Privacy Policy
Last updated: August 24, 2026
This Privacy Policy explains how Roman Hyrych (“Lorenest”, “we”, “us”) collects, uses, and shares personal data when you use our website at lorenest.app and our products, including the Clicklore desktop application (collectively, the “Service”).
We are committed to data minimisation: we collect only what is necessary to provide and improve the Service. We never sell your personal data.
1. Information We Collect
1.1. Anonymous usage data (Free tier)
When you use Clicklore without signing in, the app sends a small anonymous heartbeat to our backend approximately once per day. This heartbeat contains:
installation_id— a random identifier generated locally on first launch and stored on your device;- application version;
- operating system family (macOS / Windows / Linux) and version;
- system locale (e.g.
en_US); - country derived from your IP address by our network provider; the raw IP address is discarded immediately and never stored.
The installation_id is never linked to any account or to other personal data. You may opt out of telemetry from the Clicklore first-launch dialog or, in the future, from Settings.
1.2. Account data (when you sign up)
When you create a Lorenest account, we collect:
- your email address;
- a hashed copy of your password (we never store raw passwords);
- if you sign in with Google: a Google account identifier received through OAuth (we do not receive your Google password);
- email verification status;
- authentication sessions and refresh tokens.
1.3. Billing data
Payments are processed by Paddle.com Market Limited (“Paddle”) acting as our Merchant of Record. We never see or store your card number, expiry, CVC, or full payment instrument. From Paddle we receive and store:
- your Paddle customer and subscription identifiers;
- subscription status and renewal dates;
- masked payment-method information (e.g. card brand, last four digits);
- transaction status and history.
Paddle is the data controller for billing data they collect to process your payment, calculate VAT/sales tax, and issue invoices. See Paddle’s privacy notice for details.
1.4. Crash and error reports
Clicklore sends crash and exception reports to Sentry so that we can diagnose failures we would otherwise never see. In the desktop app this is gated on the telemetry consent you give at first launch: if you decline, no reports are sent. A report carries the application version and the anonymous installation_id, never your account or your email address, and file paths are stripped of your operating-system user name before it leaves your device. Our backend sends its own server-side error reports to the same service.
1.5. Support requests and contact form
From inside the app. When you send a message from Contact Us in Clicklore, we receive the email address of your account, the category you chose, the subject, the message, and up to three JPG or PNG screenshots if you attach them.
Diagnostic logs with a bug report. If you choose the Bug Report category, the app also attaches a diagnostic bundle automatically. A notice directly above the Send button tells you so, and nothing leaves your device until you press Send. The bundle holds the most recent part of the application log for the current and the previous session, crash dumps from those sessions where they exist, and a short header with the application version, operating system, interface language, and the anonymous installation_id. It is capped at roughly 6 MB and trimmed if it would be larger.
Application logs record what the app itself did: which windows and dialogs opened, which features ran, and any error messages and file paths involved — so they can contain your operating-system user name and the names of files you opened. They do not contain the contents of your scripts, the output log of a script run, or anything captured while a script runs.
Support messages, attachments, and diagnostic bundles reach our support inbox as email, delivered by Resend. We do not keep the message, the attachments, or the bundle in our database: we store only a reference to your account, a shortened subject line, and the time you sent it.
From the website. If you fill out the form on /contact we receive your name, email address, subject, and message via Web3Forms (web3forms.com), which relays the message to our support inbox. We process this data solely to respond to your enquiry.
To protect this form from automated abuse, we use hCaptcha, provided by Intuition Machines, Inc. hCaptcha may process your IP address, device and browser information, interaction data (such as mouse movements, keypresses, and time spent), and challenge responses. We use it on the basis of our legitimate interest in preventing spam, fraud, and abuse.
1.6. Information we do not collect
Except for what you send us yourself, as described in section 1.5:
- Payment card data — handled exclusively by Paddle on their infrastructure.
- The contents of your scripts or recordings — everything you create in Clicklore stays on your local device.
- Screenshots, clicks, keystrokes made while running a script — Clicklore does not transmit any of this to our servers.
2. How We Use Your Information
We use the information we collect to:
- provide and operate the Service (authenticate you, sync subscription status, enable Pro features);
- process payments through Paddle and issue confirmations;
- send transactional emails (verification, password reset, payment failures, subscription notices);
- understand aggregate usage trends (number of installations per country, version adoption);
- respond to your enquiries and support requests;
- detect, prevent, and address technical issues, abuse, or security incidents;
- comply with legal obligations, including tax and accounting requirements (via Paddle).
3. Legal Bases for Processing (EU/UK users)
Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you have requested (account data, billing data, subscription management).
- Legitimate interests — to keep the Service secure and to understand aggregate usage through anonymous telemetry. You may object to this processing at any time.
- Consent — for any optional analytics or marketing communications, which you can withdraw at any time.
- Legal obligation — to retain records required by tax, accounting, or anti-fraud laws.
4. Sharing and Sub-processors
We do not sell your personal data. We share data only with the service providers listed below, each acting as a processor under our instructions or as an independent controller for their part of the service:
- Paddle.com Market Limited (United Kingdom) — payment processing, billing, VAT/sales-tax handling, invoicing, refunds.
- Resend Inc. (United States) — delivery of transactional emails (account verification, password reset) and of support messages sent from the app, including any diagnostic bundle attached to a bug report.
- Render Services, Inc. (United States) — hosting of our backend API and static website.
- Cloudflare, Inc. (United States, global) — DNS and request routing.
- GitHub, Inc. (United States) — source-code hosting, CI, and software release distribution.
- Functions Online LLC (Sentry) (United States) — error tracking and crash reports.
- SaaSWits LLP (Web3Forms) (India) — relay of website contact-form submissions to our support email.
- Intuition Machines, Inc. (hCaptcha) (United States) — automated-abuse prevention for the website contact form.
- Google LLC (United States) — only if you choose to sign in with Google OAuth.
We sign a Data Processing Agreement (DPA) with each sub-processor that acts on our behalf and use providers that contractually commit to appropriate safeguards for international data transfers (Standard Contractual Clauses where applicable).
5. Cookies and Tracking
Our marketing website sets no cookies of its own, and it stores nothing in your browser’s local or session storage. The language you are reading is part of the page address, not something we remember about you. We do not use advertising cookies, and we do not sell or share data with advertising networks.
Two pages are different, and we want to be explicit about them. On our checkout page and on our payment-update page we load Paddle.js, the browser library of Paddle.com Market Limited, our Merchant of Record. Paddle.js opens the secure payment form, and it also initialises Paddle Retain (ProfitWell) — the service Paddle uses to recover failed subscription payments and to measure engagement and retention around them. Loading Paddle.js therefore involves requests to Paddle’s own domains, including public.profitwell.com, and Paddle may set cookies or use equivalent browser storage under its own privacy notice. This is payment and retention functionality, not advertising.
We do not configure Paddle’s optional pwCustomer identification or send a separate email address through Paddle.Initialize. However, checkout uses a Paddle transaction identifier, and payment-recovery links may contain Paddle-provided recovery identifiers, so Paddle can associate the visit with the relevant transaction or subscription and show the requested form. Those identifiers are part of Paddle’s payment and recovery flow, not our own advertising tracking. We never see or store your card number, expiry date, or CVC at any point.
On 24 August 2026 we checked what those two pages actually place in your browser, and Paddle confirmed the same to us in writing. Our own pages set no cookies and write nothing to local or session storage, and the Retain (ProfitWell) script sets no cookies and uses no browser storage at all. What does get written belongs to Paddle’s own payment frame at buy.paddle.com: a check that storage is available, error-diagnostics context for that frame, and a short-lived bot-protection cookie on Paddle’s domain. All of it is partitioned to our site and is needed for the payment form to work. Paddle.js can additionally write first-party cookies that credit a purchase to an affiliate or a referral campaign; we run no affiliate programme and pass no referral parameters, and no such cookie appeared in our checks.
On that basis we do not show a cookie-consent banner on these two pages: nothing written there serves analytics or advertising, and the payment-update page has to load Paddle.js unconditionally, because that script is what draws the card-update form our payment-recovery emails link to. We will revisit this if our configuration changes. No other page on our site loads Paddle.js. For what Paddle collects in its own right, see Paddle’s privacy notice linked in section 1.3.
6. Data Retention
- Account data — retained while your account is active. If you delete your account, we anonymise or remove your personal data within thirty (30) days, except for records we must keep for legal or accounting reasons.
- Billing records — retained by Paddle and by us for the period required by tax and accounting law (typically up to ten (10) years depending on jurisdiction).
- Anonymous telemetry — retained while the installation remains active; removed automatically if no heartbeat is received for an extended period.
- Support correspondence — messages, attachments, and diagnostic bundles stay in our support inbox for as long as needed to resolve your enquiry and for a reasonable period afterwards to handle follow-ups. In our database we keep only the account reference, a shortened subject line, and the time of submission.
7. Your Rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request deletion of your personal data (“right to be forgotten”);
- request restriction of, or object to, certain processing;
- request a copy of your data in a portable format;
- withdraw consent at any time, without affecting prior lawful processing;
- opt out of anonymous telemetry from within the Clicklore application;
- lodge a complaint with your local data-protection authority.
To exercise any of these rights, contact us at lorenest.support@gmail.com. We will respond within thirty (30) days.
8. International Data Transfers
Our sub-processors are located in the United States, the United Kingdom, India, and other regions. Where personal data is transferred outside your country of residence, we rely on appropriate legal mechanisms — such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum — to ensure your data is protected to an equivalent standard.
9. Children’s Privacy
The Service is not directed to children under the age of sixteen (16). We do not knowingly collect personal data from children under sixteen. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Security
We apply reasonable technical and organisational measures to protect your personal data, including password hashing with Argon2, encrypted transport (HTTPS/TLS), storage of authentication tokens in your operating-system keychain, and access controls on our backend. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Material changes will be communicated through the Service or by email where appropriate.
12. Contact Us
For questions about this Privacy Policy or to exercise your rights, contact us at:
Roman Hyrych
Bulevardul Petroliştilor, 013358 Bucharest, Romania
Email: lorenest.support@gmail.com