Privacy policy
Draft. Not yet in effect. This page names Lanternwright LLC (formation pending) as its operator. That company has not been formed yet, and the page has not been reviewed. It will be updated and confirmed before anything is sold.
Lanternwright makes software that keeps your data on your own device. This policy covers this website and, in one section per product, what each Lanternwright product handles.
The short version
- This website sets no cookies, runs no analytics or tracking, and loads nothing from other companies' servers.
- Lanternwright products are built to keep your data on your own device. Each product's section below lists what it keeps and every time it can use the network.
- Personal data is never sold, rented or used for advertising.
Who this policy is from
This policy is published by Lanternwright LLC (formation pending), which runs lanternwright.com and makes the products listed on it. You can reach it at support@lanternwright.com.
What this website collects
- Nothing, when you just browse. No cookies, no analytics, no fingerprinting and no third-party scripts, fonts or images.
- Standard request data that every web host receives (your IP address, browser type and the page requested). Cloudflare Pages (Cloudflare, Inc.) handles it to serve and protect the site.
- Your light or dark theme choice, only if you use the theme switch. It is saved in your own browser's storage, never sent anywhere, and you can clear it with your browser's site data.
- If you join a waitlist, you send an email from your own email app. Your address and message arrive in the studio's inbox like any other email.
- Anything you choose to send by email to support@lanternwright.com.
Services that handle data
These services process data for the website. Each one has its own privacy policy.
- Cloudflare Pages (Cloudflare, Inc.)
- Hosts and serves this website. Like any web host, it receives your IP address and browser details with each request. Its privacy policy.
- Cloudflare Email Routing (Cloudflare, Inc.)
- Receives email sent to support@lanternwright.com and delivers it to the studio's inbox.
How it is used
- Waitlist addresses: to send you one email when the product you chose launches. Nothing else is sent to them.
- Email you send: to read and answer it.
- Request data: so the host can deliver pages and keep the site secure.
How long it is kept
- Waitlist emails: until the launch email for that product is sent, then deleted, or sooner if you ask.
- Email you send: as long as needed to answer it, and deleted on request.
- Request data: kept by Cloudflare Pages (Cloudflare, Inc.) under its own policy. This site keeps no logs of its own.
Purchases
Nothing is sold yet. Before anything is, this policy will name the payment provider. It will take payment and handle card details; Lanternwright will receive only your email address and what you bought, to deliver your license and give support.
What is never done
- Selling or renting personal data.
- Advertising or ad tracking.
- Sharing data with data brokers.
- Sending email you did not ask for.
Products
Every product below is in development and not yet available, so none of them has collected anything yet. Each section describes the product as it is built today and will be checked again before that product launches.
Netkeep
Your sales, costs, receipts and trips stay in your browser's storage on your device. There is no account, no server, no analytics and no third-party script.
What it keeps on your device
- Sales, order lines, fees, refunds, shipping labels and marketplace-collected sales tax from the reports you import (only the columns Netkeep needs)
- Purchases, lots and items, with costs, sources, dates and statuses
- Receipt photos, re-encoded on save with location and camera data removed
- Expenses and trips (dates, purposes, places and miles)
- Your own fee and mileage rates, saved column layouts, import history and settings
- Your license, if you add one. It holds a one-way fingerprint of the email it was issued to, never the email itself.
What it never keeps
- Buyer names, usernames, emails, phone numbers and addresses found in marketplace reports. They are dropped before anything is saved.
When it uses the network
These are the only times Netkeep uses the network. Anything not listed here never leaves your device.
- Update check
- When: Off until you turn it on.
- What is sent: A plain request for one small file, about once a week or when you press Check now, with no cookies, no identifiers and none of your records. Like any web request, the host can see your IP address.
- Sent to: The Lanternwright update host.
What reaches Lanternwright
Nothing. Netkeep sends no data to Lanternwright.
Telemetry
None. Netkeep has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
Everything stays on your device until you delete it. Delete everything removes it all. Backups and exports are files you save and control.
Caption Glass
Audio is processed in memory on your PC and never written to disk or sent anywhere. Captions are saved only if you turn on history, and only on your PC.
What it keeps on your device
- Your settings and your license
- Caption history, only if you turn it on. It stays on your PC and expires automatically after the time you choose.
What it never keeps
- Audio from your microphone or from what your PC plays
When it uses the network
These are the only times Caption Glass uses the network. Anything not listed here never leaves your device.
- Speech model download
- When: Only when you ask for it.
- What is sent: A download request for the speech model you pick. The file is checked against a pinned checksum. Nothing about you or your audio is sent.
- Sent to: The host of that speech model.
- Dictation cleanup (Pro)
- When: Off until you turn it on.
- What is sent: Text you dictate, to be tidied before it is typed
- Sent to: A server you choose, on the same PC unless you explicitly allow another.
What reaches Lanternwright
Nothing. Caption Glass sends no data to Lanternwright.
Telemetry
None. Caption Glass has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
Caption history, if you turn it on, expires automatically and can be cleared at any time. Nothing else about your use is kept.
Counter
Everything stays on your device. No account, no server that receives your data, no analytics and no third-party code. Offer letters are never uploaded; you type the figures.
What it keeps on your device
- Your offers and current job as you typed them, your ask inputs and display preferences
- Settings, including your license code if you enter one. It holds a one-way fingerprint of the email it was issued to, never the email itself.
- Your private outcome log
What it never keeps
- What you type on the Practice page. It stays in the page's memory for that visit only.
When it uses the network
These are the only times Counter uses the network. Anything not listed here never leaves your device.
- Update check
- When: Not active in current builds.
- What is sent: In a build that has an update address, a plain request for one small file at most once a day, with no identifiers. It can be turned off in Settings.
- Sent to: The Lanternwright update host.
- Rewording with a local language model
- When: Off until you turn it on.
- What is sent: The text of one script and the model name
- Sent to: A model you run on your own device (only local addresses are accepted).
What reaches Lanternwright
Nothing. Counter sends no data to Lanternwright.
Telemetry
None. Counter has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
Everything stays in your browser until you delete it. Delete everything removes it all after a confirmation.
Kindstart
Your tasks, steps, notes and focus sessions stay in one file on your PC. There are no analytics, crash reports, ads or third-party SDKs.
What it keeps on your device
- Your tasks, steps, notes, lists, focus sessions, settings and routines, in one file on your PC
- Your Pro license, if you add one. It holds a one-way hash of the email used to buy it, never the address.
- Window positions and the time of the last update check
When it uses the network
These are the only times Kindstart uses the network. Anything not listed here never leaves your device.
- Update check
- When: On by default, and you can turn it off.
- What is sent: A request for the newest version number, with no identifiers. It never installs anything. It is explained on the first-run screen and turns off with one switch.
- Sent to: The Lanternwright update host.
- Try local AI (Pro)
- When: Off until you turn it on.
- What is sent: One task's title and notes, only when you press the button
- Sent to: The AI server you choose, such as Ollama, LM Studio or KoboldCpp on your own PC.
What reaches Lanternwright
Nothing. Kindstart sends no data to Lanternwright.
Telemetry
None. Kindstart has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
Everything stays on your PC until you delete it. Delete everything removes every task, step, session and setting, and uninstalling offers to remove the data folder.
Also worth knowing
- Kindstart has no fields for health information and never asks for any.
Readglass
Readglass works inside your browser and collects nothing. There is no account, no analytics, no tracking, no ads and no crash reporting.
What it keeps on your device
- Your settings: font, spacing, line focus, colors, theme, voice and speed, pronunciation dictionary, and the simplify address and model name
- Your list of sites set to always on or with their own settings
- Your profiles
- Your Pro license key, if you enter one. It holds a one-way hash of the email used to buy it, not the address.
What it never keeps
- Anything about the sites you visit in private windows
When it uses the network
These are the only times Readglass uses the network. Anything not listed here never leaves your device.
- Online read-aloud voices
- When: Off until you turn it on.
- What is sent: The text being read aloud. Your browser sends it to the voice's provider. Online voices are labeled and need a one-time opt-in.
- Sent to: The provider of the online voice you pick.
- Simplify a paragraph (Pro)
- When: Off until you turn it on.
- What is sent: The paragraph you pick, only when you ask
- Sent to: A language model server you run yourself or choose.
What reaches Lanternwright
Nothing. Readglass sends no data to Lanternwright.
Telemetry
None. Readglass has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
Everything is kept in your browser's extension storage until you reset it or remove the extension.
Prop Press
Nothing you make leaves your device. There is no account, analytics, telemetry, ads, crash reporting or remote fonts, and the page's security policy blocks every network connection.
What it keeps on your device
- Your current draft, images included, in your browser's storage
- Your theme and printing preferences
- Your license and any template packs you installed
When it uses the network
These are the only times Prop Press uses the network. Anything not listed here never leaves your device.
- Update check
- When: On by default, and you can turn it off.
- What is sent: Only in builds that include it: one small file at most once a day, with no cookies, referrer or identifiers. It is explained on first run, waits a day before its first check, and can be turned off.
- Sent to: The Lanternwright update host.
What reaches Lanternwright
Nothing. Prop Press sends no data to Lanternwright.
Telemetry
None. Prop Press has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
Kept in your browser until you remove it: Remove license, Remove pack, or clear the browser's site data.
Also worth knowing
- Project files, PNGs, PDFs and Foundry journals are made only when you click an export, and go wherever you save them.
Pacing Companion
Nothing you enter leaves your device unless you save or share a file yourself. The app has no account, no analytics and no third-party code, and it makes no network requests of its own.
What it keeps on your device
- Your check-ins: energy, symptoms, crash or flare marks and notes
- Your energy envelope plans and activity costs
- Your settings and your supporter code, if you add one
When it uses the network
Never. Pacing Companion makes no network requests of its own.
What reaches Lanternwright
Nothing. Pacing Companion sends no data to Lanternwright.
Telemetry
None. Pacing Companion has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
Kept on your device until you delete it. Delete everything removes it all.
Also worth knowing
- A separate consumer health data policy will be published on this site before Pacing Companion launches.
Shelfmend
Shelfmend runs on your computer, collects nothing, and sends nothing anywhere except to your own Audiobookshelf server, and only when you ask it to.
What it keeps on your device
- The config file, if you create one
- Plans, the undo journal and reports, in its state folder
- Quarantined copies, until you purge them
- metadata.json files in book folders, only when you apply an author or series plan to a folder library
What it never keeps
- Your Audiobookshelf API token in any file. It is read from an environment variable and never printed or logged.
When it uses the network
These are the only times Shelfmend uses the network. Anything not listed here never leaves your device.
- Audiobookshelf API mode
- When: Only when you ask for it.
- What is sent: Requests to read your libraries and, when you apply a plan, to edit metadata or remove duplicate records
- Sent to: Your own Audiobookshelf server, and no other address.
- Series name lookups
- When: Off until you turn it on.
- What is sent: Search terms only: a book title and an author
- Sent to: Your own Audiobookshelf server, which asks its metadata provider as it does for its own matching.
What reaches Lanternwright
Nothing. Shelfmend sends no data to Lanternwright.
Telemetry
None. Shelfmend has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
Everything is on your own disk. Delete the state and quarantine folders to remove it.
Also worth knowing
- Reports can contain folder and file names. A redact option replaces every path, title, name and ID before you share one.
Vault Herald
Vault Herald reads your files and writes plain files. No account, no server, no telemetry, and no network use at all.
What it keeps on your device
- Only the output it builds (the Foundry module and wiki folders), where you tell it to write them
When it uses the network
Never. Vault Herald makes no network requests of its own.
What reaches Lanternwright
Nothing. Vault Herald sends no data to Lanternwright.
Telemetry
None. Vault Herald has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
The output files are yours. Delete them whenever you like.
Thingstead
Thingstead runs on your machine, reads transcripts read-only, keeps its index in your home directory, and sends nothing anywhere until you set up a tracker, a digest destination, a hub or a language model command. Everything it sends passes one redaction gate first.
What it keeps on your device
- Its search index and settings, in your home directory
- Tracker tokens, digest secrets and the hub key, in your operating system's keychain or a private credentials file
- Your Pro license file, checked offline
What it never keeps
- Changes to your transcripts. They are opened read-only and never written, locked or renamed.
When it uses the network
These are the only times Thingstead uses the network. Anything not listed here never leaves your device.
- Tracker linking
- When: Off until you turn it on.
- What is sent: Links and new cards, written only after you confirm the exact redacted payload
- Sent to: The tracker you connect (GitHub Issues, Jira or Trello).
- Daily digest (Pro)
- When: Off until you turn it on.
- What is sent: A redacted summary of what your sessions did
- Sent to: The destination you set up, such as a Discord thread or an email address.
- Multi-machine hub (Pro)
- When: Off until you turn it on.
- What is sent: Redacted, signed session metadata
- Sent to: A hub you run yourself.
- Language model titles and summaries (Pro)
- When: Off until you turn it on.
- What is sent: Redacted session text, under a daily cost cap
- Sent to: Your own command or API key.
What reaches Lanternwright
Nothing. Thingstead sends no data to Lanternwright.
Telemetry
None. Thingstead has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
The index lives on your machine until you delete it. Rebuilding it re-reads your transcripts.
Also worth knowing
- Redaction is best-effort. Sessions you mark private never leave the machine.
Mimir
Mimir runs on your computer and transcribes speech there. There is no Mimir account or server, no telemetry, and the license is checked on your PC. Nothing about your game leaves your computer unless you turn on a feature that says it does.
What it keeps on your device
- Live audio, in memory only while it is transcribed
- Recorded audio, only if you turn recording on, deleted after the number of days you set
- Transcripts, recaps and a search index built from your vault
- Voiceprints, only when you enroll someone for Pro speaker ID
- AI spend totals (amounts and counts only, no text)
- Your license (a one-way hash of the buyer's email, not the email), and AI keys in your operating system's keyring
When it uses the network
These are the only times Mimir uses the network. Anything not listed here never leaves your device.
- AI answers and recaps
- When: Off until you turn it on.
- What is sent: Your question, matching passages from your notes, the last few minutes of transcript and campaign context; for recaps, the session transcript. Every call is checked against your spend caps first.
- Sent to: The AI provider you choose with your own key (Anthropic or an OpenAI-compatible service), or nobody if you use a model on your own PC.
- Discord voice feature
- When: Off until you turn it on.
- What is sent: Your Discord user ID, so the bot can join your channel. No audio is sent.
- Sent to: A Discord bot you run yourself.
- Model downloads
- When: On first use.
- What is sent: Ordinary download requests for speech and search models, with nothing about your game
- Sent to: The model publishers' hosts (Hugging Face and GitHub).
What reaches Lanternwright
Nothing. Mimir sends no data to Lanternwright.
Telemetry
None. Mimir has no telemetry, analytics or crash reporting, so there is nothing to opt out of.
Keeping and deleting
Recordings and transcripts can be deleted automatically after the number of days you set. One command lists everything Mimir keeps and another deletes it.
Also worth knowing
- Transcribing people is recording them. The person running Mimir is responsible for getting the table's agreement, and Mimir prints a notice to share first.
Your rights and choices
You can ask what data is held about you, ask for it to be corrected or deleted, and withdraw consent at any time.
Email support@lanternwright.com and you will get an answer within 30 days, at no charge.
Depending on where you live (for example the EU, the UK or California), you may have further rights, including the right to complain to your local data protection authority.
Children
This site and its waitlists are not meant for children under 13. If you believe a child has joined a waitlist, email support@lanternwright.com and the address will be deleted.
Changes to this policy
Changes are posted on this page with a new last-updated date. If a change would use your data in a new way, you will be asked first.
Contact
Questions or requests about privacy: