Privacy
Last updated 6 August 2026
The short version: the audio from your table never leaves your computer. Your transcripts and notes are files on your own disk. When LoreMonkey uses an AI feature it sends relevant text to our server, which passes it to the model provider and sends the answer back. We do not sell your data or use it for advertising.
Who we are
LoreMonkey is operated by LoreMonkey in Sweden, which is the controller of the personal data described here. For anything in this policy, write to hello@loremonkey.com.
What stays on your computer
These parts of LoreMonkey run entirely on your machine and send nothing anywhere:
- Audio. Sound from your table or your Discord call is captured, turned into text, and discarded. It is not recorded to a file and it is not uploaded.
- Transcripts. The text of your session is written to your own disk, in your LoreMonkey folder. You can read, back up or delete those files yourself.
- Your campaign notes. Character sheets, campaign files and any archive you import stay in that same folder.
- Archive search. When LoreMonkey looks something up from an old session, that search happens locally against your own files.
- Speaker attribution. Working out who is talking uses the Discord client already running on your computer. Nothing joins your voice channel and no audio is sent to Discord by us.
What we receive
The AI features need a model, and the model is not on your computer. When one of them runs, LoreMonkey sends the following to our server, which forwards it to our model provider and returns the answer:
- A recent extract of the session transcript, including the character names you have tagged people with.
- A compressed version of your campaign and character notes.
- Passages your own archive search picked out as relevant.
- For Ask LoreMonkey, the question you typed and the thread it belongs to.
This happens when LoreMonkey checks whether the moment needs a suggestion, when you ask a question, when you generate context files from your documents, and when you ask for a session recap. It does not happen continuously, and the activity log in the app shows you every time it does.
We use that content to produce the answer and to count usage against your plan. LoreMonkey does not use it to train models, sell it or share it for advertising. Anthropic states that API inputs and outputs are not used for model training by default.
LoreMonkey's server forwards each request without writing its prompt or response to the account database. It stores usage metadata such as the feature used, model name, token counts, cost and whether a live prompt was delivered. Under Anthropic's standard API policy, inputs and outputs are deleted from its systems within 30 days. Anthropic lists limited exceptions for legal obligations and usage-policy enforcement.
Your account
We hold the small amount of information an account needs:
- Your email address, and a hashed password if you signed up that way.
- Your Discord or Google account identifier, if you signed in with one of those. We do not get your password from them.
- Which plan you are on and when it renews.
- Counters of how much of your plan you have used this month.
Payments
Subscriptions are handled by Stripe. Your card details go to Stripe and never to us. We receive the fact that a payment succeeded, which plan it was for, and when it renews or ends. Stripe processes that data under its own privacy policy.
Who else is involved
- Anthropic receives the text described above in order to generate a response.
- Railway hosts the server that sits between the app and the model.
- Stripe processes payments.
- Google and Discord, only if you choose to sign in with them.
- Cloudflare serves this website and counts its page views.
This website itself sets no cookies and runs no advertising or third party trackers. We use Cloudflare Web Analytics, which counts page views without cookies and without building a profile of you.
Some of these providers are outside the European Economic Area, so handling your data can involve sending it to a country with different privacy laws. Where an EEA transfer needs a safeguard, we use the provider's applicable data-processing terms and EU standard contractual clauses. Contact us if you want more information about a particular transfer.
Why we are allowed to hold it
Under the GDPR we need a reason for each thing we do with your data. Ours are straightforward. We process your account details and the content you send to an AI feature because we need to in order to give you the service you signed up for. We keep short operational logs and usage counters because we have a legitimate interest in keeping the service working, stopping abuse and billing correctly. We keep payment records because the law requires it.
The other people at your table
LoreMonkey transcribes a conversation that other people are part of, and they have not agreed to anything with us. Tell your group that the session is being transcribed, before you start. In some places that is the law, and everywhere it is the decent thing to do.
If someone at your table wants their part of a session removed, the transcript is a file on your computer and you can delete it. If you believe content about you was sent to us by someone else and you want it dealt with, write to hello@loremonkey.com.
What you can ask us to do
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete your account and everything attached to it. Email hello@loremonkey.com and we will deal with it within 30 days. Deleting your account does not touch the files on your own computer, because we never had them.
You can also object to processing we base on legitimate interests, ask us to restrict it, or ask for your data in a portable form. If you think we have handled your data badly, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), or to the data protection authority in the EU country you live in.
Children
LoreMonkey is not intended for children under 13, and we do not knowingly create accounts for them.
Changes
If this policy changes in a way that matters, we will say so in the app rather than quietly editing this page. The date at the top always reflects the current version.