Privacy policy
Last updated: 2026-09-18
This website sells and delivers LGM-OS licences. Here is, plainly, what is kept about you, why, who it is shared with and what you can ask for at any time.
Your NAS does not pass through here. Your files, your photos, your cameras and your backups stay on your own machine, at home. LGM-OS works with this website switched off: the licence is checked inside the machine itself.
What is kept about you
From your account
- Your email address. It is how you sign in, and what your licences are tied to.
- Your password, hashed (bcrypt). The password as you type it is not stored anywhere and cannot be recovered: neither you nor we can ever read it again.
- If you switch on two-step verification: the secret you share with your authenticator app, and the fingerprints of your recovery codes. The recovery codes themselves are not stored, which is why they are shown only once.
- If you add a passkey (a device's face, fingerprint or PIN): that device's public key, its identifier, the name you give it and when it was last used. A public key opens nothing: whoever took that table could not sign in with it.
From your licences
- The signed key, the plan, whether it is active or revoked, and the dates.
- The identifier of the purchase that paid for it, which is what stops two licences from being issued for the same payment.
From your NAS, if you activate a licence on it
- A machine fingerprint: a digest the NAS works out on its own, with nothing personal inside. It only tells «the same machine again» from «a different machine», because each licence is good for one.
- The name you gave the machine.
- Every twelve hours, while it is switched on: the LGM-OS version it runs, when it was last seen, total and free space, how many alerts are pending, whether the LGM Connect tunnel is running, the fingerprint of its panel's certificate and your local network addresses with their port.
And that is everything the machine reports. No file names, no folders, no user accounts, nothing about what you do with it. It is what lets your account tell you «1.68.0 · seen 3 h ago · 2.1 TB free» without opening the panel, and what tells us which version each machine runs without having to ask anyone.
From LGM Connect, if you use it
The name you chose for your address, the identifier of the tunnel that reaches your home and the last time your NAS asked for its token. If you do not use LGM Connect, none of this exists.
From running the shop
Everything done from the admin side —issuing a licence, revoking it, deleting it, releasing a machine— leaves one line with the date, who did it, a short detail and the IP address it was done from. It is what answers «who did this, and when?» the day there is a question about a purchase.
While you sign in
So that nobody can try passwords in bulk, the server counts attempts per IP address and per account. That count lives in the server's memory, clears itself within minutes and never reaches any database.
What is not kept
- Your password in the clear. Never.
- Your card. The payment screen belongs to Polar and lives on their domain: card numbers never pass through this server, not for an instant.
- Your files. They stay on your machine.
- No profiles, no advertising, no data sold to anyone. That business does not exist here.
Your email is not used to write to you either: this website sends no email at all. There is no newsletter and no email alerts, so there is nothing to unsubscribe from.
Who it is shared with
- Polar (polar.sh), the shop. It is the merchant of record for the licence, so it is Polar who charges you and who declares and pays the VAT of your country. Your email and an internal number for your account are sent, so the payment can be tied to it; Polar sends back word that it is paid. Your card details are theirs and never ours.
- Cloudflare, only if you switch on LGM Connect. Your NAS's public address and the tunnel that reaches your home are created there, so the traffic coming in through that address goes over their network. Without LGM Connect, Cloudflare plays no part.
- GitHub. The large downloads —the installation image, the update packages and the LGM Connect apps— are served from there. When you press «Download», your browser goes to GitHub and GitHub sees that request.
- This website's hosting provider. The provider running this server records the requests in its own access log, like any server on the internet.
- Discord and Ko-fi are links to third-party pages. Nothing is sent to them from here; if you open them, their rules apply and not ours.
Visits to this website
Visits are measured here, with nobody in between: no cookies and no third-party service. What is kept are daily aggregate counts —which pages were viewed, where people arrive from, and whether it is a phone or a computer—, not people's visits. Your IP address is not stored, and if your browser asks not to be tracked (Do Not Track or the Global Privacy Control signal), nothing is counted at all.
Why it may be kept
- Because it is needed to give you what you bought: without an email there is no account, and without an account there is nowhere for your licences to live, nor any way to know they are yours.
- Because it is needed so this cannot be attacked: the attempt limits and the admin log are there for that and for nothing else.
- And because you switch it on, for everything optional: two-step verification, a passkey or LGM Connect only exist if you turn them on, and they turn off just as easily.
How long it is kept
- Your account and your licences, for as long as you have an account.
- The browser session, 30 days from the last time you use it.
- The admin log is kept: it is the memory of what happened to each licence.
- Cookies, each for its own lifetime. They are all listed, one by one, on the cookies page.
What you can do yourself, right now
Several things need no asking: you do them from My account and they take a second.
- Change your password, which also signs you out on every other device.
- Remove a passkey or switch off two-step verification.
- Release a licence from the machine holding it, to move it to another one.
Your rights
You can ask for access to your data, for it to be corrected, for it to be deleted, object to its use, and take it elsewhere.
For that, and to delete your account —this website has no button for it yet—, say so on the community, which is the contact channel there is.
And if you believe any of this is not being done properly, you can complain to the data protection authority of your country.
Children
This website is not meant for children under 14, and no data is requested knowing that it belongs to one.
If this changes
So does the date at the top, which is what it is there for. There is no email announcement for every tweak: this website sends no email.