Privacy Policy
This policy describes the data actually handled by Gothic Lock Solver.
Operator
Service operator: Mateusz Szydłowski
Contact: gothic-lock-solver.oblivious024@passfwd.com
No accounts or tracking
Gothic Lock Solver does not require user accounts and does not use cookies, analytics tools, advertising, or profiling mechanisms. The application does not require personal data and does not create user profiles. The hosting provider may process technical connection data required to operate and secure the service.
Solver input
The solver processes lock configuration data: plate count, positions, dependencies, and target state. This information is used to calculate a solution and should not contain personal data.
Completion statistics, feedback, and chest catalog
The official chest catalog is stored in the versioned data/chests.json file and is read-only for public users of the website.
Player chest suggestions are sent from the backend to a Formspree moderation endpoint. The suggestion form does not require contact details and should not include personal contact data.
Suggestions are used only for moderation and possible preparation of an approved entry in the official catalog. They are not stored in the application's production SQLite database.
On Render Free, runtime SQLite stores temporary operational data (completion deduplication records, voluntary feedback, and wrong-marker reports). This runtime data is ephemeral and may disappear after restart, redeploy, or environment reset.
Technical data and logs
The application does not write raw IP addresses or User-Agent values to its database or application access logs. To prevent overload, an incoming IP address is used to create a secret-keyed one-way rate-limit identifier. In the current configuration, this identifier is kept only in process memory for the duration of the relevant rate-limit window (up to 60 minutes) and is automatically removed after expiry during request handling; it also disappears completely when the process restarts. Render and its network providers may independently process IP addresses, request times, paths, headers, and diagnostic or security logs under their own policies and retention settings.
Infrastructure
The included deployment configuration is prepared for Render. Render acts as the infrastructure provider, terminates encrypted HTTPS connections, and provides edge DDoS protection using its network providers. Render may independently process technical connection and operational data under its own privacy policy and retention rules. The application does not control retention of Render infrastructure logs. The application does not embed an additional analytics or tracking service.
External links
Buy Me a Coffee is an external service. Its own privacy rules apply after a user follows an external link. No external widget, iframe, or marketing script is embedded by this application.
Contact and changes
Privacy questions or requests can be sent to gothic-lock-solver.oblivious024@passfwd.com. This policy may be updated when the service, hosting, or data handling changes.