Lorenzinoverse Privacy Policy
Privacy Policy
Effective: 28/08/2026
1. Who controls your data
The Lorenzinoverse and CB services are operated by a private individual based in Dublin, Ireland. That individual is the data controller for personal data processed through them. This is a personal project and not a registered company.
Contact: lorenzinoverse@gmail.com
We don’t publish a street address, because this is a personal project run from a home and not a business premises. If you’re exercising a data protection right, making a legal claim, or contacting us in an official capacity, email the address above and we’ll provide the identifying and contact details required for that purpose.
The project is not large enough to require a Data Protection Officer, so the email above reaches the person responsible directly.
2. What this covers
lorenzinoverse.com, CB Accounts, CB Network, Diversity Themes, Freing, and the CB Ecosystem apps.
3. What we collect
If you never create an account, we collect almost nothing beyond what any web server sees: your IP address, browser type, the pages you request and when you requested them, held in standard server logs by our hosting providers.
If you create a CB account:
| Data | Where it comes from |
|---|---|
| Email address | You, at signup |
| Password | You — stored only as a cryptographic hash. We never see or store your actual password |
| Username and display name | You, at signup |
| Avatar image | You, if you upload one |
| Profile details, rank, follows and follower counts | Generated as you use CB Network |
| Content you create in the apps — calendar events, contacts, tasks | You, as you use them |
| Sign-in timestamps and session data | Generated automatically for security |
Freing collects nothing. It runs entirely in your browser using local storage. Your entries, people, groups and boards never reach our servers. We can’t see them, can’t recover them, and hold no copy.
Diversity Themes is browsable without an account. Preferences you set are stored locally in your browser unless you’re signed in with a CB account.
We don’t collect special category data — health, religion, political opinions and so on — and you shouldn’t put it in your profile.
We don’t take payments, so we never collect card or bank details. Any page asking you for payment details in the name of CB or the Lorenzinoverse is not us.
4. What’s public
Your CB Network profile is public. Your username, display name, avatar, rank and follower count are visible to anyone on the internet, including people without accounts, and avatar images are served from publicly accessible URLs. Search engines may index public profiles.
Your email address is never shown publicly.
5. Why we process it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and running your account, and providing the apps you sign into | Performance of a contract |
| Sending service emails — verification, password reset, security notices | Performance of a contract |
| Keeping the services secure, preventing abuse, and debugging | Legitimate interests |
| Understanding basic aggregate usage to improve the services | Legitimate interests |
| Any optional analytics or non-essential cookies | Your consent |
| Responding to legal requests and keeping required records | Legal obligation |
Where we rely on legitimate interests, we’ve considered whether it’s fair to you and limited what we collect accordingly. You can object — see section 9.
We don’t sell your data, and we don’t use it for advertising or profiling.
6. Who we share it with
We don’t sell or trade personal data. We use a small number of service providers who process data on our behalf:
- Supabase — database, authentication and file storage
- Vercel — hosting for the websites and apps
- Cloudflare — hosting, storage and content delivery
- Mailgun — sending service emails
KEEP THIS LIST ACCURATE. Add anything else you actually use — analytics, error tracking, hosted fonts, embedded video. Remove anything you drop. A policy describing something you don’t do is a statement you can be held to.
We may also disclose data where legally required, or where necessary to protect our rights or someone’s safety.
7. International transfers
Some providers process data outside the European Economic Area, including in the United States. Where that happens, transfers are protected by the European Commission’s Standard Contractual Clauses or by an adequacy decision, including the EU–US Data Privacy Framework where the provider is certified.
8. How long we keep it
- Account data — for as long as your account exists, deleted within 30 days of you deleting the account
- Content in the apps — until you delete it, or until your account is deleted
- Server and security logs — typically up to 12 months
- Emails you send us — up to 24 months, so there’s a record of the conversation
Backups may hold copies briefly after deletion and are overwritten on a rolling basis.
9. Your rights
Under GDPR you have the right to:
- Access — get a copy of the personal data we hold about you
- Rectification — have inaccurate data corrected
- Erasure — have your data deleted
- Restriction — have us pause processing while a dispute is resolved
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — at any time, where we relied on consent
To exercise any of these, email lorenzinoverse@gmail.com. We’ll respond within one month. There’s no charge unless a request is clearly excessive or repetitive.
You can also delete your account yourself from your settings, which removes your profile and associated data.
If you’re unhappy with how we’ve handled your data, you can complain to the Irish Data Protection Commission:
Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963, Ireland
dataprotection.ie
If you live elsewhere in the EU you can complain to your own national supervisory authority instead.
10. Security
Passwords are hashed and never stored in readable form. Traffic is encrypted in transit with HTTPS. Access to the production database is restricted, and database-level access rules limit what any account can read.
No system is perfectly secure, and this is a project run by one person rather than a company with a security team. We’ll notify you and the Data Protection Commission without undue delay if a breach occurs that’s likely to affect your rights. We’re telling you the scale of the operation so you can judge for yourself what to store here.
11. Cookies and local storage
We use cookies and browser storage that are strictly necessary to run the services — keeping you signed in, remembering your theme and graphics settings, and holding your Freing workspace locally.
Strictly necessary cookies don’t require consent under the ePrivacy rules. As of the effective date above, we use no non-essential cookies, no advertising cookies and no cross-site tracking.
If you add analytics, embedded video or anything that tracks people across sites, you’ll need a consent banner that asks before it loads and genuinely works if someone says no. Update this section at the same time.
You can clear cookies and site data in your browser at any time, but doing so will sign you out and, on Freing, permanently delete your workspace.
12. Children
The services aren’t intended for anyone under 16, and you must be 16 or over to create a CB account. If we learn we’ve collected data from someone under 16, we’ll delete it. If you believe a child has given us data, email lorenzinoverse@gmail.com
13. Changes
We may update this policy. Significant changes will be flagged on the site and the effective date above updated. Previous versions are available on request.