What we collect
Loremark stores only the data needed to operate the service: your account email, display name, language preference, reading positions, and any ratings, reviews, or private notes you post. If you submit a takedown notice we also keep the name, email, and source IP you submitted it with, as the legal record requires. Ordinary server logs (IP address, user agent) are kept briefly for security and abuse prevention.
The public fact catalog is written by the operator, not by readers — there is no contribution path that takes data from your account into the public catalog. Reading-position data is treated as sensitive: it is never sold, never used for advertising or profiling, and no third party receives it linked to your identity.
Why we collect it
Lawful basis for the service itself is contract performance under GDPR Article 6(1)(b) — the chapter numbers are the entire point of Loremark; they're what makes the spoiler-aware reveals work. Takedown records are kept under Art. 6(1)(c) (legal obligation, Digital Services Act); security logs and error monitoring rest on Art. 6(1)(f) (legitimate interest in keeping the service running and un-abused).
Who processes it
We run our own servers and database at Hetzner (EU data centers). A small set of processors handle specific jobs under our instructions:
- Cloudflare — network edge in front of our servers; sees your IP address like any host does.
- WorkOS — sign-in. Handles your email and name during authentication.
- Paddle — merchant of record for Plus subscriptions. Paddle handles payment, billing, and tax data as the seller of record; your card details never reach our servers.
- Apple / RevenueCat — purchase processing for the iOS app, when available.
- Sentry — error monitoring. Error reports can include your account id and the request that failed; never passwords or payment data.
- PostHog (EU Cloud) — anonymous, cookieless usage analytics; see the next section.
- Anthropic — generates the Plus catch-up recap from our own curated chapter summaries plus the chapter window you ask about. It never receives your name, email, or account id.
- Brevo — transactional email (EU-based); carries account and takedown emails and handles the recipient address. Purchase receipts come from Paddle directly.
Where a processor is US-based, transfers rest on the EU–US Data Privacy Framework or Standard Contractual Clauses. We do not sell personal data to anyone.
Your rights
You have the rights granted under Art. 15–22 GDPR: access, rectification, erasure, restriction, portability, and objection. The settings page exposes the first three directly; the others, write to us at abuse@loremark.app. You can also lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.
Deletion
You can export all data we hold about you and delete your account from your settings. The button does what it says — no retention dark-pattern. Two narrow exceptions survive deletion because the law requires them to: takedown records (with your name and email redacted) and the audit log (with your identity removed).