Launch policy draft
Privacy Policy
What TwoLore stores, why it is needed, and the choices available to creators and recipients.
Data we process
Creator data includes account details, project content, uploads, purchase and domain records, support messages, and limited security logs. Recipient data includes access-session tokens and the replies they intentionally submit.
Access answers are stored in the cloud only as one-way hashes. Private media is stored in a private bucket and served through short-lived signed links.
Why we process it
We process data to provide the contract, protect private sites, process payments, prevent abuse, provide support, meet legal duties, and improve the product with consented analytics.
Processors and transfers
TwoLore uses infrastructure and service providers such as Vercel, Supabase, Stripe, Resend, Entri and its registrar partners, Sentry, and PostHog. Each provider processes only the data needed for its role. International transfers use the safeguards offered by those providers and applicable law.
Retention
Active project content is retained while hosting or a creator account is active. Deleted content is removed from live systems and then expires from backups under the backup schedule. Payment and tax records may be retained for the period required by law after direct identifiers are removed.
Security events are retained for a limited fraud and incident-response period. Precise production periods must be approved in the launch legal checklist before public checkout.
Your rights
You can export or delete your account from Account Settings. Depending on where you live, you may also request access, correction, restriction, portability, or objection by contacting support@twolore.com.