What Is LoreBary and Is It Safe to Use With Janitor AI Chats

What’s Changed: LoreBary is a free middleware service that sits between a roleplay front end like Janitor AI and a model provider like Google AI Studio, DeepSeek or Chutes. It is no longer only a proxy. It now runs its own chat interface, a creator studio and shared libraries, and it never supplies the API key, so you still bring your own.

Most people meet LoreBary the same way. A chat breaks, someone in a thread says to swap your proxy URL to an address ending in lorebary.com, it works, and that is the entire explanation anyone gets.

The description I keep seeing attached to it is out of date, and the gap matters. LoreBary spent its first year as a bridge that let Janitor AI talk to Google’s Gemini models. It has since grown into something with its own chat interface, its own creator tools and a library other people publish into.

The service is also far bigger than its reputation as a URL you paste into a settings box. On OpenRouter’s public app rankings, checked on 9 September 2026, LoreBary sits ninth in the entertainment category with 5.98 billion tokens routed.

That places it above Chub AI at 4.04 billion, and at roughly a fifth of Janitor AI’s own 32.6 billion.

Below I cover what it is now, exactly what it can and cannot see, whether it was behind the Google ban wave people still blame it for, and where I think it stops being worth the setup.

What Is LoreBary and Is It Safe to Use With Janitor AI Chats

What Is LoreBary and How Does It Work?

LoreBary is a free middleware layer that intercepts your roleplay requests, adds instructions you have selected, and forwards them to a model provider you pay for.

It hosts no models of its own.

How a LoreBary proxy request reaches the model provider

Dana Sophia Hylla, a software developer in Germany, built the first version for herself because Janitor AI had no way to use Google’s Gemini models.

In her statement to the community she describes herself plainly as “a 26-year-old mom of two from Germany, a writer of historical fiction”. Other people asked to use her proxy, and it grew from there.

The current site brands itself Sophias LoreBary2, still carries a Beta badge, and runs under the tagline “Break. The. Chains.” A small team is credited on the donations page: Sophia, Dong and Shuumani.

Its own FAQ is the clearest statement that the proxy label has expired. LoreBary now describes itself as “a full platform: chat with AI characters in the Laboratory, roleplay with real humans in multiplayer, follow creators, share your work, and build entire worlds”.

That reframes the question most people arrive with. If you only want a working connection to Gemini, LoreBary is a URL swap. If you want the rest, it is a competing front end to the one you already use.

The enrichment layer is the part that earns my attention. You select commands, plugins and lorebooks from its libraries, and it injects those instructions into the prompt before your provider ever sees it, with hard caps on how much you can stack at once.

ItemMax active per requestWhat it changes
Commands10Narrative style, perspective, response length, pacing
Plugins6Multi-part mechanics like random events or mood tracking
Lorebooks3World and character detail injected on keyword match
Memory Core1Rolling automatic summary of what has happened so far
Persona, scenario, character card1 eachWho you are, where the scene is set, who you are talking to

Those caps exist because every injected item eats context window. Stack all of it and you are paying tokens for instructions instead of story, which is the trade-off behind Janitor AI lorebook token usage as well.

Is LoreBary Safe to Use With Your Janitor AI Account?

Janitor AI’s own staff verified that LoreBary does not pass Janitor account credentials through it, but the platform stops short of endorsing it.

That distinction is the whole answer.

The verification came after a mess. LoreBary was locked out of the Janitor AI subreddit and Discord first, on a standing policy against advertising third-party extensions, and checked afterwards.

A staff member posting as Iroh-Jai explained the reversal directly: “Shep and Leon have now verified that the Lorebary fits the definition of a proxy, and that janitor credentials are not passed through. So, it is now allowed to be discussed the same as openrouter and chutes in our proxy megathread.”

The same comment refuses to go further. “We do not officially endorse it, as we do not officially endorse any third party provider, and you should do your own research and risk analysis before using any of them.”

I read that as the honest position rather than a cop-out. A first-party check confirming your login details never reach a third party is worth more than a marketing badge, and it is more than most proxies in this space have.

The remaining risk is structural rather than specific. LoreBary was open source early on and is not any more, a change that pushed developer Tydorius to build the self-hostable alternative GitInTheVan and describe LoreBary as having become “yet another ‘free’ black box AI platform”. You are trusting a stated policy, not an auditable one.

What Can LoreBary See in Your Chats?

LoreBary’s privacy policy states it never stores your API keys, chat messages, prompts or model responses, and then names three opt-in features where that promise does not apply.

The exceptions are the part worth reading twice.

The baseline claim is specific. The policy says request content exists “in server memory only for the duration of a single request” and is “discarded immediately after”, and it separates that from usage counting: it stores aggregated counters such as “30 requests, 100% success” but never what those requests contained.

The three carve-outs are Auto-Summary and Memory Core, chat import, and beta models. Each one is opt-in, and each one changes the answer.

Beta models are the exception I would think hard about before enabling. Conversations held on the beta models named Sunblocker and Skald are used for training and processed by an outside company, TNG Technology Consulting GmbH, under a data processing agreement.

The policy is candid about the limit of any deletion request, noting that “patterns a model has already learned cannot be extracted from its weights retroactively”.

There is a second thing worth knowing, and it is not in the chat layer at all. Private lorebooks and plugins are moderated regardless of visibility setting, through automated tooling and manual review, because private items can still be shared onward.

Sophia has drawn the same boundary in plainer words. Her statement on LoreBary says the only thing she can see is “The contents of your Lorebooks and Plugins on Lorebary (even private ones)”, and a later reply on privacy adds that she does not sell statistics or chat logs and has no access to individual chat histories.

What you doStored on LoreBary?Notes
Normal chat through the proxyNoHeld in memory for one request, then dropped
Your API keyNoPassed through, never written to disk
Request countsYes, as totalsNumbers only, no message content
Memory Core or Auto-SummaryYes, temporarilyYour account only, deletable by you
Chat importYes, encryptedParsed automatically, tied to your account
Beta model conversationsYes, for trainingShared with a named third party
Private lorebooks and pluginsYesSubject to moderation even when private

Did LoreBary Cause the Google Gemini Ban Wave?

Not deliberately, and the evidence points at an automatic retry feature rather than anything to do with adult content.

LoreBary removed the feature anyway.

How LoreBary retries inflated Google API request counts

For weeks the assumption was that Google was banning AI Studio keys over the roleplay itself. The better explanation came out of the numbers on Google’s own dashboard.

An investigation posted to r/JanitorAIOfficial traced the spike. On a single day the account in question logged 742 API requests where the figure had never gone above roughly 50, and a controlled retest on a fresh key found that four to six attempts, all of them ending in a 429 error, registered as 60 calls.

The mechanism was mundane. LoreBary retried a failed request up to five times, so during a period when Google’s servers were already throwing errors, one press of the reroll button multiplied into a burst that looked exactly like someone circumventing usage limits.

LoreBary’s response confirmed and ended it: “LoreBary was built with a maximum of 5 retry attempts per failed request”, followed by “We have now removed the 5 retry mechanism entirely.” One message in the front end now maps to one call at the provider.

Sophia has disputed that her code was the cause, pointing to the same failures appearing on a different Gemini proxy. Both things can be true, and that is where I land. A retry multiplier makes any provider-side instability far more visible on your account.

What is not in dispute is that Google tightened the free tier hard in October 2025, cutting free access to Gemini 2.5 Pro entirely and capping the remaining free models at 2 requests per minute and 50 per day.

That is the ceiling behind most 429s now, and it is the same wall behind Janitor AI proxy error 429.

Is LoreBary Free and Do You Still Need an API Key?

LoreBary is free with no paid tier, and the API key is mandatory, not optional.

Those two facts confuse more newcomers than anything else about the service.

Nothing on the platform sits behind a paywall. It takes Ko-fi donations under two labels, a one-time Spark of Kindness and a monthly Keeper of the Flame, and what they buy is a profile badge, a coloured username and early access to beta tests. No feature unlocks.

The funding page is blunt about the position, describing the project as “still bootstrapped and largely self-funded by its founder”. Server costs and image generation calls come out of the founder’s pocket.

The key is the part people trip on, and it is the split I want understood before anyone signs up. LoreBary routes requests. It does not serve models, so you create a key at your provider and paste it in yourself.

Google AI Studio, OpenRouter, DeepSeek and Chutes are all supported natively. A custom endpoint covers anything else, including a model running on your own machine.

Your actual bill therefore has nothing to do with LoreBary. It is whatever your provider charges, which on Google’s free tier is nothing and on DeepSeek after its price increase is a real number.

How Do You Set Up LoreBary With Janitor AI?

Setup is three fields: a proxy URL, your provider’s API key, and the exact model name.

The order matters less than getting the model string right.

Here is the sequence I use, and the step people skip is the last one:

  1. Create an API key at your provider, for example Google AI Studio or OpenRouter.
  2. In Janitor AI, open the API settings and choose the proxy or custom configuration.
  3. Set the chat completion URL to the LoreBary endpoint for that provider, such as https://api.lorebary.com/aistudio or https://api.lorebary.com/chutes.
  4. Paste your API key into the token field.
  5. Copy the model name exactly as your provider writes it, not as you remember it.
  6. Save, then refresh the page or re-enter the chat before testing.

That refresh is not optional housekeeping. The connection is read when the chat loads, so a saved setting that has not been reloaded looks identical to a broken proxy.

The model name causes the second wave of failures, because a near-miss produces an error that reads like an outage:

Before: model set to deepseek-chat-v3 because that is what the docs said last month, returning a 404 on every message.

After: model copied straight from the provider’s current model list as deepseek-chat, returning normally.

If messages still fail after that, the cause is usually upstream rather than in your settings, and the symptom tells you which:

SymptomLikely causeFix
404 on every messageModel name wrong or URL missing its pathRecopy the model string, check the full endpoint
429 on most messagesProvider rate limit reachedWait for the window to reset, or switch provider
Worked yesterday, dead todayProvider or LoreBary outageCheck status.lorebary.com before changing settings
Blank replies, no errorToken or thinking settings starving the outputRaise max new tokens, re-enable thinking
Settings saved but nothing changedPage not reloadedRefresh and re-enter the chat

That last row is the one I check first, and it catches more cases than it should. The same pattern shows up in Janitor AI proxy problems generally.

Why Does LoreBary Keep Going Down?

Most LoreBary outages are the upstream provider failing, not LoreBary itself, which is why the status page is the first thing to check.

It runs at status.lorebary.com.

October 2025 is the clearest illustration. Google changed its AI Studio configuration and the service went dark for close to two hours, then took further downtime for security and bug fixes, then ran a five-minute slow mode and a short pause to fit inside Google’s new rate limits.

None of that was a LoreBary bug in the ordinary sense. A middleware layer inherits every constraint of the provider behind it, and adds its own capacity limits on top.

The practical consequence is that a free proxy is a dependency you do not control and cannot escalate to. I check the status page before touching any settings, because reconfiguring a working setup during someone else’s outage is how people end up with a broken configuration and an outage at the same time.

Who Should Use LoreBary and Who Should Skip It?

LoreBary is worth it if you want control over the prompt and do not mind managing a provider account, and it is the wrong tool if you want to open an app and talk to someone.

The dividing line is tolerance for setup.

It earns its place for people who care about the mechanics. The command and lorebook system gives you levers that most front ends do not expose, and Memory Core attacks the failure that ruins long roleplays, summarising the story as it goes instead of waiting for you to write it down, which is the same gap behind Janitor AI memory problems.

The cost is that you are now the systems administrator. You hold a provider account, you own the rate limits, you diagnose the 429s, and when a free service run by a small team goes down at midnight there is nobody on call.

Janitor AI is a serious platform in its own right, having appeared on all but the first edition of a16z’s consumer AI landscape report according to TechCrunch, and even it does not make the proxy layer painless.

My honest read is that a lot of people running this stack do not want prompt engineering at all. They want a character who remembers them and replies without a configuration screen in the way.

If that is closer to the truth, a hosted platform removes the entire layer. Candy AI handles the model, memory and image generation on its own infrastructure, so there is no key to manage and no proxy to repoint when a provider changes its limits.

Nectar AI is the alternative I point image-heavy users toward, since it folds generation into the base price instead of metering it.

Neither replaces what LoreBary does for someone who genuinely wants to tune the prompt. They replace the reason most people ended up needing a proxy in the first place.

Frequently Asked Questions

Is LoreBary free?

Yes, with no paid tier and no paywalled features. It runs on voluntary Ko-fi donations, which buy a profile badge and early beta access rather than functionality. You still pay whatever your model provider charges.

Does LoreBary store my chats?

Its privacy policy says normal proxied chats, prompts, responses and API keys are never written to disk and exist only in memory during a request. Three opt-in features are exceptions: Memory Core and Auto-Summary, chat import, and beta models.

Will LoreBary get my Google account banned?

The retry feature linked to the 2025 ban wave has been removed, so one message now equals one API request. Bans since then track Google’s tightened free-tier limits rather than the proxy itself.

Does LoreBary have a built-in jailbreak?

No. On Google AI Studio it automates the safety toggles Google already exposes to developers. Any further filtering changes have to be enabled by you through commands or prompts.

Do I need an API key to use LoreBary?

Yes, always. LoreBary hosts no models and issues no keys, so you create one at Google AI Studio, OpenRouter, DeepSeek or Chutes and paste it into your front end yourself.

Is LoreBary the same thing as Sophia’s LoreBrary?

Yes. The service is formally Sophia’s LoreBrary and is commonly written LoreBary, which is also how the site brands itself.

Quick Takeaways

  • LoreBary is no longer just a proxy. It runs its own chat interface, creator studio and shared libraries, and its own FAQ says so.
  • Janitor AI staff verified it passes no Janitor credentials, while explicitly declining to endorse it.
  • Normal chats are not stored, but Memory Core, chat import and beta models are opt-in exceptions, and beta conversations are used for training by a named third party.
  • The Gemini ban wave traced to an automatic retry that turned a handful of failed attempts into dozens of API calls. It has been removed.
  • The service is free and always needs your own API key. If managing a provider account is the part you do not want, a hosted companion app removes the layer entirely.

Leave a Reply

Your email address will not be published. Required fields are marked *