Effective date: September 25, 2026 Last updated: September 25, 2026
1. Introduction
This Privacy Policy explains how Oleh Yarosh, operating Loreon ("Loreon," "we," "us," or "our") collects, uses, stores, shares, and protects information when you use Loreon.
Loreon is an AI-powered interactive storytelling platform.
If you do not agree with this Privacy Policy, do not use Loreon.
2. Who controls your data
Data controller / operator: Oleh Yarosh, operating Loreon
Contact emails:
- General: [email protected]
- Support: [email protected]
- Privacy: [email protected]
- Legal: [email protected]
3. Information we collect
We may collect the following categories of information:
3.1 Account information
- email address;
- login or authentication-related information;
- profile or account identifiers;
- subscription status and entitlement status.
If you sign in with Google, we may receive account information necessary to authenticate you and operate your Loreon account.
If you sign in with Telegram, we receive your Telegram user ID and the profile details Telegram shares, such as your name and username.
If you use Loreon without signing in, we create a guest account identified by a cookie and a hashed device signal.
3.2 Story and session information
- story choices;
- prompts or inputs you provide;
- story ideas you submit to create a story, and any text you paste in;
- your Created Stories, including their story world, title, description, characters, tags, and poster image, and any edits you make;
- session history;
- generated continuations associated with your account or session;
- saved progress, collections, and related storytelling activity;
- use of Story Keys, Actions, and other digital entitlements.
Please do not put personal information about yourself or other people into story ideas or story inputs. If you do, it is processed like the rest of your story content.
3.3 Usage and technical information
- IP address;
- browser type;
- device type;
- operating system;
- language settings;
- log data;
- approximate location inferred from technical data;
- timestamps, error logs, and security events.
For security and abuse prevention, we store IP addresses and device signals in irreversible hashed form and use them to detect automated abuse and protect account integrity. Raw IP addresses and browser details can also appear in server and error logs.
3.4 Product telemetry and engagement data
We may collect first-party product telemetry about how Loreon is used, including:
- session duration;
- reading flow;
- interaction timing;
- time before making a story choice;
- feature usage;
- story progression events;
- reread or revisit behavior;
- drop-off points;
- performance and reliability events.
3.5 Payment and billing information
Payments are processed by Paddle (which acts as Merchant of Record on the website), Google Play, or Telegram, depending on where you buy. We receive limited billing-related information such as:
- payment status;
- subscription status;
- renewal and cancellation status;
- transaction identifiers;
- country or tax-related purchase metadata;
- refund or chargeback status.
We do not store your full payment card details.
3.6 Communications
If you contact us, we may collect:
- your email address;
- message content;
- screenshots or other attachments you provide;
- support history.
3.7 Notifications
If you turn on story reminders, we store your browser push subscription or use your Telegram chat with the Loreon bot to deliver them.
4. How we use your information
We use information for the following purposes:
- to create and manage accounts;
- to authenticate users;
- to provide and operate Loreon;
- to generate story continuations and maintain story sessions;
- to write your Created Stories and generate their posters;
- to send story reminders you have turned on;
- to process purchases, subscriptions, entitlements, and billing status;
- to provide customer support;
- to monitor security, prevent fraud, detect abuse, and enforce our Terms;
- to debug, maintain, and improve the service;
- to analyze product engagement, reading behavior, pacing, choice timing, and feature effectiveness;
- to produce aggregated or effectively anonymized statistics and insights for service improvement;
- to communicate service-related notices;
- to comply with legal obligations;
- to establish, exercise, or defend legal claims.
If you choose to opt in to certain optional data uses in the future, we may also use information for those additional purposes as described at the time.
Human review. Our operator can view story ideas, Created Stories, and play sessions. We do this to investigate abuse or reported content, answer support requests, fix errors, and understand what kinds of stories readers ask for so we can improve story quality. Access is limited to the operator.
5. Legal bases
Where applicable under data protection law, we rely on one or more of the following legal bases:
- performance of a contract;
- legitimate interests;
- compliance with legal obligations;
- consent, where required.
Our legitimate interests may include:
- operating and improving Loreon;
- understanding usage and engagement;
- protecting the service against fraud, abuse, and security threats;
- maintaining platform reliability and performance;
- developing better storytelling systems and user experience;
- maintaining business records and enforcing our rights.
6. Cookies, similar technologies, and telemetry
Loreon uses essential cookies and similar technologies necessary for authentication, security, session continuity, preference handling, and core service operation. These include Cloudflare Turnstile, which checks that visitors are not bots.
Loreon also records first-party usage events and session interactions to operate, secure, debug, and improve the service, including measuring reading flow, choice timing, engagement patterns, feature usage, and reliability.
We also use the following client-side tools:
- Google Tag Manager, which loads Google Analytics and the X (Twitter) advertising pixel to measure visits and ad campaign results;
- Sentry, to record errors in the app, which can include your IP address and account identifier.
If you arrive through a Loreon short link or campaign URL, we may set a short-lived attribution identifier to measure campaign performance.
You can control some cookie preferences through your browser settings, but disabling essential cookies may affect functionality.
7. Analytics and service improvement
We use product analytics and telemetry to understand how Loreon is used and to improve the service.
This may include analyzing:
- how long users engage with stories;
- which choices are selected;
- how long users wait before taking actions;
- whether content is reread;
- where users stop, return, or disengage;
- which features are valuable or confusing.
We may use aggregated or effectively anonymized information for product improvement, research, and reporting.
If we later offer optional programs that use additional user data for service improvement beyond what is described here, we may ask for a separate opt-in.
8. Sharing of information
We may share information with:
8.1 Service providers
Third-party providers who help us operate Loreon, such as providers for:
- hosting and infrastructure;
- database services;
- email delivery;
- authentication;
- payment processing;
- fraud prevention;
- analytics and advertising measurement;
- error monitoring;
- AI/model access.
These currently include OVH (servers), Cloudflare (network, storage, bot protection), Sentry (error monitoring), Google (sign-in, analytics, Google Play), X (ad measurement), Telegram (sign-in, notifications, payments), and OpenRouter (AI models).
8.2 Payment provider
Paddle may process payments and related billing data as Merchant of Record or payment provider.
8.3 AI providers
Loreon uses AI models accessed through OpenRouter to write stories, create Created Stories and their posters, generate illustrations, and check content. To do this, your story choices, story ideas, Created Story content, and the recent story history each request needs are sent through OpenRouter to the company that runs the model. These include model developers such as OpenAI and Google, and hosting companies that run open models such as DeepSeek, GLM, and Qwen. Some of them process data in the United States, and some in Asia, including China.
8.4 Legal and safety disclosures
We may disclose information where reasonably necessary to:
- comply with law or legal process;
- respond to lawful requests by authorities;
- enforce our Terms;
- protect our rights, users, or the public;
- investigate fraud, abuse, or security incidents.
8.5 Business transfers
If Loreon is involved in a merger, acquisition, restructuring, sale of assets, or similar transaction, information may be transferred as part of that process, subject to applicable law.
9. International transfers
Because Loreon and its service providers operate in different countries, your information may be processed outside your country of residence, including in the European Union, the United States, and Asia (including China, for some AI processing).
Where required, we take reasonable steps to protect personal data in connection with such transfers.
10. Data retention
We retain information only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required by law or necessary for legitimate business purposes.
Our general retention approach includes:
- account data, session history, and Created Stories: retained while your account exists, until you delete them;
- story drafts you did not keep: deleted within 7 days;
- guest accounts: deleted, with their stories and sessions, after 12 months without activity;
- technical records of AI requests: deleted after 90 days;
- records of generated images, including the text used to create them: kept after deletion, no longer linked to your account;
- support messages: kept after account deletion, no longer linked to your account;
- deleted accounts: purged 30 days after the deletion request, except where retention is needed for legal, accounting, fraud prevention, security, dispute handling, or enforcement purposes;
- transaction and billing-related records: retained as required by law, accounting obligations, fraud prevention needs, and chargeback handling.
11. Account deletion and requests
You can delete your account in your profile settings, or by contacting [email protected] or [email protected]. We may require verification before processing a request sent by email.
When you delete your account:
- you are signed out everywhere and any subscription is canceled;
- your account is purged after 30 days, including your sessions, Created Stories, and posters. Signing in again before then cancels the deletion;
- some data may be retained where necessary for legal compliance, accounting, fraud prevention, dispute handling, security, or enforcement.
You can delete a single Created Story at any time from your collection.
Clearing guest data in your profile removes it from your device only. To have a guest account deleted from our servers, contact [email protected].
12. Marketing communications
We may send marketing emails only where you have opted in or where otherwise permitted by law.
You can unsubscribe from marketing emails at any time using the unsubscribe link or by contacting us.
Even if you opt out of marketing, we may still send service-related communications, including billing, security, support, and account notices.
Story reminders sent by browser push or the Loreon Telegram bot are sent only if you turn them on. You can turn them off in your settings, and you can also block the bot in Telegram.
13. Your rights
Depending on your location and applicable law, you may have rights to:
- access your personal data;
- correct inaccurate data;
- request deletion;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- request portability where applicable;
- lodge a complaint with a supervisory authority.
To exercise rights, contact [email protected].
We may need to verify your identity before responding.
14. Security
We use reasonable technical and organizational measures to protect information against unauthorized access, disclosure, alteration, and destruction.
However, no system can be guaranteed to be completely secure, and we cannot guarantee absolute security.
15. Children
Loreon is not intended for users under 16 years old.
If you believe a person under 16 has provided us personal data, contact [email protected] so we can review and take appropriate action.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we may notify users through the website, app, email, or another reasonable method. The updated version will be posted with a revised effective date.
17. Contact
For privacy questions or requests: