Privacy Policy
Scope and who is responsible
This Privacy Policy explains what personal data Ludora processes when you use the Ludora website at ludora.studio, the hosted apps at apps.ludora.studio and their app subdomains, and the Ludora API and desktop build service.
The data controller is the operator of Ludora, reachable at contact@ludora.studio. This policy sits alongside our Terms of Service.
It does not cover the Ludora desktop application once it runs on your own machine — that build stores your projects locally on your computer and does not send them to us — nor third-party websites you reach from links on our pages.
Short version
- We collect the minimum needed to run accounts and store your projects.
- We do not sell or rent personal data, we run no advertising, and we allow no third-party ad or profiling trackers on our pages.
- We do not use your projects or files to train machine-learning models.
- Analytics are self-hosted and aggregate — no cross-site tracking of individuals.
- You can export your work and delete your account at any time.
What we collect
Account data
If you create an account: your email address, the name (and optionally first/last name) you provide, and a securely hashed password when you sign up with email and password. We also store your account's creation date, its role (regular user or administrator), whether it has been restricted, and which sign-in methods are linked to it. We never store your password in readable form.
Sign-in and session data
When you sign in we create a session and store a session identifier in a cookie, together with the session's creation and expiry times. Requests to the API may be authenticated with an API key you generate; we store the key's identifier so it can be verified and revoked.
Your content
The projects and files you create, import or save through the hosted apps — sprites, images, audio, notes, documents, code, project metadata and per-app settings — are stored on our servers so you can get them back on your next visit. We treat them as yours; see section 5 of the Terms.
Technical and log data
Our web servers record ordinary request logs: IP address, date and time, the URL requested, HTTP status, referrer, and browser user-agent string. Application logs may record errors and security-relevant events such as failed sign-ins, blocked cross-origin requests or rate-limited traffic. We use these to keep the Service running and to investigate abuse and incidents.
Preferences
Your language choice and light/dark theme choice, stored in your browser and — for language — in a cookie so the setting carries across ludora.studio and the app subdomains.
Build requests
When you use the custom desktop builder, we process the apps and platform you selected, plus the build's status and logs, and we temporarily store the resulting download.
Messages you send us
If you email us, we keep the message and your address so we can answer and, where relevant, keep a record of the request.
We do not ask for and do not want special-category data (health, political opinions, biometrics and similar). Please do not put such data in project names or files.
Why we use it, and our legal bases
Under the GDPR, we rely on the following bases:
- Performance of a contract (Art. 6(1)(b)) — creating and managing your account, authenticating you, storing and serving your projects, producing exports and builds you request, and answering your support requests.
- Legitimate interests (Art. 6(1)(f)) — keeping the Service secure and available, preventing abuse, fraud and overload, debugging, and measuring overall usage in aggregate so we know which parts of the Service are worth maintaining. We limit what we collect for these purposes and do not build profiles of individuals.
- Consent (Art. 6(1)(a)) — where we ask for it explicitly, for anything not covered above. You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — responding to valid legal requests and keeping records we are required to keep.
We do not carry out automated decision-making that produces legal effects for you.
Analytics
We measure traffic with Umami, an open-source analytics tool that we host ourselves at studio.godaas.org. Data is not sent to an advertising network.
Umami collects aggregate page views and a small number of interaction events (for example: which navigation link or call-to-action was clicked, and language or theme switches). It records the page URL, referrer, approximate country derived from the IP address, and coarse device, browser and screen-size categories. It does not set tracking cookies and does not follow you across other websites.
Analytics of this kind rely on our legitimate interest in understanding how the Service is used. If your browser blocks the analytics script, the rest of the Service continues to work normally.
Web fonts. Our stylesheet currently loads the Manrope typeface from Google Fonts (fonts.googleapis.com). Your browser therefore contacts Google to fetch the font files, which discloses your IP address and user-agent to Google under Google's privacy policy. We do not send Google any other information about you.
Signing in with Google, GitHub, GitLab or Discord
If you choose to sign in with a third-party provider, you are redirected to that provider, which authenticates you and asks for your permission. We then receive a limited profile from it — typically your provider account identifier, your email address, your name, and whether the provider considers the email verified — and we store it to create or match your Ludora account and to link the sign-in method.
We never receive your password for that provider, and we do not post anything to your account there. Using a social sign-in also means that provider knows you signed in to Ludora; their handling of that is governed by their own privacy policy. You can remove a linked provider or delete your Ludora account at any time.
Where your data is stored
Accounts and project data are stored on servers we operate in the European Union. Some limited processing may involve providers outside the EU/EEA — for example when your browser fetches a web font. Where that happens, we rely on the safeguards the GDPR allows, such as an adequacy decision or the European Commission's standard contractual clauses.
How long we keep it
- Account data — for as long as your account exists. When you delete your account, the account record, its sessions and its linked social sign-ins are deleted.
- Your projects and files — until you delete them or delete your account. Copies may persist in operational backups for a limited period before those expire.
- Sessions — until they expire or you sign out.
- Server and security logs — normally up to 12 months, and shorter where possible; longer only if an ongoing security investigation or a legal obligation requires it.
- Analytics — kept in aggregate form, without account identifiers.
- Build artefacts — deleted shortly after the build completes or expires.
- Emails to us — as long as needed to handle the request and to keep a reasonable record of it.
Deletion is not always instantaneous: it can take a short period to propagate through caches and backups.
Security
We serve everything over HTTPS, store passwords only as salted hashes, mark session cookies HttpOnly, restrict which origins may call the API, and limit administrative access to accounts that need it. Access to hosted apps is checked per user.
No online service can promise perfect security. If we become aware of a personal-data breach that is likely to present a risk to you, we will notify the competent supervisory authority and, where required, you — as the GDPR provides. If you find a vulnerability, please report it privately to contact@ludora.studio rather than disclosing it publicly.
Your rights
If the GDPR applies to you, you have the right to:
- access the personal data we hold about you, and get a copy;
- have inaccurate data corrected;
- have your data erased — deleting your account is the fastest route;
- restrict or object to processing based on our legitimate interests;
- receive your data in a portable form (you can also export your projects from the apps at any time);
- withdraw consent, where processing was based on consent.
To exercise any of these, email contact@ludora.studio from the address on your account. We answer within one month; if a request is complex we will tell you and may take up to two further months. We may need to verify your identity before acting on a request.
You also have the right to lodge a complaint with a data-protection authority — in France the CNIL, or the authority of your country of residence.
Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data without the consent of a parent or guardian. If you believe a child has created an account without that consent, contact us and we will delete it.
Changes to this policy
We will update this page when our practices or the applicable rules change. The current version and its “last updated” date are always published here, and we will announce material changes on the website before they take effect.
Contact
Privacy questions, data requests and breach reports: contact@ludora.studio.
See also our Terms of Service.