TwoLore

Launch policy draft

Privacy Policy

What TwoLore stores, why it is needed, and the choices available to creators and recipients.

Effective date to be set before public checkout. This operational draft must be reviewed against the final legal entity, tax registrations, processor contracts, and launch countries.

Data we process

Creator data includes account details, project content, uploads, purchase and domain records, support messages, and limited security logs. Recipient data includes access-session tokens and the replies they intentionally submit.

Access answers are stored in the cloud only as one-way hashes. Private media is stored in a private bucket and served through short-lived signed links.

Why we process it

We process data to provide the contract, protect private sites, process payments, prevent abuse, provide support, meet legal duties, and improve the product with consented analytics.

Processors and transfers

TwoLore uses infrastructure and service providers such as Vercel, Supabase, Stripe, Resend, Entri and its registrar partners, Sentry, and PostHog. Each provider processes only the data needed for its role. International transfers use the safeguards offered by those providers and applicable law.

Retention

Active project content is retained while hosting or a creator account is active. Deleted content is removed from live systems and then expires from backups under the backup schedule. Payment and tax records may be retained for the period required by law after direct identifiers are removed.

Security events are retained for a limited fraud and incident-response period. Precise production periods must be approved in the launch legal checklist before public checkout.

Your rights

You can export or delete your account from Account Settings. Depending on where you live, you may also request access, correction, restriction, portability, or objection by contacting support@twolore.com.