Lora logo

Lora — Privacy Policy

Lora — Privacy Policy

Lora — Privacy Policy

Last updated: 29 July 2026

Last updated: 29 July 2026

1. About this policy

This policy explains what personal information Lora collects, why, who we share it with, and what rights you have over it.

Lora is operated by Unity Ventures FZ-LLC, a free zone company registered in the Ras Al Khaimah Economic Zone (RAKEZ), United Arab Emirates, trade licence number 47014283, registered office FDRK5135, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. We are the controller of the personal information described here.

Contact us about anything in this policy at support@getlora.app.

This policy covers the Lora app and our website. It does not cover third-party services you reach through Lora — a booking partner’s site, for example — which have their own policies.

2. Summary

What we collect:

Your account identifier from Apple or Google, your profile picture if you set one, the spots and trip plans you create, content you search for and import from TikTok and Instagram, your travel preferences, what you say to Lora in voice conversations, location if you allow it, and technical data about your device and usage.

Why:

To run the app, generate trip plans, hold voice conversations, manage subscriptions, provide support, keep the service secure, and improve it

AI processing:

Your planning inputs and voice conversations are processed by OpenAI and ElevenLabs

Where it’s stored:

Primarily in the United States (Northern Virginia)

How long:

While your account is open, plus the periods in section 11

Your rights:

Access, correction, deletion, portability, objection, complaint — sections 13 and 14

3. How you sign in

You sign in to Lora with Sign in with Apple or Sign in with Google. We do not operate passwords, so we never hold one.

From that sign-in we receive an account identifier and an email address. If you use Sign in with Apple and choose to hide your email, Apple gives us a private relay address instead of your real one — that works perfectly well with Lora, and we have no way to see the address behind it.

We do not receive your Apple or Google password, and we have no access to anything else in those accounts.

4. Information you give us

Display name:
The name shown on your profile, visible to anyone you share a trip plan with.

Profile picture:
An image you choose to upload to your profile, visible to anyone you share a trip plan with. Providing one is optional, and you can change or remove it in the app at any time.

Travel preferences:
Your answers during onboarding and afterwards — the kinds of places you like, pace, budget, and any dietary or accessibility needs you tell us about.

Some of this may be sensitive depending on where you live: dietary requirements can imply religious belief, and accessibility needs can imply health information. We collect it only because you choose to give it, use it only to tailor suggestions, and you can remove it in the app at any time.

Your content:
The spots you save, the collections you organise them into, the trip plans you generate and edit, and the names you give them.

Social content:
Lora displays publicly available posts from TikTok and Instagram, retrieved through those platforms' official APIs. You encounter this content when you search in the app, through trending and recommended selections, and when you share a post to Lora using your device's share function.

When you choose to turn a post into saved spots, we use a third-party service (ScrapeCreators) to retrieve that post's publicly available content — its caption, description and, where available, a transcript — and process it to identify the places mentioned.

We do not connect to your social accounts and cannot see anything in them.

This content contains information about other people — the creators who made the posts, and sometimes people appearing in them. We process it only to display the content and extract place information. We do not build profiles of creators. Our legal basis is our legitimate interest in operating a travel discovery service. Creators may ask us to stop displaying their content by writing to support@getlora.app.

Voice conversations:
See section 7.

Support correspondence:
If you write to us, we keep the exchange.

5. Information collected automatically

Usage data:
Which features you use, what you search for in the app, and how you move through it. This is collected via Mixpanel, and only if you agree to it when you sign up. If you decline, we don’t collect it, and every feature still works. You can change your mind at any time in the app’s privacy settings.

Device and technical data:
Device model, operating system and version, app version, language and region, IP address, and device or installation identifiers.

Diagnostic data:
Crash reports, stack traces and performance data, collected via Sentry when something goes wrong. This runs regardless of your analytics choice, because we need it to keep the app working — it records what the app was doing when it broke, not what you were doing across the app generally.

Location:
If you allow it, we use your device’s location to show nearby places, centre the map, and make suggestions relevant to where you are.

Your device gives you the choice:

  • Allow once — we receive your location for that session only.

  • While using the app — we receive it only when Lora is open on screen.

  • Always — we can also detect when you arrive somewhere new while Lora is closed.

Why “always” exists. The only thing we do with background location is notice when you’ve travelled somewhere new — landed in a different country, for example — so we can send you a notification about it. Nothing else in Lora uses background location.

We do this in the least intrusive way available. Rather than following your position continuously, we ask your device to tell us only when you’ve moved a significant distance, and we check whether that means you’re in a new region. We don’t need or use precise coordinates for this, and we don’t build a record of where you’ve been — we hold only your current region, so we can tell when it changes.

If you’d rather not have this at all, choose “while using the app” instead. Every other feature works exactly the same.

You can change or withdraw this permission at any time in your device settings. Lora works without location at all — you can search for places by name and build trip plans as normal; only the nearby-place and map-centring features are affected.

Attribution data:
How you came to install Lora — which campaign, link or creator referred you. Collected via Airbridge, and via Insert Affiliate where you arrive through an influencer link. See section 17.

Push token:
If you enable notifications, so OneSignal can deliver them.

6. Information from other sources

Place data:
When you search for a place or add one to a trip plan, your search terms and approximate location are sent to the Google Places API, which returns matching places. This returns information about places rather than about you, but the query itself is personal data in transit.

Social platforms:
When you search for social content in the app, your search terms are sent to TikTok's and Instagram's APIs, which return matching public posts. Those platforms receive the query and technical information about the request under their own terms.

Map data:
Maps are rendered by Mapbox, which receives the map area you are viewing.

Booking partners:
Viator supplies listing data for tours and experiences. If you follow a link and book, that happens on Viator’s platform under their privacy policy — we never see your payment details. We may receive confirmation that a booking occurred, for commission purposes.

Subscription status:
Apple and Google tell RevenueCat whether you have an active subscription, when it renews, and whether a trial has been used. We never receive your card number, bank details or billing address.

Referrals:
If you arrive through a referral link, we record which account or creator referred you so the reward can be credited.

7. Voice conversations and AI processing

Text-based planning:

When you generate or edit a trip plan, we send the relevant inputs — destination, dates, saved spots, stated preferences and your instructions — to OpenAI, which processes them and returns a result. OpenAI acts as our processor.

Voice conversations:

Lora can hold spoken conversations. This requires microphone access, which you grant through your device’s permission prompt and can revoke at any time in device settings.

During a voice conversation:

  • your speech is captured and processed to work out what you asked;

  • ElevenLabs produces the response and the spoken voice you hear.

We use your voice only to carry on the conversation. We do not use it to identify or authenticate you, we do not create a voiceprint, and we do not use it to infer anything about you beyond what you actually said. If you would rather not use voice at all, don’t grant microphone permission — every feature remains available by typing.

ElevenLabs stores the recording of your voice conversation and its transcript for two years, which is their standard retention period. If you would like your voice recordings deleted sooner, email support@getlora.app and we will remove them.

How long the AI providers keep your data:

OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring, then deletes them, unless the law requires otherwise.

ElevenLabs retains conversation transcripts and audio recordings for two years.

Training:

Neither provider trains their models on your data.

Data sent to the OpenAI API has not been used to train or improve OpenAI’s models since March 2023, unless a customer explicitly opts in — we have not. ElevenLabs has agreements with the model providers behind its agents that prohibit training on customer content.

AI decisions:

Trip suggestions have no legal or similarly significant effect on you, so this is not automated decision-making of the kind carrying special rights under Article 22 of the GDPR. We do not use AI to decide your access to Lora, your pricing, or anything comparable.

One practical point: don’t say or type anything into Lora you wouldn’t want processed this way. Trip notes and voice chats are not the place for sensitive information about yourself or anyone else.

8. How we use your information, and our legal basis

Where the GDPR or UK GDPR applies, we need a legal basis for each use.

Purpose: Legal basis

Creating and running your account: Performance of our contract

Storing your spots, collections and trip plans: Performance of our contract

Generating trip plans and recommendations: Performance of our contract

Displaying social content and providing social search: Performance of our contract; legitimate interest in operating a travel discovery service

Voice conversations, including microphone access: Your consent, given through the device permission prompt

Sensitive preference data (dietary, accessibility): Your explicit consent

Location for nearby suggestions: Your consent, given through the device permission prompt

Detecting arrival in a new place to notify you: Your consent, given by choosing “always”

Managing subscriptions and entitlements: Performance of our contract

Operating the referral programme and preventing abuse of it: Performance of our contract; legitimate interest in preventing fraud

Providing support: Performance of our contract; legitimate interest in helping users

Security, fraud prevention, enforcing our Terms: Legitimate interest in protecting the service and its users

Crash reporting and diagnostics: Legitimate interest in keeping the app working

Product analytics: Your consent, given at sign-up and withdrawable at any time

Install attribution and campaign measurement: Consent where required; otherwise, legitimate interest in understanding what works

Service messages (billing, security, terms changes): Performance of our contract; legal obligation

Tax, accounting and legal obligations: Legal obligation

Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object at any time (section 13).

9. Who we share your information with

Each provider below is bound by a written contract limiting them to acting on our instructions.

Provider:

  • What it does

  • What it receives

  • Backend and database — where your account and content live

  • Everything you store in Lora

  • Sign-in

  • Authentication, handled by them

  • Generates trip plans and conversation responses

  • Your planning inputs and conversation content

  • Produces Lora’s spoken voice

  • Conversation content for synthesis

  • Retrieves post content for spot detection

  • Post URLs you choose to process

  • Supply public social content via their APIs

  • Search queries and content requests

  • Place search and details

  • Search terms, approximate location

  • Map rendering

  • The map area you’re viewing

  • Tours and experiences

  • Listing requests; booking confirmations back to us

  • Subscription entitlements

  • Purchase and subscription status

  • Paywall presentation

  • Which offers you were shown and how you responded

  • Product analytics

  • Usage events and device identifiers

  • Crash and error reporting

  • Diagnostic data, device state at time of error

  • Push notifications

  • Push token, device identifiers

  • Ad attribution and campaign measurement

  • Device and campaign identifiers, install and subscription events

  • Influencer referral attribution

  • Referral and conversion events

  • Ad attribution and campaign optimisation

  • Device and campaign identifiers, install and subscription events

  • Our email — receives and stores support correspondence

  • Anything you send us by email

Advertising networks:
Airbridge and AppStack send information about installs, trials and subscriptions back to the advertising platforms we run campaigns on — Meta, Google, TikTok and Apple Ads among them — so those platforms can measure which campaigns worked and improve their targeting. This involves device and campaign identifiers linked to your activity in Lora.

Separately, our website carries Google Analytics and the Meta and TikTok advertising pixels, which share information about your visit with those companies. On our website these are set only with your consent — see section 17.

This is what US state privacy laws call “sharing” for cross-context behavioural advertising, and in some states it may count as a “sale” even though no money changes hands for your data. You can opt out — see section 14.

We also disclose information:

  • to other users — but only what you choose to share: a shared spot or trip plan, your display name, and your profile picture if you've set one;

  • where the law requires it — to courts, regulators or law enforcement acting under valid authority;

  • to prevent serious harm — including fraud and security threats;

  • to professional advisers — lawyers and accountants, under duties of confidence;

  • in a corporate transaction — if Lora or its assets are acquired or merged, in which case we will tell you before your information becomes subject to a different policy.

Payment card details are handled entirely by Apple and Google. We never receive them.

10. Where your information is stored

Lora’s backend runs on Convex, hosted in the United States (Northern Virginia). Your account and content are stored there. Our other providers operate from various countries, principally the United States and the European Union.

We are based in the United Arab Emirates. Using Lora therefore involves your information being transferred outside the country you live in.

Where we transfer personal information out of the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with encryption in transit and at rest.

You can request details of the safeguards that apply by writing to support@getlora.app.

11. How long we keep your information

Information: Retention

Account and profile: While your account is open

Profile picture: While your account is open

Spots, collections, trip plans: While your account is open

Social content retrieved via platform APIs: cached only as permitted by the source platform's API terms

Content you delete in the app: Removed from active systems immediately; purged from backups within 30 days

Closed accounts: Deleted within 30 days of closure

Voice audio recordings: 2 years (held by ElevenLabs)

Conversation transcripts: 2 years (held by ElevenLabs)

Imported post content: While your account is open

AI processing logs held by OpenAI: Up to 30 days, then deleted by OpenAI

Support correspondence: 24 months after the matter closes

Location data: Not stored as a history. We keep only your last known region, so we can tell when it changes, for as long as your account is open

Analytics data: 24 months

Crash and diagnostic logs: 90 days

Attribution data: 12 months

Subscription and transaction records: 7 years, to meet UAE tax and accounting requirements

Records needed for fraud prevention or legal claims: As long as necessary for that purpose

These are our defaults. Where the law requires us to keep something longer, we will, and where you ask us to delete something sooner we will do so unless we have a legal reason not to.

When we no longer need information we delete it or irreversibly anonymise it. Anonymised data — aggregate statistics with nothing identifying anyone — may be kept indefinitely.

12. Security

Your data is encrypted in transit and at rest. Access on our side is limited to the people who need it. Because we use Apple and Google sign-in rather than passwords, there is no password of yours for us to lose.

We review our providers’ security posture and rely on their published certifications where available.

No system is perfectly secure, and we cannot guarantee our defences will never be defeated. If a breach occurs that presents a risk to you, we will notify you and the relevant regulator as the law requires.

Tell us promptly at support@getlora.app if you think someone has accessed your account.

13. Your rights

Wherever you live, you can ask us to:

  • tell you what we hold about you and how we use it;

  • give you a copy, in a portable format where that applies;

  • correct anything inaccurate or incomplete;

  • delete your information, subject to what we must keep by law;

  • restrict or object to how we use it, including where we rely on legitimate interests;

  • withdraw consent — for analytics, microphone access, location, or sensitive preference data. This doesn’t affect what we did lawfully beforehand.

Much of this you can do directly: edit your profile and preferences, delete individual spots and trip plans, turn analytics off in the app’s privacy settings, revoke microphone or location permission in device settings, change your cookie choice on our website, and delete your account in the app.

For anything else, email support@getlora.app. We respond within one month, and will tell you if a complex request needs longer. We may need to verify it’s really you first, normally by confirming you control the account’s email address.

There’s no charge. We may decline a request that is clearly unfounded or excessive, and will explain why. We won’t treat you worse for exercising any of these rights.

14. Regional information

If you are in the EEA or the UK:

The GDPR and UK GDPR apply. Section 8 sets out our legal bases, section 10 our transfer arrangements, section 13 your rights.

You can complain to your data protection authority — in the UK, the Information Commissioner’s Office (ico.org.uk); in the EEA, the authority where you live, work, or where you think the problem occurred. We’d rather you raised it with us first, but that’s your choice.

If you are in the United States:

Sharing for advertising:
We do not sell your personal information for money. However, as described in section 9, we send install and subscription events with device identifiers to advertising platforms so they can measure and optimise our campaigns. Under California, Colorado, Connecticut, Virginia and similar state laws this counts as sharing for cross-context behavioural advertising, and under some of those laws it may also count as a sale.

How to opt out:
Email support@getlora.app with “Do not sell or share my personal information” and we will stop including your data in these transfers. On iOS you can also decline the App Tracking Transparency prompt, or turn off “Allow Apps to Request to Track” in your device settings, which prevents identifier-based tracking. We honour Global Privacy Control and other recognised opt-out preference signals where state law requires.

Depending on your state you may have the right to know what we collect and why, to access and obtain a copy, to correct inaccuracies, to delete, to opt out of sale, sharing or targeted advertising, to limit use of sensitive personal information, and not to be discriminated against for exercising these. You may use an authorised agent, and where your state provides one you may appeal a refusal — email support@getlora.app and we’ll explain the outcome in writing.

Categories we collect:

  • identifiers (email, account and device identifiers);

  • customer records (display name);

  • commercial information (subscription and transaction history);

  • internet activity (app usage);

  • geolocation (with permission);

  • audio and visual information (voice conversations and profile pictures, with permission);

  • and inferences (travel preferences).

Sources are in sections 4 to 6, purposes in section 8, recipients in section 9.

We do not respond to browser Do Not Track signals, as no common standard exists. We honour opt-out preference signals where state law requires.

If you are in the United Arab Emirates:

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies to processing in the UAE, giving you rights of access, correction, erasure, restriction, portability and objection broadly as in section 13, and a right to complain to the UAE Data Office.

15. Children

Lora carries a 13+ age rating on the App Store, reflecting that the app displays content published by others on social platforms, which we do not control and which may occasionally include mild language or references to alcohol.


Our Terms of Service require you to be at least 13 to use Lora, or 16 where local law sets a higher age of digital consent, and 18 to purchase a subscription. If you are under 18, a parent or guardian must consent to your use.


Lora is not designed for or directed at children, and we do not market it to them. We do not knowingly collect personal information from anyone below the applicable minimum age. If we learn that we have, we will delete it and close the account.


Parents and guardians can contact support@getlora.app and we will deal with it promptly.

16. Marketing and notifications

We do not currently send marketing emails. If that changes, we will only email you with your consent, every message will have an unsubscribe link, and we will update this policy first.

We do send service messages — billing notices, security alerts, and changes to our terms. These are part of running your account and aren’t marketing, so they don’t have an unsubscribe option, though closing your account stops them.

Push notifications are delivered through OneSignal if you enable them, and can be turned off at any time in your device settings.

17. Tracking and attribution

Lora uses Airbridge and AppStack to understand which campaigns and links bring people to the app, and Insert Affiliate to credit creators who refer new users. This involves device and installation identifiers, and sends conversion events to the advertising platforms described in sections 9 and 14.

App Tracking Transparency:
On iOS, we ask your permission before any of this links your activity to identifiers used by other companies. That’s Apple’s App Tracking Transparency prompt, and you can say no. Saying no doesn’t limit any Lora feature — it only reduces what we can tell about which advert brought you here. You can change your answer at any time in Settings → Privacy & Security → Tracking.

On Android, you can reset or delete your advertising ID in your device settings.

In the app:

Lora’s app does not use browser cookies. It uses device and installation identifiers for analytics, crash reporting and attribution, as described above.

On our website:

Our website uses cookies and similar technologies:

Type:

  • What it does

  • Needs your consent?

  • Strictly necessary

Keeps the site working and remembers your cookie choice:

  • No

Google Analytics:

  • Tells us how many people visit and which pages they read

  • Yes

Meta pixel:

  • Measures whether our Facebook and Instagram ads work, and lets Meta show you related ads

  • Yes

TikTok pixel:

  • Measures whether our TikTok ads work, and lets TikTok show you related ads

  • Yes

If you’re in the EEA or the UK, none of the optional cookies are set until you agree through our cookie banner. You can change your choice at any time using the cookie settings link in the site footer.

If you’re elsewhere, you can still opt out through the same link, and by using your browser’s tracking protection or a Global Privacy Control signal.

The Meta and TikTok pixels share information with those companies about your visit, which they may combine with what they already know about you. This is the website equivalent of the app-side sharing described in section 14, and the same opt-out applies.

18. Changes to this policy

We may update this policy. The “Last updated” date shows when we last did.

If a change materially affects how we use your information, we’ll tell you in the app or by email before it takes effect, and where the law requires consent we’ll ask rather than assume.

19. Contact

Unity Ventures FZ-LLC FDRK5135, Compass Building Al Shohada Road Al Hamra Industrial Zone-FZ Ras Al Khaimah, United Arab Emirates

If you’re unhappy with how we’ve handled your information, tell us — we’d rather fix it. If we can’t resolve it, you can complain to your data protection authority as described in section 14.