to.
- Legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing abuse and duplicate poll votes, keeping short-lived server and edge logs, and diagnosing failures. Our interest is running a safe, working service, balanced against your rights and freedoms.
- Consent (Art. 6(1)(a)): loading Google Analytics, Vercel Analytics, and Sentry, which happens only after you press Accept on the cookie banner. You can withdraw this consent at any time with Manage cookies in the footer, without affecting processing already carried out.
- Legal obligation (Art. 6(1)(c)): responding to lawful requests and meeting retention duties that apply to us.
Traffic.Club IT GmbH does not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you. We use AI models to generate content you ask for (scripts, captions, images, voiceover); that generation produces content, it does not make decisions about you.
6. Sharing with third parties
LoreWire shares data with a small number of providers, each covered by their own privacy policy.
- YouTube (Google LLC): when you connect a channel, your OAuth grant authorizes LoreWire to upload videos under that channel. Google's privacy policy: policies.google.com/privacy.
- Meta Platforms (Facebook, Instagram): when you connect a Facebook Page and a linked Instagram Business account, your OAuth grant authorizes LoreWire to publish Reels and posts. Meta's privacy policy: facebook.com/policy.php.
- TikTok: when you connect a TikTok account, your OAuth grant authorizes LoreWire to upload videos. TikTok's privacy policy: tiktok.com/legal/privacy-policy.
- Vercel hosts the application. Privacy policy: vercel.com/legal/privacy-policy.
- Google Cloud Storagestores rendered media files. Covered by Google Cloud's privacy commitments.
- Neon (Postgres) stores account data and the encrypted tokens. Privacy policy: neon.com/privacy-policy.
- Sign-in providers (Google, Microsoft, Reddit): if you choose to sign in with one of these, the provider authenticates you and returns a basic account identifier and, where available, your email. Reddit does not return an email, so we generate a stable internal anchor instead. Privacy policies: Google, Microsoft, Reddit.
- Brevo sends transactional email such as your one-time sign-in link, and receives your email address to deliver it. Privacy policy: brevo.com/legal/privacypolicy.
- Anthropic and OpenAI run model inference for generated scripts and captions. Their privacy policies cover what they do with inputs sent for inference.
- Google Analytics 4, when you have accepted the cookie banner, receives aggregated page-view and event data. Google's privacy policy: policies.google.com/privacy.
- Vercel Analytics and Speed Insights, when you have accepted the cookie banner, receive aggregated page-view and page-load timing data. Privacy policy: vercel.com/legal/privacy-policy.
- Sentryreceives stack traces and breadcrumbs when an error happens in your browser or on the server. We disable Sentry's default personal-data capture (no IP, no user agent) and never attach your account to a report. Privacy policy: sentry.io/privacy.
LoreWire does not sell your data and does not share it with any party for advertising purposes.
7. YouTube API Services
Features that use the YouTube Data API v3 are governed by the YouTube Terms of Service and the Google Privacy Policy. LoreWire uses these APIs only to upload videos to channels you have connected and, when enabled, to read back basic post metrics. We do not use YouTube data to build profiles for advertising, share it with brokers, or retain it after you disconnect.
You can revoke LoreWire's access to your YouTube account at any time from your Google security settings at security.google.com/settings/security/permissions. Revoking on Google's side and disconnecting from LoreWire's settings page both invalidate the stored token.
8. Cookies
The cookies LoreWire sets directly are first-party and functional. Unless noted, they are httpOnly, Secure, and SameSite=Lax.
- Sign-in cookies keep you signed in (a session identifier for readers, and a separate one for staff).
- Sign-in flow cookies exist only for the few minutes of an OAuth sign-in, to protect the exchange, then expire.
- Cookie-choice cookie (
lw_consent) remembers whether you pressed Accept or Reject. It is readable by the page so the banner knows your choice; it stores nothing else. - Anonymous-activity cookie (
lw_anon) ties this device's saved stories and progress together before you sign in. Reject clears it. - Poll cookie (
lw_vote) stops the same browser voting twice on a poll. - Your light/dark theme preferenceis kept in your browser's local storage, not a cookie.
If you accept the cookie banner, Google Analytics also sets its own cookies (typically _ga and _ga_*) to count unique visitors and remember the start of a session. Vercel Analytics uses an in-page beacon, not a cookie. Sentry does not set a cookie. Rejecting consent prevents Google Analytics from loading at all, so none of these cookies appear.
9. Retention
- Account data: kept while your account is active. Deleted within 30 days of account closure.
- Connected-account tokens: deleted within minutes of you disconnecting the account, and within 24 hours of a platform telling us the grant was revoked.
- Content you create: kept while your account is active. You can delete individual items at any time from the editor.
- Application logs: rotated on a 30-day window.
10. Your rights
- Access: email contact@lorewire.com and we will provide a copy of the data we hold about you.
- Correction: edit your profile in the editor, or email us.
- Deletion: delete your account yourself from your account page, or email us. The Data deletion section below explains every option and exactly what gets removed.
- Disconnect a social account: go to the social accounts page in settings and click Disconnect. The stored token is revoked at the platform and removed from our database immediately.
- Restriction: ask us to pause processing your data while a question about its accuracy or the lawfulness of processing is being resolved.
- Objection: object to processing we base on our legitimate interests, on grounds relating to your particular situation.
- Portability: ask for a copy of the personal data you provided to us in a structured, commonly used, machine-readable format, or ask us to send it to another provider where that is technically feasible.
- Withdraw consent: where we rely on your consent (the analytics and error tools), withdraw it at any time with Manage cookies in the footer. Withdrawing does not affect processing already carried out.
- Complain: lodge a complaint with a data protection supervisory authority. For our registered seat this is the Unabhängiges Datenschutzzentrum Saarland; you may also contact the authority where you live or work.
11. Data deletion
You can delete your LoreWire account and the data tied to it whenever you want. There are three ways to do it, and they all remove the same thing.
- Delete it yourself. Open your account page, scroll to the Danger zone, and choose "Delete my account." You confirm by typing DELETE, and the account is removed straight away. There is no undo.
- Ask us to. Email contact@lorewire.com from the address on your account and we will delete it for you, within 30 days at the latest.
- From Facebook.If you signed in with Facebook, removing LoreWire from your Facebook account's Apps and Websites settings sends us a deletion request automatically, and we delete your account when it arrives. Facebook gives you a link to a page where you can check the status and see a confirmation code.
However you ask, deleting your account erases your saved stories, likes, favorite categories, reading and watching history, and your profile name and picture. Poll votes you cast stay counted in the anonymous poll totals but are no longer linked to you. If you only want to disconnect a connected social account rather than delete everything, use Disconnect on the social accounts page instead (see Your rights above).
12. Children
LoreWire is intended for adults and is not directed at anyone under 16. We do not knowingly collect personal data from anyone under 16. If you believe someone under 16 has provided personal data, email contact@lorewire.com and we will delete it.
13. International transfers
LoreWire's infrastructure runs in the United States and the European Union depending on the provider, so some of your data is processed outside the European Economic Area.
Where data is transferred outside the EEA, we rely on an adequacy decision of the European Commission where one covers the recipient, or otherwise on the Commission's Standard Contractual Clauses together with additional technical and organizational safeguards, so your data keeps a level of protection equivalent to the one it has in the EEA.
14. Changes to this policy
Material changes are posted here with an updated effective date, and existing users receive an email notice 30 days before the change takes effect.
15. Contact
Questions, requests, and complaints go to contact@lorewire.com.