Privacy Policy

Last updated: January 2026

Developer312 (NIGHT LITE USA LLC) operates lean-forge.net (the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of personal data.

What we collect

  • Essential cookies — a single cookie-consent flag stored in localStorage and as a first-party cookie. It records your Accept/Decline choice. No personal data.
  • Server logs — IP address, user agent, request path, response code, and timing. Used for security, abuse detection, and aggregate performance analysis. Retained for 30 days.
  • API requests — your IP, the endpoint hit, and response code. Used for rate limiting and abuse detection. Not linked to your identity unless you sign in.

What we do not collect

  • No advertising trackers, no third-party analytics by default.
  • No browsing history, no fingerprinting, no cross-site tracking.
  • No personal data unless you explicitly create an account via the sign-in flow.

Your rights (GDPR / CCPA)

You have the right to access, correct, delete, or export any personal data we hold about you. To exercise any of these rights, email [email protected]. We respond within 30 days.

Data retention

  • Server logs: 30 days.
  • API rate-limit counters: 15 minutes sliding window.
  • Account data (if you sign in): until you delete your account.

Third parties

We use the following processors to operate the Service. Each is bound by a data processing agreement:

  • Railway — application hosting (Frankfurt region).
  • Neon — managed PostgreSQL (US-east).
  • Upstash — managed Redis (US-east).
  • InsForge — authentication, only invoked if you sign in.
  • Cloudflare — DNS, edge cache, and DDoS protection.

Changes to this policy

We may update this policy. The "Last updated" date at the top will reflect the change. Material changes will be announced via the site banner.

Contact

For any privacy-related question: [email protected].