Skip to main content

Privacy Policy

Last updated: August 24, 2026

Overview

This Privacy Policy explains how Lore Studio LLC d/b/a Verant ("Lore Studio," "Verant," "we," "us," or "our") collects, uses, and shares information when you visit our website or use our AI‑powered proofreading and verification services (the "Services"). This policy applies to "personal information" as defined under applicable laws (e.g., CCPA/CPRA, GDPR/UK GDPR, and the Texas Data Privacy and Security Act (TDPSA)). If you do not agree with this policy, do not use the Services.

Contact: support@verant.ai
Mailing address: 5900 Balcones Drive #11919, Austin, TX 78731, USA.
See also our Terms of Service.

Information We Collect

  • Account Information: Email address and basic profile data when you create an account and authenticate with our sign-in flow.
  • Payment Information: Subscriptions are processed by Stripe. We receive records such as your Stripe customer ID and subscription status, but we do not store full payment card numbers.
  • Content You Submit: URLs you scan, rendered webpage text/markdown, and proofreading results necessary to provide the Services. If your content contains personal information (e.g., names, emails), you represent that you have a lawful basis to process it. We process only what is needed to provide the Services and advise against submitting sensitive personal information (e.g., health or financial data) unless you have a lawful basis and appropriate safeguards. Anonymous trial scans are deleted about 30 days after they run. Scans on a signed-in account stay until you delete them or close the account.
  • Logs and Usage Data: IP address, request identifiers, timestamps, and limited diagnostic and performance data (e.g., browser type, coarse device information) for security, fraud prevention, and reliability. Anonymous scans use Cloudflare Turnstile to stop automated abuse before paid processing starts; Cloudflare's Turnstile Privacy Addendum explains that processing. We also use application logs, privacy‑aware Cloudflare platform telemetry, and Visitors analytics to monitor site use, performance, and service quality. Visitors receives the page URL, referrer, browser and operating-system information, approximate location, and Core Web Vitals. It also records selected product actions, such as starting or completing a scan and opening checkout. It uses the IP address and user agent to make a daily salted signature, then discards the IP address except for short-lived abuse controls.
  • Cookies and Similar Technologies: Essential cookies (e.g., authentication session cookies) operate the Service. Visitors persist mode stores a first-party visitor identifier so we can understand repeat visits and conversion journeys. When you sign in, we send your account id and email to Visitors so activity and Stripe revenue can be connected to your profile. Custom events do not contain scanned URLs or page copy. Visitors sends no analytics event when your browser has Global Privacy Control or Do Not Track enabled. We currently do not use advertising cookies. If we introduce non-essential cookies, we will obtain consent where required and update this policy and our disclosures.

How We Use Information

  • Provide, secure, and improve the Services.
  • Authenticate users and manage subscriptions and billing.
  • Process your content to generate proofreading results you request.
  • Monitor performance, debug, and prevent abuse or fraud.
  • Comply with legal obligations and enforce our Terms.
  • We practice data minimization and collect/process only what is necessary for the purposes above.
  • We do not use your data for automated decision‑making that produces legal or similarly significant effects (e.g., ADMT under CCPA/CPRA).

Use of AI and Browser Rendering

We render pages via Cloudflare Browser Rendering and route proofreading to third‑party AI providers through an AI gateway (which may include xAI, Anthropic, and OpenAI). We do not use your content to train our or third‑party foundation models, and we request provider settings that disable data retention and training where available. Providers maintain their own privacy policies; see xAI, Anthropic, and OpenAI. Where applicable, we comply with transparency obligations for general‑purpose AI (e.g., EU AI Act GPAI), including disclosing providers and intended use.

Legal Bases (EEA/UK)

  • Contract: to provide the Services you request.
  • Legitimate interests: to secure, operate, improve, and measure the Services, including Visitors analytics.
  • Consent: where required, for optional analytics or communications.
  • Legal obligation: to meet tax, accounting, and compliance requirements.

How We Share Information

  • Service Providers/Sub‑processors: Stripe (billing), Cloudflare (hosting, D1 database, R2 object storage, browser rendering, platform telemetry, and transactional email delivery), Better Auth Cloud (hosted authentication dashboard at dash.better-auth.com), Google (OAuth sign-in), Visitors (persistent website analytics, profiles, conversion, revenue, and performance measurement), and AI providers (xAI, Anthropic, OpenAI) via our gateway.
  • We require sub‑processors to be bound by data protection terms and implement appropriate safeguards (e.g., encryption in transit, access controls).
  • We do not sell or share personal information for cross‑context behavioral advertising.
  • Business transfers: as part of a merger, acquisition, or asset sale (we will provide notice of material changes where required by law).
  • Legal compliance and safety: to comply with law or protect rights and safety.
  • Aggregated or de‑identified data that cannot reasonably identify you may be used or shared.

International Transfers

We are based in the United States and may process information in the U.S. and other countries. Where required, we rely on appropriate safeguards (e.g., Standard Contractual Clauses, and where applicable, the EU‑U.S. Data Privacy Framework or UK‑U.S. extension for participating providers) and conduct transfer assessments as appropriate.

Retention

  • Account data: retained while your account is active and as needed for our records.
  • Anonymous trial scans: deleted about 30 days after they run. Account scans: kept until you delete them or close your account.
  • Server and request logs: target retention ≤ 30 days.
  • Billing records: retained as required by tax and accounting law.
  • Visitors analytics events and session aggregates: retained while our Visitors project is active; performance measurements are deleted by Visitors after one year. Deleting the Visitors project or account removes its analytics data.
  • We review retention periods at least annually to align with data minimization principles.

Security

We employ technical and organizational measures appropriate to the risk, including transport encryption, access controls, and least‑privilege principles. We conduct periodic security reviews and use pseudonymization where feasible. No method of transmission or storage is 100% secure.

Your Rights

Depending on your location, you may have rights to access, correct, delete, or receive a copy of your data, and to object to or restrict certain processing. You can exercise rights by contacting support@verant.ai. We may request information to verify your identity and will respond within 45 days (or as required by law), with a possible 45‑day extension where permitted.

GDPR/UK GDPR: You have rights of access, rectification, erasure, portability, restriction, and objection, and the right to lodge a complaint with your data protection authority.

CCPA/CPRA (California): We do not sell or share personal information for cross‑context behavioral advertising. You may request to know, delete, or correct personal information, and to limit the use and disclosure of sensitive personal information. Authorized agents may act on your behalf. We honor applicable opt‑out mechanisms (e.g., Global Privacy Control) where relevant.

TDPSA (Texas): Texas residents may have rights to access, correct, delete, and opt out of sales, targeted advertising, or profiling for decisions that produce legal or similarly significant effects, and the right to be free from discrimination for exercising rights.

Do Not Sell/Share My Personal Information; Targeted Advertising

We do not sell or share personal information for cross‑context behavioral advertising or engage in targeted advertising. If this changes, we will update this Policy and provide a "Do Not Sell/Share My Personal Information" mechanism and honor Global Privacy Control signals where applicable.

Third‑Party Links

Our Services may link to third‑party websites or services. Their privacy practices differ from ours; review their policies.

Children's Privacy

The Services are not directed to children under 13. If we learn a child under 13 provided personal information, we will delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice (e.g., email, in‑app, or on our website). The "Last updated" date above reflects the effective date. Continued use of the Services after changes become effective constitutes acceptance.

Controller and Contact

Lore Studio LLC d/b/a Verant
5900 Balcones Drive #11919
Austin, TX 78731, USA
support@verant.ai