Applies to the Lorae website, mobile application, and related services.
Effective Date: 9/13/2026 | Last Updated: 9/13/2026
This Privacy Policy explains how Lorae LLC ("Lorae," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information through the Lorae website, mobile application, and related services (collectively, the "Services"). Because Lorae may process information related to mental health and wellness, some information described below may be considered sensitive personal data or consumer health data under applicable law. Our separate Consumer Health Data Privacy Policy provides additional disclosures and rights relating to consumer health data.
This Privacy Policy applies to personal information we process through the Services and in connection with customer support, account administration, subscriptions, security, and our direct interactions with users. When Lorae processes protected health information ("PHI") on behalf of a HIPAA-covered healthcare provider or other covered entity as its business associate, that processing is governed by HIPAA and the applicable business associate agreement. Information that a consumer provides directly to Lorae outside a covered-entity/business-associate relationship is not automatically subject to HIPAA.
We may collect information you provide when you contact support, communicate with us, participate in feedback or research, or otherwise correspond with Lorae.
If you purchase a subscription, payment may be processed by an app store or third-party payment processor. We may receive transaction identifiers, subscription status, purchase history, and limited billing-related information. We should not receive or store full payment-card numbers unless our payment configuration specifically requires it.
We may receive personal information directly from you; automatically from your device or use of the Services; from a clinician or healthcare organization when you are connected through Lorae; from service providers that support authentication, hosting, payments, analytics, communications, security, or customer support; and from other sources at your direction or with your authorization.
Lorae may allow users to connect with a clinician or healthcare organization and to make information available through Clinician's Corner or related sharing features. The information visible to a clinician depends on the product configuration, the user's sharing choices, organization settings, and applicable law. Where Lorae represents that sharing is client-controlled, we will design the feature so that the user controls whether the applicable information is shared, subject to limited operational information that may be necessary to maintain the connection or show assignment/completion status. Information already received by a clinician may become part of that clinician's or organization's records and may not be deleted from those records merely because the user later disconnects from Lorae. A clinician's technical ability to access information does not mean that the clinician has reviewed it or will respond to it.
We may disclose personal information in the following circumstances:
Lorae does not sell personal mental health information or consumer health data for monetary consideration. Lorae does not use information that users enter about their mental health, moods, exercises, clinician relationships, or therapy-related activity for targeted advertising. If our practices change in a way that constitutes a sale, sharing for cross-context behavioral advertising, targeted advertising, or another regulated use under applicable law, we will provide any required notice, consent, or opt-out mechanism before engaging in that practice. We do not knowingly permit advertising technologies to use user-entered mental health or consumer health data for advertising or marketing.
The website and app may use cookies, software development kits ("SDKs"), pixels, local storage, analytics tools, or similar technologies for functionality, security, diagnostics, performance measurement, and permitted analytics. We will identify material third-party data practices in this Privacy Policy or other required notices and obtain consent where required. We do not intend to place advertising pixels or tracking technologies on screens or fields where users enter sensitive mental health or consumer health information. Our actual implementation must remain consistent with this statement.
If Lorae uses automated systems or artificial intelligence to generate summaries, patterns, recommendations, or other features, we will describe material uses of personal information as required by law. Lorae does not use identifiable user-entered mental health information to train external general-purpose artificial intelligence models unless we provide appropriate notice and obtain any consent required by law. Automated outputs are informational features and are not diagnoses, clinical risk assessments, or substitutes for professional judgment.
HIPAA applies only in circumstances covered by the HIPAA Rules. When Lorae acts as a business associate of a HIPAA-covered entity, Lorae will process PHI in accordance with the applicable business associate agreement and HIPAA requirements. When Lorae receives information directly from a consumer and is not acting on behalf of a HIPAA-covered entity, that information may instead be governed by this Privacy Policy, consumer health data laws, the FTC Act, the FTC Health Breach Notification Rule, and other applicable laws.
We retain personal information for as long as reasonably necessary to provide the Services, maintain an account, satisfy the purposes described in this Policy, comply with legal and contractual obligations, resolve disputes, maintain security and audit records, and enforce agreements. Retention periods vary by data type, relationship, and legal requirement.
When an account is deleted, we will delete or deidentify associated personal information unless retention is required or permitted by law, necessary for security or fraud prevention, required by a healthcare organization's recordkeeping obligations, or otherwise subject to a valid exception. Information in backups may be deleted on a delayed cycle consistent with applicable law.
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, loss, or disclosure. No system or transmission method can be guaranteed to be completely secure. Security controls and any public claims about encryption, certifications, or HIPAA-related safeguards must reflect Lorae's actual technical implementation.
Depending on where you live and the law that applies, you may have rights to access, confirm processing of, correct, delete, or obtain a copy of personal information; withdraw consent; limit or object to certain processing; opt out of sale, targeted advertising, or certain profiling; appeal a denied request; and receive information about certain disclosures.
To submit a privacy request, use the privacy controls available in the Services or contact support@loraeapp.com. We may take reasonable steps to verify your identity and authority before completing a request. We will not unlawfully discriminate against you for exercising applicable privacy rights. Where required, Lorae will recognize applicable opt-out preference signals, such as Global Privacy Control, for processing subject to those signals.
Certain information processed by Lorae may qualify as consumer health data under state law. Please review the separate Lorae Consumer Health Data Privacy Policy for additional disclosures, consent requirements, and rights.
Users may request deletion of their account and associated personal information through the in-app deletion process, if available, or by contacting the privacy contact listed below. Account deletion does not necessarily cancel an active subscription billed through an app store; users should follow the applicable app store's subscription-cancellation process.
Certain information may be retained when required or permitted by law, including records needed for security, fraud prevention, legal compliance, dispute resolution, or healthcare recordkeeping. We will explain material retention that applies to a deletion request when required.
Lorae's consumer Services are intended for individuals age 18 or older. We do not knowingly permit individuals under 18 to create consumer accounts. If Lorae later offers a service specifically intended for minors, we will implement the additional notices, consent mechanisms, safeguards, and age-appropriate practices required by applicable law before doing so.
We may create and use deidentified or aggregated information for lawful purposes, including analytics and service improvement. Where required by law, we will take reasonable measures to ensure deidentified information cannot be associated with an individual, publicly commit to maintain it in deidentified form, and not attempt to reidentify it except as legally permitted to test deidentification methods.
The Services may link to or interoperate with third-party services. Their privacy practices are governed by their own policies. Before enabling a third-party integration that receives personal information, we will evaluate and contract for appropriate privacy and security protections where required.
We may update this Privacy Policy from time to time. We will update the "Last Updated" date and provide additional notice or obtain consent when required by applicable law. Material changes will not be applied retroactively where doing so would violate applicable law.
Privacy questions and requests: support@loraeapp.com
Lorae LLC