Built to hold your worlds safely.
What we do to protect your content, your account, and your data — from infrastructure to policy.
Infrastructure & encryption
how we hostCloud infrastructure in the EU
LoreHub runs on a VPS hosted in Frankfurt, Germany — inside the EU. We're a small, pre-launch operation, so hosting is currently single-region rather than a formal multi-region setup.
Frankfurt, Germany · EUEncryption in transit
All traffic between your browser and LoreHub is sent over HTTPS/TLS. We don't publish a formal TLS-configuration grade or third-party audit today.
HTTPS / TLSCard payments via Stripe
All card payments are handled entirely by Stripe. LoreHub never sees or stores your full card number — Stripe is PCI DSS certified for that.
Stripe · PCI DSSAccess controls & analytics
LoreHub is currently a one-person operation, so production access is limited to the founder. Product analytics (Microsoft Clarity) is off by default and only runs if you consent via the cookie banner.
Founder-only access · Consent-gated analyticsYour content stays private
the commitment
We don't train on your content.
This is a commitment, not a footnote.
Your private worlds, books, characters, and generation directives are never used to train AI models — ours or anyone else's. Your data is stored in the EU. Generating text and images calls trusted third-party AI providers, which may process your prompts outside the EU under appropriate safeguards; we never let your content become someone else's training data. You can export everything at any time, and delete it completely at any time.
Compliance & certification
standardsWe're a small, pre-launch operation and hold no formal third-party security certifications yet. Here's where we actually stand today.
Responsible disclosure
security researchFound a vulnerability?
We welcome responsible security research. If you've found a vulnerability in LoreHub, please disclose it to us privately before making it public. We commit to acknowledging your report within 2 business days and keeping you informed as we investigate and resolve the issue.
Please email [email protected] with a clear description of the issue, steps to reproduce, and the potential impact. We ask that you do not access, modify, or delete other users' data during your research.
We do not currently run a formal bug bounty programme, but we acknowledge researchers publicly (with their consent) and will consider appropriate recognition for significant findings.