Privacy
What data the service processes, and why.
Last updated 30 September 2026.
Who is responsible
The data controller is Bartosz Kobyliński, a private individual in Norway. lovspor is not run by a company. Contact: kontakt@lovspor.no.
The website
The pages on lovspor.no are static. They set no cookies, run no scripts and use no analytics or tracking tools.
The web server keeps an access log of the requests it receives, for operations, troubleshooting and security. A log line describes one request, including the IP address it came from, the time, the address requested, and what the browser reported about itself. The log is rotated by size: only a limited number of older log files are kept, and the oldest are deleted automatically — in practice after a few days.
The hosted service
The lovverk service at https://lovspor.no/mcp requires sign-in, in one of two ways:
- Signing in with an account. When you connect from a chat app such as Claude or ChatGPT, you sign in with WorkOS, our sign-in provider. WorkOS processes your email address and name and — if you sign in with another account, such as Google — your identity with that provider. Our server receives an access token from WorkOS and uses only the user identifier in it, not your name or email, to recognise you and count your usage.
- Issued token. Developers can be given a token by us. We do not store the token itself, only a cryptographic hash of it, together with a label we give it, the limits that apply to it, and whether it has expired or been revoked.
Usage is counted per user and per token to enforce the quotas. The counters live only in the server's memory and are forgotten when the service restarts. Our program does not write your questions or the content of tool calls to a log. The service process does have its own operations log on the server, and it holds details of individual requests, including the IP address and the response status. It is deleted after at most 30 days.
Once an hour the service writes an aggregate summary of usage to the same operations log: how many calls were made per tool, how many were refused and by which limit, response times, and how many distinct users were active — as a number only. The summary contains no query text, no user identifiers and no IP addresses.
Semantic search and OpenAI
The semantic_search tool sends the text of your search, shortened to a fixed maximum length, to OpenAI's embedding service, which turns it into a vector. That is the only place where text you write leaves our server; the other tools send nothing onward. The search text and its vector are kept in an in-memory cache and forgotten when the service restarts. Processing at OpenAI may take place outside the EEA. Do not paste confidential or personal information into a search.
If you write to us, for example to ask for a token, we process your email and what you write in order to reply. Email to kontakt@lovspor.no is forwarded through Cloudflare.
Who processes data for us
- DigitalOcean — hosting of the server, in its Frankfurt data centre (EU).
- WorkOS — account sign-in.
- OpenAI — only the search text of
semantic_search. - Cloudflare — DNS for lovspor.no and forwarding of email to the contact address. Traffic to the website and the service does not pass through Cloudflare.
We do not sell data, show no advertising and do not use the data for profiling.
Purposes and legal basis
- Sign-in, quotas and semantic search — to provide the service you signed up for.
- Access log and operations log — legitimate interest in operating and protecting the service.
- Email — legitimate interest in replying to you.
How long data is kept
- Usage counters and the search cache — until the service restarts.
- The access log — rotated by size; in practice a few days.
- The operations log — at most 30 days.
- Issued tokens — the entry remains after the token is revoked, until we delete it.
- Your WorkOS account — until you ask us to delete it.
- Email — as long as needed to reply to you.
Your rights
Under the Norwegian Personal Data Act (personopplysningsloven) you have the right to access the data we hold about you, and to have it corrected or erased. You can also object to the processing, ask for it to be restricted, and ask to receive your data. To delete your account or have a token revoked, write to kontakt@lovspor.no. If you believe we process personal data in breach of the rules, you can complain to Datatilsynet, the Norwegian Data Protection Authority.
Changes
If we change this page, we update the date at the top. The code that does the processing described here is open: lovspor. The terms of use are on a separate page.