Skip to main content

Privacy Policy

Version 2 · Last updated 2026-07-31 13:35:00.296237+00
All documents Back Sign in

The Utility App — Privacy Policy

Effective date: 2026-07-31 Version: 2

Supersedes Version 1 (2026-05-08). Version 2 does not change what we do with your information; it describes features that were added since Version 1 and that Version 1 did not mention — connected Google/Microsoft calendars, company chat, AI-assisted features, multi-factor authentication, uploaded images, and API keys. See section 13 for a summary of what changed.

This Privacy Policy explains how The Utility App ("the Service", "we", "us") collects, uses, stores, and protects information about you when you create an account or use the Service. By creating an account or using the Service you acknowledge that you have read and understood this Policy.

The current authoritative version of this Policy is the one published in the Administrator panel of the Service. Administrators may update this Policy at any time; any changes take effect when the new version is published. Where a change is material you may be asked to re-accept the Policy before continuing to use the Service.

1. Information we collect

1.1 Account information

  • username
  • email address
  • hashed password (never stored in plain text)
  • optional profile information (full name, cellphone, timezone)
  • an optional profile picture, which is stored inside the Service's database rather than as a file
  • account role and per-app permissions
  • a record of which version of this Policy and of the Terms and Conditions you accepted, and when

1.2 Security and sign-in information

  • if you enable multi-factor authentication, a secret used to verify your authenticator app
  • for each device you mark as trusted: a hashed device token, its expiry, the browser user-agent string, and the IP address last seen using it
  • hashed values of any application-specific passwords or API keys you generate. We never store the key itself — only a hash and a short prefix so you can recognise it in a list. A lost key cannot be recovered, only revoked and replaced.

1.3 Content you create

  • notes, diary entries, lists, calendar entries, reminders, tasks and projects, bookmarks, savings and budget data, contacts, statistics, documents, worlds and stories created in the Lore app, and any other data you save while using the Service's apps
  • passwords stored in the Password Manager, which are encrypted at rest with a key derived from your master password and held only in server memory while you are signed in
  • images and files you upload

1.4 Communication features

  • If you use the Email app, you supply your own mail account's server details and credentials. These are stored encrypted so that the Service can connect on your behalf. Messages fetched from your mail server are cached by the Service so it can display them; the originals remain on your own mail provider's servers.
  • If your organisation uses Company Chat, we store the messages you send, the files you attach, which conversations you belong to, and delivery state such as how far you have read and whether you are currently active. Read receipts can be turned off individually in your settings. Message retention is set by your organisation's administrator.

1.5 Connected Google and Microsoft accounts (optional)

  • If you choose to connect a Google or Microsoft calendar, we store an encrypted access token and refresh token for that account, the email address of the connected account, the scopes you granted, and details of the calendars and events being synchronised.
  • These tokens let the Service act on your calendar on your behalf until you disconnect the account. You can disconnect at any time from within the Calendar app, and you can additionally revoke the Service's access from your Google or Microsoft account settings.
  • We request only the permissions needed for the features you use. We do not read your mail through these connections.

1.6 AI features (optional)

  • When you use AI Chat, AI Search or AI Tasks, the text of your prompt — and any content the feature is asked to work with — is sent to the AI model configured for this deployment. Your conversation history is stored so you can return to it.
  • This deployment is configured to use a self-hosted model by default. Where an operator configures an external AI provider or an external web search provider instead, your prompts are transmitted to that provider, and that provider's own privacy terms will apply to what it receives. Ask your administrator which is in use for your deployment.
  • Automated AI Tasks may store credentials you give them; these are encrypted at rest.

1.7 Technical / usage data

  • IP addresses of devices that access the Service, retained for abuse prevention and to operate the block/allow lists
  • browser user-agent string
  • timestamps of logins, sign-ups, and significant actions
  • pages and routes visited, for security, abuse-prevention and audit purposes
  • error reports generated by the Service
  • anonymous page-performance measurements, which are not stored

1.8 Cookies and local storage

  • a session cookie used to keep you signed in;
  • an optional "remember me" cookie if you opt in;
  • a CSRF cookie used to protect form submissions;
  • a theme-preference cookie;
  • if you complete a bot check, a signed cookie recording that you did.

We do not use advertising or cross-site tracking cookies.

2. How we use your information

We use the information we collect to:

  1. provide, operate, secure, and improve the Service;
  2. authenticate you and protect your account from unauthorised access;
  3. communicate with you about your account (e.g. email verification, password resets, important Service notices);
  4. deliver the notifications you have asked for, in the app and — where you have enabled it — by email;
  5. synchronise data with services you have explicitly connected, such as a Google or Microsoft calendar or your own mail server;
  6. detect, investigate, and prevent abuse, fraud, and security incidents;
  7. keep audit and error logs as required for the safe operation of the Service;
  8. record that you accepted these Terms and the Privacy Policy on a specific date and version, so we can demonstrate consent if required;
  9. administer any subscription or access grant associated with your account.

We do not use your content to train AI models, and we do not sell your personal information.

3. Legal bases (where applicable)

Where data-protection law requires a legal basis, we rely on:

  • performance of a contract with you (providing the Service you signed up for);
  • your consent — in particular for connecting a Google or Microsoft account, and for optional features you switch on;
  • our legitimate interests in operating, securing, and improving the Service; and
  • compliance with legal obligations.

Where you connect a third-party account, that consent is specific to that connection and you may withdraw it at any time by disconnecting the account.

4. Sharing of information

We do not sell your personal information. Information is shared only:

  1. With providers strictly necessary to operate the Service. Which of these are active depends on how your deployment is configured — none of them is enabled by default: - the mail server you configured in the Email app (your instruction); - the SMTP server your administrator configured for Service email; - Google and/or Microsoft, if you connect a calendar account; - Google reCAPTCHA, if bot protection is enabled; - an error-monitoring provider, if one is configured; - an AI provider and/or web-search provider, if the deployment uses an external one rather than a self-hosted model.

Your administrator can tell you which are in use. 2. With other users of the Service where you choose to share — for example by inviting someone to a company workspace, sharing a document, list, project or Lore universe, or posting in Company Chat. 3. Where required by law, regulation, court order, or other legal process. 4. To protect the rights, property, or safety of the Service operators, our users, or the public.

Content you share into a company workspace is visible to the members of that workspace according to their roles, and remains available to that workspace even if you later leave it.

5. Data retention

  1. Account data is retained for as long as your account exists.
  2. Pending (unverified) sign-ups are automatically deleted after 48 hours.
  3. Audit logs, error logs, IP-tracker entries, and acceptance records are retained for as long as reasonably necessary for security, legal, and operational purposes.
  4. Cached email messages are held only so the Email app can display them; the originals remain on your own mail provider's servers and are not affected by anything the Service deletes.
  5. Company Chat messages are retained according to the retention period set by your organisation's administrator.
  6. Items deleted in the Lore app are held in a recycle bin for 30 days before being removed permanently. A limited number of earlier revisions of each item is kept so you can restore previous versions.
  7. Trusted-device records expire automatically. Revoked API keys are kept as a record that they existed and were revoked.
  8. When your account is deleted, your personal account data and the content you created are removed, except: - records we are required to retain (such as legal-acceptance records or audit logs) for legitimate purposes; and - content you contributed to a shared company workspace, which belongs to that workspace. Ask your administrator about their policy for this.

Deleting your account does not, by itself, revoke the Service's access to a connected Google or Microsoft account. If you have connected one, you should also disconnect it in the app, or revoke access from your Google or Microsoft account settings.

6. Security

We use a range of technical and organisational measures to protect your information, including:

  • passwords are stored only as salted, hashed values, using a modern memory-hard hashing algorithm;
  • optional multi-factor authentication;
  • sensitive content — Password Manager entries, mail-account credentials, connected-calendar tokens, and AI Task secrets — is encrypted at rest;
  • the Password Manager's encryption key is derived from your master password and exists only in server memory while your vault is unlocked; it is never sent to your browser and is not recoverable by an administrator;
  • separation of each user's data at the database level, so that the database itself — not only the application — enforces the boundary for the great majority of personal data;
  • HTTPS / TLS in transit when the Service is deployed over HTTPS;
  • a strict Content Security Policy, CSRF protection on form submissions, and security headers on every response;
  • rate-limiting and brute-force protection on authentication;
  • per-IP and per-account abuse controls;
  • no page of the Service is indexable by search engines.

No system is perfectly secure; you use the Service at your own risk.

7. Your rights

Subject to applicable law, you may have the right to:

  • access the personal information we hold about you;
  • request correction of inaccurate information;
  • request deletion of your account and associated data;
  • object to or restrict certain processing;
  • receive your data in a portable, machine-readable form;
  • withdraw consent (where processing is based on consent).

You can exercise several of these yourself from within the Service:

  • Profile → Export your data, which produces a machine-readable archive;
  • Profile → Delete your account;
  • Preferences, to control which apps notify you and whether read receipts are shared;
  • Calendar → Settings, to disconnect a connected Google or Microsoft account.

For anything else, contact the Service administrator through the contact details published within the Service.

8. Content about other people

Some apps let you store information about people other than yourself — for example contacts, calendar invitees, email correspondents, and free-text content such as notes, diary entries and stories.

For that information you are the one deciding what is collected and why, and you are responsible for having a proper basis to store it and for handling any request you receive about it. The Service processes it on your instruction.

9. Automated decision-making

The Service does not make automated decisions that produce legal or similarly significant effects about you. Automated processing that does occur — spam classification in the Email app, and AI features you invoke — assists you and does not decide anything about you.

10. International data transfers

Your information may be processed in the country where the Service is operated. Where data is transferred internationally, we rely on appropriate safeguards permitted by applicable law. The external recipients listed in section 4 are the only routes by which your information leaves this Service, and each is off unless your administrator has enabled it.

11. Children

The Service is not directed at children under the age at which they can legally consent to data processing in their jurisdiction. If you believe a child has created an account without appropriate consent, please contact the Service administrator and we will remove the account.

12. Changes to this Policy

We may modify this Privacy Policy at any time by publishing an updated version in the Administrator panel. Where changes are material, users may be required to re-accept the updated Policy before continuing to use the Service.

13. What changed in Version 2

Version 2 (2026-07-31) describes existing practice more completely. It does not introduce any new use of your information. Newly described:

  • multi-factor authentication, trusted devices, application passwords and API keys (section 1.2);
  • profile pictures being stored in the database (section 1.1);
  • Company Chat, including read receipts and presence, and administrator-set retention (sections 1.4, 5.5);
  • connected Google and Microsoft calendar accounts, the tokens involved, and how to revoke them (sections 1.5, 5.8);
  • AI Chat, AI Search and AI Tasks, and where prompts are sent (section 1.6);
  • which external providers may receive data and the fact that none is enabled by default (section 4);
  • retention for Lore's recycle bin and revisions (section 5.6);
  • the self-service tools for exercising your rights (section 7);
  • your responsibilities for information about other people (section 8);
  • a statement on automated decision-making (section 9).

14. Contact

For questions about this Privacy Policy or about the personal information we hold about you, contact the Service administrator through the contact details published within the Service.