Effective 8 August 2026
Privacy Policy
What TwoLore stores, why it is needed, and the choices available to creators.
Data we process
Creator data includes account details, project content, uploads, purchase records, support messages, and limited security logs. Recipient data is limited to short-lived access-session tokens needed to open a protected gift.
Access answers are stored in the cloud only as one-way hashes. Private media is stored in a private bucket and served through short-lived signed links.
Why we process it
We process data to provide the contract, protect private sites, process payments, prevent abuse, provide support, meet legal duties, and improve the product with consented analytics.
Processors and transfers
TwoLore uses infrastructure and service providers such as Vercel, Supabase, Stripe, Brevo, Resend, and Sentry. PostHog is used only when optional analytics is configured and accepted. Each provider processes only the data needed for its role. International transfers use the safeguards offered by those providers and applicable law.
Retention
Inactive unpaid cloud drafts are deleted after 6 months. When paid hosting expires, recipient access ends and the associated content is retained for 30 days so the creator can renew or export it. Deleted content may remain in encrypted backups for up to 14 additional days.
Security events are retained for 6 months unless a longer period is needed to investigate abuse or meet a legal duty. Payment, accounting, and tax records are retained for the period required by law. Browser-only drafts remain on the creator's device until that browser storage is cleared.
Your rights
You can export or delete your account from Account Settings. Depending on where you live, you may also request access, correction, restriction, portability, or objection by contacting support@twolore.com.