Legal
Privacy Policy
Last updated: July 6, 2026
This policy explains what Loro collects today, what it processes when you connect the product, and how to contact us about your data.
1. Who operates Loro
Loro is operated by PEGUIM TECNOLOGIA LTDA, CNPJ 54.316.599/0001-04. For privacy requests, contact matheuspeguim@gmail.com.
This policy covers useloro.com, the Loro web app and service emails related to account access, billing and product operation.
2. Data we collect
We collect account data such as name, email address, profile image when provided by the sign-in provider, session records and magic-link verification tokens.
We collect workspace data such as workspace name, site URL when provided, UI locale, content locale, billing currency, autopilot setting and weekly quota.
For billing, Loro stores Stripe customer and subscription identifiers, subscription status, price reference and renewal period. Stripe processes card data; full card numbers do not touch Loro.
When you connect or provide business sources, Loro may process site pages, sitemap data, Search Console metrics, CMS content and the business knowledge you add to the Living Manual. These are used to find opportunities, draft or publish content, and measure results.
We collect product and marketing analytics such as page views, CTA clicks, signup, subscription events and product usage events when analytics is configured.
When you request a free site analysis, we collect the email address and site URL you submit, plus consent metadata (timestamp and IP address) as proof of your request.
3. How we use data
We use the site you submit to generate content opportunities and, for the free analysis, to send you those opportunities and occasional related tips by email. You can opt out at any time.
- To authenticate users and keep sessions active.
- To create and manage workspaces, billing status and access.
- To operate SEO/GEO workflows: reading business sources, prioritizing opportunities, drafting or publishing content, and measuring article-level results.
- To send service emails such as magic links, account notices and billing-related messages.
- To monitor reliability, security and the product funnel without logging secrets or full payment card data.
4. Processors and third-party services
Loro uses managed providers to run the service: Google Cloud Run and Firebase Hosting for hosting, Neon for Postgres, Auth.js with Google OAuth and Resend for sign-in, Stripe for billing, PostHog for analytics when configured, and GitHub Actions for deployment.
When AI-assisted product features are enabled, prompts may include the business content needed to generate or review Loro outputs. We do not send payment card data to AI providers.
5. Cookies and local storage
Loro uses cookies needed for authentication, session continuity and locale routing. Analytics cookies or browser storage may be used by PostHog when product analytics is configured.
The current app is not built around advertising pixels or resale of personal data.
6. Retention
Account, workspace and billing records are kept while the account is active and for the period needed to operate the service, resolve disputes, comply with legal or tax obligations, and protect against abuse.
Magic-link tokens and sessions expire according to the authentication provider settings. Analytics and operational logs are kept only as long as useful for product, reliability and security purposes.
Lead analysis snapshots (email, site and generated opportunities) are kept for up to 90 days and then expire, unless linked to an account you create.
7. Your choices and rights
You can ask us to confirm whether we process your personal data, access it, correct it, request deletion or anonymization where applicable, and receive information about sharing with service providers.
Some requests may be limited when we need to keep data to provide the service, comply with legal obligations, prevent fraud, resolve disputes or keep billing records.
Marketing emails include a one-click unsubscribe link, and you can opt out at any time; unsubscribing stops the analysis reinforcement emails.
8. Security
Loro uses HTTPS, managed authentication, server-side authorization, environment-based secrets, Stripe-signed webhooks and database-backed sessions. Access to private product areas requires login and subscription status checks.
No system is risk-free. If we identify a material incident affecting your data, we will investigate, mitigate and communicate according to the impact and applicable requirements.
9. Changes
We update this page when the product or data processing changes materially. The date at the top shows the current public version.