Lorelit Privacy Policy
Effective date: September 22, 2026
Last updated: September 22, 2026
1. Who we are and what this policy covers
Lorelit is operated by Honoululu Inc., incorporated in Delaware, United States, with its registered address at 3524 Silverside RD STE 35B, Wilmington, DE 19810, United States ("Lorelit," "we," "us," or "our"). We are responsible for the personal information described in this policy and act as its controller where that term applies.
This policy explains how we handle personal information when you use Lorelit's applications, official website, AI character conversations, story and creative tools, and related support services (the "Services"). Features differ by platform and version. A data category described below applies when you use the corresponding feature.
The Services are intended for markets outside mainland China, including Hong Kong, Macau, and Taiwan, subject to applicable law and platform availability. We do not offer or direct the Services to mainland China. Your privacy rights depend on the laws that apply to you; this market scope does not waive any mandatory rights.
Contact us about privacy or your data rights at develop@honoululuai.com, or write to the address above, marked "Privacy." Our Terms of Service describe the rules for using the Services. This policy explains our practices; it does not replace a separate consent where one is required.
2. Information we handle
| Category | Examples and source | Why we handle it |
|---|---|---|
| Account and authentication information | Email address you provide; account ID; handle and profile information; verification and session records; a salted password hash if you create a password in a web version that supports password sign-in. If you choose a supported Apple or Google sign-in option, we receive the provider's account identifier and the information it makes available, such as an email address or private relay address. | Create and protect your account, authenticate you, connect sign-in methods, and communicate about your account. |
| Preferences and activity | Language and display settings, selected interests, saved characters, likes, follows, blocked accounts, and feature choices you make. Some preferences remain on your device. | Apply your choices, organize your library, and personalize the experience. |
| Creative content and AI context | Messages, prompts, character descriptions, personas, pinned memories, conversation summaries, scene state, story choices, and generated responses. You provide inputs; the Services generate outputs and context. | Produce and continue conversations and stories, apply your selected persona and memory, and save or synchronize content as described in Section 3. |
| Images and other media | Images you select or upload, reference images, generation prompts, generated images or videos, and associated file and generation metadata. | Create avatars, covers, scenes, and other media; store and deliver requested results. |
| Purchase and usage records | Product and transaction identifiers, signed purchase-verification data, subscription status and dates, credit balances and ledger entries, model or feature used, request identifiers, token usage, and generation status. These come from you, the Services, payment platforms, and generation providers. | Verify purchases, deliver subscriptions and credits, calculate usage charges, prevent duplicate charges and fraud, and handle refunds and support. We do not receive your full payment-card number from Apple in-app purchases. |
| Technical and security information | IP address when connecting to our infrastructure; authentication rate-limit records; request timestamps, errors, and service diagnostics. Hosting and content-delivery providers may process connection and browser or device information. | Deliver the Services, diagnose failures, secure accounts, prevent abuse, and operate infrastructure. |
| Communications and reports | Support messages, attachments you send, reported content identifiers, report reasons and details, and our responses. | Respond to requests, investigate complaints, enforce our rules, and resolve disputes. |
Please use fictional details for personas and conversations and avoid submitting real-world sensitive information, such as information about health, sex life, sexual orientation, religion, or racial or ethnic origin. In particular, do not submit passwords, payment credentials, government identifiers, or another person's private information without a lawful basis. A story can be fictional even if you use a real name; we do not treat all story content as verified facts about you.
We access photos you choose through the available upload or device-picker flow. You can manage applicable permissions in your device settings. Denying a permission may prevent the related feature from working.
3. How conversations and creative content are processed
Local conversations and cloud synchronization
In the mobile app, conversation history is stored on your device by default. When you enable cloud synchronization for a conversation, its messages and relevant conversation state are uploaded and stored under your account so they can be synchronized. Account information, cloud personas, balances, and transaction records are stored on our servers separately from that conversation setting. Website storage and synchronization depend on the features available in the version you use.
Local storage does not mean that AI generation happens entirely on your device. When you request a response, necessary context passes through our servers to the AI service. This can include the character description, your selected persona, relevant recent messages, conversation summaries, scene state, pinned memories, and your current input. We may also send relevant context to generate suggestions, summarize a conversation, or prepare media you request.
For mobile conversations without cloud synchronization, the chat gateway does not persist the full conversation or suggestion text as a conversation history. It does retain usage and billing metadata, and separate media, upload, support, and reporting features may store the material you submit to them. The AI providers' handling of generation requests is a separate part of this data flow.
AI and media providers
When you use an AI-powered feature, we share the information needed to carry out your request with the AI and media services described in Annex A. Text generation can pass through OpenRouter to the endpoint serving the selected model. Image generation can use OpenRouter or GenLab, and available video-generation features can use fal.ai or GenLab and their upstream providers. Providers receive the input and reference material needed for the requested generation and associated technical or task metadata. Some media tasks also include a service-specific identifier derived from your account ID; that identifier is not anonymous merely because it is transformed.
The model developer, routing service, and company hosting the model endpoint may be different organizations. Selecting a model does not, by itself, establish a particular storage country, retention period, or training policy.
No training or model-quality evaluation
Lorelit does not use your messages, prompts, personas, uploaded content, or generated outputs to train or fine-tune AI models, or to conduct human or automated model-quality evaluations. We do not create training or evaluation datasets from that content.
We use operational information, such as request status, latency, errors, and billing usage, to run the Services and resolve technical problems. If you send us a report or choose to share content with support, authorized personnel may review the relevant material to address that request, a safety issue, or a legal obligation. Such case-specific handling is not a program for scoring responses or evaluating model quality.
We send content to external AI services to obtain the generation you request, not to commission training or evaluation of models. External providers have their own data-handling practices. Depending on the provider, endpoint, applicable agreement, and settings, they may retain inputs, outputs, and technical records, permit human access for security or compliance, or use content for their own model improvement. Those practices are distinct from Lorelit's own use of content. We do not represent every external service as operating with no retention, no human access, or no provider-side training.
Annex A identifies the services used in the generation chain and links to available provider notices. These notices supplement our explanation; they do not remove our responsibility for disclosures we make or replace consent required by law. Contact develop@honoululuai.com if you need information about a particular generation service or wish to make a data-rights request involving a provider. We will assist with requests concerning processing we arrange and involve the relevant provider where required.
Turning off cloud synchronization does not prevent the external processing necessary for an AI request you choose to send. Our commitment not to train or evaluate models using your content does not mean AI generation occurs on your device.
Private and published content
A private conversation is not displayed in the public character directory merely because you use it to generate a reply or enable synchronization. Personnel and providers may need to process content for delivery, support, security, or handling a report, within their authorized roles. We do not describe the Services as end-to-end encrypted.
If you choose to publish a character or other content through a supported feature, the published information and associated creator profile may be visible to other users. Published content may be reviewed before or after publication. Other users may save or copy what you make public.
Some image and video workflows use links that can be opened by anyone who has the link. A private conversation setting does not necessarily make a referenced media link private. Do not upload confidential material to a workflow that does not provide the access controls you need.
4. Purposes and legal bases
We use the information described above to provide requested features, manage accounts and purchases, protect the Services, answer support requests, handle reports, and meet applicable legal obligations. We do not treat accepting our Terms as blanket consent to unrelated processing.
Where European Economic Area or United Kingdom data-protection law applies, the following bases apply only to processing necessary for the stated purpose:
| Purpose | Legal basis |
|---|---|
| Account access, requested AI generation, selected synchronization, and delivering purchases | Performance of our contract with you, or steps you request before entering it. |
| Proportionate security, abuse prevention, debugging, and handling ordinary support or enforcement matters | Our legitimate interests in providing a reliable and safe service, balanced against your rights. Contract necessity or a legal obligation may instead apply to a particular request. |
| Required financial records, lawful requests, and compliance duties | Compliance with an applicable legal obligation. |
| Optional processing that requires consent, such as non-essential tracking if introduced | Your consent, which you may withdraw without affecting the lawfulness of earlier processing. |
The Services do not require you to disclose real-world special-category information to take part in fictional stories. If a feature requires us to process such information under EEA/UK law, we must establish an applicable additional legal condition before doing so. Where we rely on explicit consent, we will request it separately and explain how to withdraw it. Merely including sensitive information in a prompt, or accepting our Terms, does not automatically provide that consent. You can contact us to request deletion of sensitive information you submitted unintentionally.
5. Who receives information
We disclose information as needed for these purposes to:
- Infrastructure providers, including hosting, database, storage, and content-delivery services. Our backend uses Runway infrastructure with AWS database and storage services.
- AI and media providers, as explained in Section 3 and Annex A, to process the content and context required for generation.
- Authentication and transactional email providers, including supported Apple/Google sign-in services and Mailgun for sign-in emails. Sign-in emails are service messages; we disable email tracking in our sign-in email integration.
- Payment platforms, including Apple, for purchases, subscription lifecycle events, verification, and refund handling. These platforms also handle information under their own notices.
- Other users or recipients you select, when you publish, share, or send content to them.
- Professional advisers and competent authorities, where reasonably necessary to comply with law, respond to valid legal process, establish or defend claims, or protect people and the Services.
- A successor or potential transaction counterparty, if reasonably necessary in a merger, acquisition, financing, or transfer of the business, subject to appropriate confidentiality and legal requirements. We will give notice of material changes to how your information is handled.
Providers processing information for us must be subject to appropriate contractual protections. Some providers also act independently for their own legal, security, or account-management purposes. Their independent processing is governed by their notices and applicable law; this does not remove our responsibility for our own processing and disclosures.
6. Cookies, local storage, analytics, and advertising
The Services use device or browser storage to keep session information, preferences, and local content. In web versions that use cookie-based sign-in, the first-party lorelit_sid cookie maintains your session for up to 30 days unless it is replaced or cleared earlier. It is used for authentication, not advertising. Other browser storage holds preferences and account-specific local content until you clear it or the relevant application function removes it. Mobile devices store local content and sign-in information through the app's storage facilities.
Clearing browser or app storage can sign you out and remove content held only on that device. Your browser may let you block cookies, but cookie-based sign-in will then be unavailable.
We use operational and transaction records to understand service performance, diagnose failures, and administer usage and billing. Lorelit does not currently display third-party advertisements or use your information to deliver targeted advertising. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use private conversation content for advertising.
If we introduce optional product analytics or advertising technologies, we will first update the relevant disclosures to identify the information, recipients, purposes, and controls, and obtain consent where required.
Where law requires a choice for non-essential storage or tracking, we will obtain that choice before enabling it. Browser and operating-system controls may also allow you to limit storage or permissions, although necessary features may then stop working.
7. Retention, deletion, and local copies
We retain personal information only for as long as reasonably necessary for the purposes described in this policy. The appropriate period depends on the service you request, whether your account remains active, the nature and sensitivity of the information, your deletion choices, and any applicable legal requirements. A longer period may be necessary for a specific legal obligation, unresolved payment or dispute, or security investigation; this does not permit us to keep unrelated information indefinitely.
When information is no longer needed for a permitted purpose, we delete it or make it anonymous so that it can no longer reasonably be linked to you. Replacing your name with an account identifier does not, by itself, make information anonymous. We do not use retained or anonymized conversation content to create model-training or evaluation datasets.
| Information | Retention or deletion rule |
|---|---|
| Device-only content | Remains in local storage until you delete it or the storage is cleared. Device or operating-system backups and copies you export are controlled separately. |
| Active account, cloud personas, and synchronized content | Retained to operate your account and the features you use, subject to deletion requests and applicable exceptions. |
| Deleted cloud conversations or messages | Deletion removes them from normal use and synchronization results. A deletion marker can remain in the database, and the content is not necessarily physically erased by that action. In the current cloud-sync system, the stored copy can remain until the associated account is deleted. You may request earlier erasure through our privacy contact; we will assess and respond under applicable law. |
| Authentication records | Sign-in codes expire after ten minutes; code records older than one day are removed by scheduled cleanup. Mobile session records expire after 30 days and are subsequently cleaned up, unless access is revoked sooner. Security and infrastructure logs have a separate retention schedule. |
| Uploaded and generated media | Kept to deliver, display, or save the asset you requested. A generation record or copy held by a media provider has a separate lifecycle. Requests to erase an asset require consideration of the storage object and delivery copies as well as the account record. |
| Technical and security logs | Kept for the period needed to investigate operational failures, prevent repeated abuse, and resolve identified incidents. Relevant criteria include the incident's severity, whether it remains open, and any applicable claim or legal-preservation period. |
| Support, moderation, and complaint records | Kept while a request, review, or dispute is active and for a proportionate period afterward where needed to document its resolution, prevent repeated abuse, or handle a related claim. |
| Purchase and accounting records | Kept to verify entitlements, reconcile purchases and refunds, and satisfy applicable accounting, tax, fraud-prevention, and legal-preservation obligations. Any required post-deletion retention is limited to the necessary records and period. |
| Backups and delivery caches | Deleted information may remain temporarily in backups or caches until the relevant copy is overwritten, expires, or can otherwise be removed through its normal lifecycle. These residual copies are not kept to provide ongoing access to deleted content or to train or evaluate models. Access to backup copies is limited to necessary recovery, security, or legal-preservation purposes. |
| External AI and media provider records | Retention depends on the provider and endpoint arrangements described in Section 3. Our local-conversation setting does not determine a provider's retention period. |
You can request account deletion in the mobile app through Settings → Delete Account, or contact develop@honoululuai.com. The account-deletion flow invalidates existing sign-in sessions and schedules the account for deletion after a 30-day waiting period. Signing in successfully during that period cancels the pending account deletion. Contact us if you need to exercise a legal erasure right without using that recovery period; mandatory legal deadlines continue to apply.
Deleting an account does not automatically cancel an Apple subscription. Manage the subscription separately through your Apple account. Deleting an account also does not remotely erase every local device copy, downloaded file, public repost, or provider record. We will explain any information we must retain and arrange deletion with relevant providers where required.
8. International processing and security
Your information may be processed outside your country, including in the United States, where our backend database is hosted. AI, media, email, and other infrastructure providers may process information in additional countries. Those countries may have different data-protection laws from your country.
Processing locations depend on the service and model endpoint involved. We do not promise that all information stays in your country or that every provider processes it in the same location as our backend. Information may be accessible to courts, law-enforcement agencies, or other authorities under the laws of the country where it is processed.
For transfers subject to EEA/UK restrictions, an applicable adequacy decision or another valid transfer mechanism, such as approved contractual safeguards, is required, together with supplementary measures where necessary. We will apply the safeguards required by applicable law. Accepting our Terms or using the Services does not, by itself, waive those protections. You can contact develop@honoululuai.com for information about the locations and safeguards relevant to your information and how to obtain a copy of applicable safeguards, subject to legitimate confidentiality redactions.
We use technical and organizational measures intended to protect information, including authenticated access to account-scoped features and encrypted transport for service connections. Security measures reduce risk but cannot guarantee absolute protection. Protect your sign-in methods and devices, and contact us if you suspect unauthorized use.
9. Your choices and privacy rights
You can use available controls to update profile information, manage personas and content, choose conversation synchronization, manage device permissions, and request account deletion. For information held only on your device, we may need your help to locate or export it; please do not send an entire private conversation when a smaller description will resolve your request.
Depending on your location and applicable law, you may have rights to access and obtain a copy of your information; correct it; request deletion or restriction; obtain portable data; object to processing, including processing based on legitimate interests; withdraw consent; and complain to a data-protection authority. Where applicable, you also have protections concerning decisions made solely by automated processing that have legal or similarly significant effects. AI story generation is not intended to make such decisions about you.
Submit a request to develop@honoululuai.com. We may request proportionate information to verify your identity or an authorized agent's authority. We will respond within the period required by applicable law, explain any lawful limitation, and tell you how to appeal where an appeal right applies. We will not unlawfully discriminate against you for exercising your rights. Some features cannot operate without the information necessary to provide them.
For individuals covered by EEA/UK law, we normally respond within one month and will inform you within that period if a permitted extension is necessary. You may complain to your local supervisory authority.
Additional information for US residents
Where applicable US state law gives you these rights, you may request confirmation of processing, access to specific information and categories, correction, deletion, and a portable copy. You may also have a right to opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or profiling used for decisions with legal or similarly significant effects, and to limit certain uses of sensitive information. We do not use fictional AI conversations to make eligibility, employment, credit, or comparable decisions about you.
Our collection categories are identifiers and account information; commercial and transaction information; internet or other electronic activity and technical information; user-provided text, images, and other media; communications; and preferences. Depending on what you choose to submit, content or credentials may also contain information considered sensitive under state law. We use it for the purposes described in Sections 2–4, rather than to infer sensitive real-world characteristics for advertising. We obtain it from you, your use of the Services, your selected sign-in or payment platform, and our service providers.
We disclose the relevant categories to infrastructure and generation providers to operate requested features, to sign-in and payment providers for their respective functions, and to support personnel or advisers where needed for a request or legal matter. Content becomes available to other users when you choose a publishing or sharing feature. The category-specific purposes, recipients, and retention criteria appear in Sections 2, 5, and 7.
As stated in Section 6, we do not sell personal information or share it for cross-context behavioral advertising. We do not knowingly sell or share the information of persons under 16. Because the current Services do not conduct those activities, no sale or advertising-sharing activity needs to be stopped when your browser sends a Global Privacy Control signal. This statement is not a claim that such a signal disables necessary authentication or local storage.
You or an authorized agent can submit a rights request to develop@honoululuai.com. We may verify identity and authority before disclosing or deleting information. Where an appeal right applies, reply to our decision or email the same address with “Privacy appeal” and explain the issue; a review will consider the decision and the information you provide. We will give the outcome within the applicable deadline and explain available regulatory complaint routes if we deny the appeal.
10. Age restriction
Lorelit is intended for people 18 or older, or the higher age required to use the Services under local law. We do not intend to collect personal information from anyone below that minimum age. An age confirmation is self-reported and does not necessarily involve independent verification of identity or date of birth.
If you believe a person below the minimum age has provided information to Lorelit, contact develop@honoululuai.com. We will investigate and take appropriate steps to restrict access and delete information as required by law.
11. Changes and contact
We will update this policy when our practices change and show the effective date above. For material changes, we will provide an appropriate notice, such as an in-app notice or an email, before the change takes effect where required. We will obtain fresh consent where applicable law requires it; a policy update alone does not authorize a new incompatible use of previously collected information.
Privacy contact: develop@honoululuai.com
Controller: Honoululu Inc.
Postal address: 3524 Silverside RD STE 35B, Wilmington, DE 19810, United States
Annex A — AI and media services
The table below describes the generation services used by Lorelit. A service receives the information relevant to the feature you use; a single request is not necessarily sent to every service listed. The available feature, selected model, routing, and generation stage determine which services are involved.
| Service or processing route | Information processed for the request | Purpose | Further information |
|---|---|---|---|
| OpenRouter, Inc. and the model endpoints reached through OpenRouter | Prompts, relevant conversation and character context, selected persona and memory, generated responses, and request/usage metadata; image prompts or media where the selected feature uses them. | Generate text and suggestions, summarize context, prepare creative material, and generate images through supported models. | OpenRouter Privacy Policy, data-collection explanation, and upstream provider practices. The hosting provider for a model may differ from its developer. |
| GenLab media orchestration and its upstream generation services | Generation prompts, selected reference images or their URLs, generated media, task identifiers, service-specific account identifiers, and generation status. | Upload reference material, submit and track image or video jobs, and return or deliver generated assets. | The GenLab name identifies the orchestration service used in Lorelit's media pipeline. Its upstream service depends on the requested feature and model. Contact develop@honoululuai.com for information about the processing chain relevant to your request. |
| fal.ai and the model services used through fal.ai | Video prompts, reference-image URLs, generation parameters, generated video, task identifiers, and technical status information. | Generate and retrieve video scenes and continuations where that route is enabled. | fal Privacy Policy. The applicable model endpoint may impose additional conditions. |
These services may use infrastructure or model-hosting providers to process a request. A model brand shown in Lorelit identifies a model option, not necessarily the legal entity that hosts it. International processing is explained in Section 8; we do not assign one unverified storage country to all upstream endpoints.
The data categories in this table describe generation inputs and related records, not permission to send your entire account or unrelated private conversations to every provider. Provider retention and independent uses are addressed in Section 3. If the services or purposes materially change, we will update this policy and provide any notice or consent process required by law.