Torch & Lily

Privacy
Policy.

Effective: April 2026 · v1.0

Torch & Lily is built by a single developer who believes your data is yours. This policy explains what we collect, why, and how it is stored. It is written plainly on purpose.

1. What We Collect

  • Account information: When you sign in via Google or GitHub OAuth, we receive your name, email address, and profile picture from your chosen provider. We do not collect passwords.
  • API keys: When you generate an API key, we store a one-way SHA-256 hash of the key. The plaintext key is shown to you exactly once and never stored on our servers.
  • API usage logs: We log request metadata (endpoint, timestamp, response code) for rate limiting and abuse prevention. Logs do not contain request or response bodies.
  • Contact form submissions: If you use the Vox contact form, we store your name, email, and message so we can respond.
  • Newsletter subscription: If you subscribe to the Epistulae newsletter, we store your email address for delivery purposes.

2. What We Do Not Collect

  • We do not use cookies for advertising or tracking.
  • We do not embed third-party analytics, pixel trackers, or ad networks.
  • We do not sell, share, rent, or monetize your personal data under any circumstances.
  • We do not profile users or build behavioral models.

3. How Data Is Stored

All data is stored in a Supabase-hosted PostgreSQL database with Row Level Security (RLS) policies enforced on every table. Authentication is handled entirely by Supabase Auth. The database is hosted in the United States.

4. Third-Party Services

We use the following third-party services to operate Torch & Lily:

  • Supabase — database, authentication, and storage.
  • Railway — backend API hosting.
  • Netlify — frontend hosting and form processing.
  • Resend — transactional email delivery (welcome emails, newsletter broadcasts).
  • Google & GitHub — OAuth identity providers (we receive only the data you authorize).

Each service has its own privacy policy governing how they handle data on their infrastructure.

5. MCP & API Access

The same data-handling rules apply to all access methods, whether REST API, MCP server (Streamable HTTP transport at api.torchandlily.com/mcp), or any future channel. Authentication is the same shared API key in every case, and we never log request payloads or model output.

All Torch MCP tools are read-only by design — they query a fixed corpus of historical Catholic data and cannot modify, delete, or write any user information.

For OAuth 2.0–authenticated connections (e.g. claude.ai web client), the same data-handling rules apply. Access tokens are short-lived (1 hour) JWTs signed by Torch & Lily; refresh tokens rotate on every use and can be revoked at any time from your dashboard. We never persist access tokens — verification is stateless via signature. We retain refresh token hashes (not plaintext) until revoked or expired (30 days).

6. Data Retention

Account data is retained as long as your account exists. If you delete your account via the dashboard, your profile, API keys, and associated data are removed. API usage logs are retained for a reasonable period for security and abuse prevention, then purged.

7. Your Rights

You may request deletion of your account and personal data at any time by using the account deletion feature in your dashboard, or by contacting us at dev@torchandlily.com. We will respond promptly.

8. Children

Torch & Lily does not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.

9. Changes to This Policy

We may update this policy as the project evolves. Material changes will be communicated via the Changelog. Continued use after changes constitutes acceptance.

10. Contact

For any questions about this policy or your data, reach out via the Vox contact form or email dev@torchandlily.com.

Torch & Lily · 2026