Skip to content

Legal

Privacy

Last updated

Lamplit is made by a small team, and “we” below means us. This page lists everything this website and the Lamplit app send anywhere, who receives it, how long it is kept, and how to have it removed. If you find something it does not cover, that is a bug — please tell us at hello@lamplitphoto.com.

This website

The pages set no cookies, run no analytics or third-party trackers, and load no fonts, scripts or images from anyone else’s server. That is why there is no cookie banner.

Your browser’s own storage keeps three small flags for this site: your dark/light choice, whether you have already given an address on the download page (so it does not ask twice), and whether the page-load animation has played this visit. They never leave your device and we cannot read them.

The site is hosted by Vercel, which keeps standard server logs, including IP addresses, for security and abuse prevention. We do not use them to build a profile of you.

Sign-ups: the download page and “tell me” forms

The address form on /download, the forms at the foot of other pages, and the app’s “add a week” prompt when a trial ends all send us the same few things: your email address, where you heard about Lamplit if you pick an answer, which form you used, and whether you ticked the product-news box.

  • The address is stored in Airtable and added toLoops, the service that sends our email. Both are US companies.
  • By default we use it only to write to you about the thing you asked for: your trial, and when Lamplit can be downloaded. That mail is not marketing and you are not on any mailing list.
  • Product news is opt-in, and confirmed. The box is unticked. If you tick it, we send one email throughResend with a link; only pressing the button on the page it opens adds you to product news. Every such message has a one-click unsubscribe link.
  • If both Airtable and Loops fail, we email the address to our own inbox so it is not lost.
  • To stop the forms being abused we count sign-ups per connection using a one-way, secret-salted hash of your IP address, kept for up to two days. The address itself is not stored.

Kept for: twelve months from sign-up, then deleted unless you have bought a licence or confirmed product news; product news contacts are kept until you unsubscribe or ask us to delete them.

Licence checks

Licence keys are issued by Lemon Squeezy (a US company), which will also be the merchant of record when licences go on sale: it will hold your name, billing address and payment details under its own privacy policy, and we will not see your card.

  • Activating a key sends the key and a device label such as “Lamplit (macOS)” to Lemon Squeezy, which returns an instance ID for that computer. Your computer’s name is not sent. (Lamplit 0.3.0 and earlier sent the computer’s name as the label; updating replaces that.)
  • About once a day while the app can reach the internet, it sends the key and instance ID to Lemon Squeezy to check the licence is still valid, and to this website, which asks Lemon Squeezy the same question and returns a signed answer the app can trust offline. We do not store the key: our logs keep at most the first few characters of a one-way hash of it.
  • Both services see your IP address, as any server you connect to does.

Update checks

Each time it starts, Lamplit asks this website whether there is a newer version. That request is answered from files hosted onGitHub (a US company), so Vercel and GitHub see your IP address and the request headers, which include the app’s version. Nothing else is sent.

Place names and maps

Lamplit names places from an atlas built into the app, which works offline. On top of that, unless you switch off “Online place lookups” in Settings, the Location dialog uses two free services built on OpenStreetMap data:

  • When the dialog shows a pin — a photo’s own GPS position, or one you drop — the pin’s coordinates are sent to Nominatim(nominatim.openstreetmap.org, run by the OpenStreetMap Foundation in the UK) to look up the place name.
  • When you type in the dialog’s search box, what you type and the centre of the map (to rank nearby results first) are sent toPhoton (photon.komoot.io, run by komoot in Germany).

Whenever the Location dialog shows a map, it loads map tiles fromOpenFreeMap (tiles.openfreemap.org), whatever that setting says. The tiles it asks for show which area you are looking at, which starts at the photo’s position when it has one.

Each of these services also sees your IP address and the app’s name and version. Nothing is sent to them unless you open the Location dialog; no image, filename or folder name is ever sent; none of it passes through us; and you can point the two lookups at other servers in Settings.

Usage pings, crash reports and feedback

Every build of the app can send three things to this website. Nothing is sent until a notice explaining it has been on your screen, and the first two can be switched off in the app.

A usage ping, once per install per twenty hours or so. It contains: a random install ID generated on your machine, the app and build version, your platform, OS version and processor architecture, when this install first ran and how many days ago that was, and a set of counters accumulated since the last ping — sessions, folders opened, photos scanned, largest folder, photos rated, photos coloured, photos exported, exports, seconds in the app, the camera model strings your files came from, and the file extensions you opened. That is the whole list; anything else in a request is discarded.

A crash report, sent at the next launch after a crash — never from inside one. It is the same fields as a ping without the counters, plus when the crash happened, whether it came from the Rust or JavaScript side, the error message, the source file and line inside Lamplit that produced it, and the version that crashed. File paths are removed from the message by the app before it is saved, and again by this website before it is stored. (Lamplit 0.3.0 and earlier did not remove them in the app; this website removes them from every report it receives, whichever version sent it.)

Feedback, only when you press Send. Your message, the kind you chose, and the address you typed if you typed one. Whether the diagnostics above ride along is a checkbox you control; with it off we get your message, the install ID and the app version, and nothing about your machine.

What is never sent

  • No file paths, folder names or filenames. Folder names carry client names, and this is the rule the whole design bends around.
  • No image data, no thumbnails, and no EXIF beyond the camera model string.
  • Nothing you typed into a photo — captions, IPTC fields, or the content of a rating.
  • No device fingerprint and no third-party analytics of any kind. There is no Google Analytics, no Sentry, no product-analytics SDK in the app or on this site.

The install ID is 128 random bits made on your machine. It is not derived from your hardware, your account or your address, it means nothing anywhere else, and it exists so that two pings from the same copy of Lamplit can be recognised as one install rather than two.

The off switch, and where it all goes

Pings and crash reports are off unless you turn them on: the box in the app’s first-run notice starts unticked, and the switch in Settings turns both on or off. (In Lamplit 0.3.0 and earlier that box started ticked; your saved choice carries over, so check Settings if you are not sure.) Feedback is unaffected by that switch, because pressing Send is an explicit act each time.

The rows land in a Neon Postgres database (a US company), and each feedback report is also emailed to our inbox throughResend. None of it is sold, rented or shared.

Your IP address is not stored with any of this. To stop these endpoints being flooded we keep a counter against a one-way, secret-salted hash of the address for up to two days, in its own table, never alongside your telemetry.

Kept for: pings and crash reports about thirteen months, feedback two years, then deleted automatically. To have them deleted sooner, email us your install ID — the app shows it under “What gets sent” in the feedback dialog — and every row carrying it goes.

When you email us, and the mail we receive

Mail sent to hello@lamplitphoto.com is forwarded by ImprovMX to our inbox, which is aGmail account, so Google holds it too. Notifications this site sends us — feedback reports, and a sign-up we could not store — arrive in that same Gmail inbox. Mail we send comes from this domain through Resend, or through Loops for sign-up mail.

Everyone who receives something

  • Vercel — hosts this site and its functions; server logs.
  • Neon — database for pings, crash reports, feedback and rate-limit counters.
  • Airtable — sign-up records.
  • Loops — sign-up contacts and the mail sent to them.
  • Resend — confirmation mail and notifications to us.
  • ImprovMX and Google (Gmail) — our inbox.
  • Lemon Squeezy — licence keys, activations and, later, checkout.
  • GitHub — hosts the update files.
  • OpenStreetMap Foundation (Nominatim),komoot (Photon) and OpenFreeMap — place names and map tiles, directly from the app.

We do not sell your details, rent them, or share them with anyone else.

Children

Lamplit is a professional tool and is not directed at children. We do not knowingly collect information from anyone under 16.

Your rights, and deletion

Wherever you live, you can ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted. Write to hello@lamplitphoto.com from the address you signed up with, or include your install ID for telemetry. We delete it from Airtable, Loops and our database, and tell you when it is done. Licence and purchase records held by Lemon Squeezy can be removed through them, and we will help.

Changes

If this policy changes materially, the date at the top changes, and anyone who confirmed product news is told. We will not quietly broaden what we collect and rely on you re-reading this page.