Privacy Policy
Last updated: July 1, 2026
This Privacy Policy explains how Lynx handles personal data when you visit the website, contact Lynx, join early access, use the developer documentation, or integrate the Lynx API or SDK into a game.
Lynx is a lightweight community-event backend for indie games. It allows games to contribute to shared community events, sync event progress, and offer rewards when shared goals are reached.
Lynx is designed to collect as little personal data as reasonably possible.
1. Who operates Lynx?
Lynx is operated by:
Ádám Kormos
Hungary
Email: adam.kormos34@gmail.com
For privacy questions, data requests, or concerns, contact:
adam.kormos34@gmail.com
2. Scope of this Privacy Policy
This Privacy Policy applies to:
- the Lynx website
- the Lynx API
- the Lynx SDK
- the Lynx documentation
- early access communication
- developer support communication
- technical logs and service operation
This Privacy Policy does not apply to games made by third-party developers, even if those games integrate Lynx.
If you play a game that uses Lynx, the developer or publisher of that game is responsible for their own game, their own privacy policy, and their own player-facing data practices.
3. Important note for game developers
If you integrate Lynx into your game, you are responsible for explaining to your players how your game uses Lynx.
You should update your own game’s privacy policy if your game uses Lynx to send event progress, installation identifiers, reward claim state, technical request metadata, or other information to the Lynx API.
Do not send unnecessary personal data to Lynx.
In particular, do not send:
- player names
- player email addresses
- account passwords
- payment information
- chat messages
- precise location data
- government IDs
- health data
- sensitive personal data
- any data that is not required for the Lynx integration to work
Lynx is not designed to store direct player identities.
4. Information Lynx may collect
The information Lynx may process depends on how you use the service.
4.1 Website visitors
When you visit the Lynx website, the hosting and infrastructure provider may process basic technical data such as:
- IP address
- browser type and version
- device type
- operating system
- requested URL
- referring page, if available
- date and time of the request
- approximate region derived from network information
- security, firewall, and performance logs
This data is used to deliver the website, protect it from abuse, diagnose technical problems, and maintain security.
4.2 Early access applicants and developer contacts
If you contact Lynx by email, Discord, GitHub, a form, or any other communication channel, Lynx may process:
- your name, if provided
- your email address
- your Discord username or display name, if provided
- your studio or project name, if provided
- your message content
- information about your game
- links you choose to share
- your communication history with Lynx
- technical or business details you voluntarily provide
This information is used to respond to you, evaluate early access requests, provide developer support, and keep track of communication.
4.3 Developers using Lynx
If you integrate Lynx into a game or test the API, Lynx may process developer-related technical information such as:
- game ID
- game display name
- developer or studio name
- developer contact email, if provided
- game key and game admin password credential metadata
- enabled or disabled game status
- subscription or access status
- relay IDs used by the game
- API request timestamps
- error logs
- security logs
- support communication
- integration notes shared by the developer
Game keys, game admin passwords, and admin keys should be treated as credentials. Game Admin Passwords and admin keys must not be included in public builds or client-side code.
4.4 End users / players of games using Lynx
Lynx does not require player accounts.
When a game uses the Lynx SDK or API, Lynx may process limited pseudonymous technical and gameplay-event data, such as:
- installation ID or similar pseudonymous identifier
- installation token or token metadata
- game ID
- relay ID
- relay progress
- increment amount
- sync state
- reward claim availability
- reward claim acknowledgement state
- local claimed version or server completion version
- request timestamps
- idempotency keys
- API error information
- abuse-prevention and security metadata
This data is used to make shared events and reward claim logic work.
Lynx does not intentionally collect direct player identity information such as player names, email addresses, or account profiles.
4.5 API and security logs
For security, debugging, abuse prevention, and service reliability, Lynx may process logs that include:
- IP address
- request method
- requested endpoint
- response status
- timestamp
- user agent
- game ID
- relay ID
- error details
- rate-limit or abuse-prevention signals
- Cloudflare security and performance metadata
These logs are used to detect errors, prevent abuse, protect the service, investigate incidents, and improve reliability.
5. How Lynx uses information
Lynx uses information for the following purposes:
- to operate the website
- to provide the API and SDK functionality
- to process shared event progress
- to sync relay state
- to create and validate reward claim state
- to prevent duplicate or fraudulent reward claims
- to prevent abuse, spam, and attacks
- to debug technical problems
- to improve the developer experience
- to respond to early access requests
- to provide developer support
- to manage game access and credentials
- to maintain security and service integrity
- to comply with legal obligations, where applicable
6. Legal bases for processing
Where GDPR or similar laws apply, Lynx relies on the following legal bases.
6.1 Legitimate interests
Lynx may process technical, security, API, and operational data based on legitimate interests, including:
- operating the service
- securing the website and API
- preventing abuse
- debugging errors
- improving reliability
- maintaining developer integrations
- protecting the integrity of relay progress and reward claim flows
6.2 Contract or pre-contractual steps
Lynx may process developer contact and early access data when it is necessary to:
- respond to your request
- evaluate an early access application
- provide access to the service
- provide developer support
- manage an integration relationship
6.3 Consent
Lynx may rely on consent where you voluntarily provide optional information, join a Discord server, subscribe to a future mailing list, or agree to optional communications.
Where processing is based on consent, you may withdraw consent at any time.
6.4 Legal obligation
Lynx may process or retain information where necessary to comply with applicable legal obligations.
7. Cookies and local storage
The Lynx website currently does not use advertising cookies, tracking cookies, or third-party analytics cookies.
The website may use strictly necessary technical features required to load, secure, and deliver the site.
If Lynx later adds analytics, advertising, newsletter tools, embedded third-party widgets, or non-essential cookies, this Privacy Policy will be updated. Where required, consent will be requested before those tools are used.
8. Analytics
Lynx currently does not use third-party analytics on the website.
If analytics are added later, this section will be updated to explain:
- what analytics provider is used
- what data is collected
- why it is collected
- how long it is kept
- whether consent is required
- how users can opt out, where applicable
9. Hosting and infrastructure
Lynx uses Cloudflare services, including Cloudflare Pages and Cloudflare Workers, to host and operate the website and API.
Cloudflare may process technical data, request metadata, logs, and security information as part of providing hosting, security, networking, and performance services.
Cloudflare’s own privacy policy applies to Cloudflare’s processing of data as an infrastructure provider.
10. Communication providers
If you contact Lynx by email, your email provider and the recipient email provider may process message metadata and content.
If you join or contact Lynx through Discord, Discord may process your data according to Discord’s own terms and privacy policy.
If you interact with Lynx through GitHub or similar platforms, those platforms may process your data according to their own terms and privacy policies.
11. Data sharing
Lynx does not sell personal data.
Lynx may share or make data available only in limited situations:
- with hosting and infrastructure providers needed to operate the service
- with communication providers used to respond to you
- with service providers needed for security, debugging, or support
- if required by law, legal process, or valid authority request
- if necessary to protect Lynx, developers, users, or the public from abuse, fraud, or security threats
- with your permission or at your request
Lynx does not share developer contact information with other developers without permission.
12. Data retention
Lynx keeps personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Typical retention periods or criteria include:
- website and security logs: kept for a limited period as needed for security, debugging, and abuse prevention
- early access emails and developer communication: kept while the conversation, application, support issue, or developer relationship remains relevant
- game integration records: kept while the game has access to Lynx or while needed for operational records
- relay and event data: kept while the relay, event, or integration remains active or relevant
- installation and reward claim state: kept while needed to provide sync, claim, and anti-duplicate functionality
- legal or administrative records: kept as long as required by applicable law or legitimate operational needs
When data is no longer needed, Lynx will delete it, anonymize it, or retain it only in a form that no longer reasonably identifies a person.
13. Security
Lynx uses reasonable technical and organizational measures to protect the service and the data it processes.
These measures may include:
- HTTPS
- API authentication
- game admin passwords and admin tokens
- token hashing or encryption where appropriate
- access controls
- security logging
- rate limiting or abuse prevention
- infrastructure-level protection through Cloudflare
No online service can be guaranteed to be perfectly secure.
Developers are responsible for keeping their own credentials secure and for not exposing admin keys in public builds, repositories, screenshots, logs, or client-side code.
14. International transfers
Lynx uses online infrastructure and third-party providers that may process data in countries other than your own.
Where required, Lynx relies on appropriate safeguards used by its service providers for international transfers of personal data.
15. Your rights
Depending on where you live, you may have rights regarding your personal data.
These may include the right to:
- request access to your personal data
- request correction of inaccurate or incomplete data
- request deletion of your personal data
- object to certain processing
- request restriction of processing
- request a copy of your data
- withdraw consent where processing is based on consent
- lodge a complaint with a data protection authority
To make a request, contact:
adam.kormos34@gmail.com
Lynx may need to verify your identity before responding to certain requests.
Some data may not be deleted immediately if it must be kept for legal, security, abuse-prevention, or legitimate operational reasons.
16. Rights of players using games that integrate Lynx
If you are a player of a third-party game that uses Lynx, you should first contact the developer or publisher of that game for privacy requests related to your game data.
Lynx may not be able to identify you directly, because Lynx is designed to avoid player accounts and direct player identity data.
If you contact Lynx about data from a game integration, include enough information to help identify the relevant integration, such as:
- the game name
- the developer or publisher
- the approximate date of use
- any installation or support identifier shown by the game, if available
Do not send passwords, payment data, or unrelated personal information.
17. Children’s privacy
Lynx is a developer-facing service and is not intended to be used directly by children.
Lynx does not knowingly collect personal information from children.
Developers integrating Lynx into games are responsible for determining whether their own game is directed to children and for complying with any child privacy laws that apply to their game.
18. Automated decision-making
Lynx does not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.
Lynx may use technical checks to prevent abuse, validate API requests, prevent duplicate claims, or protect service integrity.
19. Do Not Track
Some browsers offer “Do Not Track” signals.
The Lynx website currently does not use third-party analytics or advertising tracking. Because there is no common industry standard for responding to Do Not Track signals, Lynx does not currently respond to them separately.
20. Changes to this Privacy Policy
This Privacy Policy may be updated as Lynx develops.
If material changes are made, the updated version will be posted on this page with a new “Last updated” date.
21. Contact
For privacy-related questions, requests, or concerns, contact:
adam.kormos34@gmail.com
