Security & trust

Built to hold your worlds safely.

What we do to protect your content, your account, and your data — from infrastructure to policy.

§ 01

Infrastructure & encryption

how we host
§ hosting

Cloud infrastructure in the EU

LoreHub runs on a VPS hosted in Frankfurt, Germany — inside the EU. We're a small, pre-launch operation, so hosting is currently single-region rather than a formal multi-region setup.

Frankfurt, Germany · EU
§ in transit

Encryption in transit

All traffic between your browser and LoreHub is sent over HTTPS/TLS. We don't publish a formal TLS-configuration grade or third-party audit today.

HTTPS / TLS
§ payments

Card payments via Stripe

All card payments are handled entirely by Stripe. LoreHub never sees or stores your full card number — Stripe is PCI DSS certified for that.

Stripe · PCI DSS
§ access & analytics

Access controls & analytics

LoreHub is currently a one-person operation, so production access is limited to the founder. Product analytics (Microsoft Clarity) is off by default and only runs if you consent via the cookie banner.

Founder-only access · Consent-gated analytics
§ 02

Your content stays private

the commitment

We don't train on your content.
This is a commitment, not a footnote.

Your private worlds, books, characters, and generation directives are never used to train AI models — ours or anyone else's. Your data is stored in the EU. Generating text and images calls trusted third-party AI providers, which may process your prompts outside the EU under appropriate safeguards; we never let your content become someone else's training data. You can export everything at any time, and delete it completely at any time.

§ 03

Compliance & certification

standards

We're a small, pre-launch operation and hold no formal third-party security certifications yet. Here's where we actually stand today.

Data protection GDPR & UK GDPR Our approach
Payment security PCI DSS Via Stripe
§ 04

Responsible disclosure

security research

Found a vulnerability?

We welcome responsible security research. If you've found a vulnerability in LoreHub, please disclose it to us privately before making it public. We commit to acknowledging your report within 2 business days and keeping you informed as we investigate and resolve the issue.

Please email [email protected] with a clear description of the issue, steps to reproduce, and the potential impact. We ask that you do not access, modify, or delete other users' data during your research.

We do not currently run a formal bug bounty programme, but we acknowledge researchers publicly (with their consent) and will consider appropriate recognition for significant findings.