Skip to content

Privacy Policy

What Lanpage stores when you use the product, why, where it lives and how to get it removed. It covers Lanpage.co itself, not the sites our customers publish — those are governed by policies their owners write.

Who we are

Lanpage is a service that publishes the web pages a mobile app needs in order to ship: a landing page, a privacy policy, terms, support and data deletion pages. Write to support@lanpage.co about anything in this document, from the address on your account.

Two different roles, and this policy is one of them

For your account and the content you write, we decide what is collected and why, and this policy is the whole answer. For the addresses your visitors submit to an email capture block, you decide and we only hold them for you — that role has its own document, the Data Processing Terms, because the obligations are not the same.

What we store about you

Your name, your email address and a hashed password when you create an account; the content you write for your apps and the images you upload; the record of your subscription and which plan it is; and the emails you send us for support. We also keep server logs containing IP addresses and request paths for a short period, to operate the service and to see an attack while it is happening.

Why we store it

To run the account you asked for, to serve the sites you publish, to take payment and keep the records an invoice requires, to answer you when you write, and to keep the service secure and available. We do not build profiles, we do not run advertising, and we do not use your content or your visitors' addresses to train models — ours or anyone else's. We count page views on a server we operate ourselves, and that is the whole of it: no third-party analytics, no session recording, no heatmaps, no A/B testing, and no company on the receiving end of the counts.

The legal basis for each of these

Where the law you live under asks us to name one, this is it. Running your account, serving the sites you publish and taking payment are the performance of the agreement between us: without them there is no product to give you. Keeping billing records is a legal obligation neither we nor Paddle can waive. Keeping the service secure and available, and answering you when you write, rest on our legitimate interest in operating it, which we have weighed against what you would expect from a tool that publishes pages on your behalf. Nothing here rests on your consent, which is why there is no consent banner and nothing that stops working if you were to withdraw one.

What we store on behalf of your visitors

If you enable the email capture block, the addresses your visitors submit are stored against your app and are visible only to you. You decide what to do with them; we never email them ourselves. You can export or delete them at any time from your app settings, and the Acceptable Use Policy says what you may do with them. We also count how many times each page of your published site is opened, and show you the result. Those counts hold nothing about the people who did the opening: no address, no device, no identifier, and no row that describes a visit — only how many, of which page, on which day, in which language and from what kind of place.

Who processes it with us

Payments run through Paddle, the merchant of record. Transactional email is sent through Resend. Uploaded images are stored in Cloudflare R2. A hosting provider in the United States runs the application and the database. Counting page views adds nobody to this list, because the counter runs on a server we operate rather than a service somebody sells us. The Data Processing Terms list each one and what it can see. We do not sell data to anyone.

Where it is stored

The application and the database run on servers in the United States, and the providers above operate internationally. If you are somewhere else, using Lanpage means your data is transferred to and stored in a country whose data protection rules are not the ones you live under. What travels with it is the contract we have with each provider: those contracts include the European Commission's Standard Contractual Clauses, which is the mechanism the law provides for exactly this and the one every provider on our list offers. We say this plainly rather than burying it, because it is the kind of thing that decides whether a service is right for you.

Cookies

A session cookie so you stay signed in, and preference cookies remembering your language and whether you asked for the light or the dark interface. No advertising, no cross-site tracking. Page views are counted without putting anything in your browser at all. The Cookie Policy is the full list.

How long we keep it

Account data lives as long as your account does. Deleting an app removes its content and the addresses captured through it; closing your account removes everything associated with it, other than the billing records an invoice obliges us and Paddle to keep, which is as long as tax law requires and can be up to ten years. Server logs rotate by size rather than by date: the container keeps its most recent few megabytes of output and drops the rest as it writes, so how long a request line survives depends on how much traffic follows it, and nothing archives them anywhere else. Backups are taken nightly and pruned after 14 days, so something you deleted can survive in one for up to that long before it is gone for good. Those backups are for recovering from a failure of ours; we do not restore an individual account, app or document from one, which is the other half of a deletion actually meaning deletion.

How we protect it

Everything is served over HTTPS. Passwords are stored hashed and never in a form we could read. The dashboard and the private preview are served with no-store and are never indexed, and every query for private data is filtered by the account that owns it. No system is immune, and if data of yours is exposed we will tell you what happened, what we know and what we are doing about it, without waiting until we have a complete answer.

Your choices

You can ask for a copy of what we hold, correct anything wrong, export your captured addresses, delete an app, and close your account and have the data erased. You can also ask us to restrict what we do with it while a question about it is open, object to a use that rests on our legitimate interest, and have what you gave us handed to you in a form another service can read. Write from the address on the account and we will act on it within 30 days. If we cannot tell that a request is really yours we will ask for something more before acting, because handing your data to somebody impersonating you would be the worse mistake. A request that repeats one we have already answered, or that is plainly not about your own data, we may decline — and we will say which and why rather than going quiet. If you think we have handled your data badly, tell us first, and you can also complain to the data protection authority of the country you live in.

When somebody else asks us for your data

Courts, regulators and police occasionally ask a service provider for what it holds about a customer. We hand over data only where we are legally required to, we ask for the actual legal process rather than an email that sounds official, and we give the narrowest thing that answers the request rather than everything we have. We will tell you it happened, so you can do something about it, unless we are legally forbidden from telling you — and where a gag has a time limit, we tell you when it lifts.

Children

Lanpage is a tool for people shipping software and it is not aimed at children. We do not knowingly keep an account for someone below the age at which they could agree to this on their own; if we learn that we have, we close it and delete the data.

Changes

If this policy changes we publish the new version with a new effective date, and for anything material we tell account holders by email rather than expecting them to notice.

Effective date: 2026-09-10