UNOFFICIAL FAN-MADE TOOL

Gothic Lock Solver

Configure the mechanism and find a shortest path to opening the lock.

← Back to solver

Privacy Policy

This policy describes the data actually handled by Gothic Lock Solver.

Operator

Service operator: Mateusz Szydłowski

Contact: gothic-lock-solver.oblivious024@passfwd.com

No accounts or tracking

Gothic Lock Solver does not require user accounts and does not use cookies, analytics tools, advertising, or profiling mechanisms. The application does not require personal data and does not create user profiles. The hosting provider may process technical connection data required to operate and secure the service.

Solver input

The solver processes lock configuration data: plate count, positions, dependencies, and target state. This information is used to calculate a solution and should not contain personal data.

Completion statistics, feedback, and chest catalog

The official chest catalog is stored in the versioned data/chests.json file and is read-only for public users of the website.

Player chest suggestions are sent from the backend to a Formspree moderation endpoint. The suggestion form does not require contact details and should not include personal contact data.

Suggestions are used only for moderation and possible preparation of an approved entry in the official catalog. They are not stored in the application's production SQLite database.

On Render Free, runtime SQLite stores temporary operational data (completion deduplication records, voluntary feedback, and wrong-marker reports). This runtime data is ephemeral and may disappear after restart, redeploy, or environment reset.

Technical data and logs

The application does not write raw IP addresses or User-Agent values to its database or application access logs. To prevent overload, an incoming IP address is used to create a secret-keyed one-way rate-limit identifier. In the current configuration, this identifier is kept only in process memory for the duration of the relevant rate-limit window (up to 60 minutes) and is automatically removed after expiry during request handling; it also disappears completely when the process restarts. Render and its network providers may independently process IP addresses, request times, paths, headers, and diagnostic or security logs under their own policies and retention settings.

Infrastructure

The included deployment configuration is prepared for Render. Render acts as the infrastructure provider, terminates encrypted HTTPS connections, and provides edge DDoS protection using its network providers. Render may independently process technical connection and operational data under its own privacy policy and retention rules. The application does not control retention of Render infrastructure logs. The application does not embed an additional analytics or tracking service.

External links

Buy Me a Coffee is an external service. Its own privacy rules apply after a user follows an external link. No external widget, iframe, or marketing script is embedded by this application.