Privacy
Public site privacy notice
1. Who this notice covers
This notice describes measurement on the public marketing and documentation site at loremem.com, and how that measurement coordinates with product-entry links into the hosted Console at app.loremem.com. It does not replace any separate product terms that apply after you sign in to the Console.
2. What we measure
On the public site we may measure page usage and performance, referral and campaign parameters that a visitor already carries in the URL, the visitor's analytics consent state, and product-entry clicks such as starting with Lore or opening open-source install paths. Measurement is limited to these public-site signals; it is not a full product telemetry system for authenticated Console activity.
3. Cloudflare Web Analytics
Cloudflare Web Analytics provides a privacy-oriented traffic and performance baseline. It may load without a Google Analytics consent grant. When enabled, it is configured through the environment variable NEXT_PUBLIC_CLOUDFLARE_WEB_ANALYTICS_TOKEN. Cloudflare Web Analytics does not intentionally collect form fields, memory contents, or authenticated project data from the public site.
4. Google Analytics 4
Google Analytics 4 loads only after analytics consent is set to granted. The measurement ID comes from NEXT_PUBLIC_GA4_MEASUREMENT_ID when the operator has enabled it. On the public site, custom events are limited to select_start_lore and select_open_source_install, with parameters source_path, content_locale, cta_location, and content_slug. The loader configures GA with send_page_view:false so automatic pageviews are not emitted by the default configuration.
5. Consent cookie
Analytics preference is stored in a first-party cookie named loremem_analytics_consent. Allowed values are granted and denied. The cookie is set with Path=/, Max-Age=31536000 (one year), and SameSite=Lax. On production hosts under loremem.com the cookie uses Domain=.loremem.com so consent can be shared across the public site and the hosted Console subdomain. The cookie includes Secure when the page is served over HTTPS.
6. Attribution query parameters
Public call-to-action links that open hosted Console login may preserve only the bounded campaign keys utm_source, utm_medium, utm_campaign, utm_content, and utm_term, plus the attribution fields source_path, content_locale, cta_location, and content_slug. UTM keys and values are bounded to conservative campaign identifiers (short alphanumeric tokens with limited punctuation). Arbitrary query keys and non-conforming values are not copied into the hosted login URL.
7. What we do not send in custom analytics parameters
Custom public analytics parameters do not include email addresses, personal names, authentication tokens, memory contents, project or organization names or IDs, OAuth tokens, free-form user input, or raw search-box text. Event normalization rejects paths that carry query strings, fragments, control characters, backslashes, encoded traversal sequences, empty or ./.. segments, or double-slash prefixes, and rejects slugs that are not simple lowercase identifiers.
8. Retention
Retention for Google Analytics 4 and Cloudflare Web Analytics follows the operator-configured retention settings inside those products. This notice does not invent a fixed retention period beyond what the operator configures in each service.
9. How to accept, reject, or change consent
The public site presents equal-weight accept and reject controls when consent is unknown. After a choice is stored, a persistent Analytics preferences control remains available so you can change your mind. Accepting updates the consent cookie and allows the GA loader to render when a measurement ID is configured. Rejecting after a previous grant writes denied and reloads the page so already-loaded Google Analytics scripts are removed from the document. Clicks made while consent was unknown or denied are not replayed after a later grant; only new post-consent interactions can produce events.
10. Contact for non-sensitive reports
For non-sensitive questions about this public site notice, open an issue at https://github.com/FFatTiger/lore/issues. Please do not post sensitive information in public GitHub issues: do not post passwords, tokens, personal data, memory contents, or other confidential material. The repository currently has no private privacy or support email address, and this notice does not invent one.
11. Production enablement status
Production Google Analytics measurement remains blocked until the project owner supplies and approves a private contact channel for sensitive privacy requests. Until that gate is met, production deploys may ship the consent UI and optional Cloudflare token, but must leave the GA measurement ID unset.
12. Last updated
This notice was last updated on 2026-07-23.