Privacy Policy

Last updated: October 1, 2026

Bilan — Privacy / Confidentialité

English

Bilan reads only the Apple Health categories the user chooses to make accessible. HealthKit-derived measurements, local reports, the emergency card and sharing history remain in the app's local container. Bilan does not require an account, does not use advertising or tracking SDKs, does not send HealthKit-derived data to LorisLabs servers and does not store it in iCloud or CloudKit.

The user can manually create a PDF, CSV, JSON or text snapshot and then chooses a destination in Apple's system share sheet. Once the user shares a copy with another person or service, Bilan cannot recall that external copy. On iPhone and iPad, “Delete all local data” removes Bilan's local SwiftData records, imported document library and its encryption key, emergency card, sharing history, preferences, access ledger, temporary exports, pending/delivered notifications and legacy Bilan keychain items. It does not alter records stored by Apple Health, original files selected for import, or copies already transferred to another device.

The optional Mac companion receives an archive only after the user starts a local transfer and confirms the pairing code on both devices. The transfer is encrypted directly between the selected Apple devices on the local network; it does not pass through or remain on a LorisLabs server. A received archive remains in the Mac app's local container until the user deletes it.

The optional Foundation Models assistance runs on device when supported. Deterministic validation remains authoritative, and the model cannot share data automatically or provide a diagnosis.

Français

Bilan lit uniquement les catégories d’Apple Santé que vous choisissez de rendre accessibles. Les mesures issues de Santé, les rapports locaux, la carte d’urgence et l’historique de partage restent dans le conteneur local de l’application. Bilan ne nécessite pas de compte, n’utilise pas de publicité ni de SDK de suivi, n’envoie pas ces données aux serveurs de LorisLabs et ne les stocke pas dans iCloud ou CloudKit.

Vous pouvez créer manuellement un export PDF, CSV, JSON ou texte, puis choisir sa destination dans la feuille de partage d’Apple. Bilan ne peut pas rappeler une copie que vous avez partagée avec une autre personne ou un autre service.

Sur iPhone et iPad, « Supprimer toutes les données » efface les enregistrements locaux de Bilan, sa bibliothèque de documents importés et sa clé de chiffrement, la carte d’urgence, l’historique de partage, les préférences, le registre d’accès Santé, les exports temporaires, les notifications et les anciens éléments du trousseau de Bilan. Cette action ne modifie ni les données d’Apple Santé, ni les fichiers originaux choisis pour l’importation, ni les copies déjà transférées vers un autre appareil. Si l’effacement est incomplet, l’application le signale.

Le compagnon Mac reçoit une archive uniquement lorsque vous lancez un transfert local et confirmez le code d’association sur les deux appareils. Le transfert est chiffré entre ces appareils sur le réseau local, sans passer par un serveur de LorisLabs. L’archive reçue reste dans le conteneur local de l’application Mac jusqu’à sa suppression sur ce Mac.

Le compagnon Apple Watch affiche les mesures accessibles et permet de saisir un événement de journal, mis en attente de transmission vers l’iPhone associé.

L’assistance facultative Foundation Models s’exécute sur l’appareil lorsqu’elle est prise en charge. Les validations déterministes restent prioritaires ; le modèle ne partage pas automatiquement vos données et ne fournit pas de diagnostic.

Introduction

LorisLabs ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how our applications — Clasp, TypeMetrics, Moi, Lumen for Frigate, CoreShield AI, Sinkhole, Synthesis, Éclair, ProofCheck, Byty, and Velya (collectively, the "Apps") — handle your information. For Clasp, the specific processing and service exceptions are detailed below, including referral-status requests at launch. For the other Apps, our guiding principle is simple: your data belongs to you, and it stays on your device, except where specific community or verification features require otherwise and only with your explicit opt-in.

By using our Apps, you agree to the practices described in this policy.

Data Controller

The data controller for all personal data processed through the Apps is:

LorisLabs
LorisLabs Team
Email: [email protected]
Website: https://lorislab.fr

LorisLabs has not appointed a Data Protection Officer (DPO) as the scale of our data processing does not meet the thresholds set by GDPR Article 37. For any data protection inquiries, please contact us at [email protected].

Lawful Basis for Processing

For the limited data processing activities in our Apps, we rely on the following lawful bases under GDPR Article 6(1):

Optional Support and Feedback Service

Some Apps and help.lorislab.fr let you report a problem, suggest an improvement, ask a question and continue a private conversation with LorisLabs. This service is optional. Opening the support screen does not send a report.

What is sent. You review and confirm the report before it leaves the App. A report contains the text and request type you choose, the App identifier, version and build, platform, operating-system version, language, a random report identifier and a versioned consent receipt. Device model and bounded technical state codes are optional and require the corresponding selection. The initial service does not accept screenshots, file attachments or an email address. The website sends your message, selected App, request type and language; App and operating-system versions are marked as unknown.

Diagnostics. Automatic diagnostic recording is a separate permission, disabled by default. When enabled by a compatible App, the local journal is limited to technical codes, 24 hours, 1,000 events and 2 MiB. It must not contain raw logs, URLs, camera names, images, health data, precise location, vehicle identifiers, credentials or user content. Upload occurs only while the App is active. Uploaded diagnostic batches are deleted after at most 30 days. Disabling the feature stops new uploads and clears the local queue; the App also offers deletion of already uploaded batches.

Security and access. The SDK and server apply secret and personal-data redaction to report text, although you should still review the preview and avoid entering passwords or sensitive content. The service uses HTTPS, one-time anti-abuse challenges and unguessable private capabilities. The capability is stored in the device Keychain or, on the website, represented by the private conversation link. Anyone who obtains that link can access the conversation. LorisLabs staff access the service through a separate authenticated operator interface. Cloudflare processes network routing and security metadata, including IP addresses, to deliver and protect the service. The origin service uses IP-derived rate-limit counters in memory and does not keep public access logs.

Retention and deletion. The full report text, conversation and any contact data are kept for at most 90 days. A minimal structured case record without the message text is kept for at most 365 days to measure recurring defects and prevent duplicate work. You may delete the request sooner from the conversation. Deletion removes report content, replies, links and related records. A signed, non-content erasure record containing a keyed one-way identifier and completion time is retained to prevent an older backup or repeated request from restoring deleted content. Encrypted backups must be reconciled against this record before restored data becomes available.

LorisLabs relies on its legitimate interests to answer a support request you deliberately send, protect the service from abuse, identify recurring defects using the minimized case record and preserve effective deletion (GDPR Art. 6(1)(f)). Optional diagnostics also require your explicit in-App choice and can be disabled and deleted through the controls described above. You may stop using the conversation at any time and use its deletion control. For access, correction or deletion questions, email [email protected] without sending credentials or private support links in the message.

Service facultatif d’aide et de feedback

Certaines Apps et help.lorislab.fr permettent de signaler un problème, proposer une amélioration, poser une question et poursuivre une conversation privée avec LorisLabs. Ce service est facultatif. Ouvrir l’écran d’aide n’envoie aucun rapport.

Données envoyées. Vous relisez et confirmez le rapport avant son départ de l’App. Il contient le texte et le type de demande que vous choisissez, l’identifiant, la version et le build de l’App, la plateforme, la version du système, la langue, un identifiant aléatoire de rapport et une preuve de consentement versionnée. Le modèle d’appareil et des codes d’état technique bornés sont facultatifs et nécessitent la sélection correspondante. La version initiale du service n’accepte ni capture d’écran, ni pièce jointe, ni adresse email. Le site envoie votre message, l’App choisie, le type de demande et la langue ; les versions de l’App et du système y sont indiquées comme inconnues.

Diagnostics. L’enregistrement automatique des diagnostics dépend d’une autorisation distincte, désactivée par défaut. Lorsqu’une App compatible l’active, le journal local est limité à des codes techniques, 24 heures, 1 000 événements et 2 Mio. Il ne doit contenir ni journaux bruts, ni URL, ni nom de caméra, ni image, ni donnée de santé, ni position précise, ni identifiant de véhicule, ni secret, ni contenu utilisateur. L’envoi a lieu uniquement lorsque l’App est active. Les lots de diagnostics envoyés sont supprimés sous 30 jours au plus. Désactiver cette fonction arrête les nouveaux envois et efface la file locale ; l’App propose aussi la suppression des lots déjà envoyés.

Sécurité et accès. Le SDK et le serveur appliquent une suppression automatique des secrets et de certaines données personnelles dans le texte, mais vous devez toujours relire l’aperçu et éviter les mots de passe ou contenus sensibles. Le service utilise HTTPS, des défis anti-abus à usage unique et des capacités privées impossibles à deviner. Cette capacité est conservée dans le trousseau de l’appareil ou, sur le site, représentée par le lien privé de conversation. Toute personne qui obtient ce lien peut accéder à la conversation. L’équipe LorisLabs utilise une interface opérateur séparée et authentifiée. Cloudflare traite les métadonnées réseau, notamment les adresses IP, pour acheminer et protéger le service. Le service d’origine utilise en mémoire des compteurs de limitation dérivés de l’adresse IP et ne conserve pas de journal public d’accès.

Conservation et suppression. Le texte intégral du rapport, la conversation et les éventuelles coordonnées sont conservés au maximum 90 jours. Un dossier structuré minimal, sans le texte du message, est conservé au maximum 365 jours afin de mesurer les défauts récurrents et d’éviter le travail en double. Vous pouvez supprimer la demande plus tôt depuis la conversation. La suppression efface le contenu, les réponses, les liens et les enregistrements associés. Un registre signé, sans contenu, conserve un identifiant à sens unique avec clé et la date d’effacement afin d’empêcher qu’une ancienne sauvegarde ou une nouvelle requête restaure les données supprimées. Toute sauvegarde chiffrée doit être réconciliée avec ce registre avant que les données restaurées deviennent accessibles.

LorisLabs se fonde sur ses intérêts légitimes pour répondre à une demande de support que vous envoyez volontairement, protéger le service contre les abus, identifier les défauts récurrents à l’aide du dossier minimisé et garantir l’effectivité de la suppression (art. 6(1)(f) du RGPD). Les diagnostics facultatifs exigent aussi votre choix explicite dans l’App et peuvent être désactivés et supprimés avec les contrôles décrits ci-dessus. Vous pouvez cesser d’utiliser la conversation à tout moment et employer son contrôle de suppression. Pour toute demande d’accès, de rectification ou d’effacement, écrivez à [email protected] sans transmettre d’identifiants ni de lien privé de support dans le message.

Website Analytics

We use Umami, a privacy-friendly, open-source analytics tool that we self-host on our own servers. If you accept analytics when visiting our website:

Learn more about Umami's privacy practices at umami.is.

Newsletter

On our website, you can optionally sign up to receive an email when we ship a new app. This newsletter signup is separate from the Apps. Clasp can transmit email addresses contained in enabled sources when you authorize external AI, as described in its section below; this does not subscribe you to the newsletter.

Information We Collect

Most LorisLabs app data stays on the user's device or services the user controls. Some optional or user-requested features use LorisLabs-operated verification, relay, or website services. The app-specific sections identify the data, purpose, provider, retention, and deletion controls for each such feature. LorisLabs Apps contain no advertising SDKs, and LorisLabs does not sell personal data.

Unless an app-specific section below expressly says otherwise, LorisLabs does not collect the following data from the Apps:

Apple and Google may provide anonymized or aggregated store analytics, such as crash reports and install counts, under their own controls. Any information processed by a LorisLabs-operated feature is described separately below.

How Our Apps Work

Core app data is processed on your device or by services you configure and control. Specific optional or user-requested features use store, cloud, verification, or relay services only as described in the app-specific sections below.

On-Device Data Storage

Local app data uses encrypted platform storage appropriate to the operating system, including Apple Keychain and container storage or Android Keystore and app storage. Deleting an app removes its app-container data, subject to device backups, store records, and service-side retention described in the app-specific sections.

On-Device AI Processing

AI-powered features in our Apps (such as posture analysis in TypeMetrics and threat detection in CoreShield AI) run on-device using Apple's CoreML framework. No data is sent to external servers for AI processing unless you explicitly choose to use an optional cloud-based AI provider. Clasp's supported providers, explicit external-AI permission, and separate Apple Speech behavior are described in its section below.

App-Specific Details

Filova — Music Transfer Privacy Details

Filova transfers playlists between music services. It has no server: matching runs entirely on your device, and your data is sent only to the music service you choose, via that service's official API, to perform the transfer you requested. LorisLabs does not receive, store, or retain your playlists, listening data, or account credentials.

Services You Connect

You sign in to each service only when you choose to (Apple Music via Apple's MusicKit; TIDAL, YouTube Music, and Spotify via OAuth). Access tokens are stored in the device Keychain and are never transmitted to LorisLabs. You can disconnect any service at any time in Filova's Settings, which deletes its cached authorization from your device.

YouTube Data

When you connect YouTube Music, Filova uses the YouTube API Services. By using this feature you agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.

Filova requests the https://www.googleapis.com/auth/youtube authorization solely to act on your own YouTube account, at your request: to read the titles of your playlists so you can pick one to transfer, and to create a new playlist and add the matched videos to it. Filova never posts, comments, subscribes, deletes, rates, or modifies anything you did not explicitly initiate, and never accesses other users' data. YouTube data is used only to perform the transfer you asked for and is not stored by Filova or LorisLabs.

You can revoke Filova's access to your Google account at any time at myaccount.google.com/permissions. Filova's cached YouTube authorization is removed from your device when you disconnect the service or delete the app.

The Vault

Before each transfer, Filova saves a local snapshot of the resolved playlist on your device (so a transfer can always be undone). These snapshots are stored locally and are not transmitted to LorisLabs.

No Analytics or Tracking

Filova contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics, which you can opt out of in your device settings.

Synthesis — Education App Privacy Details

Data Storage

All user content in Synthesis — including notes, notebooks, pages, flashcards, drawings, templates, study statistics, and attachments — is stored locally on your device. When iCloud sync is enabled (opt-in), data is synced across your devices using Apple's CloudKit framework with Apple's end-to-end encryption. LorisLabs never has access to your synced data.

On-Device AI

Synthesis uses Apple's Foundation Models framework (available on Apple Silicon devices running iOS 26+) for AI-powered features including summarization, flashcard generation, quiz creation, and writing assistance. All AI processing occurs entirely on your device. No prompts, notes, or generated content are transmitted to LorisLabs or any third party.

If you choose to configure an optional third-party cloud AI provider (such as OpenAI or Anthropic), data you send to those services is governed by their respective privacy policies. This feature is off by default, requires your explicit configuration, and API keys are stored securely in the iOS/macOS Keychain.

Device Permissions

Synthesis may request the following permissions, each used solely for on-device functionality:

No Analytics or Tracking

Synthesis contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. We do not collect usage patterns, session data, feature usage statistics, or any behavioral data. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.

Children's Privacy & Education Compliance

Synthesis offers a "Young Student" persona designed for learners under 13, which includes parental controls and age-appropriate content. Because Synthesis processes all data on-device with no data collection by LorisLabs:

iCloud Sync

When you enable iCloud sync in Synthesis (disabled by default), your data is synced using Apple's CloudKit with the following protections:

Clasp — Clipboard & Semantic Search Privacy Details

Local Storage and Data Sources

Clasp 4.0 stores clipboard history, snippets, audio notes, and search indexes on your device. Processing depends on the features and providers you enable. iCloud synchronization, external AI, speech recognition, and referral services can send data off your device as described below.

System permissions authorize access to a source; they do not replace Clasp's separate permission for sending content to external AI. If you enable a source and external AI, the text needed from that source may be sent for indexing or other selected AI functions.

External AI, Search, and Automatic Processing

Clasp supports local Apple processing, OpenAI, and a user-configured Ollama server for supported AI features. Available providers depend on the feature and device. External AI is disabled until you explicitly allow it in Settings. Saving an API key or having previously selected a provider does not grant this permission in Clasp 4.0.

External providers apply their own terms, retention controls, and deletion procedures. Consult OpenAI's privacy policy, its API data controls, and the policy of your Ollama server operator. Do not assume that all endpoints or accounts have identical retention, or that vectors cannot reveal information about their source text.

Audio and Speech Recognition

Local Whisper transcribes audio on your device. Apple Speech requests on-device recognition when it is available; otherwise, recognition may use Apple's network services, subject to the system's Speech Recognition permission. Apple Speech is separate from the OpenAI/Ollama consent switch. If you select OpenAI transcription, Clasp sends the audio file to OpenAI only with external-AI permission. Audio recordings and resulting transcripts are also stored locally for Audio Notes.

iCloud Synchronization

When enabled, Clasp uses Apple's CloudKit private database for supported synchronized content, including clipboard items and snippets. Eligible knowledge records can also synchronize. This sends the relevant content to Apple under your iCloud account; it is separate from external-AI permission and from the LorisLabs referral service. Turning off synchronization does not itself erase existing local or cloud copies. Cloud storage and account controls are governed by Apple's iCloud services.

Referral and Purchase Verification Service

Clasp connects to the LorisLabs-operated service at referrals.lorislab.fr to check referral rewards. Status requests can occur at app launch and use an app identifier and a stable random UUID kept in the Keychain. This service is separate from external AI and is not disabled by the external-AI switch.

When you request a referral code, the service stores the UUID, app identifier, referral code, creation time, and reward status. When you claim a purchase-related referral, Clasp sends the transaction identifier and product identifier. The service verifies the transaction with Apple and stores referral attribution and purchase-related records, including the original transaction identifier, product, purchase date, referral token, reward status, and related events. These requests do not contain your clipboard history or AI prompts.

The service uses Cloudflare Workers and KV storage. User and referral records currently have no automatic expiry or deletion schedule and can remain indefinitely until removed. Uninstalling Clasp, clearing local history, or revoking external AI does not delete these server records. To request access, correction, or deletion, contact [email protected]. Requests are handled through support; the app does not provide automatic referral-record deletion or guarantee that all records disappear immediately after a request.

Reports, Retention, and Your Choices

Clasp can prepare a report locally and offer the system sharing interface. If you choose to share it, the selected recipient receives the report, which can include your description, system context, and diagnostics. Review its contents before sharing.

Use the app's controls to delete local items, clear history, and manage indexed sources. Removing the app is not a deletion request to Apple, an AI provider, a report recipient, or the referral service; backups, cloud copies, Keychain entries, and service records can remain subject to their respective controls. For privacy questions or requests concerning data held by LorisLabs, contact [email protected]. For data held by your AI provider or server operator, use their request and account controls as well.

Clasp's in-app statistics are distinct from the service requests described above. The referral identifier is used for referral and reward attribution. Apple may separately provide store analytics under its own settings and policies. These distinctions do not mean that Clasp collects no data: the remote flows and retained referral records are described in this section.

Sinkhole — Encrypted DNS Privacy Details

System DNS configuration

Sinkhole for iPhone and iPad helps you choose a DNS-over-HTTPS provider and adds its configuration through Apple’s DNS Settings API, with your approval. It does not create a VPN tunnel or operate a DNS server.

Your selected provider

iOS sends DNS requests directly to the provider you choose. That provider may receive your IP address and requested domain names; its own privacy policy and filtering rules apply. An optional endpoint test sends a DNS test request to that provider. LorisLabs does not receive those queries.

Local preferences

The app stores setup and interface preferences on your device. Sinkhole does not inspect or retain your DNS queries or browsing history. It has no account, advertising SDK, analytics SDK or telemetry.

Your controls

You can select, replace or remove the configuration in iOS Settings. A VPN or device-management policy may override system DNS behavior.

CoreShield AI — Network Security Privacy Details

How CoreShield AI Works

CoreShield AI is a macOS network security application that uses Apple's Network Extension framework to inspect network traffic locally on your Mac. All threat analysis runs on-device using Apple's CoreML framework. CoreShield AI does not route your traffic through any external server operated by LorisLabs.

Data Collected and Stored On-Device

Device Permissions

CoreShield AI requests the following system permissions, each used solely for on-device security functionality:

On-Device AI

Threat detection and traffic classification in CoreShield AI use Apple's CoreML framework. All AI models run entirely on your Mac. No network traffic data, DNS queries, or security events are sent to external servers for AI processing unless you explicitly configure an optional cloud AI provider with your own API key.

No Analytics or Tracking

CoreShield AI contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.

404 Network — Network Diagnostics Privacy Details

How 404 Network Works

404 Network is a comprehensive network diagnostics toolkit. It performs ping, traceroute, port scanning, DNS lookups, speed tests, device discovery, and security audits — all directly from your iOS device. Network operations are executed on-device using system APIs (ICMP sockets, NWConnection, URLSession, mDNS/Bonjour).

Data Stored On-Device

Community Speed Map (Opt-In)

404 Network includes an optional Community Speed Map feature. When explicitly enabled in Settings → Community → "Share Speed Results", the following anonymized data is shared via Apple CloudKit:

Community sharing is disabled by default. No personal identifiers (name, email, device ID) are included. Data is stored in a CloudKit public database accessible to other 404 Network users for comparing ISP performance.

Location Data

404 Network requests location permission for two purposes:

Location data is never stored in full precision. Community map coordinates are always rounded to a ~500m grid before transmission.

Bluetooth

The BLE Scanner feature uses CoreBluetooth to discover nearby Bluetooth Low Energy devices. Device names, UUIDs, RSSI, and GATT profiles are stored locally. No Bluetooth data is transmitted to any server.

Network Extensions

404 Network includes optional VPN/content filter extensions for traffic inspection and packet capture. These extensions operate locally — no traffic is routed through external servers. The VPN tunnel connects to localhost for on-device packet analysis.

Speed Test

Speed tests download and upload data from Cloudflare's speed test infrastructure (speed.cloudflare.com). This is a direct connection between your device and Cloudflare — LorisLabs does not operate or have access to any speed test server. Cloudflare's privacy policy applies to their infrastructure.

No Analytics or Tracking

404 Network contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.

Third-Party Services

Most core app paths are on-device or connect directly to services the user controls. Optional, user-requested, or store-backed features may involve the following third parties:

Apple App Store and Google Play

Our Apps may be distributed through the Apple App Store or Google Play. Apple and Google process store, download, and payment information under their respective privacy policies. LorisLabs does not receive payment-card details. Android purchase and integrity evidence is handled only as described in the Lumen Android section below.

Optional AI API Providers

For Clasp 4.0, use the feature-specific external-AI and speech-recognition details in the Clasp section above. Other Apps (including Moi) allow you to optionally configure third-party AI providers such as OpenAI or Anthropic (Claude) by providing your own API keys. If you choose to enable these integrations:

Apple App Analytics

We may receive anonymized, aggregated analytics from Apple about app usage (crash reports, install counts). This data cannot identify individual users. You can opt out by navigating to Settings > Privacy > Analytics on your device.

Data Security

We use platform security controls and minimize the scope of each service-backed feature:

Lumen for Frigate on Android — Privacy Details

Lumen connects directly to the Frigate NVR server address configured by the user. LorisLabs does not receive or store the user's Frigate credentials, camera feeds, recordings or event images through this direct connection.

Google Play purchases and integrity. When a user buys or restores Lumen Pro, the Android app sends a random request identifier, package name, product identifier, Google Play purchase token and a request-bound Play Integrity token to the LorisLabs entitlement-verification service over HTTPS. The service asks Google Play to verify licensing, application integrity, device integrity and purchase status. Google acts as the store and verification provider, and Cloudflare transports the public HTTPS request. LorisLabs does not receive payment-card details.

Raw purchase and integrity tokens are processed for verification but are not logged or retained by LorisLabs. To prevent replay and conflicting grants, the service stores a keyed purchase-token digest with the product identifier, entitlement expiry and last successful verification time. It automatically deletes that record after 90 days without a successful Google-backed verification, with an hourly purge. A later restore is checked again with Google Play.

Firebase Cloud Messaging. The Android app includes Google Firebase Cloud Messaging for optional camera-event notifications. Firebase may process a Firebase installation identifier, FCM registration token, package and app-version information, and device or network routing information needed to operate and secure delivery. The current app can receive data-only FCM messages, applies the user's notification filters on the device and builds the visible notification locally.

LorisLabs Android notification relay. An authenticated relay subscription, when configured, contains the FCM token, Frigate server identifier, notification label filters and minimum score, locale, app version and last-update time. For delivery, the relay processes event and review identifiers, camera name, label or sub-label, zones, score, timestamps, severity, and whether a clip or snapshot is available. It sends that metadata through Firebase; it does not receive the user's Frigate credentials, live feed, recording, clip, snapshot or event image. The private relay transport uses Tailscale. This Android release does not automatically register its FCM token with the LorisLabs relay, so it does not create such a relay subscription by itself.

Relay subscriptions are deleted after 90 days without a successful refresh, checked at startup and hourly. Tokens rejected by Firebase as unregistered or not found are removed immediately. An authenticated deletion request removes the exact server-and-token binding and does not reveal whether it existed.

There is no LorisLabs account in this Android version. For a privacy question or a request concerning purchase-verifier or relay data, email [email protected]. Do not send Frigate credentials, camera content, FCM tokens, or raw Google Play purchase or integrity tokens by email or place them in a URL. LorisLabs will provide a secure verification procedure if information is needed to find the relevant record. Verifier deletion requires fresh Google-backed app, integrity and purchase evidence; an authenticated request deletes matching keyed digests atomically. This release does not yet expose that deletion action in the app. A later user-requested purchase restore may create a new digest after Google verification.

Lumen for Frigate sur Android — Informations de confidentialité

Lumen se connecte directement à l'adresse du serveur Frigate NVR configurée par l'utilisateur. LorisLabs ne reçoit ni ne conserve les identifiants Frigate, les flux de caméras, les enregistrements ou les images d'événements transmis par cette connexion directe.

Achats Google Play et intégrité. Lorsqu'un utilisateur achète ou restaure Lumen Pro, l'application Android transmet au service LorisLabs de vérification des droits, via HTTPS, un identifiant de requête aléatoire, le nom du package, l'identifiant du produit, le jeton d'achat Google Play et un jeton Play Integrity lié à la requête. Le service demande à Google Play de vérifier la licence, l'intégrité de l'application et de l'appareil, ainsi que l'état de l'achat. Google agit comme boutique et prestataire de vérification ; Cloudflare transporte la requête HTTPS publique. LorisLabs ne reçoit aucune donnée de carte bancaire.

Les jetons d'achat et d'intégrité bruts sont traités pour la vérification, mais ne sont ni journalisés ni conservés par LorisLabs. Afin d'empêcher les rejeux et les attributions de droits incompatibles, le service conserve une empreinte avec clé du jeton d'achat, l'identifiant du produit, l'expiration du droit et la date de la dernière vérification réussie. Cet enregistrement est automatiquement supprimé après 90 jours sans nouvelle vérification réussie auprès de Google Play ; une purge est exécutée chaque heure. Une restauration ultérieure est de nouveau vérifiée auprès de Google Play.

Firebase Cloud Messaging. L'application Android intègre Google Firebase Cloud Messaging pour les notifications facultatives d'événements de caméra. Firebase peut traiter un identifiant d'installation Firebase, le jeton d'inscription FCM, les informations de package et de version de l'application, ainsi que les informations techniques d'appareil ou de routage réseau nécessaires au fonctionnement et à la sécurité de la livraison. L'application actuelle peut recevoir des messages FCM contenant uniquement des données, applique les filtres de notification de l'utilisateur sur l'appareil et construit localement la notification visible.

Relais de notifications Android LorisLabs. Lorsqu'elle est configurée, une inscription authentifiée au relais contient le jeton FCM, l'identifiant du serveur Frigate, les filtres de libellés et le score minimal de notification, la langue, la version de l'application et la date de dernière mise à jour. Pour la livraison, le relais traite les identifiants d'événement et de revue, le nom de la caméra, le libellé ou sous-libellé, les zones, le score, les horodatages, la gravité et la disponibilité éventuelle d'un clip ou d'un instantané. Il envoie ces métadonnées via Firebase ; il ne reçoit ni identifiant Frigate, ni flux en direct, ni enregistrement, clip, instantané ou image d'événement. Le transport privé du relais utilise Tailscale. Cette version Android n'inscrit pas automatiquement son jeton FCM auprès du relais LorisLabs et ne crée donc pas elle-même une telle inscription.

Les inscriptions au relais sont supprimées après 90 jours sans actualisation réussie, avec un contrôle au démarrage puis toutes les heures. Les jetons signalés par Firebase comme désinscrits ou introuvables sont supprimés immédiatement. Une demande de suppression authentifiée retire l'association exacte entre serveur et jeton sans révéler si elle existait.

Cette version Android ne crée aucun compte LorisLabs. Pour une question relative à la vie privée ou une demande concernant les données du vérificateur d'achats ou du relais, écrivez à [email protected]. N'envoyez par email et ne placez dans une URL aucun identifiant Frigate, contenu de caméra, jeton FCM, jeton d'achat Google Play brut ou jeton d'intégrité. LorisLabs fournira une procédure de vérification sécurisée si des informations sont nécessaires pour retrouver l'enregistrement concerné. La suppression des données du vérificateur exige des preuves récentes, validées par Google, concernant l'application, l'intégrité et l'achat ; une requête authentifiée supprime atomiquement les empreintes correspondantes. Cette version ne propose pas encore cette action de suppression dans l'application. Une restauration d'achat demandée ultérieurement par l'utilisateur peut créer une nouvelle empreinte après vérification par Google.

Face Data (Lumen for Frigate)

Lumen for Frigate includes face recognition features that allow you to register and identify known people in your camera feeds. This section explains how face data is collected, used, and stored.

What Face Data Is Collected

When you use the face recognition feature, you may upload photographs of people from your device's photo library to your self-hosted Frigate NVR server. These photographs are used by your Frigate server to identify known people in camera feeds. The Lumen app acts solely as a client — it transmits the photos you select directly to your own server and displays face thumbnails retrieved from it.

How Face Data Is Used

Face data is used exclusively for the purpose of identifying known people in your camera feeds on your self-hosted Frigate NVR. The app displays face thumbnails and recognition results fetched from your server. LorisLabs does not process, analyze, or perform any computation on face data — all face recognition processing occurs on your own Frigate NVR hardware.

Third-Party Sharing

Face data is never transmitted to LorisLabs, Apple, or any third party. All face images and recognition data remain exclusively on your self-hosted Frigate NVR server, which you own and control. The app communicates only with your server over your local network or VPN — no relay servers or intermediaries are involved.

Storage Location

All face data is stored on your self-hosted Frigate NVR server. The Lumen app does not persistently store face images on your Apple device beyond standard temporary URL caching managed by the operating system.

Data Retention

Face data persists on your Frigate NVR server until you choose to delete it. You can delete individual face images or entire face registrations at any time through the Lumen app or through Frigate's web interface. LorisLabs has no ability to access, modify, or delete your face data as it resides entirely on hardware you control.

Your Control

You have full control over your face data at all times. You can add, view, and delete face registrations directly within the app. The face recognition feature is optional and requires your explicit action to register any face photographs.

Rampart for OPNsense — Firewall Monitoring Privacy Details

Rampart connects your device directly to your own OPNsense firewall. All monitoring and management data flows only between your device and your firewall — LorisLabs operates no servers in this path and never receives your network data.

Credentials & Keys

Optional Cloud AI Features

Rampart's AI Assistant and Terminal co-pilot are off unless you supply your own Anthropic API key. When enabled:

Éclair — EV Navigation Privacy Details

Location Data

Éclair requires location permission for navigation and route planning. Your location data is processed entirely on your device and is never transmitted to LorisLabs. Location history is stored locally in SwiftData for trip analytics and driving statistics. You can delete individual trips or clear all location history at any time within the app.

Vehicle Data

Éclair connects to your electric vehicle through multiple methods:

Charging Station Data

Éclair searches for charging stations using the Open Charge Map API. Search queries contain your approximate location to find nearby chargers. No personal identifiers are included in these requests. Charger results are cached locally.

Parking Features

Éclair searches for nearby parking using third-party APIs:

Parking search count is tracked locally for freemium gating purposes and is never transmitted.

Traffic Data Collection

Éclair includes a community traffic intelligence system. When traffic data sharing is enabled in Settings:

Traffic data sharing can be disabled at any time in Settings.

Community Features & Incident Reporting

Éclair includes opt-in community features that require Apple Sign-In:

Community features are disabled by default and require explicit opt-in and Apple Sign-In.

Carpooling (Preview)

Éclair includes an optional carpooling feature, labeled as "Preview", that facilitates cost-sharing rides between users. This feature is structured as non-commercial ride-sharing (covoiturage) in compliance with French Transport Code Article L3132-1.

Carpooling is off by default, requires explicit opt-in in Settings, and requires an active community profile with Apple Sign-In.

AI Features

Éclair's three-tier AI system processes data as follows:

Cross-Border Data Transfers

When you enable community features, data is stored in Apple CloudKit, which may process and store data on servers located outside the EU/EEA. Apple provides appropriate safeguards for international data transfers under GDPR Articles 44–49. See Apple's Privacy Policy for details.

If you connect your vehicle via SmartCar, data is transmitted to SmartCar Inc. (US-based). See SmartCar's Privacy Policy. If you use optional cloud AI providers (Anthropic, OpenAI), data is transmitted to US-based servers and is subject to their respective privacy policies.

For on-device-only usage (the default), no personal data is transferred outside your device.

CarPlay

When used with CarPlay, Éclair displays navigation and charge information on your vehicle's display. No additional data collection occurs through CarPlay beyond what is described above.

Device Permissions

Éclair requests the following permissions, each used solely for on-device functionality:

Location Permission Justification

Éclair requests "Always" location permission (rather than "When In Use") for the following specific reasons:

You can change location permission to "When In Use" or revoke it entirely at any time in iOS Settings > Privacy & Security > Location Services > Éclair. Background trip recording and traffic collection will not function without "Always" permission, but all other features remain available.

Data Retention

Éclair retains data for the following periods:

Data Deletion & GDPR Rights

You can delete your community profile, ride history, incident reports, and all local data at any time within the app. Deleting your community profile removes your profile record, associated trust score events, and incident reports from CloudKit. Anonymous traffic segment contributions cannot be individually deleted as they contain no user identifiers.

Account deletion: In compliance with Apple App Store Review Guideline 5.1.1(v), Éclair provides in-app account deletion for community profiles. Deleting your account removes all associated data from CloudKit, except carpooling ride records within the legal retention period (12–24 months), which are retained in anonymized form with participant IDs removed.

Under GDPR, you have the following rights regarding your personal data:

To exercise any of these rights, contact [email protected]. We will respond within one month as required by GDPR Article 12(3). You also have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) at www.cnil.fr if you believe your data protection rights have been violated.

No Analytics or Tracking

Éclair contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.

Heol — Email Client Privacy Details

Email Data

Heol connects directly to your email provider via IMAP and SMTP protocols. All email messages, headers, subjects, sender addresses, and metadata are stored locally on your device in an encrypted SQLite database (SQLCipher). LorisLabs never has access to your emails — the app communicates only with your email provider's servers.

Credentials

Your IMAP/SMTP credentials (passwords, OAuth tokens) are stored exclusively in the iOS/macOS Keychain. API keys for optional AI providers are also stored in the Keychain. Credentials are never transmitted to LorisLabs servers.

On-Device AI Processing

Heol uses multiple on-device AI features that run entirely on your device:

Optional Cloud AI Providers

Heol allows you to optionally configure third-party AI providers (such as Anthropic Claude or OpenAI) using your own API key. If you enable a cloud provider:

Contacts, Calendar, Location, Reminders

Heol requests access to your Contacts (to show sender details), Calendar (to create events from emails), Location (for location-based snooze), and Reminders (to create follow-up tasks). Each permission is requested only when you use the corresponding feature, and all data is processed on-device. LorisLabs never receives this data.

Microphone & Speech Recognition

If you use voice input in Heol's AI chat, audio is processed on-device using Apple's speech recognition. Audio is not recorded, stored, or transmitted to any server.

Data Storage & Encryption

Tracker Blocking

Heol blocks known email tracking pixels and strips EXIF metadata from images displayed in emails. Blocked tracker domains are matched against a locally-stored blocklist — no network requests are made for tracker detection.

End-to-End Encryption (PGP)

Heol supports optional PGP encryption for email content. PGP keys are stored locally on your device and are not synced to iCloud. Encryption and decryption happen entirely on-device.

Data Deletion

You can delete individual emails, clear cached data, or remove entire email accounts at any time within the app. Uninstalling the app removes all associated data from your device, including the encrypted database and Keychain entries.

Analytics & Telemetry

Heol contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.

ProofCheck — Device Verification Privacy Details

What ProofCheck Is

ProofCheck is a device-inspection and verification app for iPhone, iPad, Mac, and Apple Vision Pro. It runs a battery of diagnostic tests on the local device (sensors, battery, storage, warranty status, etc.), combines them into a "trust score", and produces a report that a seller can share with a buyer via a short code or link. Unlike most LorisLabs apps, ProofCheck does collect and transmit personal data by design, because the product purpose is for a buyer to verify a seller's device across the internet. This section explains exactly what is collected, why, where it is stored, and how you can delete it.

Data We Collect

Where Your Data Is Stored

What Is Shared Publicly When You Share a Report

When a seller generates a share code, a report copy is written to the CloudKit public database so a buyer can fetch it. We minimize what is placed in the public record. Publicly-shared records expire automatically and are periodically purged.

Third-Party Verification Pages

ProofCheck also supports a web-viewer flow where a buyer without the app scans a QR code and opens https://lorislab.fr/verify#<fragment>. The entire report payload travels in the URL fragment (which never leaves the buyer's browser and is not sent to our server logs). The page performs integrity verification in-browser using JavaScript. No personally-identifying fields are transmitted to LorisLabs beyond standard web-server access logs (IP, User-Agent) which are retained for 30 days for security purposes.

Account Deletion and Data Erasure

In compliance with Apple App Store Review Guideline 5.1.1(v) and GDPR Article 17 (right to erasure), ProofCheck provides in-app account deletion. From Settings → Account you can:

If Delete All My Data encounters any record it cannot delete (e.g., due to iCloud being unavailable), you will be informed and can retry when connectivity is restored.

Retention

Device Permissions

No Analytics or Tracking

ProofCheck contains no third-party analytics SDKs, no tracking pixels, no advertising frameworks, and no behavioral telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.

Children's Privacy

ProofCheck is not directed at children under 13 and we do not knowingly collect personal information from children. In the EU, Sign in with Apple requires users to be at least the digital age of consent in their member state (16 in France under CNIL guidelines).

Velya — Smart Alarm Privacy Details

What Velya Is

Velya is a smart alarm app for iPhone (with Apple Watch, Mac, and widget companions) built on Apple's AlarmKit framework. Its purpose is to wake you reliably — breaking through silent mode, Do Not Disturb, and Focus — and to run optional automations around your alarms. Velya is a privacy-first, on-device app: it requires no account, no sign-in, and LorisLabs operates no server that receives your data. App Privacy: Data Not Collected.

Data Stored On Your Device

Optional Remote Control (Self-Hosted)

Velya includes an optional feature for advanced users to trigger or reschedule alarms remotely — for example from a home-automation system. This requires you to run your own self-hosted relay server. You provide a server address and an access token (which you generate on your own server) in Settings; the token is stored in the iOS Keychain on your device. All communication is between your device and your own server. LorisLabs does not operate any relay or backend, and receives no data through this feature. The app is fully functional without it.

Notifications

With your permission, Velya sends local notifications before alarms and when your automations run. On iOS versions before 26 (where AlarmKit is unavailable), notifications are also used as the wake mechanism.

Device Permissions

No Analytics or Tracking

Velya contains no third-party analytics SDKs, no tracking pixels, no advertising frameworks, and no behavioral telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.

Arcyra — Preview Privacy Details

Arcyra is a macOS utility, distributed by Developer ID direct download (not through the App Store) and currently offered as an unvalidated engineering preview — see arcyra.html for its full preview status and limits.

Data Collected

The only data category Arcyra collects is Customer Support data (linked to your identity) — information you provide if you contact us for help, such as your email address and the content of your message. This is collected solely to respond to your request and is not used for any other purpose.

No Tracking

Arcyra does not track you and contains no tracking domains, analytics SDKs, advertising frameworks, or behavioral telemetry of any kind. Mission activity, receipts, and settings are stored locally on your Mac.

Home Assistant & MQTT (Off by Default)

Arcyra includes optional integrations for publishing mission status to a self-hosted MQTT broker or Home Assistant instance. These integrations are disabled by default and only become active if you explicitly enable them and configure your own broker/instance address in Settings. When enabled, communication is directly between your Mac and the server you specified — LorisLabs does not operate any relay and receives no data through this feature.

No Telemetry

Arcyra sends no telemetry — no crash reports, usage statistics, or diagnostics are transmitted to LorisLabs or any third party.

Children's Privacy

Most of our Apps do not collect personal information and are suitable for users of all ages. However, certain features in specific apps do involve data collection:

If you are a parent or guardian and believe your child has created a community profile or used carpooling without authorization, please contact us at [email protected] and we will promptly delete the account and associated data.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our Apps or applicable regulations. We will notify users of significant changes through app updates or on our website. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued use of our Apps after changes constitutes acceptance of the revised policy.

Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:

Email: [email protected]

Website: Support Page