§ privacy

A few numbers, when you run it. Here’s why.

lore — network monitor

# every connection one run of npx lore-wrapped makes

01 why we ask
why.ts — the three reasons, and the one rule
  1. fn rank(you)

    So your report can rank you.

    “Top 5% for steering” only means something next to everyone else. Your report downloads the public index and does the ranking on your machine.

  2. fn publish(index)

    So everyone gets the index.

    Which models get redirected most, who gets sworn at, how long agents really run on their own. Nobody else measures this, so we publish it, free, for anyone to read.

  3. fn pay(you)

    So we can pay you for the right things.

    The counts show what kinds of work are out there: which agents and models, how long they run, how people steer them. That tells us what the paid program in the manifesto should build first. They tell us what, never who.

  4. assert(!traceable(you))

    We couldn’t trace them back to you if we tried.

    No account, no id, no IP kept: lore’s server runs on Cloudflare, which sees an address only to deliver the request and stop floods. We publish only aggregates over 25+ runs, and we never publish or sell a raw row. That’s on purpose.

02 every field

The whole payload. Commented.

This is what npx lore-wrapped stats prints, for a fictional run. It’s generated from the code that sends it, and the collector rejects anything that isn’t on it. On the left: everything lore reads, which stays where it is.

payload.jsonc — what leaves your machine
payload.jsonc
JSONCnothing runs in the background
03 turn it off

One line. No hard feelings.

~ — zsh

$ npx lore-wrapped stats off # every run, until stats on

$ npx lore-wrapped --no-stats # this run

$ export DO_NOT_TRACK=1 # the cross-tool standard

$ export DISABLE_TELEMETRY=1 # told Claude Code not to phone home? lore won’t either

$ npx lore-wrapped --offline # nothing leaves at all

# CI and piped runs never send.

04 audit us

You shouldn’t have to trust us. Have your agent check.

Paste this into Claude Code, Codex or any agent. It reads lore’s code before you run it and tells you what it takes and how worried to be.

audit prompt

Audit the npm package lore-wrapped before I run it. Assume it might be lying to me.

  1. Get the code without running it: npm pack lore-wrapped, then unpack the .tgz into a scratch folder (or clone its GitHub repo).
  2. Find every network call (fetch, http, https, net, dns, WebSocket, and any child process that could reach the network) and every file it reads or writes outside that folder.
  3. For each one: what data, sent where, when, and what triggers it.
  4. Compare that with the Privacy section of the package's README.md and flag anything it sends that isn't listed there.
  5. Run npx lore-wrapped stats and check that the printed payload is all the code would send.
  6. Rate each finding none, low, medium or high risk, then give me a one-line verdict: is it safe to run, and what should I turn off?
05 your email

Only if you join the waitlist. Gone when you ask.

The waitlist (on the manifesto, or at the end of your report) keeps your email, in its own list, apart from the anonymous stats and never linked to them. It’s used once: to tell you the paid program is open. Anything else: inquiries@lore-wrapped.com.