Legal

Privacy Policy

Last updated July 15, 2026

Lore is a company memory layer for AI agents. We help teams turn scattered internal knowledge from tools like Slack, Notion, GitHub, Gmail, Google Drive, Linear, Discord, Microsoft Workspace, and other workplace systems into structured company memory that authorized agents and users can query.

Because Lore works with internal company information, privacy, permissioning, and trust are core parts of the product. This Privacy Policy explains what we collect, how we use it, and how companies control the data they connect to Lore.

This policy may be updated as Lore matures.

Trust principles

  • We do not sell company data.
  • We do not train shared models on private company knowledge.
  • Customers control which tools and sources are connected.
  • Customers control which users, agents, and tokens can access their company memory.
  • We design Lore to respect source permissions, consent settings, and scoped access.

Information we collect

We collect different types of information depending on how you use Lore.

Waitlist, demo, and contact information

When you join the waitlist, request a demo, contact us, or communicate with Lore, we may collect your name, email address, company name, role, and any message or details you choose to provide.

Account information

When you create or use a Lore account, we may collect basic account information such as your name, email address, company or workspace membership, role, authentication status, and account settings.

Connected company data

When a company connects tools such as Slack, Notion, GitHub, Gmail, Google Drive, Linear, Discord, Microsoft Workspace, or similar services, Lore may process content from those tools only for the purpose of building, maintaining, securing, and serving that company's memory layer.

Connected company data may include messages, documents, pages, issues, pull requests, commits, comments, metadata, timestamps, source URLs, authorship information, and other content made available through the permissions granted by the customer.

Lore only processes connected sources according to the permissions, consent settings, and access scopes configured for that company.

Source and permission metadata

Lore may store metadata about connected sources, such as workspace IDs, channel names, page names, repository names, file names, source URLs, timestamps, access modes, and permission settings. This helps Lore preserve provenance, enforce access controls, and show where extracted knowledge came from.

Technical and usage information

We may collect technical information such as usage events, API activity, MCP token activity, connection status, error logs, performance metrics, system diagnostics, and security events. We use this information to operate, secure, debug, and improve Lore.

How we use information

We use information to:

  • respond to waitlist, demo, and contact requests
  • create and manage user accounts
  • connect approved company tools
  • apply source consent and permission settings
  • extract and structure company knowledge
  • build and maintain a company-specific memory layer
  • serve relevant context to that company's authorized users, agents, APIs, and MCP clients
  • show source provenance and review workflows
  • monitor reliability, performance, usage, and security
  • debug errors and improve the product experience

Lore does not sell company data.

Lore does not use a company's private knowledge to train shared models.

Company memory and agent access

Lore is designed to make company knowledge available through controlled interfaces such as dashboards, APIs, and MCP endpoints.

Companies are responsible for deciding which tools to connect, which permissions to grant, which sources to include, which users should have access, and which agents or tokens may query Lore.

Lore provides controls to help companies scope access. For example, companies may choose which sources to ingest, restrict repository-derived knowledge, revoke MCP tokens, and review extracted nodes before relying on them.

Source permissions and restricted knowledge

Lore is built to respect source-level access rules where supported.

Lore separates memory into company, team, and personal branches. A user can retrieve only branches they currently belong to. GitHub repository-derived knowledge also keeps its repository permission gate, and private chat sources must be explicitly assigned to a personal or team branch before Lore will ingest them.

If Lore cannot verify whether a user should have access to restricted knowledge, Lore is designed to fail closed rather than expose that information.

Consent and filtering

Lore uses consent and filtering controls to decide what information may be retained and processed.

By default, Lore ingests only positively classified public company sources. Private channels, direct messages, and group messages are excluded unless a verified Slack invitation/direct message routes the source to personal memory or an admin assigns the exact source to a team memory branch. Externally shared conversations and content that cannot be positively classified remain excluded.

Lore also applies safety protections such as secret redaction, pseudonymization, sensitive-content review, and extraction leak scanning where available. These protections are designed to reduce the risk of storing credentials, tokens, or sensitive personal information.

Third-party connections

Lore connects to third-party services through official APIs where available. Examples may include Slack, Notion, GitHub, Gmail, Google Drive, Linear, Discord, Microsoft Workspace, and similar systems.

Access to those services is based on permissions granted by the customer or user. These permissions can typically be changed or revoked through the connected service.

When a third-party connection is removed or revoked, Lore may no longer be able to sync new information from that service. Existing information already processed by Lore may remain until deleted, expired, archived, or removed according to the company's data controls.

Model providers and AI processing

Lore may use AI model providers to extract, summarize, classify, embed, or retrieve company knowledge. When we use model providers, the purpose is to provide Lore's service to the customer.

Lore does not use a customer's private company knowledge to train shared models.

Data control and deletion

Customers should be able to control which systems are connected to Lore, which sources are ingested, which users or agents have access, and which tokens are active.

As Lore matures, we will continue improving controls for visibility, permissioning, deletion, retention, auditability, and data management.

Customers may request deletion or removal of connected data by contacting Lore.

Security

We take reasonable steps to protect the information processed by Lore. Because Lore may handle sensitive company knowledge, security is a core product priority.

Security measures may include scoped access controls, token revocation, source consent, secret redaction, restricted-source filtering, encryption where appropriate, logging, monitoring, and internal access limits.

As an early-stage product, we will continue improving and documenting our security practices as the service matures.

Data sharing

We do not sell personal information or company knowledge.

We may use trusted service providers to operate Lore, such as hosting, infrastructure, databases, analytics, communication, authentication, security, and AI processing providers. These providers should only access information as needed to help us provide, secure, and improve the service.

We may also disclose information if required by law, regulation, legal process, or to protect the rights, safety, and security of Lore, our users, customers, or others.

Data retention

We retain information for as long as needed to provide Lore, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support customer-controlled company memory.

Retention periods may vary depending on the type of information, customer configuration, connected source, and product settings.

Processed raw connector payloads are deleted after seven days by default. Structured knowledge and minimal provenance remain until the customer deletes them, withdraws source consent, or the applicable retention rule removes them.

Changes to this policy

We may update this Privacy Policy as Lore evolves. If we make meaningful changes, we will update the date at the top of this page.

Contact

Questions about this Privacy Policy can be sent to:

info@loreai.io