Privacy Policy
Last updated: May 9, 2026
This Privacy Policy describes how Tanagram, Inc. ("Tanagram," "we," "us," or "our") collects, uses, and shares your personal information when you use Lore, our shared thread library for coding agent sessions (collectively, the "Services").
If you have a separate Data Processing Agreement or Addendum with us, those terms supersede.
Information We Collect
Information You Provide to Us
We collect information that you provide directly to us, including:
- Account Information. When you sign in, we collect your name, email address (via our authentication provider), organization name, and profile metadata such as display name, handle, bio, and avatar.
- Payment Information. When you purchase a paid plan, we collect payment card information and billing details through our third-party payment processor.
- Communications. When you contact us or our support team, we collect the contents of your messages and any information you choose to provide.
- Feedback. Suggestions or feedback you provide about our Services.
Information We Collect Automatically
When you use our Services, we automatically collect certain information, including:
- Usage Data. Information about how you interact with our Services, including features used, pages viewed, and the time and duration of your activities.
- CLI Telemetry. When you use the Lore CLI, we collect command name, CLI version, command duration, environment, and your operating system username and hostname to help us understand reliability and usage.
- Device and Log Information. Information about the device or environment you use to access our Services, including browser type, IP address, access times, and referring URLs.
- Cookies and Similar Technologies. We use cookies and similar technologies to keep you signed in and to understand how the Services are used. You can control cookies through your browser settings.
Information from Your Use of the Services
- Coding Agent Transcripts. When you upload a session to Lore, we store the full transcript content — your prompts, the assistant's responses, tool calls, tool results, and any thinking or planning blocks captured by the agent — in object storage, and we parse the transcript into structured records in our database.
- Session Metadata. Alongside each transcript we store metadata such as the working directory path, repository origin, file paths touched during the session, the agent skills invoked, and timestamps.
- AI-Generated Artifacts. We use third-party AI providers to generate short summaries, titles, decision extracts, and cover images for your threads. The generated text and images are stored in our database alongside the source thread.
- Comments, Mentions, and Favorites. Comments you post on a thread, @-mentions you create in docs, follow relationships, and favorites you mark are stored to power the social and discovery features of the Services.
- Integration Data. Information from third-party services you choose to connect, such as your repository host or coding agent.
How We Protect Your Data
Lore is built around the assumption that coding agent transcripts contain sensitive material, and we give you several controls to limit what is collected and who can see it:
- Account-controlled default visibility. New threads follow your Share new threads with my workspace setting, which is on by default. If you belong to a workspace, new threads normally start as
workspace; if you do not belong to one or turn the setting off, they start asprivate. - Per-thread visibility. You can change any thread's visibility at any time between
private(only you),workspace(members of your organization), andpublic(world-readable, surfaced in the Discover feed). Public threads are the only threads exposed to unauthenticated visitors. - Local upload scope. The CLI daemon starts with no Claude Code directories allowed; you opt in through the post-login TUI wizard or
lore listen create <path>. On a true first run, the desktop app starts with all Claude Code projects allowed and lets you narrow that scope in Configure Session Upload…. Both surfaces store local upload filters at~/.lore/upload-filters.jsonwith file permissions that prevent other users on the same machine from reading it. Sessions outside the configured scope are ignored. Explicit one-off commands likelore exportbypass the filters so you can still share one session on demand. - Client-side upload filters. The same local filter file can also include or exclude uploads by repository or agent skill. Filtered sessions are not uploaded to our servers.
- Soft delete. You can delete your threads at any time. Deleted content is hidden from all views immediately; permanent removal from underlying storage is performed through our administrative process.
- Encryption in transit and at rest. Data is transmitted over TLS and stored in encrypted object storage and managed databases.
No internet or electronic storage system is completely secure, and we cannot guarantee absolute security. The controls above reduce risk; they do not eliminate it. Treat Lore as you would any other system that stores source-code-adjacent content, and use the upload filters and redaction tools to keep secrets and sensitive paths out of your uploads.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Services
- Generate thread titles, summaries, decision extracts, and cover images
- Process transactions and send related information, including confirmations and invoices
- Respond to your comments, questions, and requests, and provide customer support
- Send you technical notices, updates, security alerts, and administrative messages
- Monitor and analyze trends, usage, and activities in connection with our Services
- Detect, investigate, and prevent fraudulent or abusive use of the Services
- Personalize and improve your experience
- Develop new products, services, and features
- Comply with legal obligations and protect our rights and the rights of our users
Information Sharing and Disclosure
We may share your information in the following circumstances:
- With your consent. We may share your information when you give us permission to do so, including when you set a thread's visibility to
workspaceorpublic. - Service providers. We share information with third-party service providers who perform services on our behalf, including authentication, payment processing, AI-powered summarization and image generation, object storage, error monitoring, product analytics, and customer support tooling.
- Business transfers. If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
- Legal requirements. We may disclose your information if required to do so by law or in response to valid requests by public authorities.
- Protection of rights. We may disclose information to protect the rights, property, or safety of Tanagram, our users, or others.
- Aggregated data. We may share aggregated or de-identified information that cannot reasonably be used to identify you.
Machine Learning and AI
We do not develop or train foundation AI models. We do not use your transcripts or Customer Content to train third-party AI models. We do use third-party AI providers to generate the per-thread summaries, titles, and images described above; those providers process the inputs we send them under their own terms and do not retain that content for training under the contracts we have in place.
Data Retention
We retain your information for as long as your account is active or as needed to provide you with our Services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Upon request, we will delete your account-level information within 60 days, subject to our legal and operational requirements. Threads you delete are removed from all visible surfaces immediately; permanent removal from underlying storage is completed through our administrative process on a periodic basis.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from those in your country. By using our Services, you consent to the transfer of your information to the United States and other countries where we operate.
Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information, including:
- Access and portability. The right to access and receive a copy of your personal information.
- Correction. The right to correct inaccurate or incomplete information.
- Deletion. The right to request deletion of your personal information.
- Objection. The right to object to our processing of your personal information.
- Restriction. The right to request restriction of processing.
- Withdrawal of consent. The right to withdraw consent where we rely on consent to process your information.
To exercise these rights, please contact us at [email protected].
European Users
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
- Legal basis for processing. We process your personal information based on the performance of our contract with you, our legitimate interests in operating and improving our Services, your consent (which you can withdraw at any time), and compliance with legal obligations.
- Supervisory authority. You have the right to lodge a complaint with a supervisory authority in your jurisdiction.
California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information we collect, use, and disclose
- The right to request deletion of your personal information
- The right to opt out of the sale of your personal information (we do not sell personal information)
- The right to non-discrimination for exercising your privacy rights
To exercise these rights, please contact us at [email protected].
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of our Services after any changes indicates your acceptance of the updated Privacy Policy.
Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Tanagram, Inc.
838 Walker Rd Suite 21-2
Dover, DE 19904
Email: [email protected]