Lorely

Lorely policies

Subprocessors and providers

Who can process information when you use Lorely.

Status and languageProvisional public information for TestFlight. Final legal review is pending.Last updated: September 12, 2026. Available in English.

Inventory status

This provisional inventory describes services integrated with Lorely and the data categories they can process. Deployment-specific activation, contractual roles, processing regions, international transfers, and data-processing agreements are still being reviewed. It is not a verified list of every provider active in every environment.

A service that receives private book content is identified below. Optional AI providers are listed separately and receive content only when selected for an enabled feature. No statement below certifies a provider’s retention or training settings.

Storage and hosting

Supabase supports database and file storage: uploaded EPUBs, extracted structure and text, generated enhancements, reading progress, anonymous identity, support reports, purchase metadata, and separately collected beta emails. Private book content: yes.

Railway hosts API and background processing. It can process private book content and generated enhancements while running those services, plus operational and identity metadata. Private book content: yes.

Vercel hosts the marketing and policy website. Website requests and beta intake can involve connection metadata and information you submit. The website is not a book uploader or reader. Private book content: not part of the website flow.

Analytics, diagnostics, and app integrity

PostHog supports permitted website analytics, opt-in iOS analytics, and bounded operational AI telemetry when enabled. These flows use identifiers, outcomes, counts, and timings; they exclude private book text, titles, prompts, and generated content.

Sentry supports essential crash and error monitoring with sanitized technical diagnostics. It must not receive EPUB text, prompts, generated content, or private support descriptions.

Google Firebase App Check supports app-integrity checks using app, device-attestation, and security metadata. It does not receive private book content through this integration.

Purchases

RevenueCat synchronizes subscription and purchase access using anonymous app identity, product and entitlement identifiers, transaction references, and purchase status. Private book content: no.

Apple provides App Store billing, purchase management, and TestFlight distribution. Apple’s own terms and privacy information apply to those services. Lorely does not send EPUB content to Apple as purchase data. Apple’s role may differ from a processor acting only on Lorely’s instructions.

Optional AI providers

Lorely integrates OpenAI and xAI for configured text generation, and xAI and Google Gemini for configured image generation. Integration does not mean that every provider is active. Enabled tasks can send bounded private book context, generation instructions, and image references and receive generated text or images. Private book content: yes, when selected.

The enabled provider list and verified data-handling settings must be confirmed before paid launch. Contact support for information about your beta environment before choosing cloud processing.

Changes and questions

This page will be updated when reviewed provider arrangements change. For questions about a provider, processing location, retention, or your data rights, contact support.

Contact

Contact support@getlorely.com for questions about this policy.

HomeTerms of ServicePrivacy PolicyCopyright PolicyAI Features PolicySubprocessorsAnalytics & ConsentSupport