Privacy Policy
This policy explains how Lora processes personal data when you use the Lora website, web application, browser extension, APIs, or support channels (together, the Service).
The controller is:
Lora, c/o Simon Brachhold, Waiblinger Str. 48, 70734 Fellbach, Germany Email: feedback@uselora.com
If an employer or other organization provides your Lora workspace, that organization may be the controller for workspace content and member activity while Lora processes the data on its behalf. Contact your organization if your request concerns data it controls.
Information Collection and Use
Depending on the features you use, Lora processes:
- Account and profile data: email address, name, profile image, language, time zone, account identifiers, workspace memberships, roles, and sign-in methods.
- Workspace content: shortcuts, destination URLs, folders, tags, comments, invitations, settings, and other content you or your organization submit.
- Authentication and security data: session and security events, passkey public-credential data and metadata, Google account identifiers when you choose Google sign-in, and a phone number when an enabled phone-verification feature requires it. Lora does not receive your Google password or the private key stored by your passkey provider.
- Shortcut and product activity: shortcut opens, access method, timestamps, workspace and shortcut identifiers, approximate location derived from an IP address, and browser, device, and operating-system information. Eligible plans use this data for personal or workspace analytics.
- Website and diagnostic data: pages visited, referrer, interaction metadata, IP address, browser and device information, and error or performance diagnostics. The marketing site uses product analytics to understand page, click, scroll, and form activity.
- Billing and support data: plan, subscription, transaction status, invoices, and the messages and contact details you send to support. Stripe processes payment details; Lora does not store complete card numbers.
Lora does not request precise GPS location. Dynamic routing and analytics may derive an approximate country, region, or city from an IP address; this can be inaccurate.
Third Party Access
Lora processes personal data to provide and secure the Service, authenticate users, resolve shortcuts, operate workspaces, process subscriptions, communicate about accounts and support requests, diagnose failures, prevent abuse, and improve the product.
Depending on the activity, the legal basis is performance of a contract, compliance with a legal obligation, Lora’s legitimate interests in operating and securing the Service, or consent where consent is requested. You can withdraw consent for future processing at any time; withdrawal does not affect processing that was lawful before it.
Service Providers and Transfers
Lora uses service providers only for the functions described below. The data each provider receives depends on the feature you use:
- Vercel — hosting
- Neon — database
- Upstash — caching
- Sentry — error and performance diagnostics
- Mixpanel — product analytics
- Resend — email
- Stripe — subscriptions, billing, tax, and payment processing
Some providers process data outside the European Economic Area. Where required, Lora relies on an applicable adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism. Provider policies describe their locations and safeguards in more detail.
Lora may also disclose data when required by law, to protect the Service and its users, in connection with a business transaction, or when you direct Lora to share it. Lora does not sell personal data.
Opt-Out Rights
Uninstalling the browser extension stops its future operation on that browser, but it does not delete your Lora account or workspace data. You can use available in-product controls or contact Lora to request account deletion. Your organization may need to handle requests concerning data it controls.
Data Retention Policy
Lora keeps personal data only as long as needed for the purposes described above, including while an account or workspace is active and for applicable security, dispute-resolution, accounting, and legal-retention periods afterward. Retention can differ by data category and contract. Deleted data may remain in restricted backups until the relevant backup cycle expires.
Children
The Service is intended for workplace use and is not directed to children. Lora does not knowingly collect personal data from children. If you believe a child has provided personal data, contact Lora so the situation can be investigated and handled as required by law.
Security
Lora uses technical and organizational safeguards designed to protect personal data, including encryption in transit and access controls. No online service can guarantee absolute security.
Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of your personal data, and to object to certain processing. You may also withdraw consent and lodge a complaint with a competent data protection authority. Lora may need to verify your identity before completing a request.
Changes
Lora may update this policy to reflect changes to the Service, providers, or law. The date at the top shows the latest revision. Material changes will be communicated where required; merely continuing to use the Service is not treated as consent where the law requires a separate choice.
This privacy policy is effective as of 27 August 2026.
Contact Us
For privacy questions or requests, email feedback@uselora.com. If your request concerns an employer-managed workspace, you may also need to contact that organization.