Lerp

Privacy Policy

Less data. More clarity.

What the library keeps, why it keeps it, and how to ask us to remove it.

Effective 25 September 2026.

01

Who is responsible

Lerp (lerp.gallery) is operated by an independent developer based in Hong Kong, responsible for the personal data described here. Contact support@lerp.gallery with privacy questions.

02

Accounts and sign-in

We store your email, account creation date, passkey public keys and credential identifiers, hashed session tokens, sign-in challenge hashes, session expiry, and limited device information for your session list. We do not receive your passkey’s private key or biometric data. Essential HttpOnly cookies keep you signed in; localStorage holds signed-out boards and interface preferences.

03

Boards and connected agents

We store boards you save to an account or share, their items and sharing identifiers. Anyone with a shared link can read its board. API keys are stored as hashes with a prefix, label, scope, expiry and last use. OAuth grants, registered client details and hashed tokens live in Cloudflare KV. MCP call records keep account, credential, tool, time and usage information to enforce quotas and show account activity.

04

Payments

Stripe processes checkout, subscriptions and the billing portal. We keep Stripe customer and subscription identifiers, plan status, billing periods and webhook event identifiers. We do not store full card details. Stripe holds payment and invoice information under its own privacy policy.

05

Messages, launch list and delivery logs

We keep what you submit: contact details, suggestions, claims, removal requests and their decisions. Joining the launch list stores your email and signup time for a launch announcement, not unrelated marketing. Email delivery logs include the recipient, subject, plain text and HTML body, link, expiry and provider delivery identifier or failure. An owner can view these logs, including short-lived sign-in codes. Ask by email to leave the launch list.

06

Security and analytics

Cloudflare hosts the service, database, object storage, OAuth storage, email and owner-only Access sign-in. Turnstile checks public forms for abuse. Rate limits use short-lived hashes of network address, action and time window; raw addresses are not stored in that table. Cloudflare may process request addresses, browser information and operational logs for security. Cookie-free Cloudflare Web Analytics measures aggregate visits and performance without advertising cookies or a tracking pixel in email.

07

Reference content and AI

We store public-site recordings, stills, extracted design tokens, measurements and editorial notes. TypeSafe and DashScope process selected public-site material for classification and prompt generation. Suggestions and credit claims may be analysed for triage. Do not submit secrets or sensitive personal information in these fields. We do not sell personal data or use sign-in emails as model prompts.

08

Retention, deletion and access

You can delete an account from Account, which cancels billing and removes account records and connected access. Delivery logs, support requests, security logs and necessary accounting records may remain separately; email support@lerp.gallery to request access, correction or deletion. We retain opt-out domains to avoid recapturing removed sites. Expired rate-limit windows are cleaned after a day when forms are used. Account deletion does not erase every separately retained record immediately.

09

Your choices and questions

Email support@lerp.gallery for privacy requests or launch-list removal. Depending on where you live, you may have rights to access, correct, export, erase or restrict processing and complain to a regulator. Our providers may process data internationally.

A person, not a maze. support@lerp.gallery