Privacy Policy
LorelAI Privacy Policy
Effective date: June 26, 2026
This policy explains how Helixiora handles personal data for LorelAI, including the LorelAI web app, API, mobile app, Slack bot, connected data pipelines, demo requests, and the public website where this policy is published.
1. Who we are and scope
LorelAI is provided by Helixiora, a company registered in the Netherlands. This policy applies to LorelAI websites, including lorelai.app and www.lorelai.app, the LorelAI product at app.lorelai.app, the LorelAI API at api.lorelai.app, the mobile app, Slack bot features, and customer deployments unless a customer agreement or data processing agreement says otherwise.
For customer workspace content that an organization connects to LorelAI, Helixiora generally acts as a processor and processes that data on the customer's instructions. For website use, demo requests, commercial communications, account administration, service security, and legal compliance, Helixiora acts as a controller.
2. Personal data we process
The categories of personal data depend on how a customer configures LorelAI and which integrations are enabled. They may include:
- Demo and contact details, such as your work email address, name, organization, message content, and related communications.
- Account and profile data, such as email address, full name, avatar, role, organization membership, active status, email verification status, optional profile fields, and Google account identifiers when Google sign-in is used.
- Authentication and security data, including password hashes, API key hashes and fingerprints, refresh-token hashes, session cookie metadata, OAuth state, device names, sign-in events, and abuse-prevention metadata.
- Customer knowledge content, including datasets, dataset items, source metadata, Google Drive file metadata and extracted text, Slack channel or thread metadata and message content selected for indexing, uploaded documents, document chunks, embeddings, and indexing job state.
- Chat and AI interaction data, including chat threads, prompts, assistant responses, source references, feedback, response timing, provider response identifiers, selected model profile, tool-use summaries, and verification or review workflow activity.
- Integration configuration and secrets, including Google Drive, Slack, MCP server settings, OAuth tokens, bearer tokens, provider API keys, SendGrid configuration, and related connection metadata. Secrets stored by LorelAI are encrypted or hashed as appropriate.
- Mobile and notification data, including notification content, read state, preferences, APNs or FCM device tokens, device platform, and device name when push notifications are enabled.
- Technical, analytics, and observability data, such as IP address, device and browser information, request metadata, page views, product events, diagnostic events, error reports, traces, logs, and security monitoring records.
3. Connected sources and AI processing
LorelAI can connect to customer-authorized knowledge sources. Native data sources include Google Drive and Slack. LorelAI also supports MCP servers, including catalog entries such as Google Drive, Slack, Linear, Notion, Atlassian, Asana, ClickUp, HubSpot, GitHub, Sentry, Stripe, Supabase, Vercel, Cloudflare, Box, Context7, custom MCP servers and customer-configured sources. Availability depends on product configuration, organization policy, provider availability, and the permissions granted by the user or customer.
Connected data may be indexed into PostgreSQL/pgvector by extracting text, splitting it into chunks, generating embeddings, and storing source metadata. At chat time, LorelAI retrieves relevant chunks and may call approved MCP tools to answer a user's question, show source references, and support review or verification workflows.
LorelAI uses database-backed LLM profiles and embedding profiles. Chat providers are OpenAI-compatible endpoints selected by the customer, super admin, or user where the product permits personal profiles. Prompts, retrieved context, source snippets, and tool results may be sent to the selected AI provider as needed to generate an answer. Embedding providers receive text chunks as needed to create searchable vectors.
We do not sell customer data. We do not use customer workspace content to train public AI models unless this is expressly agreed with the customer. Third-party AI, integration, hosting, storage, observability, and communication providers process data only as needed to provide the configured service and subject to the applicable customer agreement.
LorelAI is designed to assist users with finding and understanding internal knowledge. It is not intended to make solely automated decisions that produce legal or similarly significant effects about individuals.
4. How we use personal data
We process personal data to:
- provide, operate, maintain, and secure LorelAI
- create and administer user accounts, organizations, roles, sessions, and access controls
- connect authorized data sources, preserve configured permissions, and keep datasets indexed
- generate answers, citations, summaries, source references, and verification workflows
- operate the Slack bot, mobile app, push notifications, email verification, and password reset flows
- respond to demo requests, support requests, and business communications
- debug issues, monitor reliability, prevent abuse, and protect the service
- meet contractual, legal, tax, accounting, and compliance obligations
- improve product quality, where permitted by agreement and applicable law
Our legal bases may include performance of a contract, steps taken before entering into a contract, legitimate interests, consent where required, compliance with legal obligations, and customer instructions where we act as processor.
5. Cookies, analytics, and tracking
The LorelAI product uses essential cookies and similar technologies for authentication, refresh sessions, CSRF and origin protections, OAuth flows, preferences, security, and integration flows. Browser authentication cookies are designed to be HttpOnly and host-only on the API origin. The mobile app uses token-based authentication and may store tokens locally using platform secure-storage mechanisms.
Product deployments can use Sentry for error and performance monitoring, including optional replay features when configured, and PostHog for product analytics when configured. Sentry's default PII sending is disabled in the app configuration unless explicitly changed by an operator. PostHog can receive page views, product events, user identifiers, and organization identifiers to understand product usage.
The public marketing website at lorelai.app and www.lorelai.app is a containerized Next.js site. This repository does not include third-party analytics or error tracking scripts for that marketing site. It may load media through third-party delivery services, including Unsplash and Cloudflare R2-hosted assets, and server infrastructure may create standard request and security logs.
6. Sharing and processors
We share personal data only where needed to provide LorelAI, operate the website, comply with law, or follow customer instructions. Recipients may include:
- hosting, reverse proxy, DNS, container registry, and deployment infrastructure providers
- PostgreSQL/pgvector database infrastructure and backup systems used to store application data, extracted text, chunks, and embeddings
- AI and embedding providers configured through OpenAI-compatible LLM profiles or embedding profiles
- Google services for Google sign-in, Google Picker, Google Drive access, and Google Drive webhook notifications
- Slack services for OAuth, indexed Slack content, Slack bot functionality, and Slack event webhooks
- MCP providers selected by users or organizations, including hosted catalog providers and custom MCP servers
- Sentry for error monitoring, performance diagnostics, and optional replay features when configured
- PostHog for product analytics when configured
- LangSmith for LangGraph/RAG tracing when configured
- SendGrid for transactional email such as email verification, password reset, and account emails when configured
- Apple Push Notification service and Firebase Cloud Messaging for mobile push notifications when enabled
- Grafana Synthetic Monitoring or similar monitoring tools used to check service health
We may also disclose information to professional advisers, authorities, or other parties where required by law or necessary to protect rights, users, customers, and service security.
7. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit, restricted access controls, least-privilege operational access, protection of integration credentials, logging, backups, deployment-level separation, rate limits, and origin checks. Passwords, API keys, and refresh tokens are stored as hashes where the plaintext is not needed after issuance. Datasource credentials, MCP tokens, OAuth secrets, SendGrid API keys, and runtime-provider API keys are encrypted when stored by LorelAI.
Google Drive and Slack webhooks are protected with provider verification mechanisms. MCP server URLs, transports, allowed tools, and OAuth state are validated and controlled by platform and organization policy. No system is perfectly secure, but we work to limit access to people and systems that need it for legitimate operational purposes.
8. Retention
Customer workspace content is retained according to the customer agreement, product configuration, and deletion instructions. Datasets, source metadata, extracted text, chunks, embeddings, chat history, credentials, model profiles, MCP settings, notifications, and audit or job records are retained while needed to provide the configured service or until deleted according to the applicable product workflow.
Demo, support, security, billing, and legal records are retained only for as long as needed for the purposes described in this policy unless a longer period is required by law. Backups, logs, and monitoring records may remain for a limited period before routine expiry.
9. International transfers
Helixiora is based in the Netherlands. Depending on the customer configuration and the processors used for a deployment, personal data may be processed in countries outside the European Economic Area. Where required, we use appropriate safeguards such as adequacy decisions, standard contractual clauses, data processing agreements, and transfer impact measures.
10. Your privacy rights
Depending on your location and the processing at issue, you may have the right to:
- access the personal data we hold about you
- ask us to correct inaccurate or incomplete personal data
- ask us to delete personal data where applicable
- ask us to restrict processing in certain circumstances
- receive personal data in a structured, commonly used format where portability applies
- object to processing based on legitimate interests or direct marketing
- withdraw consent where processing is based on consent
If your personal data is part of a customer workspace, please contact that organization first because it usually controls the relevant source system and LorelAI workspace. You can also contact us, and we will route the request appropriately where we act as processor.
You can submit access, deletion, correction, portability, restriction, objection, consent withdrawal, and other privacy requests through the LorelAI privacy request form.
You also have the right to lodge a complaint with a data protection authority. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens.
11. Children
LorelAI is a business product and is not directed to children. We do not knowingly collect personal data from children through the public website.
12. Changes to this policy
We may update this policy when LorelAI, our technology, or legal requirements change. We will update the effective date and, where appropriate, provide additional notice.
13. Contact
Questions about this policy or privacy requests can be sent to Helixiora at hello@helixiora.com, or submitted through the privacy request form.
Helixiora, Scharlakenhof 7, 2272 JV Voorburg, Netherlands.