Privacy policy
Effective 6 September 2026
This policy explains how Lorena Labs handles personal information in connection with Stella Loop: our website, hosted application, desktop application, API and command-line tools. Contact info@lorenalabs.com with privacy questions or requests.
Who is responsible for your information
Stella Loop is operated by Lorena Labs Ltd, a company registered in England and Wales with company number 16991625. Our registered office and postal contact address is 20 Wenlock Road, London, England, N1 7GU, United Kingdom. In this policy, “Lorena Labs”, “we”, “us” and “our” mean Lorena Labs Ltd.
Lorena Labs is responsible for information we use to manage our relationship with you, authenticate accounts, operate and secure the service, and respond to enquiries. When an organization uses Stella Loop to manage its work or collect feedback, that organization normally decides why and how its workspace information is processed. We process that information to provide the service on its instructions. Your organization's administrator is the first point of contact for requests concerning its workspace.
This policy does not replace a data processing agreement or govern an independently operated, self-hosted deployment. Other services you connect have their own privacy notices.
Information we handle
- Account information: email address, profile name and image where provided, identity-provider identifiers, organization memberships, roles and authentication records.
- Workspace content: project information, documents, intents, reports, proposals, epics, tasks, comments, conversation messages, feedback, attachments and the associated activity history. Connected repositories and integrations can supply additional content, including information about collaborators.
- Service and security information: access and request records, IP addresses, device or browser information, application version, error details, native notification identifiers, execution records and usage or cost information.
- Information you send us: enquiries, early-access requests and feedback, including screenshots or other attachments you choose to include.
- Integration configuration: permissions, account references and credentials that you or your administrator provide to connect authorized services and execution environments.
Please avoid putting passwords, unrelated personal information or sensitive information into free-text fields, screenshots or prompts. Provide service credentials only through the settings intended for them.
Signing in with Google
If you choose Google sign-in, WorkOS handles the authentication exchange. We use the identity information Google provides, such as your account identifier, email address, name and profile image, to establish and identify your Stella Loop account. Google sign-in requests basic identity, email and profile access. It does not request access to Gmail messages, Google Drive files, calendars or contacts.
You can review or remove Stella Loop's Google connection in your Google Account connections. Removing that connection does not by itself delete information already held in Stella Loop. Contact us or your workspace administrator to request deletion of that information.
Why we use information
We use information to provide accounts and workspaces; authenticate users and enforce permissions; synchronize authorized integrations; run requested analyses, conversations and development workflows; deliver notifications; measure service usage; troubleshoot problems; prevent abuse; and respond to support and privacy requests. We also use information where needed to meet legal obligations or handle disputes.
Where European or UK data protection law applies and we act as a controller, the basis depends on the activity: performing our agreement with you, our legitimate interests in operating and protecting the service and responding to enquiries, compliance with legal obligations, or your consent where required. You may withdraw consent without affecting processing that occurred before withdrawal. You may also object to processing based on legitimate interests.
Who can receive information
Workspace content is available to the people and agents authorized by your organization's settings. Administrators manage membership, integrations, execution access, retention and other organization controls. Check those settings before sharing information.
We use service providers to operate Stella Loop, including WorkOS for authentication, Convex for backend processing and storage, Cloudflare for hosted-app and download delivery, and Vercel for website hosting. Infrastructure providers can process technical request information needed to deliver and secure these services. Authorized staff and support providers may access information when needed to operate the service, investigate a problem or carry out your request.
Features that use AI or external runners send the relevant task context, prompts, files and outputs to the model provider or execution environment selected by the workspace or deployment. Supported model integrations include Anthropic, OpenAI and Google. Which provider receives a particular task depends on configuration; merely signing in does not start an agent run. Review the selected provider's terms and your organization's settings before submitting confidential information.
We may also disclose information where required by law, to protect people or the service, or in connection with a business transfer subject to appropriate confidentiality and notice requirements. We do not sell personal information or share it for cross-context behavioural advertising.
Local storage and website measurements
The web and desktop applications store session information and preferences locally so you can remain signed in and retain settings. Identity providers may use their own cookies during sign-in. Clearing browser or desktop application data can remove your local session and settings; it does not delete the workspace's server-side records.
The marketing site includes first-party interaction measurements, such as the page path and which navigation link was selected. In the current configuration these events remain in the page and are not sent to an analytics endpoint. Hosting providers still process ordinary delivery and security logs. We will update this notice and obtain consent where required before introducing non-essential tracking that requires it.
Retention and deletion
We retain information for the purposes described here, taking account of the active account or workspace, organization settings, security needs, disputes and legal obligations. Different records have different retention rules. For example, conversation bodies and feedback attachments have configurable retention periods. Archiving a project hides it from ordinary navigation; it does not erase its contents.
Deletion or a retention sweep may remove content while retaining a limited tombstone, audit record or activity history to preserve the integrity of the workspace. Backup copies and provider records can remain until their retention cycles expire. We restrict information retained solely for those purposes. Ask us or your administrator about the retention and deletion rules that apply to a specific record.
International processing and security
Your workspace, integrations and service providers may process information outside your country. Where a restricted international transfer is subject to European or UK data protection law, the applicable agreement must provide an appropriate transfer mechanism, such as an adequacy decision or approved contractual safeguards. Contact us for information about the safeguards applicable to your service.
We use access controls and technical measures intended to protect information, but no system can guarantee complete security. You are responsible for protecting your account, API keys and connected execution environments and for reporting suspected unauthorized access promptly.
Your choices and rights
Depending on applicable law, you may request access to, correction of, deletion of or a portable copy of your personal information; request restriction of processing; object to certain processing; or withdraw consent. Send requests to info@lorenalabs.com. We may need to verify your identity and involve your workspace administrator. Some requests are limited by other people's rights or legal requirements.
You may complain to the UK Information Commissioner's Office, or to the data protection authority where you live or work or where you believe a violation occurred. We welcome the opportunity to address your concern directly first, but you do not have to contact us before exercising that right.
Children and policy updates
Stella Loop is a professional development tool and is not directed to children. If you believe a child has supplied personal information, contact us so we can investigate and take appropriate action.
We will update this page when our practices change, identify the revision date and provide additional notice where a material change or applicable law requires it.