LoveLore is built for a handful of people, never an audience. This policy explains what we collect, why, who can see it, and the choices you have. It's run by Henfish LLC (“LoveLore”, “we”, “us”). Questions? Email [email protected].
The short version
- Your sites are private — only people an admin invites can see them.
- We don't sell your data, show ads, or use trackers or analytics.
- We don't use your photos or words to train AI.
- Location data is removed from photos when you upload them.
- You can ask us for a copy of your data, or to delete it, any time.
1. What we collect
Your account
- Name and email address — to identify you and let you sign in. We email you only about your account and orders: confirming your address, resetting your password, and order updates — never marketing without asking.
- Password — stored only as a one-way hash (scrypt). We never see or store your actual password.
What you add to sites
- Photos, captions, moments and milestones, letters, and the site's story (names, dates, the letter, quiz, reasons, gifts).
- Things you choose on a site — for example your quiz answers, gift choices and note on a Love Story, or letters you write on a Family Album.
- Information about other people that you include, such as a partner's name, a child's name and birthday, or people in photos. Please only add this if you have the right to (see our Terms).
Sites and invitations
- Which sites you're part of and your role on each (admin or viewer).
- Invites: who created them, the role, an optional label (like “Grandma”) and when they expire. We store only a scrambled (hashed) version of each invite link's secret, not the link itself.
- When you last opened each site, so your dashboard can show what's new.
Family trees
- Admins can add people to a site's family tree (names, years, a portrait from the site's photos, and how they're related). If two families link their sites — both admins must agree — each side sees the other's tree, and the albums the other side chose to share. Either side can unlink at any time. Admins can also tag people from the tree in photos (by name, optionally at a spot in the photo). We don't use face recognition.
Guest uploads
- If you share photos through a site's guest upload link or QR code, we store the photos and the name you type, so the site's admins know who shared them. You don't need an account.
Orders and payments
- If you order prints or keepsakes, or pay for a plan, we keep what you ordered, the amounts, and the order's status. For orders we also keep the name, shipping address and phone number you give at checkout (the phone number is only for the delivery carrier), and a copy of the photos in the order, so it can be made even if the photos are later removed from the site.
- Payments are handled by Stripe. We never see or store your full card number — we receive only a payment reference, the amount, and the details above.
Reports
- If you report a problem, we keep your report (the reason and details you give), your name or email so we can follow up, and which site or photo it's about. Reports are seen only by our team.
Technical information
- IP address — used to limit repeated sign-in and sign-up attempts (these counters are kept in our database for up to an hour, then deleted), and recorded with sign-in, sign-up and password-change events in our activity log for security.
- Activity log — a record of actions such as signing in, creating or deleting a site, inviting or removing people, and adding or deleting photos, moments and letters (who, what, when — never the photos or text themselves). A site's admins can see the activity on their site, without IP addresses. It's kept for 90 days.
- Server logs — like most websites, our hosting provider records requests (IP address, browser, page and time) to keep the service running and secure. These are kept for a limited period.
- Error reports — when something breaks on our side, we record what went wrong and on which page address, so we can fix it. They don't include your photos or what you wrote. Fixed ones are deleted.
- Passkeys — if you add one, we store its public key, a name (like “iPhone”) and when it was last used. The private key and your Face ID, fingerprint or screen lock never leave your device.
2. Photos
When you upload a photo we remove its hidden metadata — including GPS location — and store it privately in three sizes: a full-resolution copy (kept so the photo can be printed later; it isn't shown on sites) and two smaller copies for viewing. We keep the date the photo was taken so the album can sort it, and the photo's color profile so prints look right. Each time a photo is shown, we check that the person asking is a member of that site, then give their browser a private link to the file that stops working within two hours. Deleting a photo deletes all three copies.
3. How we use it
- To provide LoveLore: show your sites to the people on them, store your content, sign you in.
- To keep it safe: prevent abuse, spam and unauthorized access, and investigate problems.
- To make and ship your orders, and to process payments and refunds.
- To email you about your account (confirming your email, password resets, invites someone sends you, orders) and — unless you turn them off in Account settings — about activity on your sites, like a new letter or new photos.
- To support you when you contact us.
- To comply with the law and enforce our Terms.
We don't sell or rent your information, we don't use it for advertising, we don't build profiles of you, and we don't use your content to train artificial-intelligence models.
4. Who can see your information
- People on the same site. Everyone on a site can see its content. Your name appears where it's relevant (for example “From Sam” on a letter or “Shared by Sam” on a dashboard). Admins of a site can see the names and email addresses of its members, and your answers or letters on that site (except letters still sealed — until their date, only the person who wrote one can read it).
- Our team. A small number of people who run LoveLore can access accounts and site content — including sealed letters — but only when needed to operate or secure the service, help you when you ask, or meet a legal obligation.
- Service providers who work for us under contract: DigitalOcean (servers, database and photo storage), Stripe (payments) and Resend (sending our emails — your address and the message). When you order a print, a print partner receives the photos in your order and your shipping name and address to make and ship it. They may only use your data to provide their service to us.
- When the law requires it — for example a valid legal request, or to report child sexual abuse material to NCMEC and law enforcement — or to protect someone from serious harm.
- If LoveLore changes hands (for example a merger or sale), your information may transfer to the new owner, who must keep honoring this policy or tell you before changing it.
5. Cookies and local storage
We use only what's needed for LoveLore to work — no advertising or analytics cookies:
lovelore_session— keeps you signed in. It lasts up to 90 days or until you sign out, and can't be read by scripts on the page.lovelore_webauthn— only while you add or use a passkey: a one-time challenge that expires after five minutes.lovelore_guest— only if you share photos through a guest upload link: a random ID (for up to a year) so a link's “photos per guest” limit works. It isn't linked to an account.- Local storage — on a Love Story, your browser remembers whether you've already opened the letter, so it doesn't show the envelope every visit. This stays on your device.
Fonts are served from our own servers. If a site admin adds a music link hosted somewhere else, your browser loads that file from the other website, which may see your IP address.
6. Where your data is stored
LoveLore is hosted on DigitalOcean. Your data may be stored and processed in the United States or other countries where our providers operate, which may have different data-protection laws from where you live. Where required, we use appropriate safeguards for these transfers.
7. How long we keep it
- Your account — until you delete it (or ask us to).
- Site content — until an admin deletes it or the site is deleted. If you leave a site, content you added to it (such as a letter) stays on that site unless you or an admin delete it.
- Invites — until they're used, revoked or the site is deleted.
- Orders and payment records — as long as the law requires us to keep them for tax and accounting (usually 7 years). The photo copies kept with an order are deleted about a year after it's delivered.
- Sign-in / sign-up counters — up to 1 hour, in memory.
- Activity log (including IP addresses on sign-in events) — 90 days.
- Reports — up to 2 years after they're resolved. Content we're legally required to preserve (for example after a report to NCMEC) is kept, hidden, for as long as the law requires.
- Backups — deleted data may remain in backups for up to 30 days before it's overwritten.
8. Security
We hash passwords, keep photos in private storage, encrypt connections with HTTPS, check access on every page and photo, limit repeated sign-in attempts, and give our team access only when needed. No system is perfectly secure, so please use a strong, unique password. If we learn of a breach affecting your information, we'll notify you as the law requires.
9. Your rights and choices
- See and correct — you can change your name in Account settings. For anything else, email us.
- Get a copy of your information.
- Delete your account (Account settings) or a site you own (Studio → Settings). Deleting your account deletes your login, the sites only you run, and letters you wrote.
- Leave a site you were invited to, any time, from your dashboard.
- Object or restrict certain uses of your information, where the law gives you that right.
Email [email protected] to make a request. We'll respond within 30 days (sooner where the law requires) and may need to confirm it's really you. We won't treat you differently for using your rights. Depending on where you live (for example the EU, UK or California), you may also have the right to complain to your local data-protection authority.
For people in the EU and UK: we process your information to provide the service you signed up for (our contract with you), for our legitimate interests in keeping LoveLore secure and preventing abuse, and to meet legal obligations. Henfish LLC is the controller of your account information. For content on a site, the site's admins decide what's shared and with whom.
For California residents: we don't sell or share personal information for cross-context behavioral advertising, and we don't use sensitive personal information to infer characteristics about you.
10. Children
LoveLore isn't directed to children under 13, and we don't knowingly let children under 13 create an account. Family Albums may contain photos and details of children, added by their parents, guardians or people they've trusted — that content is controlled by the album's admins. If you're a parent or guardian and want information about your child removed, or believe a child under 13 has an account, email [email protected] and we'll take care of it.
11. Changes to this policy
If we change this policy in a meaningful way, we'll let you know on LoveLore (and by email once we send email) before the change takes effect. The date at the top shows the latest version.
12. Contact
Henfish LLC
[email protected]