Skip to content

Privacy Policy for Lore

Effective date: July 27, 2026

Last updated: July 29, 2026

Lore is an independent product operated by Erick Dronski. This policy applies to the Lore iOS app, the Lore website at lore-web-liart.vercel.app, and the related account, support, and backend services (together, "Lore").

Questions or privacy requests can be sent to esdronski@gmail.com.

1. The short version

  • You can browse places and use the core scanner without creating an account.
  • Live camera scanning, device heading, and nearby-place ranking normally stay on your device. Lore does not store a continuous camera feed or a continuous location history.
  • If you are signed in and explicitly choose Identify with Google, Lore sends one current camera frame to Google Cloud Vision for that request. Lore does not save that frame in Lore storage.
  • Lore stores account and activity data only for features you choose, such as synced visits, journal notes and photos, private web Lore and media, preferences, badges, and Lore+ access.
  • Your journal and private web Lore are visible only to your account. The current release does not publish journal notes, journal photos, or private web Lore to other travelers.
  • Lore does not sell personal information, show third-party ads, or track you across other companies' apps or websites.

2. Data Lore processes

FeatureDataPurpose and storage
Browsing and mapsRequested city, place, tour, and story records; standard network request dataDelivers the map and historical content. Hosting and content providers may receive IP address, user agent, requested URL, and timing data in ordinary server logs.
Live scannerCamera video, precise location while in use, heading, motion, and AR session dataRanks and positions nearby places. This normally runs on-device and is not written to Lore's database. Apple frameworks may process data under Apple's terms when precise geo tracking is enabled.
Optional Google identificationOne JPEG camera frame and the signed-in account identifier needed to enforce a per-user quotaSent only after an explicit confirmation to identify a landmark. Lore relays the frame to Google Cloud Vision and does not save the frame in Lore storage. The returned landmark name and confidence are shown for the request.
AccountEmail address, authentication identifier, password hash handled by Supabase, and optional profile informationCreates and secures the account and syncs account features. Lore never receives a readable password.
Visits and journalVisited place identifiers, timestamps, notes, and journal photos you choose to saveSyncs your passport and private travel journal across signed-in sessions. Journal entries and photos are visible only to your account. Lore does not infer or store a continuous route from these records.
Preferences and achievementsOnboarding state, interests, hidden categories, story preferences, badges, and Insight totalsPersonalizes ranking and keeps your progress.
Lore+StoreKit entitlement and introductory-offer state; Apple-signed transaction data used to verify the purchase; product, transaction identifiers, purchase or expiry dates, environment, and the account entitlement created from that verificationUnlocks paid features, supports restoration across devices and account recreation, prevents one purchase from being claimed by multiple active accounts, and processes subscription lifecycle events such as renewal, expiry, refund, and revocation. Lore verifies signed transaction data on its backend and retains limited transaction metadata. Apple handles payment-card information; Lore does not receive it.
Support and earlier release-update requestsEmail address and the contents of messages you send; email previously submitted to the release waitlistReplies to support requests and sends a release update that was previously requested. The public waitlist is now closed.
Private web LoreA title, story, map pin, tags, and photos or videos you choose to saveSaves a private entry to My Lore for your account. Its media is stored in an owner-only bucket and displayed through short-lived signed links. The website's separate public submission form remains closed.
Earlier public web submissionsText, media, attribution, moderation state, and related place data previously submitted through the websiteThe website's public contribution form is closed. Existing pending, rejected, or private submissions remain account-linked until deleted. Accepted factual records may remain only after account identifiers and public attribution are removed.

The current iOS release does not include third-party advertising, behavioral analytics, or crash-reporting SDKs. Apple, Supabase, Vercel, and other service providers may still create limited operational and security logs as part of providing their services.

3. Camera, location, and AR

Lore asks for camera and location permission only when a feature needs them. Location is requested while Lore is in use, not as continuous background tracking. You can browse the map without granting camera access, and you can change permissions at any time in iOS Settings.

The normal scanner uses the device camera, location, heading, motion sensors, and Apple AR frameworks to rank and position known places. Lore does not run facial recognition, create face templates, or use camera or AR data for advertising, profiling, or data brokerage.

The optional Identify with Google action is separate from normal scanning. It requires a signed-in account and an explicit confirmation before one frame is uploaded. Do not use that action when a frame contains information you do not want processed by Google Cloud Vision.

The website scanner uses browser camera, location, and orientation permissions for local geometric ranking. Public web cloud-image recognition is disabled, so the website does not upload scanner frames for AI identification.

4. Service providers

Lore uses the following providers to operate the service:

ProviderRole
AppleApp distribution, StoreKit purchases, device permissions, and Apple camera, location, and AR frameworks.
SupabaseAuthentication, database, storage, and Edge Functions.
Google CloudOptional Cloud Vision landmark identification after explicit confirmation.
VercelWebsite hosting and operational request logs.
WikimediaPublic historical summaries and media requested by Lore features.
OpenFreeMap, Mapterhorn, and Amazon Web ServicesMap styles, map tiles, and terrain data requested by the web map.
YouTube and linked social platformsOptional external or embedded public media that you choose to open.

These providers receive only the data needed for their role. Lore requires providers that process personal data on its behalf to use it only to provide the contracted service and to afford the same or equivalent privacy protection described here, subject to their published terms and applicable law.

Lore may also disclose information when reasonably necessary to comply with law, protect users or the service, investigate abuse, or complete a business transfer. Lore does not share personal information for targeted advertising.

5. Retention and deletion

  • Account, profile, preferences, visits, journal, badges, and entitlement rows are retained while your account is active and are deleted when you delete the account.
  • Journal photos, private web Lore media, and other account-owned storage objects are deleted with the account.
  • The website's contribution form is closed. Private web Lore and existing pending or rejected public submissions and their media are deleted with the account. Accepted factual records may remain only in de-identified form, without the account identifier or public attribution.
  • When an account with an Apple purchase is deleted, Lore removes the account's active Apple entitlement and detaches the purchase from that account. Lore retains the Apple original transaction identifier and limited purchase lifecycle metadata without an account link as needed to prevent duplicate claims, process refunds or revocations, and restore the same verified purchase after account recreation. Financial and transaction records may also be kept as required for fraud prevention, accounting, tax, dispute, and legal duties.
  • A waitlist email is retained until the requested release communication is sent or you ask for removal. Support correspondence is retained only as long as reasonably needed to resolve the request, prevent abuse, and meet legal obligations.
  • Lore does not save camera frames sent for optional Google identification.
  • Provider-controlled backups and security logs may persist for a limited period under the provider's retention policy. They are not used to recreate a deleted account except where required for disaster recovery, security, or legal compliance.

6. Your choices

Camera and location

You can deny or revoke camera, location, and motion permissions in iOS Settings or browser settings. Features that need a denied permission will be unavailable, but the rest of Lore remains usable where technically possible.

Journal and private Lore

Journal notes and photos in the iOS app, and Lore entries saved through the website, are private to your account in the current release. There is no public traveler-note sharing control. Do not treat a private entry as a backup for the only copy of important material.

Account deletion

In the iOS app, open Profile > Settings > Delete account. On the website, open Profile > Account > Delete account. Deletion removes the authentication record and associated private account data described above. The limited, account-detached Apple purchase record described in Section 5 may remain.

Deleting a Lore account does not cancel an Apple subscription. Apple controls App Store billing; manage it at Apple Subscriptions.

If you cannot access the deletion control, email esdronski@gmail.com from the account email.

Access and correction

You can update available profile information in Lore. To request access, correction, or deletion that is not available in the product, contact the email above. Lore may verify the request before acting on it.

7. Children

Lore accounts are for people age 13 or older. Browsing does not require an account. Lore does not knowingly collect personal information from children under 13. If you believe a child under 13 created an account, contact us and we will delete it.

8. Security and international processing

Lore uses access controls, encrypted network transport, row-level database security, private storage for journal and web Lore media, rate limits, and authenticated server functions. No service can guarantee absolute security.

Lore and its providers primarily process data in the United States. If you use Lore elsewhere, your information may be transferred to and processed in the United States, subject to applicable safeguards and provider terms.

9. Changes to this policy

Lore may update this policy as features or providers change. Material changes will be reflected by a new effective date and, when appropriate, an in-app or website notice. The version published at lore-web-liart.vercel.app/privacy is the current version.

10. Contact