Skip to content
LoneMade
HomeContact usTermsPrivacy
PRIVACY

Privacy Policy

This Privacy Policy explains how Hao Yin, an individual operator in the United States, handles information when you use LoneMade.

September 19, 2026

1. Data controller and contact

The data controller is Hao Yin, an individual operator in the United States. For privacy requests, contact privacy@lonemade.com. For general support contact support@lonemade.com; for billing contact billing@lonemade.com.

2. Information you provide

  • Account information: email address and display name.
  • Authentication information: password hash, email verification data, password reset data, sessions and security tokens. Passwords and bearer tokens are not stored in plaintext.
  • OAuth information: Google or GitHub subject identifier, verified email and basic profile information when you choose OAuth sign-in. We do not store provider access tokens.
  • User content: tool form inputs, AI prompts, generated outputs, file names, file metadata and uploaded files.
  • Provider information: user-configured Provider endpoints and API keys, stored encrypted so LoneMade can make the request you asked for.
  • Support and communications: messages you send to our support or privacy addresses.

3. Information collected automatically

  • Request and security data such as request time, request path, request ID, error codes, IP/network information and security events.
  • Operational data such as mail delivery status, provider usage, generation status, audit events, backup evidence and deletion records.
  • We do not currently use Google Analytics, advertising pixels, marketing trackers, location data, contacts, Google Drive, Gmail or Google Calendar data.

4. How we use information

  • Provide, secure and maintain LoneMade: contract performance and legitimate interests.
  • Authenticate accounts, verify email and prevent abuse: contract performance and legitimate interests.
  • Run AI tools, files and Provider connections: contract performance.
  • Manage Credits and future subscriptions or billing: contract performance when those features are enabled.
  • Send necessary service, security and policy notices: legitimate interests and legal obligations.
  • Respond to support and privacy requests: contract performance and legitimate interests.
  • Meet legal, accounting and security obligations: legal obligations and legitimate interests.

5. Google and GitHub data

Google OAuth requests only the openid, email and profile scopes. We use the returned verified email, subject and basic profile to create an account, sign in and automatically link an existing LoneMade account with the same verified email. GitHub OAuth is used for the equivalent basic identity purpose.

We do not read Gmail, Google Drive, contacts, calendar or other Google APIs. We do not sell Google or GitHub data, use it for advertising or use it to train an AI model. We share it only with the authentication, infrastructure and AI service components needed to provide the LoneMade feature you requested.

6. Cookies and tracking

  • Necessary cookies maintain login sessions and core security controls. These cannot be disabled while using the service.
  • A short-lived OAuth state cookie protects OAuth sign-in and is deleted after the callback.
  • The lonemade-locale cookie remembers your language preference.
  • We do not currently use analytics or marketing cookies and do not store long-term identity tokens in localStorage.

7. Sharing and service providers

We do not sell personal information. We share information only as needed to provide the service, protect users, comply with law or complete a transaction.

  • Cloud hosting and PostgreSQL/Redis infrastructure.
  • Cloudflare R2 for private object storage.
  • ZeptoMail or the configured SMTP provider for account and service email.
  • ClamAV for private file malware scanning.
  • The AI Provider selected by you or configured by an administrator. Prompts, files or generated data needed for a request may be sent to that Provider.
  • Google and GitHub for OAuth sign-in when you choose it.
  • Waffo Pancake only when paid checkout is enabled; payment card information is handled by Waffo Pancake and is not stored by LoneMade.

8. Security

If a security incident materially affects your rights, we will notify affected users and regulators within the period required by applicable law, with a target of 72 hours where that standard applies.

  • TLS/HTTPS for transport.
  • Argon2id password hashing and HttpOnly, SameSite session cookies.
  • AES-GCM encryption for Provider keys, system secrets and protected mail payloads.
  • CSRF, Origin and administrator access controls.
  • Private object storage and ClamAV scanning for uploaded files.
  • Encrypted local backups, audit logs and operations alerts.
  • We do not place passwords, API keys, OAuth tokens, signed URLs or user prompts in ordinary application logs.

9. Retention and deletion

  • Account information is kept while the account is active and then processed through the account deletion workflow.
  • Generated content is normally retained for 90 days unless a different system setting or legal requirement applies.
  • Private files are normally retained for 30 days or until their configured expiry/deletion workflow completes.
  • Sessions last up to 7 days by default and expire or are revoked earlier when appropriate.
  • Verification and reset payloads are cleared after expiry or consumption.
  • Credits, financial and audit records may be retained for accounting, fraud prevention and legal obligations.
  • Encrypted backups follow their own retention and deletion-recovery journal process.

10. Your rights

Depending on where you live, you may have rights to know, access, correct, delete, restrict or object to processing, receive portable data and withdraw consent. Contact privacy@lonemade.com with enough information for us to locate the account. We aim to respond within 30 calendar days, subject to applicable legal deadlines and verification of the request.

You may complain to the data protection or consumer privacy authority with jurisdiction over you.

11. Cross-border processing

LoneMade is operated from the United States. Cloud, storage, email, OAuth and AI Providers may process information in the United States or other countries. Where required, we use contractual, adequacy or other lawful safeguards for cross-border processing.

12. Children

LoneMade is intended for people aged 18 or older. We do not knowingly collect information from children. If you believe a child provided information, contact privacy@lonemade.com and we will investigate and delete it where required.

13. Third-party services and changes

Third-party services have their own privacy policies, and this policy applies to information LoneMade directly handles. We may update this policy when the service or law changes. Material changes will be announced through the service or your registered email when required, and the effective date will be updated here.

14. Contact

  • Privacy requests: privacy@lonemade.com
  • Support and security: support@lonemade.com
  • Billing: billing@lonemade.com
  • General contact: hello@lonemade.com
  • Partnerships: partners@lonemade.com

This policy describes current LoneMade behavior. It is not legal advice and may be updated when the service or applicable law changes.

TermsPrivacyContact usprivacy@lonemade.com