Privacy Policy.
Lorah is a local-first desktop application. The following describes how data flows in Lorah as of the date above.
For the full plain-language trust story (what stays local, what providers see, what Lorah's servers see), read Local-first by design.
What stays on your machine
Your workspaces, teammates, project memory, chat history, document library, and provenance records are stored locally in ~/Library/Application Support/Bond2/ (macOS) or %APPDATA%\Bond2\ (Windows). LaGuardAI does not have access to this data.
What goes to AI providers
When you send a message in Lorah, the relevant prompt content is sent directly from your machine to the AI provider you selected (Anthropic, OpenAI, Google, Perplexity, or xAI) using the API key you provided. These providers’ privacy policies apply to that data.
What we collect
License records, stored by our license service: your email, your Stripe customer ID, your plan type (monthly or yearly), your subscription status, and the date. Account and payment processing is handled by Stripe (email, payment method, billing address) under their privacy policy.
An install heartbeat. About once a day the app checks whether your license is still valid. That check also records a random install identifier, the app version, your operating system, your license type (trial, paid or grant), and an approximate country. The install identifier is a random value generated on your machine — it is not derived from your hardware and is not linked to your name or email. The country is resolved by our load balancer before the request reaches our service: we never receive or store your IP address. This tells us how many people use Lorah, on which versions and platforms — and nothing whatsoever about your work.
Aggregate website analytics on lorah.ai, via Cloudflare Web Analytics. It sets no cookies, stores no personal data, and does not track you across other sites. That is why you see no cookie banner here.
Crash reports, only if you switch them on. Crash reporting is off by default. If you turn it on, at first run or in Settings → Data & Privacy, Lorah sends short content-free reports: the error type, your app version and platform, and whether a sync succeeded or failed. Never chat content, memory, file names, prompts or API keys. You can read every queued report in Settings before it’s sent. Two further switches, also off by default: a redacted diagnostic snapshot, and linking reports to your install’s license.
What we do not collect
Your API keys. Your prompts. Your completions. Your project content. Your chat history. Your documents. No content of your work, ever. No crash reports that capture your data. No cookies and no cross-site tracking on this website. No advertising networks. We do not sell or share your data.
Contact
Privacy questions: privacy@lorah.ai or message Yoram Golandsky directly.