Privacy Policy
Why Led Light
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Why Led Light stores campaign progress, lamp settings, undo history, unfinished scenes, language and accessibility preferences, and named creations with their cover images on your device. Names of creations are not uploaded. Online daily scenes create an automatic installation identifier and a random secret stored in your device Keychain; the server stores a hash of that secret, the identifier and creation time. The server records which daily scene was issued, its date and issue time, and reported completion attempts and completion time. Requests also reach Railway hosting infrastructure, which processes network information such as IP addresses and operational request metadata. The application uses a transport address temporarily in memory for request limiting, without storing it in the application database. The app does not request your name, email, location, contacts or an account.
How we use information
Local information lets you continue a puzzle, undo moves, keep an album and remember preferences. The installation secret authorizes access to this installation's daily-scene records and deletion. Server records preserve issued daily scenes, accept idempotent completion reports and allow aggregate completion counts from real results. Network and operational information is used to provide the HTTPS service, limit abuse, diagnose failures and maintain availability. Campaign and free theatre work offline; online daily scenes are optional and have a labelled local fallback.
Service providers and sharing
The backend and its persistent SQLite database are hosted by Railway. Railway receives traffic and infrastructure information as the hosting provider. The app has no advertising, analytics SDK, third-party sign-in, email delivery or social-sharing integration. Local creations are not sent to the server. Application logs contain startup events or random request identifiers for failures, without installation secrets or request bodies. Infrastructure logs are controlled by Railway and deployment settings. We do not sell personal information or share it with advertisers.
Data retention
Device progress, creations, covers, cached daily masks and preferences remain until you erase the relevant local data or remove it through device storage controls. The installation secret remains in Keychain until successful server-data deletion; removing the app may not remove Keychain information. Active server installation, issued-scene and completion records remain until deletion is requested. The application does not implement a fixed automatic expiry period. Request-limiting entries are temporary process-memory state and expire during use or when the process restarts. Hosting log retention is governed by Railway and deployment settings; we do not promise a duration that has not been verified. No separate backup service or scheduled backup is configured by this application.
Deleting your information
Settings provides Erase local progress, which removes local progress, saved creations, covers and cached daily masks; it does not delete server records. Delete my server data sends an authorized deletion request using this installation's secret, removes its active installation and daily-scene records, and revokes the secret. After a successful response the app removes the Keychain secret, daily cache and pending completion reports. If the network request fails, the secret is retained so you can retry. A new secret is created if online daily scenes are used again. Without the original secret the app cannot recover or authenticate deletion of an old installation. Infrastructure logs and any operator-enabled snapshots are separate from the active database; the application cannot guarantee immediate removal from those copies. If a snapshot is restored, any known deletion request must be applied again before its data is used.
Permissions and your choices
The app requests no camera, photo-library, microphone, location, contacts, tracking or notification permissions. No permission is needed for local play or the private album. You can avoid online daily-scene use and continue with the offline campaign, free theatre and a local daily fallback when networking is unavailable. Device network settings control network access. Changes to sound, language, control size and reduced motion are available in Settings.
Your privacy rights
You can inspect your local album and progress, delete creations, erase local progress and request deletion of server records directly in Settings. For privacy questions or requests concerning access, correction or deletion, contact Hyacinth8Grestham@icloud.com. Applicable rights depend on your location. Do not include your installation secret in email. The operator may need information sufficient to locate and verify a request because the app has no account, email identifier or cross-device recovery system.
Security
Online requests use HTTPS. Each installation receives its own cryptographically random secret, stored in device Keychain with device-only accessibility; only its SHA-256 hash is stored on the server. The server checks authorization for daily scenes, issued masks, completion and deletion, and isolates records by installation. Local progress and cover writes use iOS file protection and atomic writes where applicable. Input validation, request limits and bounded request bodies reduce abuse. Public home and privacy pages require no login or cookies. No transmission or storage mechanism can guarantee absolute security.
Children’s privacy
Why Led Light is intended for puzzle players aged 12 and above and is not designed to collect identifying information from children. There are no accounts, advertising or purchases. A parent or guardian concerned about a child's installation data may use the app's deletion controls or contact Hyacinth8Grestham@icloud.com. Online daily scenes still create the limited installation and network records described in this policy.
Changes to this policy
This policy may change if the app's data practices or hosting change. The current policy is published on this page with its effective date and is linked from app Settings. Material changes will be reflected in the policy and, when appropriate, communicated in an app update. The contact address for privacy questions is Hyacinth8Grestham@icloud.com.