LOKEE PRIVACY POLICY
Effective date: 25 June 2026 (25.06.2026)
Product: Lokee
Legal URL: https://lokee.app/privacy
1. Controller
The controller of personal data processed in connection with Lokee is:
IsnTech Paweł Arent
Tax ID / NIP: PL7123459159
Address: ul. Pana Wołodyjowskiego 3/81, 20-627 Lublin,
Poland
Product and privacy contact: support@lokee.app
Legal notices: legal@lokee.app
2. What Lokee is
Lokee is a local-first knowledge vault for writers, worldbuilders, researchers, historians, RPG creators and narrative teams. It helps users organise entities, relationships, timelines, source fragments, documents, boards and structured project knowledge. The intended use is fiction-first and history-first work, not the operation of a database about private persons.
Free local use does not require an account. Account, sync, web, team, billing and managed AI features are optional online features.
3. Local-first rule
Purely local vault content remains on the user’s device. We do not normally have access to local vault files, local SQLite caches, local JSON entity files, local imported documents, local AI review batches or local board/timeline state. Local data leaves the device only when the user enables or uses a feature that requires transfer, such as account login, cloud sync, web access, backup/history, managed AI, support with file attachment, billing or analytics in the web version.
Local vault deletion, local backup, local disk encryption, device security and operating-system access control are the user’s responsibility.
4. Sensitive and private personal data warning
Lokee is not designed as a system for storing private or sensitive personal data. Users must not use Lokee as a primary repository for medical records, HR files, customer records, identity documents, children’s data, financial credentials, passwords, API keys, biometric data, criminal-offence data, political/religious/health/sexual-orientation data, or other information that requires a special legal basis or enhanced security regime.
For cloud sync, managed AI, support attachments and team features, users must not submit special-category personal data, illegal content, sexual exploitation content, child sexual abuse material, non-consensual intimate material, unlawful drug-trafficking material, content facilitating violence or serious crime, or content that violates third-party rights. We do not proactively inspect purely local vaults, but use of online services for prohibited content may lead to deletion, suspension, reporting, preservation of evidence and cooperation with competent authorities where required or permitted by law.
Where a business customer needs Lokee to process personal data on its behalf, that is not covered by default consumer/product terms and requires a separate written Data Processing Agreement.
5. Data categories
Depending on the features used, we may process:
- Account data: email address, display name, account ID, hashed password, OAuth ID, login events, account settings and subscription status.
- Billing data: Stripe customer ID, subscription data, payment status, invoices, tax and accounting data, refund records and communication about payments. Stripe handles full card data.
- Cloud sync and history data: full vault content, JSON entity files, relationships, timelines, board state, assets, imported documents, metadata and version/history data where the user enables sync or cloud features.
- AI processing data: uploaded documents, vault content or selected source material submitted by the user to managed AI features, plus extraction/review batches until the user accepts or rejects them.
- Support data: messages sent to support, attachments, diagnostic information and correspondence.
- Technical/security data: IP address, device/browser metadata, session IDs, operating system, app version, event logs, security logs and error information.
- Analytics/cookie data: Google Analytics and similar web analytics data for the website and web version, including visits, use of the account panel, app downloads and conversion events, subject to consent where required.
- Newsletter/communication data: email address, delivery data and opt-in/opt-out status where newsletters or marketing messages are used.
6. Purposes and legal bases
| Purpose | Legal basis under GDPR |
|---|---|
| account creation, login and core online features | Article 6(1)(b), contract |
| free local product communication and support | Article 6(1)(b) or Article 6(1)(f), legitimate interest |
| cloud sync, history, restore and team features | Article 6(1)(b), contract |
| managed AI features requested by the user | Article 6(1)(b), contract; consent where required for optional processing |
| billing, invoices, accounting and tax retention | Article 6(1)(b), contract; Article 6(1)(c), legal obligation |
| security, abuse prevention and service protection | Article 6(1)(f), legitimate interest |
| complaints, claims and legal defence | Article 6(1)(f), legitimate interest |
| optional analytics, non-essential cookies and marketing | Article 6(1)(a), consent |
7. Cloud location and storage
The planned primary cloud provider is Microsoft Azure, with EU hosting and Poland Central as the intended region where technically available. GitHub is used for code storage and development automation. Cloudflare is used for domain/DNS and edge services.
Where cloud sync is enabled, the current model stores full vault content with history/version data. Retention for version history has not yet been finally fixed and may be limited by plan or technical policy later. Downgrades do not immediately delete user data, but access, sync, edits, upload capacity, export options or new writes may be limited until the account is brought within plan limits.
After account deletion, cloud account and sync data are targeted for deletion within 30 days, except where retention is required for billing, tax, legal claims, security or backup integrity.
8. AI processing
Managed AI features may use OpenAI and Anthropic. BYOK (bring your own key) is planned only for the local desktop version, not as a cloud-stored account setting. For now, AI may process whole uploaded documents when the user starts an extraction or similar workflow.
We do not use vault content to train our own models and do not intend to do so. Managed AI prompts and outputs are not stored as general AI logs by Lokee. However, extraction/review batches are stored until the user accepts, rejects or otherwise resolves them, because review-gating is part of the product. External AI providers may process submitted content according to their applicable terms and processing settings.
AI credits may be purchased separately. Coupons or promotional credits may be issued.
9. Recipients and providers
Current and planned provider categories include:
| Provider | Purpose | Current notes |
|---|---|---|
| Microsoft Azure | Cloud hosting, operations, application infrastructure, databases, storage, logs and sync services | Primary cloud target; EU region, Poland Central where technically available. |
| GitHub | Code repository, development workflow and GitHub Actions | Code storage and deployment/build automation. |
| Cloudflare | Domain hosting, DNS, security and edge services | Domain and DNS layer for lokee.app. |
| Stripe | Payments, subscriptions, invoices, billing IDs and payment-status events | Card details handled by Stripe; vendor may issue additional Polish/VAT invoice records where Stripe invoices are insufficient for tax-ID presentation. |
| OpenAI | Optional managed AI features initiated by the user | Used for document extraction, classification, summaries or related AI workflows. |
| Anthropic | Optional managed AI features initiated by the user | Used as an additional or alternative managed AI provider. |
| Google / Google Analytics | Website and web-app analytics after consent where required | Includes analytics such as visits, account use, downloads and conversion events. |
| Resend | Product, transactional and support email | Current email delivery provider. |
| Microsoft Graph / Microsoft 365 | Future newsletter or email sending | Planned future provider for newsletters or operational email. |
We may also share data with accountants, tax advisers, legal advisers, auditors, banks, courts, public authorities and law-enforcement bodies where required or permitted by law.
We do not sell personal data.
10. International transfers
We prefer EU/EEA processing where available. Some providers, including Stripe, OpenAI, Anthropic, Google, GitHub, Cloudflare or Resend, may involve processing outside the EEA. Where required, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, supplementary safeguards or provider data-processing terms.
11. Retention
| Data | Retention |
|---|---|
| Account data | Until account deletion, then targeted deletion within 30 days, unless longer retention is legally required. |
| Cloud sync data | Until deletion by the user or account deletion, subject to backup/history behaviour and legal/security exceptions. |
| Version/history data | Retained as part of sync/history until deleted, overwritten, pruned or limited by future plan rules; final fixed period is not yet set. |
| Billing/tax records | Generally 5 years from the end of the calendar year in which the tax obligation arose, or longer if legally required. |
| Support correspondence | For the time needed to handle the request and defend claims. |
| Technical/security logs | Generally 30 days, unless longer retention is needed for security, abuse investigation or legal claims. |
| Analytics/cookies | According to consent settings and the Cookie Policy. |
| AI prompts/outputs | Not retained as general logs by Lokee; review batches remain until accepted/rejected/resolved by the user. |
12. User rights
Users may request access, rectification, deletion, restriction, portability, objection to legitimate-interest processing and withdrawal of consent. Requests should be sent to support@lokee.app or legal@lokee.app.
Users may lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, Poland.
13. Children and minors
Lokee is not directed to children. Users under 18 may use Lokee only with consent and supervision of a parent or legal guardian. We do not actively verify age at registration. Paid use by minors may require guardian involvement under applicable law.
14. No automated legal-effect decisions
We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects on users. Technical limits, payment status, security checks, anti-abuse rules and plan restrictions may be automated, but users may contact support.
15. Changes
We may update this Privacy Policy when the product, providers, pricing, AI features, cloud architecture or legal requirements change. The current version will be published at https://lokee.app/privacy.
This document is a production draft for a Poland/EU-first launch and should be reviewed by a qualified Polish lawyer before publication.