Bilan — Privacy / Confidentialité
English
Bilan reads only the Apple Health categories the user chooses to make accessible. HealthKit-derived measurements, local reports, the emergency card and sharing history remain in the app's local container. Bilan does not require an account, does not use advertising or tracking SDKs, does not send HealthKit-derived data to LorisLabs servers and does not store it in iCloud or CloudKit.
The user can manually create a PDF, CSV, JSON or text snapshot and then chooses a destination in Apple's system share sheet. Once the user shares a copy with another person or service, Bilan cannot recall that external copy. On iPhone and iPad, “Delete all local data” removes Bilan's local SwiftData records, imported document library and its encryption key, emergency card, sharing history, preferences, access ledger, temporary exports, pending/delivered notifications and legacy Bilan keychain items. It does not alter records stored by Apple Health, original files selected for import, or copies already transferred to another device.
The optional Mac companion receives an archive only after the user starts a local transfer and confirms the pairing code on both devices. The transfer is encrypted directly between the selected Apple devices on the local network; it does not pass through or remain on a LorisLabs server. A received archive remains in the Mac app's local container until the user deletes it.
The optional Foundation Models assistance runs on device when supported. Deterministic validation remains authoritative, and the model cannot share data automatically or provide a diagnosis.
Français
Bilan lit uniquement les catégories d’Apple Santé que vous choisissez de rendre accessibles. Les mesures issues de Santé, les rapports locaux, la carte d’urgence et l’historique de partage restent dans le conteneur local de l’application. Bilan ne nécessite pas de compte, n’utilise pas de publicité ni de SDK de suivi, n’envoie pas ces données aux serveurs de LorisLabs et ne les stocke pas dans iCloud ou CloudKit.
Vous pouvez créer manuellement un export PDF, CSV, JSON ou texte, puis choisir sa destination dans la feuille de partage d’Apple. Bilan ne peut pas rappeler une copie que vous avez partagée avec une autre personne ou un autre service.
Sur iPhone et iPad, « Supprimer toutes les données » efface les enregistrements locaux de Bilan, sa bibliothèque de documents importés et sa clé de chiffrement, la carte d’urgence, l’historique de partage, les préférences, le registre d’accès Santé, les exports temporaires, les notifications et les anciens éléments du trousseau de Bilan. Cette action ne modifie ni les données d’Apple Santé, ni les fichiers originaux choisis pour l’importation, ni les copies déjà transférées vers un autre appareil. Si l’effacement est incomplet, l’application le signale.
Le compagnon Mac reçoit une archive uniquement lorsque vous lancez un transfert local et confirmez le code d’association sur les deux appareils. Le transfert est chiffré entre ces appareils sur le réseau local, sans passer par un serveur de LorisLabs. L’archive reçue reste dans le conteneur local de l’application Mac jusqu’à sa suppression sur ce Mac.
Le compagnon Apple Watch affiche les mesures accessibles et permet de saisir un événement de journal, mis en attente de transmission vers l’iPhone associé.
L’assistance facultative Foundation Models s’exécute sur l’appareil lorsqu’elle est prise en charge. Les validations déterministes restent prioritaires ; le modèle ne partage pas automatiquement vos données et ne fournit pas de diagnostic.
Introduction
LorisLabs ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how our applications — Clasp, TypeMetrics, Moi, Lumen for Frigate, CoreShield AI, Sinkhole, Synthesis, Éclair, ProofCheck, Byty, and Velya (collectively, the "Apps") — handle your information. For Clasp, the specific processing and service exceptions are detailed below, including referral-status requests at launch. For the other Apps, our guiding principle is simple: your data belongs to you, and it stays on your device, except where specific community or verification features require otherwise and only with your explicit opt-in.
By using our Apps, you agree to the practices described in this policy.
Data Controller
The data controller for all personal data processed through the Apps is:
LorisLabs
LorisLabs Team
Email: [email protected]
Website: https://lorislab.fr
LorisLabs has not appointed a Data Protection Officer (DPO) as the scale of our data processing does not meet the thresholds set by GDPR Article 37. For any data protection inquiries, please contact us at [email protected].
Lawful Basis for Processing
For the limited data processing activities in our Apps, we rely on the following lawful bases under GDPR Article 6(1):
- Consent (Art. 6(1)(a)): Community features (profiles, incident reporting, traffic data sharing, carpooling), optional cloud AI integrations, and any data shared via CloudKit. You may withdraw consent at any time by disabling the relevant feature in Settings or deleting your community profile. Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.
- Contract performance (Art. 6(1)(b)): Processing required to provide functionality you request — including route calculation, navigation, energy modeling, parking search, vehicle data display, and Google Play purchase verification. Integrity signals used with purchase verification also help prevent fraud and conflicting entitlement grants.
- Legal obligation (Art. 6(1)(c)): Retention of carpooling ride records for 12–24 months to comply with potential law enforcement requests (réquisition judiciaire) under French procedural law.
- Legitimate interest (Art. 6(1)(f)): Freemium usage tracking (e.g., parking search count) to enforce feature gating. This data is stored locally and never transmitted.
Optional Support and Feedback Service
Some Apps and help.lorislab.fr let you report a problem, suggest an improvement, ask a question and continue a private conversation with LorisLabs. This service is optional. Opening the support screen does not send a report.
What is sent. You review and confirm the report before it leaves the App. A report contains the text and request type you choose, the App identifier, version and build, platform, operating-system version, language, a random report identifier and a versioned consent receipt. Device model and bounded technical state codes are optional and require the corresponding selection. The initial service does not accept screenshots, file attachments or an email address. The website sends your message, selected App, request type and language; App and operating-system versions are marked as unknown.
Diagnostics. Automatic diagnostic recording is a separate permission, disabled by default. When enabled by a compatible App, the local journal is limited to technical codes, 24 hours, 1,000 events and 2 MiB. It must not contain raw logs, URLs, camera names, images, health data, precise location, vehicle identifiers, credentials or user content. Upload occurs only while the App is active. Uploaded diagnostic batches are deleted after at most 30 days. Disabling the feature stops new uploads and clears the local queue; the App also offers deletion of already uploaded batches.
Security and access. The SDK and server apply secret and personal-data redaction to report text, although you should still review the preview and avoid entering passwords or sensitive content. The service uses HTTPS, one-time anti-abuse challenges and unguessable private capabilities. The capability is stored in the device Keychain or, on the website, represented by the private conversation link. Anyone who obtains that link can access the conversation. LorisLabs staff access the service through a separate authenticated operator interface. Cloudflare processes network routing and security metadata, including IP addresses, to deliver and protect the service. The origin service uses IP-derived rate-limit counters in memory and does not keep public access logs.
Retention and deletion. The full report text, conversation and any contact data are kept for at most 90 days. A minimal structured case record without the message text is kept for at most 365 days to measure recurring defects and prevent duplicate work. You may delete the request sooner from the conversation. Deletion removes report content, replies, links and related records. A signed, non-content erasure record containing a keyed one-way identifier and completion time is retained to prevent an older backup or repeated request from restoring deleted content. Encrypted backups must be reconciled against this record before restored data becomes available.
LorisLabs relies on its legitimate interests to answer a support request you deliberately send, protect the service from abuse, identify recurring defects using the minimized case record and preserve effective deletion (GDPR Art. 6(1)(f)). Optional diagnostics also require your explicit in-App choice and can be disabled and deleted through the controls described above. You may stop using the conversation at any time and use its deletion control. For access, correction or deletion questions, email [email protected] without sending credentials or private support links in the message.
Service facultatif d’aide et de feedback
Certaines Apps et help.lorislab.fr permettent de signaler un problème, proposer une amélioration, poser une question et poursuivre une conversation privée avec LorisLabs. Ce service est facultatif. Ouvrir l’écran d’aide n’envoie aucun rapport.
Données envoyées. Vous relisez et confirmez le rapport avant son départ de l’App. Il contient le texte et le type de demande que vous choisissez, l’identifiant, la version et le build de l’App, la plateforme, la version du système, la langue, un identifiant aléatoire de rapport et une preuve de consentement versionnée. Le modèle d’appareil et des codes d’état technique bornés sont facultatifs et nécessitent la sélection correspondante. La version initiale du service n’accepte ni capture d’écran, ni pièce jointe, ni adresse email. Le site envoie votre message, l’App choisie, le type de demande et la langue ; les versions de l’App et du système y sont indiquées comme inconnues.
Diagnostics. L’enregistrement automatique des diagnostics dépend d’une autorisation distincte, désactivée par défaut. Lorsqu’une App compatible l’active, le journal local est limité à des codes techniques, 24 heures, 1 000 événements et 2 Mio. Il ne doit contenir ni journaux bruts, ni URL, ni nom de caméra, ni image, ni donnée de santé, ni position précise, ni identifiant de véhicule, ni secret, ni contenu utilisateur. L’envoi a lieu uniquement lorsque l’App est active. Les lots de diagnostics envoyés sont supprimés sous 30 jours au plus. Désactiver cette fonction arrête les nouveaux envois et efface la file locale ; l’App propose aussi la suppression des lots déjà envoyés.
Sécurité et accès. Le SDK et le serveur appliquent une suppression automatique des secrets et de certaines données personnelles dans le texte, mais vous devez toujours relire l’aperçu et éviter les mots de passe ou contenus sensibles. Le service utilise HTTPS, des défis anti-abus à usage unique et des capacités privées impossibles à deviner. Cette capacité est conservée dans le trousseau de l’appareil ou, sur le site, représentée par le lien privé de conversation. Toute personne qui obtient ce lien peut accéder à la conversation. L’équipe LorisLabs utilise une interface opérateur séparée et authentifiée. Cloudflare traite les métadonnées réseau, notamment les adresses IP, pour acheminer et protéger le service. Le service d’origine utilise en mémoire des compteurs de limitation dérivés de l’adresse IP et ne conserve pas de journal public d’accès.
Conservation et suppression. Le texte intégral du rapport, la conversation et les éventuelles coordonnées sont conservés au maximum 90 jours. Un dossier structuré minimal, sans le texte du message, est conservé au maximum 365 jours afin de mesurer les défauts récurrents et d’éviter le travail en double. Vous pouvez supprimer la demande plus tôt depuis la conversation. La suppression efface le contenu, les réponses, les liens et les enregistrements associés. Un registre signé, sans contenu, conserve un identifiant à sens unique avec clé et la date d’effacement afin d’empêcher qu’une ancienne sauvegarde ou une nouvelle requête restaure les données supprimées. Toute sauvegarde chiffrée doit être réconciliée avec ce registre avant que les données restaurées deviennent accessibles.
LorisLabs se fonde sur ses intérêts légitimes pour répondre à une demande de support que vous envoyez volontairement, protéger le service contre les abus, identifier les défauts récurrents à l’aide du dossier minimisé et garantir l’effectivité de la suppression (art. 6(1)(f) du RGPD). Les diagnostics facultatifs exigent aussi votre choix explicite dans l’App et peuvent être désactivés et supprimés avec les contrôles décrits ci-dessus. Vous pouvez cesser d’utiliser la conversation à tout moment et employer son contrôle de suppression. Pour toute demande d’accès, de rectification ou d’effacement, écrivez à [email protected] sans transmettre d’identifiants ni de lien privé de support dans le message.
Website Analytics
We use Umami, a privacy-friendly, open-source analytics tool that we self-host on our own servers. If you accept analytics when visiting our website:
- What we collect: Page views, referrer source (e.g., Google, direct), country-level location, device type (desktop/mobile), and operating system. We also track whether you click an App Store download button (as an aggregate count, not tied to you).
- Where it's stored: On our own self-hosted server. No data is sent to third parties.
- Retention: Analytics data is retained for 12 months, then automatically deleted.
- No cookies: Umami does not set any cookies. Your IP address is anonymized and never stored.
- Your choice: Analytics only load if you explicitly accept. You can change your preference at any time via the "Privacy Settings" link in the footer of every page.
Learn more about Umami's privacy practices at umami.is.
Newsletter
On our website, you can optionally sign up to receive an email when we ship a new app. This newsletter signup is separate from the Apps. Clasp can transmit email addresses contained in enabled sources when you authorize external AI, as described in its section below; this does not subscribe you to the newsletter.
- Purpose: To notify you when a new LorisLabs app is released. Nothing else — no marketing series, no third-party offers, no list-selling.
- Legal basis: Your explicit consent (GDPR Art. 6(1)(a)), given by checking the consent box and confirming via a double opt-in email. You are not subscribed until you click the confirmation link.
- Data collected: Your email address, plus the timestamp and IP address of your consent (kept as proof of consent, as required by GDPR accountability under Art. 7(1)).
- Processor: We use Brevo (Sendinblue SAS, Paris, France) to send these emails and manage the list. Brevo acts as our data processor under a standard data processing agreement and does not use your email for its own purposes.
- Spam protection: The signup form uses Cloudflare Turnstile to block automated abuse. Turnstile runs a challenge in your browser and does not use tracking cookies or build an advertising profile; see Cloudflare's privacy documentation.
- Retention: We keep your email address for as long as you remain subscribed. If you never confirm the double opt-in email, the unconfirmed entry is automatically discarded after a short period.
- Your rights: Every email includes a one-click unsubscribe link. You can also withdraw consent at any time by emailing [email protected], and you have the right to access, rectify, or erase this data under GDPR Articles 15–17.
Information We Collect
Most LorisLabs app data stays on the user's device or services the user controls. Some optional or user-requested features use LorisLabs-operated verification, relay, or website services. The app-specific sections identify the data, purpose, provider, retention, and deletion controls for each such feature. LorisLabs Apps contain no advertising SDKs, and LorisLabs does not sell personal data.
Unless an app-specific section below expressly says otherwise, LorisLabs does not collect the following data from the Apps:
- Personal identifiers (name, email, phone number)
- Usage analytics or behavioral data
- Location data
- Device fingerprints or advertising identifiers
- Clipboard contents, typing data, conversations, or any user-generated content
Apple and Google may provide anonymized or aggregated store analytics, such as crash reports and install counts, under their own controls. Any information processed by a LorisLabs-operated feature is described separately below.
How Our Apps Work
Core app data is processed on your device or by services you configure and control. Specific optional or user-requested features use store, cloud, verification, or relay services only as described in the app-specific sections below.
On-Device Data Storage
Local app data uses encrypted platform storage appropriate to the operating system, including Apple Keychain and container storage or Android Keystore and app storage. Deleting an app removes its app-container data, subject to device backups, store records, and service-side retention described in the app-specific sections.
On-Device AI Processing
AI-powered features in our Apps (such as posture analysis in TypeMetrics and threat detection in CoreShield AI) run on-device using Apple's CoreML framework. No data is sent to external servers for AI processing unless you explicitly choose to use an optional cloud-based AI provider. Clasp's supported providers, explicit external-AI permission, and separate Apple Speech behavior are described in its section below.
App-Specific Details
- Byty is a Mac storage optimizer and backup tool. File metadata (paths, sizes, dates) is stored locally for scan history. Smart Scan's AI cleanup runs on-device using Apple Intelligence by default — nothing leaves your Mac. A cloud provider is strictly optional: only if you explicitly enable it and supply your own Anthropic API key does Smart Scan send anonymized file paths (not file contents) to Anthropic's Claude API. In that case, file paths are sanitized to remove usernames before being sent, using your own API key stored in the macOS Keychain. LorisLabs does not receive, store, or retain any file paths or scan data. See Anthropic's Privacy Policy at anthropic.com/legal/privacy for details on how they process your API requests. Photo backup credentials (SMB passwords, encryption keys) are stored in macOS Keychain and never transmitted to LorisLabs.
- Velya is a smart alarm clock for iPhone and Apple Watch. Your alarms, routines, and settings are stored on your device and synced across your own devices through your private iCloud (CloudKit) — LorisLabs cannot see them. Sleep data is read from Apple Health (HealthKit) on-device to optimize your wake time and is never written back to Health, transmitted off your device, or sent to LorisLabs. Optional features you explicitly enable: Calendar access (read-only) to schedule a smart wake around your first event; Location to estimate travel time to that event; and Home Assistant / Node-RED / webhook integrations that talk directly to servers you configure on your own network, using credentials stored in the device Keychain — that traffic never passes through LorisLabs. Shared alarms use Apple's CloudKit sharing, only with the people you invite. LorisLabs does not collect, receive, or store your alarm, health, calendar, or location data.
- Clasp provides clipboard history, audio notes, and search across enabled sources. Storage is local with optional iCloud synchronization; AI and transcription may use local or remote providers. External AI requires separate permission, while referral-status requests use a LorisLabs service. See the "Clasp — Clipboard & Semantic Search Privacy Details" section below for the data, destinations, and controls.
- TypeMetrics records typing metrics locally. The AI Vision Coach analyzes camera input on-device for posture feedback — no facial data, biometrics, or images are stored or transmitted. On visionOS, TypeMetrics uses ARKit hand tracking to provide real-time finger placement feedback during typing sessions. Hand position data is processed entirely on-device in real time; no hand tracking video, skeletal data, or hand images are stored, recorded, or transmitted to any server.
- Moi stores all conversations, memory, and indexed documents locally. System integrations (Calendar, Mail, Notes, Contacts) are accessed through Apple's official APIs with your explicit permission.
- Lumen for Frigate connects directly to your self-hosted NVR over your local network or VPN for camera feeds — those bytes never traverse LorisLabs infrastructure and we have no access to them. For multi-device push delivery (Apple Bridge mode) and browser-based Settings access (Web Settings), the app uses a single stateless edge service operated by LorisLabs (
relay.lorislab.fr, a Cloudflare Worker) that signs CloudKit Server-to-Server requests on your behalf. Event metadata (camera name, label, score, zones), event thumbnails (JPEG), and event clips (MP4) flow through this edge hop on their way into your own iCloud account; the relay holds nothing at rest beyond per-user pairing tokens hashed with SHA-256. The relay never sees your live camera feeds, even when these features are enabled. On Android, user-requested Google Play purchase verification uses the LorisLabs entitlement-verification service as described in the "Lumen for Frigate on Android" section below. See the "Face Data (Lumen for Frigate)" section below for details on how face recognition data is handled. - Lumen Cam uses your device's camera and microphone to stream video over your local network to your self-hosted Frigate NVR. All streaming occurs directly between your device and your server — no data passes through LorisLabs servers. Camera and audio data are never recorded or stored by the app. Frigate server credentials are stored in iCloud Keychain (shared with Lumen for Frigate).
- CoreShield AI inspects network traffic locally using a macOS Network Extension. All threat analysis runs on-device via CoreML. Packet contents are never stored or transmitted externally.
- Sinkhole configures encrypted DNS through Apple’s DNS Settings API. iOS sends queries directly to your selected provider, whose privacy policy applies. Sinkhole does not create a VPN or inspect or store DNS queries. See the Sinkhole section below.
- 404 Network performs network diagnostics (ping, traceroute, port scanning, speed tests, device discovery) entirely on-device. Network scan results are stored locally in SwiftData. When Community Map sharing is enabled (opt-in), anonymized speed test results (ISP name, connection type, approximate location rounded to ~500m) are shared via CloudKit. Router integration credentials are stored in the iOS Keychain. See the "404 Network — Network Diagnostics Privacy Details" section below.
- Synthesis stores all notes, notebooks, flashcards, study data, and attachments locally on your device using Apple's SwiftData framework. AI features (summarization, flashcard generation, quiz creation) run entirely on-device using Apple's Foundation Models framework — no data is sent to external servers unless you explicitly configure an optional cloud AI provider with your own API key.
- Heol is a privacy-first email client. All email data (messages, metadata, contacts, AI analysis) is stored locally in an encrypted on-device database. Phishing detection runs entirely on-device via CoreML — no email content is ever sent to external servers for threat analysis. IMAP/SMTP credentials are stored in the iOS/macOS Keychain. See the "Heol — Email Client Privacy Details" section below for full details.
- LumenTV is the Apple TV companion to Lumen for Frigate. It connects directly to your self-hosted NVR over your local network or VPN. No camera feeds, detection data, or credentials pass through LorisLabs servers. Server credentials are stored in the tvOS Keychain and synced from Lumen via iCloud Keychain.
- Éclair is an electric vehicle navigation and trip planning app. It processes route calculations, energy models, and AI coaching entirely on-device. Location data is used for navigation and is stored locally. Vehicle data (SoC, battery health) from OBD-II adapters or brand APIs is processed and stored on-device. Parking searches use OpenStreetMap and ParkAPI — no personal data is sent with these queries. If you opt in to community features (traffic sharing, incident reporting, carpooling), anonymized or pseudonymized data is shared via CloudKit. See the "Éclair — EV Navigation Privacy Details" section below.
- ProofCheck is a device-verification app for used-electronics sellers and buyers. It collects and transmits specific data (Apple Sign-In email, coarse location, device identifiers, diagnostic trust signals) to Apple CloudKit databases so buyers can verify reports shared by sellers. See the "ProofCheck — Device Verification Privacy Details" section below for full details.
- AuroraPulse is currently in development. Privacy details will be published before the app launches. Like all LorisLabs apps, AuroraPulse will be built on our privacy-first architecture with on-device processing and no analytics SDKs.
- Velya is a smart alarm app built on AlarmKit. Alarms, automation rules, and all settings are stored on-device. Apple Health sleep data is read on-device to power smart wake and the sleep history screen — it is never transmitted off your device. Location (with your permission) is used on-device for location-based automations and bedtime detection. Optionally, advanced users can connect Velya to their own self-hosted "relay" server for remote alarm control; LorisLabs operates no server and receives no data. See the "Velya — Smart Alarm Privacy Details" section below for full details.
- Filova moves your playlists between music services (Apple Music, TIDAL, YouTube Music, Spotify) on your explicit request. LorisLabs operates no server and never receives your music data — matching runs on your device, and your playlists are sent only to the destination service you choose, through that service's official API, using access tokens stored in the device Keychain. See the "Filova — Music Transfer Privacy Details" section below for full details, including YouTube data handling.
Filova — Music Transfer Privacy Details
Filova transfers playlists between music services. It has no server: matching runs entirely on your device, and your data is sent only to the music service you choose, via that service's official API, to perform the transfer you requested. LorisLabs does not receive, store, or retain your playlists, listening data, or account credentials.
Services You Connect
You sign in to each service only when you choose to (Apple Music via Apple's MusicKit; TIDAL, YouTube Music, and Spotify via OAuth). Access tokens are stored in the device Keychain and are never transmitted to LorisLabs. You can disconnect any service at any time in Filova's Settings, which deletes its cached authorization from your device.
YouTube Data
When you connect YouTube Music, Filova uses the YouTube API Services. By using this feature you agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
Filova requests the https://www.googleapis.com/auth/youtube authorization solely to act on your own YouTube account, at your request: to read the titles of your playlists so you can pick one to transfer, and to create a new playlist and add the matched videos to it. Filova never posts, comments, subscribes, deletes, rates, or modifies anything you did not explicitly initiate, and never accesses other users' data. YouTube data is used only to perform the transfer you asked for and is not stored by Filova or LorisLabs.
You can revoke Filova's access to your Google account at any time at myaccount.google.com/permissions. Filova's cached YouTube authorization is removed from your device when you disconnect the service or delete the app.
The Vault
Before each transfer, Filova saves a local snapshot of the resolved playlist on your device (so a transfer can always be undone). These snapshots are stored locally and are not transmitted to LorisLabs.
No Analytics or Tracking
Filova contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics, which you can opt out of in your device settings.
Synthesis — Education App Privacy Details
Data Storage
All user content in Synthesis — including notes, notebooks, pages, flashcards, drawings, templates, study statistics, and attachments — is stored locally on your device. When iCloud sync is enabled (opt-in), data is synced across your devices using Apple's CloudKit framework with Apple's end-to-end encryption. LorisLabs never has access to your synced data.
On-Device AI
Synthesis uses Apple's Foundation Models framework (available on Apple Silicon devices running iOS 26+) for AI-powered features including summarization, flashcard generation, quiz creation, and writing assistance. All AI processing occurs entirely on your device. No prompts, notes, or generated content are transmitted to LorisLabs or any third party.
If you choose to configure an optional third-party cloud AI provider (such as OpenAI or Anthropic), data you send to those services is governed by their respective privacy policies. This feature is off by default, requires your explicit configuration, and API keys are stored securely in the iOS/macOS Keychain.
Device Permissions
Synthesis may request the following permissions, each used solely for on-device functionality:
- Camera — For scanning documents and capturing images to embed in notes. Images are stored locally and never transmitted.
- Microphone — For voice annotations attached to blocks and audio recording within pages. Audio data is stored locally and never transmitted.
- Speech Recognition — For on-device voice-to-text transcription. Processing occurs entirely on-device using Apple's Speech framework.
- Photo Library — For importing images into notes. Selected images are copied into the app's local storage.
No Analytics or Tracking
Synthesis contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. We do not collect usage patterns, session data, feature usage statistics, or any behavioral data. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.
Children's Privacy & Education Compliance
Synthesis offers a "Young Student" persona designed for learners under 13, which includes parental controls and age-appropriate content. Because Synthesis processes all data on-device with no data collection by LorisLabs:
- COPPA (Children's Online Privacy Protection Act) — Synthesis does not collect personal information from children or any users. Parental consent is recommended for users under 13.
- FERPA (Family Educational Rights and Privacy Act) — Synthesis does not access, collect, or store education records. All student data remains on the student's device under their control.
- GDPR (General Data Protection Regulation) — As no personal data is collected or processed by LorisLabs, GDPR data subject rights (access, rectification, erasure, portability) are inherently satisfied — your data is always under your control on your device.
iCloud Sync
When you enable iCloud sync in Synthesis (disabled by default), your data is synced using Apple's CloudKit with the following protections:
- Data is encrypted in transit using TLS and at rest on Apple's servers.
- LorisLabs cannot access your synced data — it is stored in your private CloudKit database tied to your Apple ID.
- You can disable sync at any time in the app's settings. Disabling sync does not delete your local data.
- File attachments are synced as CloudKit Assets with the same encryption protections.
Clasp — Clipboard & Semantic Search Privacy Details
Local Storage and Data Sources
Clasp 4.0 stores clipboard history, snippets, audio notes, and search indexes on your device. Processing depends on the features and providers you enable. iCloud synchronization, external AI, speech recognition, and referral services can send data off your device as described below.
- Clipboard and snippets — Clasp saves text, images, files, and links for clipboard history and reuse. Text used for indexing, summaries, or conversations can be sent to an external AI provider after you grant the separate external-AI permission.
- Audio notes — Clasp records audio with your microphone permission. Transcription may be local or remote, depending on the provider described below.
- Contacts — With Contacts permission and indexing enabled, Clasp reads contact information. The indexed text includes names, organizations, job titles, phone numbers, and email addresses. Contact notes are not accessed.
- Calendar and reminders — Enabled sources use EventKit to read information such as titles, dates, locations, and notes for search.
- Mail, Notes, and Messages on macOS — Enabled sources can index mail subjects, senders, recipients, and a short text excerpt exposed by Spotlight; note titles and text previews from the local Notes database; and message text from the local Messages database. Access depends on macOS permissions and data availability.
- User-selected files on macOS — Clasp indexes supported content in folders you select and authorize through the file picker.
- Keyboard extension on iOS — The optional keyboard reads shared Clasp snippets and inserts the text you select. Its shared storage is separate from enabling external AI in the main app.
System permissions authorize access to a source; they do not replace Clasp's separate permission for sending content to external AI. If you enable a source and external AI, the text needed from that source may be sent for indexing or other selected AI functions.
External AI, Search, and Automatic Processing
Clasp supports local Apple processing, OpenAI, and a user-configured Ollama server for supported AI features. Available providers depend on the feature and device. External AI is disabled until you explicitly allow it in Settings. Saving an API key or having previously selected a provider does not grant this permission in Clasp 4.0.
- Data sent — Depending on the feature, requests can contain clipboard and indexed-source text, search queries, prompts, conversation content, and transcripts. OpenAI transcription also sends the selected audio file.
- Automatic work — When enabled, semantic indexing and summaries may run in the background without a separate confirmation for each item. With OpenAI embeddings selected, the source text and semantic search queries are sent to OpenAI; the vectors returned are stored in the local search index.
- Destinations — OpenAI requests go to its API. Ollama requests go to the server address you configure; that server may be on your device, your network, or elsewhere. Its operator controls any server-side storage. Local Apple AI processing does not use these external-AI routes.
- Credentials — Your OpenAI API key is stored in the device Keychain and sent to OpenAI to authenticate API requests. These AI requests do not pass through a LorisLabs AI relay.
- Your control — You can withdraw external-AI permission in Settings. This blocks new external-AI requests, including new retry attempts; it does not recall requests already sent or delete provider copies. Changing the Ollama server address requires renewed permission. Disabling permission does not silently replace the embedding model in an existing index.
External providers apply their own terms, retention controls, and deletion procedures. Consult OpenAI's privacy policy, its API data controls, and the policy of your Ollama server operator. Do not assume that all endpoints or accounts have identical retention, or that vectors cannot reveal information about their source text.
Audio and Speech Recognition
Local Whisper transcribes audio on your device. Apple Speech requests on-device recognition when it is available; otherwise, recognition may use Apple's network services, subject to the system's Speech Recognition permission. Apple Speech is separate from the OpenAI/Ollama consent switch. If you select OpenAI transcription, Clasp sends the audio file to OpenAI only with external-AI permission. Audio recordings and resulting transcripts are also stored locally for Audio Notes.
iCloud Synchronization
When enabled, Clasp uses Apple's CloudKit private database for supported synchronized content, including clipboard items and snippets. Eligible knowledge records can also synchronize. This sends the relevant content to Apple under your iCloud account; it is separate from external-AI permission and from the LorisLabs referral service. Turning off synchronization does not itself erase existing local or cloud copies. Cloud storage and account controls are governed by Apple's iCloud services.
Referral and Purchase Verification Service
Clasp connects to the LorisLabs-operated service at referrals.lorislab.fr to check referral rewards. Status requests can occur at app launch and use an app identifier and a stable random UUID kept in the Keychain. This service is separate from external AI and is not disabled by the external-AI switch.
When you request a referral code, the service stores the UUID, app identifier, referral code, creation time, and reward status. When you claim a purchase-related referral, Clasp sends the transaction identifier and product identifier. The service verifies the transaction with Apple and stores referral attribution and purchase-related records, including the original transaction identifier, product, purchase date, referral token, reward status, and related events. These requests do not contain your clipboard history or AI prompts.
The service uses Cloudflare Workers and KV storage. User and referral records currently have no automatic expiry or deletion schedule and can remain indefinitely until removed. Uninstalling Clasp, clearing local history, or revoking external AI does not delete these server records. To request access, correction, or deletion, contact [email protected]. Requests are handled through support; the app does not provide automatic referral-record deletion or guarantee that all records disappear immediately after a request.
Reports, Retention, and Your Choices
Clasp can prepare a report locally and offer the system sharing interface. If you choose to share it, the selected recipient receives the report, which can include your description, system context, and diagnostics. Review its contents before sharing.
Use the app's controls to delete local items, clear history, and manage indexed sources. Removing the app is not a deletion request to Apple, an AI provider, a report recipient, or the referral service; backups, cloud copies, Keychain entries, and service records can remain subject to their respective controls. For privacy questions or requests concerning data held by LorisLabs, contact [email protected]. For data held by your AI provider or server operator, use their request and account controls as well.
Clasp's in-app statistics are distinct from the service requests described above. The referral identifier is used for referral and reward attribution. Apple may separately provide store analytics under its own settings and policies. These distinctions do not mean that Clasp collects no data: the remote flows and retained referral records are described in this section.
Sinkhole — Encrypted DNS Privacy Details
System DNS configuration
Sinkhole for iPhone and iPad helps you choose a DNS-over-HTTPS provider and adds its configuration through Apple’s DNS Settings API, with your approval. It does not create a VPN tunnel or operate a DNS server.
Your selected provider
iOS sends DNS requests directly to the provider you choose. That provider may receive your IP address and requested domain names; its own privacy policy and filtering rules apply. An optional endpoint test sends a DNS test request to that provider. LorisLabs does not receive those queries.
Local preferences
The app stores setup and interface preferences on your device. Sinkhole does not inspect or retain your DNS queries or browsing history. It has no account, advertising SDK, analytics SDK or telemetry.
Your controls
You can select, replace or remove the configuration in iOS Settings. A VPN or device-management policy may override system DNS behavior.
CoreShield AI — Network Security Privacy Details
How CoreShield AI Works
CoreShield AI is a macOS network security application that uses Apple's Network Extension framework to inspect network traffic locally on your Mac. All threat analysis runs on-device using Apple's CoreML framework. CoreShield AI does not route your traffic through any external server operated by LorisLabs.
Data Collected and Stored On-Device
- Location Data — CoreShield AI requests location permission to identify the WiFi network you are connected to and to detect potential evil twin access points (rogue networks impersonating legitimate ones). Location data is stored locally on your device and is never shared with LorisLabs or any third party.
- Bluetooth Scanning — CoreShield AI uses CoreBluetooth to scan for nearby Bluetooth devices to provide network environment awareness and detect potential threats. Bluetooth scan results are used in real-time for display purposes and are not persistently stored. No Bluetooth data is transmitted to any server.
- DNS Query Logging — DNS queries made by your Mac are monitored locally for threat detection and DNS filtering. Query logs (domain names, timestamps, blocked/allowed status) are stored on your device in a local database. DNS logs are never shared externally. You control the retention period and can clear logs at any time.
- Network Traffic Metadata — Connection destinations, protocols, ports, and bytes transferred are monitored for security analysis. This metadata is stored locally on your device and is never shared with LorisLabs or any third party. Actual packet contents are never stored or transmitted externally.
- Device Identifiers — Bluetooth device identifiers (UUIDs, device names) are used solely for identifying nearby devices in the network environment view. These identifiers are not used for tracking and are not transmitted to any server.
Device Permissions
CoreShield AI requests the following system permissions, each used solely for on-device security functionality:
- Network Extension — Required to inspect and filter network traffic on your Mac. Requires approval in System Settings > Privacy & Security.
- Location — Required to identify WiFi network names (SSID) and detect evil twin access points. macOS requires location permission for WiFi network identification.
- Bluetooth — Required for scanning nearby Bluetooth devices for network environment awareness.
On-Device AI
Threat detection and traffic classification in CoreShield AI use Apple's CoreML framework. All AI models run entirely on your Mac. No network traffic data, DNS queries, or security events are sent to external servers for AI processing unless you explicitly configure an optional cloud AI provider with your own API key.
No Analytics or Tracking
CoreShield AI contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.
404 Network — Network Diagnostics Privacy Details
How 404 Network Works
404 Network is a comprehensive network diagnostics toolkit. It performs ping, traceroute, port scanning, DNS lookups, speed tests, device discovery, and security audits — all directly from your iOS device. Network operations are executed on-device using system APIs (ICMP sockets, NWConnection, URLSession, mDNS/Bonjour).
Data Stored On-Device
- Tool Results — Ping, DNS, traceroute, speed test, port scan, and audit results are stored locally in SwiftData. These are never transmitted to any server.
- Discovered Devices — IP addresses, MAC addresses, hostnames, open ports, and device types found during network scans are stored locally.
- Network Profiles — Gateway IP, SSID, and scan history per network are stored locally.
- Router Credentials — If you configure router integration (MikroTik, OPNsense, UniFi), credentials are stored in the iOS Keychain — never in UserDefaults, files, or cloud storage.
- AI API Keys — If you configure optional cloud AI providers (Claude, OpenAI), API keys are stored in the iOS Keychain.
Community Speed Map (Opt-In)
404 Network includes an optional Community Speed Map feature. When explicitly enabled in Settings → Community → "Share Speed Results", the following anonymized data is shared via Apple CloudKit:
- ISP name (detected from your public IP via Cloudflare)
- Connection type (WiFi, Cellular, Ethernet)
- Speed metrics (download/upload Mbps, latency, jitter, packet loss)
- Approximate location — your GPS coordinates are rounded to a ~500m grid before storage. Your exact location is never stored or transmitted.
Community sharing is disabled by default. No personal identifiers (name, email, device ID) are included. Data is stored in a CloudKit public database accessible to other 404 Network users for comparing ISP performance.
Location Data
404 Network requests location permission for two purposes:
- WiFi SSID detection — iOS requires location permission to access the current WiFi network name via NEHotspotNetwork.
- Community Speed Map — When community sharing is enabled, your approximate location (~500m) is used to position speed results on the map.
Location data is never stored in full precision. Community map coordinates are always rounded to a ~500m grid before transmission.
Bluetooth
The BLE Scanner feature uses CoreBluetooth to discover nearby Bluetooth Low Energy devices. Device names, UUIDs, RSSI, and GATT profiles are stored locally. No Bluetooth data is transmitted to any server.
Network Extensions
404 Network includes optional VPN/content filter extensions for traffic inspection and packet capture. These extensions operate locally — no traffic is routed through external servers. The VPN tunnel connects to localhost for on-device packet analysis.
Speed Test
Speed tests download and upload data from Cloudflare's speed test infrastructure (speed.cloudflare.com). This is a direct connection between your device and Cloudflare — LorisLabs does not operate or have access to any speed test server. Cloudflare's privacy policy applies to their infrastructure.
No Analytics or Tracking
404 Network contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.
Third-Party Services
Most core app paths are on-device or connect directly to services the user controls. Optional, user-requested, or store-backed features may involve the following third parties:
Apple App Store and Google Play
Our Apps may be distributed through the Apple App Store or Google Play. Apple and Google process store, download, and payment information under their respective privacy policies. LorisLabs does not receive payment-card details. Android purchase and integrity evidence is handled only as described in the Lumen Android section below.
Optional AI API Providers
For Clasp 4.0, use the feature-specific external-AI and speech-recognition details in the Clasp section above. Other Apps (including Moi) allow you to optionally configure third-party AI providers such as OpenAI or Anthropic (Claude) by providing your own API keys. If you choose to enable these integrations:
- Data you send to these services (prompts, text content) is transmitted to their servers and governed by their respective privacy policies.
- This feature is off by default and requires your explicit configuration.
- API keys you provide are stored securely in the iOS/macOS Keychain and are never transmitted to LorisLabs.
- You can disable these integrations at any time and revert to fully on-device processing.
Apple App Analytics
We may receive anonymized, aggregated analytics from Apple about app usage (crash reports, install counts). This data cannot identify individual users. You can opt out by navigating to Settings > Privacy > Analytics on your device.
Data Security
We use platform security controls and minimize the scope of each service-backed feature:
- App sandboxing restricts each app's data access to its own container.
- Encrypted storage — data is stored in encrypted containers managed by the operating system.
- Credential storage uses Apple Keychain or Android Keystore-backed app storage, as appropriate to the platform.
- Transport security — LorisLabs-operated verification and relay services require HTTPS. Connections to user-configured self-hosted services follow the address and local-network policy selected by the user and may use local HTTP where an app explicitly permits it.
- Minimized service scope — where LorisLabs operates a verification or relay service, its purpose, processed data, and retention are bounded in the relevant app-specific section.
Lumen for Frigate on Android — Privacy Details
Lumen connects directly to the Frigate NVR server address configured by the user. LorisLabs does not receive or store the user's Frigate credentials, camera feeds, recordings or event images through this direct connection.
Google Play purchases and integrity. When a user buys or restores Lumen Pro, the Android app sends a random request identifier, package name, product identifier, Google Play purchase token and a request-bound Play Integrity token to the LorisLabs entitlement-verification service over HTTPS. The service asks Google Play to verify licensing, application integrity, device integrity and purchase status. Google acts as the store and verification provider, and Cloudflare transports the public HTTPS request. LorisLabs does not receive payment-card details.
Raw purchase and integrity tokens are processed for verification but are not logged or retained by LorisLabs. To prevent replay and conflicting grants, the service stores a keyed purchase-token digest with the product identifier, entitlement expiry and last successful verification time. It automatically deletes that record after 90 days without a successful Google-backed verification, with an hourly purge. A later restore is checked again with Google Play.
Firebase Cloud Messaging. The Android app includes Google Firebase Cloud Messaging for optional camera-event notifications. Firebase may process a Firebase installation identifier, FCM registration token, package and app-version information, and device or network routing information needed to operate and secure delivery. The current app can receive data-only FCM messages, applies the user's notification filters on the device and builds the visible notification locally.
LorisLabs Android notification relay. An authenticated relay subscription, when configured, contains the FCM token, Frigate server identifier, notification label filters and minimum score, locale, app version and last-update time. For delivery, the relay processes event and review identifiers, camera name, label or sub-label, zones, score, timestamps, severity, and whether a clip or snapshot is available. It sends that metadata through Firebase; it does not receive the user's Frigate credentials, live feed, recording, clip, snapshot or event image. The private relay transport uses Tailscale. This Android release does not automatically register its FCM token with the LorisLabs relay, so it does not create such a relay subscription by itself.
Relay subscriptions are deleted after 90 days without a successful refresh, checked at startup and hourly. Tokens rejected by Firebase as unregistered or not found are removed immediately. An authenticated deletion request removes the exact server-and-token binding and does not reveal whether it existed.
There is no LorisLabs account in this Android version. For a privacy question or a request concerning purchase-verifier or relay data, email [email protected]. Do not send Frigate credentials, camera content, FCM tokens, or raw Google Play purchase or integrity tokens by email or place them in a URL. LorisLabs will provide a secure verification procedure if information is needed to find the relevant record. Verifier deletion requires fresh Google-backed app, integrity and purchase evidence; an authenticated request deletes matching keyed digests atomically. This release does not yet expose that deletion action in the app. A later user-requested purchase restore may create a new digest after Google verification.
Lumen for Frigate sur Android — Informations de confidentialité
Lumen se connecte directement à l'adresse du serveur Frigate NVR configurée par l'utilisateur. LorisLabs ne reçoit ni ne conserve les identifiants Frigate, les flux de caméras, les enregistrements ou les images d'événements transmis par cette connexion directe.
Achats Google Play et intégrité. Lorsqu'un utilisateur achète ou restaure Lumen Pro, l'application Android transmet au service LorisLabs de vérification des droits, via HTTPS, un identifiant de requête aléatoire, le nom du package, l'identifiant du produit, le jeton d'achat Google Play et un jeton Play Integrity lié à la requête. Le service demande à Google Play de vérifier la licence, l'intégrité de l'application et de l'appareil, ainsi que l'état de l'achat. Google agit comme boutique et prestataire de vérification ; Cloudflare transporte la requête HTTPS publique. LorisLabs ne reçoit aucune donnée de carte bancaire.
Les jetons d'achat et d'intégrité bruts sont traités pour la vérification, mais ne sont ni journalisés ni conservés par LorisLabs. Afin d'empêcher les rejeux et les attributions de droits incompatibles, le service conserve une empreinte avec clé du jeton d'achat, l'identifiant du produit, l'expiration du droit et la date de la dernière vérification réussie. Cet enregistrement est automatiquement supprimé après 90 jours sans nouvelle vérification réussie auprès de Google Play ; une purge est exécutée chaque heure. Une restauration ultérieure est de nouveau vérifiée auprès de Google Play.
Firebase Cloud Messaging. L'application Android intègre Google Firebase Cloud Messaging pour les notifications facultatives d'événements de caméra. Firebase peut traiter un identifiant d'installation Firebase, le jeton d'inscription FCM, les informations de package et de version de l'application, ainsi que les informations techniques d'appareil ou de routage réseau nécessaires au fonctionnement et à la sécurité de la livraison. L'application actuelle peut recevoir des messages FCM contenant uniquement des données, applique les filtres de notification de l'utilisateur sur l'appareil et construit localement la notification visible.
Relais de notifications Android LorisLabs. Lorsqu'elle est configurée, une inscription authentifiée au relais contient le jeton FCM, l'identifiant du serveur Frigate, les filtres de libellés et le score minimal de notification, la langue, la version de l'application et la date de dernière mise à jour. Pour la livraison, le relais traite les identifiants d'événement et de revue, le nom de la caméra, le libellé ou sous-libellé, les zones, le score, les horodatages, la gravité et la disponibilité éventuelle d'un clip ou d'un instantané. Il envoie ces métadonnées via Firebase ; il ne reçoit ni identifiant Frigate, ni flux en direct, ni enregistrement, clip, instantané ou image d'événement. Le transport privé du relais utilise Tailscale. Cette version Android n'inscrit pas automatiquement son jeton FCM auprès du relais LorisLabs et ne crée donc pas elle-même une telle inscription.
Les inscriptions au relais sont supprimées après 90 jours sans actualisation réussie, avec un contrôle au démarrage puis toutes les heures. Les jetons signalés par Firebase comme désinscrits ou introuvables sont supprimés immédiatement. Une demande de suppression authentifiée retire l'association exacte entre serveur et jeton sans révéler si elle existait.
Cette version Android ne crée aucun compte LorisLabs. Pour une question relative à la vie privée ou une demande concernant les données du vérificateur d'achats ou du relais, écrivez à [email protected]. N'envoyez par email et ne placez dans une URL aucun identifiant Frigate, contenu de caméra, jeton FCM, jeton d'achat Google Play brut ou jeton d'intégrité. LorisLabs fournira une procédure de vérification sécurisée si des informations sont nécessaires pour retrouver l'enregistrement concerné. La suppression des données du vérificateur exige des preuves récentes, validées par Google, concernant l'application, l'intégrité et l'achat ; une requête authentifiée supprime atomiquement les empreintes correspondantes. Cette version ne propose pas encore cette action de suppression dans l'application. Une restauration d'achat demandée ultérieurement par l'utilisateur peut créer une nouvelle empreinte après vérification par Google.
Face Data (Lumen for Frigate)
Lumen for Frigate includes face recognition features that allow you to register and identify known people in your camera feeds. This section explains how face data is collected, used, and stored.
What Face Data Is Collected
When you use the face recognition feature, you may upload photographs of people from your device's photo library to your self-hosted Frigate NVR server. These photographs are used by your Frigate server to identify known people in camera feeds. The Lumen app acts solely as a client — it transmits the photos you select directly to your own server and displays face thumbnails retrieved from it.
How Face Data Is Used
Face data is used exclusively for the purpose of identifying known people in your camera feeds on your self-hosted Frigate NVR. The app displays face thumbnails and recognition results fetched from your server. LorisLabs does not process, analyze, or perform any computation on face data — all face recognition processing occurs on your own Frigate NVR hardware.
Third-Party Sharing
Face data is never transmitted to LorisLabs, Apple, or any third party. All face images and recognition data remain exclusively on your self-hosted Frigate NVR server, which you own and control. The app communicates only with your server over your local network or VPN — no relay servers or intermediaries are involved.
Storage Location
All face data is stored on your self-hosted Frigate NVR server. The Lumen app does not persistently store face images on your Apple device beyond standard temporary URL caching managed by the operating system.
Data Retention
Face data persists on your Frigate NVR server until you choose to delete it. You can delete individual face images or entire face registrations at any time through the Lumen app or through Frigate's web interface. LorisLabs has no ability to access, modify, or delete your face data as it resides entirely on hardware you control.
Your Control
You have full control over your face data at all times. You can add, view, and delete face registrations directly within the app. The face recognition feature is optional and requires your explicit action to register any face photographs.
Rampart for OPNsense — Firewall Monitoring Privacy Details
Rampart connects your device directly to your own OPNsense firewall. All monitoring and management data flows only between your device and your firewall — LorisLabs operates no servers in this path and never receives your network data.
Credentials & Keys
- OPNsense API credentials (key and secret) are stored in the iOS/macOS Keychain and used only to reach the firewall you configured. They are never transmitted to LorisLabs.
- SSH key (Terminal) — When you use the in-app Terminal, Rampart generates an ed25519 SSH key on your device. The private half stays in the Keychain and never leaves the device; you install only the public half on your firewall. The firewall's SSH host key is pinned on first connection (trust-on-first-use), and any later change is flagged for your review before you reconnect.
Optional Cloud AI Features
Rampart's AI Assistant and Terminal co-pilot are off unless you supply your own Anthropic API key. When enabled:
- The context you ask about — firewall status data for the Assistant, or the terminal command and output you explicitly ask the co-pilot to explain or act on — is sent to Anthropic's Claude API using your own key, and is governed by Anthropic's Privacy Policy.
- Your API key is stored in the iOS/macOS Keychain and is never transmitted to LorisLabs. LorisLabs does not receive, store, or retain any of your firewall data or terminal content.
- The AI only proposes commands — it never runs anything on its own. You review and run every command yourself.
- You can remove the API key at any time to disable all cloud AI and keep Rampart fully direct-to-firewall.
Éclair — EV Navigation Privacy Details
Location Data
Éclair requires location permission for navigation and route planning. Your location data is processed entirely on your device and is never transmitted to LorisLabs. Location history is stored locally in SwiftData for trip analytics and driving statistics. You can delete individual trips or clear all location history at any time within the app.
Vehicle Data
Éclair connects to your electric vehicle through multiple methods:
- OBD-II Bluetooth — Vehicle telemetry (state of charge, battery temperature, energy consumption) is read via a Bluetooth OBD-II adapter and processed on-device. No vehicle data is transmitted to LorisLabs.
- Brand APIs (Renault, Volvo) — If you connect via a manufacturer API, authentication tokens are stored in the iOS Keychain. Vehicle data retrieved from these APIs is stored locally.
- SmartCar API — If you connect via SmartCar, OAuth tokens are stored in the iOS Keychain. SmartCar's privacy policy applies to data processed by their service.
- Manual Entry — No external connections. All data is stored locally.
Charging Station Data
Éclair searches for charging stations using the Open Charge Map API. Search queries contain your approximate location to find nearby chargers. No personal identifiers are included in these requests. Charger results are cached locally.
Parking Features
Éclair searches for nearby parking using third-party APIs:
- OpenStreetMap Overpass API — Parking location queries are sent as geographic bounding box coordinates. No personal identifiers, device IDs, or user data are included. Results are cached locally for 7 days.
- ParkAPI (parkendd.de) — Real-time parking availability queries are sent by city name and coordinates. No personal identifiers are included. City lists are cached for 24 hours.
- Payment App Integration — Éclair can deep-link to third-party parking payment apps (PayByPhone, EasyPark) if installed on your device. No payment data is processed, stored, or transmitted by Éclair. You interact directly with the payment app. If the payment app is not installed, Éclair redirects to its App Store listing.
Parking search count is tracked locally for freemium gating purposes and is never transmitted.
Traffic Data Collection
Éclair includes a community traffic intelligence system. When traffic data sharing is enabled in Settings:
- What is collected: Average speed per road segment, stop events, route deviation indicators, and energy consumption anomalies.
- Anonymization safeguards: Raw GPS traces are never uploaded. All data is aggregated on-device into road segment averages. Coordinates are converted to H3 spatial cell hashes (not exact locations). Timestamps are coarsened to 5-minute intervals.
- K-anonymity gate: Traffic data for a road segment is only uploaded to CloudKit when at least 3 users have contributed data for that segment. This prevents individual trip traces from being reconstructable.
- No user IDs: Traffic segment records in CloudKit contain no user identifiers. Individual contributions are not traceable to any user.
- Storage: Traffic data is stored in the CloudKit public database (
iCloud.com.lorislab.eclair). LorisLabs does not operate separate servers for traffic data.
Traffic data sharing can be disabled at any time in Settings.
Community Features & Incident Reporting
Éclair includes opt-in community features that require Apple Sign-In:
- Community Profile — When you sign in, a profile is created containing: your first name and last initial (e.g., "Kevin N."), vehicle model, member-since date, and a computed trust score. Your full name, email address, and Apple ID are not exposed to other users. Profiles are stored in the CloudKit public database.
- Incident Reporting — You can report road incidents (accidents, police controls, road closures, hazards, construction, weather). Reports include: incident type, location, direction of travel, and your reporter ID. Other users can upvote or downvote incidents. Incidents auto-expire after 1–7 days depending on type.
- Trust Score — A reputation score (0–100) is computed from an audit trail of events (confirmed incident reports, ride ratings, user reports). The score is computed from the event log — never stored as a mutable value. Trust score events are stored in CloudKit.
Community features are disabled by default and require explicit opt-in and Apple Sign-In.
Carpooling (Preview)
Éclair includes an optional carpooling feature, labeled as "Preview", that facilitates cost-sharing rides between users. This feature is structured as non-commercial ride-sharing (covoiturage) in compliance with French Transport Code Article L3132-1.
- Data collected: Ride requests (origin, destination, departure time, passenger count), booking confirmations, in-ride messages between participants, post-ride ratings, and ride history.
- Cost-splitting: The cost-splitting algorithm calculates shares based on actual trip costs (energy, tolls, vehicle wear). The algorithm is designed so that drivers cannot profit — cost-sharing is capped at actual trip cost.
- Messaging: In-ride messages are stored in CloudKit and are visible only to ride participants. Messages are not end-to-end encrypted.
- Ratings & Moderation: Post-ride ratings affect trust scores. Users with low trust scores (below 40) or who are suspended cannot access carpooling. Users can be reported, which triggers trust score penalties. Repeated offenses result in 7-day bans or permanent suspension.
- Data retention: Carpooling ride records (including route, participants, and cost breakdown) are retained for 12–24 months. This retention period is required for potential law enforcement requests (réquisition judiciaire) under applicable French and EU law (GDPR Article 6(1)(c)).
- Anonymized vs. identifiable data: Anonymous traffic data (segment averages with no individual traces) is kept separate from identifiable ride data (which includes participant IDs and routes).
Carpooling is off by default, requires explicit opt-in in Settings, and requires an active community profile with Apple Sign-In.
AI Features
Éclair's three-tier AI system processes data as follows:
- Apple Intelligence — Runs entirely on-device. No data leaves your device.
- Local LLM (Ollama) — Runs on your local network. No data leaves your network.
- Cloud AI (Claude, OpenAI) — If you configure a cloud provider with your own API key, trip data you choose to analyze is sent to their servers. This is off by default. API keys are stored in the iOS Keychain. See Anthropic's Privacy Policy and OpenAI's Privacy Policy for details on how they handle your data.
Cross-Border Data Transfers
When you enable community features, data is stored in Apple CloudKit, which may process and store data on servers located outside the EU/EEA. Apple provides appropriate safeguards for international data transfers under GDPR Articles 44–49. See Apple's Privacy Policy for details.
If you connect your vehicle via SmartCar, data is transmitted to SmartCar Inc. (US-based). See SmartCar's Privacy Policy. If you use optional cloud AI providers (Anthropic, OpenAI), data is transmitted to US-based servers and is subject to their respective privacy policies.
For on-device-only usage (the default), no personal data is transferred outside your device.
CarPlay
When used with CarPlay, Éclair displays navigation and charge information on your vehicle's display. No additional data collection occurs through CarPlay beyond what is described above.
Device Permissions
Éclair requests the following permissions, each used solely for on-device functionality:
- Location (Always) — Required for navigation, route tracking, background trip recording, and traffic data collection. Location data is stored locally; only anonymized segment data is shared if traffic sharing is enabled.
- Bluetooth — Required for OBD-II adapter connectivity. No Bluetooth data is transmitted externally.
- Speech Recognition — Required for voice commands during navigation. Processing occurs on-device.
- Notifications — Required for charge alerts, navigation updates, incident alerts, and carpooling notifications.
Location Permission Justification
Éclair requests "Always" location permission (rather than "When In Use") for the following specific reasons:
- Background trip recording: To accurately track your route, energy consumption, and driving statistics while the app is in the background or the screen is off during navigation.
- Live Activities: To update your Lock Screen with real-time navigation progress and charge status.
- Traffic data collection: If enabled, to contribute anonymized segment speed data while navigating in the background.
You can change location permission to "When In Use" or revoke it entirely at any time in iOS Settings > Privacy & Security > Location Services > Éclair. Background trip recording and traffic collection will not function without "Always" permission, but all other features remain available.
Data Retention
Éclair retains data for the following periods:
- Trip history & driving statistics: Stored locally indefinitely until you delete them within the app.
- Community profiles: Stored in CloudKit indefinitely until you delete your profile.
- Incident reports: Auto-expire after 1–7 days depending on type.
- Trust score events: Stored in CloudKit for the lifetime of your community profile. Deleted when you delete your profile.
- Traffic segment data: Anonymous segment averages in CloudKit are retained indefinitely as they contain no user identifiers.
- Carpooling ride records: 12–24 months (legal retention requirement), then permanently deleted.
- Carpooling messages: Retained for the same period as their associated ride record (12–24 months).
- Vehicle data (OBD-II readings): Stored locally indefinitely until you delete them or disconnect the vehicle.
- Parking search cache: OpenStreetMap results cached 7 days; ParkAPI city lists cached 24 hours.
Data Deletion & GDPR Rights
You can delete your community profile, ride history, incident reports, and all local data at any time within the app. Deleting your community profile removes your profile record, associated trust score events, and incident reports from CloudKit. Anonymous traffic segment contributions cannot be individually deleted as they contain no user identifiers.
Account deletion: In compliance with Apple App Store Review Guideline 5.1.1(v), Éclair provides in-app account deletion for community profiles. Deleting your account removes all associated data from CloudKit, except carpooling ride records within the legal retention period (12–24 months), which are retained in anonymized form with participant IDs removed.
Under GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) — Request a copy of your personal data.
- Right to rectification (Art. 16) — Correct inaccurate data.
- Right to erasure (Art. 17) — Request deletion of your data, subject to legal retention obligations.
- Right to restrict processing (Art. 18) — Request that we limit how we process your data.
- Right to data portability (Art. 20) — Receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — Object to processing based on legitimate interest.
- Right regarding automated decisions (Art. 22) — Éclair's trust score is computed algorithmically from your activity history. You have the right to request human review of trust score decisions that affect your access to features (e.g., carpooling eligibility).
- Right to withdraw consent — You may withdraw consent for any optional feature at any time by disabling it in Settings.
To exercise any of these rights, contact [email protected]. We will respond within one month as required by GDPR Article 12(3). You also have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) at www.cnil.fr if you believe your data protection rights have been violated.
No Analytics or Tracking
Éclair contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.
Heol — Email Client Privacy Details
Email Data
Heol connects directly to your email provider via IMAP and SMTP protocols. All email messages, headers, subjects, sender addresses, and metadata are stored locally on your device in an encrypted SQLite database (SQLCipher). LorisLabs never has access to your emails — the app communicates only with your email provider's servers.
Credentials
Your IMAP/SMTP credentials (passwords, OAuth tokens) are stored exclusively in the iOS/macOS Keychain. API keys for optional AI providers are also stored in the Keychain. Credentials are never transmitted to LorisLabs servers.
On-Device AI Processing
Heol uses multiple on-device AI features that run entirely on your device:
- Phishing Detection — Uses custom CoreML models to classify email threats. No email content is sent to any server for threat analysis. This is a core privacy guarantee of Heol.
- Email Triage — AI priority scoring, category classification, urgency detection, and action item extraction all run on-device via CoreML and Apple Intelligence.
- Email Summaries — Generated on-device using Apple's Foundation Models framework when available.
Optional Cloud AI Providers
Heol allows you to optionally configure third-party AI providers (such as Anthropic Claude or OpenAI) using your own API key. If you enable a cloud provider:
- Email content (subjects, body text, sender addresses) may be sent to the configured provider for AI processing (summarization, chat, composition assistance).
- A clear privacy warning is shown when you first enable a cloud provider.
- You can switch back to on-device-only processing at any time.
- LorisLabs does not operate these cloud services and has no access to the data you send to them.
Contacts, Calendar, Location, Reminders
Heol requests access to your Contacts (to show sender details), Calendar (to create events from emails), Location (for location-based snooze), and Reminders (to create follow-up tasks). Each permission is requested only when you use the corresponding feature, and all data is processed on-device. LorisLabs never receives this data.
Microphone & Speech Recognition
If you use voice input in Heol's AI chat, audio is processed on-device using Apple's speech recognition. Audio is not recorded, stored, or transmitted to any server.
Data Storage & Encryption
- All email data is stored in an encrypted SQLite database (SQLCipher) on your device.
- The database encryption key is stored in the Keychain and synced via iCloud Keychain for multi-device access.
- iOS Data Protection (completeUntilFirstUserAuthentication) is applied to the database directory.
- PDF sanitization output is written to the system temporary directory and cleaned up automatically.
- Quarantined phishing emails are stored in a dedicated directory excluded from iCloud backup.
Tracker Blocking
Heol blocks known email tracking pixels and strips EXIF metadata from images displayed in emails. Blocked tracker domains are matched against a locally-stored blocklist — no network requests are made for tracker detection.
End-to-End Encryption (PGP)
Heol supports optional PGP encryption for email content. PGP keys are stored locally on your device and are not synced to iCloud. Encryption and decryption happen entirely on-device.
Data Deletion
You can delete individual emails, clear cached data, or remove entire email accounts at any time within the app. Uninstalling the app removes all associated data from your device, including the encrypted database and Keychain entries.
Analytics & Telemetry
Heol contains no analytics SDKs, no tracking pixels, no advertising frameworks, and no telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.
ProofCheck — Device Verification Privacy Details
What ProofCheck Is
ProofCheck is a device-inspection and verification app for iPhone, iPad, Mac, and Apple Vision Pro. It runs a battery of diagnostic tests on the local device (sensors, battery, storage, warranty status, etc.), combines them into a "trust score", and produces a report that a seller can share with a buyer via a short code or link. Unlike most LorisLabs apps, ProofCheck does collect and transmit personal data by design, because the product purpose is for a buyer to verify a seller's device across the internet. This section explains exactly what is collected, why, where it is stored, and how you can delete it.
Data We Collect
- Email Address (Sign in with Apple) — If you choose to sign in as a seller (to have your reports cryptographically associated with a persistent identity), Apple returns your email address. ProofCheck stores this email to label your generated reports. Purpose: App functionality. Linked to user: yes. Used for tracking: no.
- Coarse Location — ProofCheck uses
CLLocationManagerwith reduced accuracy (approximate location, not precise GPS) and IP-based geolocation to confirm that the device's claimed region matches its physical location. This is a trust signal in the score. Purpose: App functionality. Linked to user: yes (it is persisted into your trust report). Used for tracking: no. - Device Identifiers — On macOS, ProofCheck reads the Mac's serial number (via
IOPlatformSerialNumber). On iOS / iPadOS / visionOS, ProofCheck derives a stable per-installation identifier fromidentifierForVendor. These identifiers are stored in your report for anti-fraud and buyer-side comparison. Purpose: App functionality. Linked to user: yes. Used for tracking: no. - Performance & Diagnostic Data — ProofCheck records thermal state, battery health, sensor health, storage figures, warranty/coverage status, jailbreak/SIP indicators, system boot time, and similar trust signals. These are combined into your trust score and persisted into the report. Purpose: App functionality. Linked to user: yes. Used for tracking: no.
Where Your Data Is Stored
- Private CloudKit database (
iCloud.com.lorislab.proofcheck) — Your personal report history is stored in your private CloudKit database, tied to your Apple ID. Only you can read it. LorisLabs cannot access it. Apple provides encryption in transit (TLS) and at rest. - Public CloudKit database (
iCloud.com.lorislab.proofcheck) — When you explicitly generate a shareable code for a buyer, a redacted copy of the report is written to the public database so the buyer can retrieve it with the code. Publicly-shared reports are subject to redaction rules (see below) and automatically expire. - IP Geolocation Service — To determine the network region for the trust score, ProofCheck queries a LorisLabs-operated Cloudflare Worker which returns coarse geographic information (country/region/city/ISP) from the caller's IP. The Worker does not log requests. Your IP address is observable by Cloudflare as a technical necessity of the HTTPS request; Cloudflare's privacy policy applies to their edge network.
- On-device — Your signed-in email, dev-mode preferences, and cached device catalog are stored on-device in
UserDefaultsand the Keychain (for sensitive items).
What Is Shared Publicly When You Share a Report
When a seller generates a share code, a report copy is written to the CloudKit public database so a buyer can fetch it. We minimize what is placed in the public record. Publicly-shared records expire automatically and are periodically purged.
Third-Party Verification Pages
ProofCheck also supports a web-viewer flow where a buyer without the app scans a QR code and opens https://lorislab.fr/verify#<fragment>. The entire report payload travels in the URL fragment (which never leaves the buyer's browser and is not sent to our server logs). The page performs integrity verification in-browser using JavaScript. No personally-identifying fields are transmitted to LorisLabs beyond standard web-server access logs (IP, User-Agent) which are retained for 30 days for security purposes.
Account Deletion and Data Erasure
In compliance with Apple App Store Review Guideline 5.1.1(v) and GDPR Article 17 (right to erasure), ProofCheck provides in-app account deletion. From Settings → Account you can:
- Sign Out — removes the Apple ID email from the device. Your reports in your private CloudKit database are kept (tied to your Apple ID).
- Delete All My Data — deletes all your reports from your private CloudKit database, purges cached app preferences on-device, deletes the dev-mode Keychain item if any, and clears the App Attest key identifier. Publicly-shared reports that have not yet expired are also deleted. This action is irreversible.
If Delete All My Data encounters any record it cannot delete (e.g., due to iCloud being unavailable), you will be informed and can retry when connectivity is restored.
Retention
- Private reports: retained until you delete them or delete your account.
- Public shared reports: automatically expire after the period shown in-app; expired records are deleted.
- On-device preferences: retained until you sign out, delete the app, or use Delete All My Data.
Device Permissions
- Location (When In Use / reduced accuracy): required for the physical-region trust signal. You can deny location and the app will continue to work (the region signal simply contributes less to the score).
- Camera & Photos: optional, used for the camera / display-dead-pixel diagnostic tests. Image data is processed in memory and never transmitted.
- Microphone: optional, used for the speaker / microphone diagnostic tests. Audio is processed in memory and never transmitted.
- Network: required for CloudKit, IP geolocation, warranty lookup, and time-sync trust checks.
No Analytics or Tracking
ProofCheck contains no third-party analytics SDKs, no tracking pixels, no advertising frameworks, and no behavioral telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.
Children's Privacy
ProofCheck is not directed at children under 13 and we do not knowingly collect personal information from children. In the EU, Sign in with Apple requires users to be at least the digital age of consent in their member state (16 in France under CNIL guidelines).
Velya — Smart Alarm Privacy Details
What Velya Is
Velya is a smart alarm app for iPhone (with Apple Watch, Mac, and widget companions) built on Apple's AlarmKit framework. Its purpose is to wake you reliably — breaking through silent mode, Do Not Disturb, and Focus — and to run optional automations around your alarms. Velya is a privacy-first, on-device app: it requires no account, no sign-in, and LorisLabs operates no server that receives your data. App Privacy: Data Not Collected.
Data Stored On Your Device
- Alarms, automation rules & settings — stored on-device (SwiftData / UserDefaults). If you enable iCloud, they sync through your own private iCloud account via CloudKit; LorisLabs cannot read them.
- Apple Health (sleep) — with your permission, Velya reads sleep-analysis samples from HealthKit to wake you within a smart window at your lightest sleep phase, and to display your sleep history and trends. This data is read and processed entirely on-device and is never transmitted off your device or to LorisLabs. Velya does not write any data to Health.
- Location — with your permission, Velya uses location (including in the background, "Always") for location-based automations you create (enabling/disabling alarms when you arrive at or leave a place) and to help detect your bedtime. Location is processed on-device; it is never collected or transmitted. You can deny location and Velya still works fully with manual alarms.
- Weather — weather-based automation rules use Apple WeatherKit. Weather queries are made for your local conditions to evaluate rules; no personal data is attached.
Optional Remote Control (Self-Hosted)
Velya includes an optional feature for advanced users to trigger or reschedule alarms remotely — for example from a home-automation system. This requires you to run your own self-hosted relay server. You provide a server address and an access token (which you generate on your own server) in Settings; the token is stored in the iOS Keychain on your device. All communication is between your device and your own server. LorisLabs does not operate any relay or backend, and receives no data through this feature. The app is fully functional without it.
Notifications
With your permission, Velya sends local notifications before alarms and when your automations run. On iOS versions before 26 (where AlarmKit is unavailable), notifications are also used as the wake mechanism.
Device Permissions
- Alarms (AlarmKit): the core permission — lets Velya's alarms ring through silent mode, Do Not Disturb, and Focus.
- Notifications: optional, for pre-alarm and automation alerts.
- Apple Health (read-only): optional, for smart wake and sleep history. On-device only.
- Location (Always / When In Use): optional, for location automations and bedtime detection. On-device only.
No Analytics or Tracking
Velya contains no third-party analytics SDKs, no tracking pixels, no advertising frameworks, and no behavioral telemetry. The only information we may receive is anonymized, aggregated data from Apple's App Analytics program, which you can opt out of in your device settings.
Arcyra — Preview Privacy Details
Arcyra is a macOS utility, distributed by Developer ID direct download (not through the App Store) and currently offered as an unvalidated engineering preview — see arcyra.html for its full preview status and limits.
Data Collected
The only data category Arcyra collects is Customer Support data (linked to your identity) — information you provide if you contact us for help, such as your email address and the content of your message. This is collected solely to respond to your request and is not used for any other purpose.
No Tracking
Arcyra does not track you and contains no tracking domains, analytics SDKs, advertising frameworks, or behavioral telemetry of any kind. Mission activity, receipts, and settings are stored locally on your Mac.
Home Assistant & MQTT (Off by Default)
Arcyra includes optional integrations for publishing mission status to a self-hosted MQTT broker or Home Assistant instance. These integrations are disabled by default and only become active if you explicitly enable them and configure your own broker/instance address in Settings. When enabled, communication is directly between your Mac and the server you specified — LorisLabs does not operate any relay and receives no data through this feature.
No Telemetry
Arcyra sends no telemetry — no crash reports, usage statistics, or diagnostics are transmitted to LorisLabs or any third party.
Children's Privacy
Most of our Apps do not collect personal information and are suitable for users of all ages. However, certain features in specific apps do involve data collection:
- Éclair community features and carpooling: These features require Apple Sign-In and collect personal data (display name, ride history, messages). Community features require users to be at least 16 years old (the digital age of consent in France under CNIL guidelines). Carpooling requires users to be at least 18 years old. Minors under 16 may not create a community profile. Minors aged 16–17 may use community features (incident reporting, traffic sharing) but may not use carpooling.
- Synthesis Young Student persona: Includes parental controls and age-appropriate content. See the Synthesis privacy section for COPPA and FERPA details.
- All other apps: Do not collect personal information from any users, including children. No account creation is required.
If you are a parent or guardian and believe your child has created a community profile or used carpooling without authorization, please contact us at [email protected] and we will promptly delete the account and associated data.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our Apps or applicable regulations. We will notify users of significant changes through app updates or on our website. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued use of our Apps after changes constitutes acceptance of the revised policy.
Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
Email: [email protected]
Website: Support Page