Privacy Policy
What data rulepack collects, why, and your choices.
Last updated: 2026-05-31
This Privacy Policy explains how Lyrra ("we", "us") handles personal data when you use rulepack (the website, registry API, and CLI). We aim to collect only what the Service needs to work.
What we collect
When you sign in (GitHub OAuth):
- Your GitHub login (username), email, display name, and avatar URL, as provided by GitHub.
- A session and the API tokens you create for the CLI (stored as hashes, not plaintext).
- Your preferences (UI language, theme) and the scope you claim.
When you publish or browse:
- Packs you publish — names, versions, metadata, and file contents — which are public.
- Aggregate, fire-and-forget events: download and page-view counts per pack. We do not build advertising profiles.
Automatically:
- Standard server logs (IP address, user agent, timestamps) for security, abuse prevention, and debugging.
We do not use third-party advertising or analytics trackers.
How we use it
- To operate the Service: authenticate you, attribute and serve your packs, run search, and show download/view counts.
- To secure the Service: detect and prevent abuse, and meet legal obligations.
Hosting and third parties
We self-host the Service. Our database and search index run on our own infrastructure — they are not third-party services and are not publicly exposed. The third parties actually involved are:
- GitHub — you sign in with GitHub, which provides your profile data. Your use of GitHub is governed by GitHub's own policies.
- Hosting / network providers — the server host that runs our infrastructure and Cloudflare (network/CDN) process data only as needed to deliver the Service.
Public pack content is, by design, visible to everyone. We do not sell your personal data or use third-party advertising trackers.
Retention
- Account data is kept while your account exists.
- Published versions are immutable and public and may remain available even after account changes, because others may depend on them.
- Logs are kept for a limited period for security and operations.
Your choices and rights
- Update your name, language, and theme in Settings; rename or manage your scope there too.
- Revoke CLI tokens at any time in Settings → Tokens.
- Request access to, correction of, or deletion of your personal account data by contacting us. Note that public published versions generally cannot be unpublished, since the registry's immutability is what consumers rely on; contact us if a version contains data that must be removed.
International users
The Service is operated from Japan; using it means your data may be processed there. Where local law (e.g. GDPR) grants additional rights, we honour applicable requests.
Children
The Service is not directed to children under the age required to consent to data processing in their jurisdiction.
Changes
We may update this Policy; material changes are reflected here with a new "last updated" date.
Contact
Privacy questions or requests: [email protected].
Last updated on