Lorescent / Privacy

Privacy Policy

This Privacy Policy explains in detail how Story Stroll, LLC, through Lorescent, collects, accesses, uses, stores, shares, retains, and deletes information, including data received through Google API Services.

Effective September 2, 2026

1. Who we are

Lorescent is an institutional story-intelligence platform operated by Story Stroll, LLC. In this Policy, “Lorescent,” “Story Stroll,” “we,” “us,” and “our” refer to Story Stroll, LLC in connection with the Lorescent service.

Lorescent is primarily designed for organizations and their authorized users. An institution may separately determine what information it collects, uploads, or otherwise processes through its workspace. In those circumstances, the institution may act as the organization responsible for that information and Lorescent may process it on the institution’s behalf, subject to the applicable agreement.

2. Information we collect

We may collect account and profile information such as name, email address, organization, role, authentication information, and account preferences; institution and workspace information; billing and subscription information; support, procurement, demo, and sales communications; and technical information such as browser type, device information, IP address, timestamps, diagnostic data, and service usage activity.

Lorescent also processes information that authorized users choose to upload, create, connect, or analyze in the service. Depending on an institution’s use, this may include interviews, transcripts, notes, quotations, source materials, photographs, audio, video, documents, story concepts, research, institutional records, collaboration activity, and other content (“Customer Content”).

When an authorized user connects a third-party service or integration, Lorescent may receive the information and permissions necessary to provide that integration. The scope of information available through an integration depends on the permissions granted by the user or institution.

3. Google API Services and Google user data

This section specifically describes Lorescent’s use of information received from Google API Services. A Google connection is optional and begins only when an authorized user or institution administrator chooses to connect a Google account and grants the permissions shown on Google’s OAuth consent screen.

Google account data: when a user signs in with Google or connects a Google service, Lorescent may receive the user’s Google account identifier, name, email address, profile information, and authorization status. We use this information to authenticate the user, identify the connected account, bind the connection to the correct Lorescent user or institution, and maintain an audit record of authorized integration activity.

Google Drive data: the institution Drive connection currently requests the Google OAuth scopes drive.readonly, drive.file, and email. Within Lorescent, use of those permissions is restricted to institution-approved Drive roots or files otherwise explicitly selected by an authorized user. Lorescent may access file and folder identifiers, names, MIME types, parent relationships, Drive identifiers, web links, timestamps, size and capability information, and approved file contents. Read access is used to list, retrieve, preview, stream, import, transcribe, index, and analyze approved source files. File-level write access is used to create requested Lorescent-managed folders and files, deliver Story Study materials or release documents, and create files requested by an authorized user. Lorescent does not rename, alter, move, or delete an institution’s original Drive files as part of ordinary archive management.

Optional Google Workspace connections: a user may separately connect Gmail to send an outbound note or Lorescent link; Lorescent does not read or ingest that user’s Gmail inbox. A user may connect Google Docs to list or import a document the user selects and to create or link collaborative documents; Google Calendar to create requested interview, access, or Story deadline events; Google Sheets to create requested exports; and Google Slides to create requested starter presentations. Lorescent accesses only the Google service and permissions the user chooses to authorize.

4. How Lorescent uses Google user data

Lorescent uses Google user data only to provide or improve user-facing features that are visible in Lorescent and requested by an authorized user or institution. Those purposes include account authentication; connecting the correct Google account; importing institution-approved source material; creating searchable archive records, transcripts, Evidence Moments, quotations, findings, and Story development context; streaming approved media; creating requested Google files or calendar events; delivering requested materials to an approved Drive destination; maintaining synchronization state and external links; troubleshooting integration failures; and protecting the service.

When an authorized user asks Lorescent to analyze, transcribe, summarize, retrieve, or generate material from an approved Google file, the selected file content may be processed by contracted infrastructure, transcription, or AI service providers only as needed to provide that requested Lorescent feature. Lorescent does not use Google user data for advertising, retargeting, profiling for ads, credit or lending decisions, surveillance, sale to data brokers, or training general-purpose AI models.

Lorescent’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. If Lorescent materially changes how it uses Google user data, we will update this Policy and obtain any additional consent required before using the data for the new purpose.

5. Google data storage, sharing, retention, and deletion

OAuth access and refresh credentials are stored and managed in Base44’s secure connector infrastructure. They are not stored in Lorescent Customer Content, institution records, or ordinary application logs. Lorescent may store the connected account label; Google file or folder identifiers, names, types, links, timestamps, and parent relationships; allowed Drive boundaries; synchronization state; external-record relationships; and integration audit events.

Original Google files remain in Google unless the authorized user directs a supported Google action. When a user imports or processes a Google file, Lorescent may store a copy of selected or extracted content and Lorescent-derived records—such as text, transcripts, summaries, quotations, evidence, metadata, and Story development material—inside the institution’s Lorescent workspace. When Lorescent creates a Google Doc, Sheet, Slide, calendar event, folder, or other requested item, the created item remains in the connected Google service and Lorescent may store its identifier, link, title, and status.

Google user data may be available to authorized users of the same institution workspace and to service providers that process it solely for hosting, security, connector operation, transcription, AI-assisted processing, support, or another purpose necessary to provide Lorescent. We do not sell Google user data, share it with advertising platforms or data brokers, or permit service providers to use it for their own independent purposes. Human access is limited to the user’s direction, support or security needs, legal requirements, or authorized institution administration.

Google-derived information is retained only for as long as reasonably necessary to provide the connected feature, maintain the institution’s requested Lorescent archive, satisfy the applicable agreement, protect security, or comply with law. A user can disconnect a personal Google integration in Lorescent and can revoke Google authorization through the Google Account permissions page. Revocation or disconnection stops future API access after the revocation is processed, but it does not automatically delete content already imported into Lorescent or records created from that content. An authorized user or institution administrator may delete supported Lorescent records or request deletion of stored Google-derived data by contacting us. Residual copies may remain for a limited period in backups, security logs, or legally required records before deletion or isolation.

6. How we use information

We use information to provide, secure, maintain, and improve Lorescent; authenticate users; administer institution workspaces; process subscriptions; deliver requested features and integrations; provide support; communicate about the service; detect abuse, fraud, security incidents, or technical problems; comply with law and contractual obligations; and understand service performance and adoption.

Customer Content may be processed to provide Lorescent features such as search, transcription, organization, evidence extraction, narrative analysis, recommendations, summaries, story development, collaboration, and other requested intelligence or generative features.

7. AI-assisted processing

Some Lorescent features use artificial intelligence or machine-assisted analysis to organize, summarize, classify, compare, retrieve, or generate material from Customer Content. AI-assisted results may be incomplete or inaccurate and should be reviewed by an authorized human before they are relied on for publication, institutional decisions, factual claims, or other consequential uses.

Lorescent does not treat AI output as a substitute for an institution’s editorial, legal, research, records-management, or privacy review. Additional contractual terms may govern how Customer Content is handled by subprocessors that support AI-enabled functionality.

8. How we disclose information

We may disclose information to vendors and service providers that help us operate Lorescent, including hosting, infrastructure, authentication, communications, payments, analytics, security, customer-support, and AI or data-processing providers, subject to appropriate contractual or operational restrictions.

We may also disclose information when directed by an authorized institution or user; when reasonably necessary to comply with law, legal process, or valid governmental requests; to protect the rights, safety, integrity, or security of Lorescent, our users, or others; or in connection with a merger, financing, acquisition, reorganization, or sale of all or part of the business, subject to applicable legal requirements.

We do not sell Customer Content. We do not sell personal information in the ordinary meaning of selling personal data for money.

9. Institutional data, education records, and sensitive information

Institutions are responsible for determining whether particular information is appropriate to place in Lorescent and for configuring access, permissions, retention, releases, and workflows consistent with their own policies and legal obligations.

If an institution proposes to use Lorescent with education records or other regulated or sensitive information, the institution should evaluate that use under its applicable FERPA, privacy, records-management, contracting, security, consent, and data-classification requirements. Lorescent does not represent that every possible use of the service is appropriate for every category of regulated information merely because the service is available to the institution.

Where an institution and Story Stroll enter into a data processing agreement, institutional agreement, order form, or other written contract that contains privacy or security terms, that agreement controls to the extent it conflicts with this general Policy.

10. Data retention and deletion

We retain information for as long as reasonably necessary to provide the service, fulfill the purposes described in this Policy, comply with contractual and legal obligations, resolve disputes, maintain security, and enforce agreements. Retention periods may vary by data type and by an institution’s configuration or agreement.

Institutions may have tools or contractual processes for exporting or deleting Customer Content. Some information may remain temporarily in backups, logs, security records, or records we are legally required or reasonably permitted to retain.

11. Security

We use administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. No online service can guarantee absolute security, and institutions should use Lorescent in accordance with their own security and access-control requirements.

Additional information about Lorescent’s security posture, institutional controls, and procurement considerations is available on our Security & Governance and Procurement & Data pages.

12. Cookies and local storage

Lorescent may use cookies, browser storage, session storage, and similar technologies that are necessary for authentication, security, preferences, session continuity, product functionality, and service measurement. Browser settings may allow users to restrict some storage technologies, although doing so can prevent parts of Lorescent from functioning correctly.

13. Your choices and rights

Users may be able to review or update certain account information within the service. Requests concerning Customer Content should generally be directed first to the institution that controls the relevant workspace.

Depending on applicable law and the relationship involved, individuals may have rights concerning access, correction, deletion, restriction, objection, or portability of certain personal information. We may need to verify identity and authority before completing a request, and some requests may be subject to legal or contractual exceptions.

14. Children

Lorescent is an institutional service and is not directed to children under 13 for independent consumer use. Institutions that use Lorescent in connection with minors are responsible for determining and documenting the permissions, consents, releases, and legal basis required for their use.

15. Changes to this Policy

We may update this Privacy Policy as Lorescent, our practices, or applicable requirements evolve. When we make material changes, we will update the effective date and may provide additional notice when appropriate.

16. Contact

Questions about this Privacy Policy, Google user data, institutional data handling, access requests, or deletion requests may be emailed to patrick@storystrollstudios.com or mailed to Story Stroll, LLC, Bangor, Maine, United States. Please identify the relevant Lorescent account or institution without including passwords, OAuth tokens, or sensitive source content. For information controlled by an institution, we may direct the request to the institution responsible for the applicable workspace.