Skip to content

Legal

Privacy Policy

Effective

1. Who we are

LyEve Labs operates lyeve.com, the customer portal, the marketing site, and the issuance API for license JWTs. This policy applies to those services. It does not apply to data you store inside your self-hosted LyEve CMS instances. That data stays on your infrastructure and we never see it.

LyEve Labs operates from Indonesia and is the controller of the personal data this policy describes. Our registration details, once issued, are published in the legal notice.

2. What we collect

When you create an account or purchase a subscription, we collect:

  • Email address and password (hashed with argon2id, never stored in plain text).
  • Display name, and the company name and country attached to your payment.
  • If you sign in with GitHub: your GitHub user ID, the email address and name GitHub shares with us, and the tokens GitHub returns for that sign-in. We ask GitHub for nothing beyond your basic profile and email.
  • Payment information, processed by PayPal. We never see or store card numbers. PayPal returns only a tokenized payer / transaction ID.
  • License key activations: the instance ID, host fingerprint, and IP of any host that posts to /api/v1/license/activate.
  • When you accept the Terms of Service: the version you accepted, when, and the IP address and browser user agent you accepted from, kept as the record of that agreement.
  • To limit how often we email one address, a one-way digest of the address, deleted a day after the last email to it.
  • Server logs (request method, path, status code, timestamp, IP) retained 30 days for security and debugging.
  • When you write to us, join a waitlist, or request a community discount: your name, email address, what you tell us (for a discount request, your project and its monthly revenue), and the IP address and browser user agent the request came from.
  • Website visits to lyeve.com: the page path without its query string, the referring page without its query string, campaign tags, your browser's user agent, which pricing buttons you press, and a visitor identifier our server derives from your IP address and user agent with a key it replaces every day and then deletes. We use it to count visits and see which pages lead to a purchase. The identifier counts you once a day and cannot link one day's visits to another's. Your IP address is not stored. After 30 days we cut the user agent down to the browser's name, such as Chrome or Firefox. After 13 months we delete the visit record. Nothing is stored in your browser, no cookie is set, and nothing is recorded when your browser sends Do Not Track or Global Privacy Control.
  • When you create an account from a link that names a campaign or comes from another website: the campaign tags and the name of that website, recorded once with your account and deleted with it. Links on lyeve.com carry them to signup in the address itself, not in your browser's storage. Nothing is carried or recorded when your browser sends Do Not Track or Global Privacy Control.
  • When you use the customer portal signed in: which portal pages you open, recorded against your account, to see which features are used. We record the page, not its address, so no license or invoice number is kept. The record is deleted after 13 months, or with your account. Nothing is recorded when your browser sends Do Not Track or Global Privacy Control, or while LyEve support has your account open.

The self-hosted CMS verifies its license JWT offline against an embedded Ed25519 public key. It transmits no telemetry or analytics to LyEve. If you configure it with your opaque license key rather than a signed token, it sends that key and a random install identifier to our license server to obtain a token, at startup and before the token expires, and we record that install against your account. Nothing else is sent.

3. How we use it

  • Authenticate your account and issue session cookies.
  • Issue, rotate, and revoke license JWTs for your subscription.
  • Send transactional email (verification, receipts, password reset) through Amazon SES.
  • Bill subscriptions and one-time orders through PayPal, and process refunds where applicable.
  • Detect and investigate abuse, such as key sharing.

We do not sell, rent, or trade your personal data to third parties. We do not use it to train AI models.

5. Subprocessors

A short, current list lives at lyeve.com/legal/subprocessors. Today we rely on:

  • PayPal: payment processing, subscriptions, and one-time orders.
  • Amazon Web Services: transactional email delivery through Amazon SES, and object storage for media and release artifacts, both in the ap-southeast-1 (Singapore) region.
  • Amazon Web Services (Amazon EC2): hosting in Frankfurt (eu-central-1), in the EU. The application and the PostgreSQL database holding account, billing and license records are moving there and run on our own servers. No managed database service is involved.
  • Cloudflare: DNS, TLS, protection against attacks, and delivery of lyeve.com. It handles the IP address and request details of every visit, worldwide.

If you choose to sign in with GitHub, GitHub handles that sign-in under its own privacy policy and is not our subprocessor for it.

6. International transfers

Where personal data is transferred outside your jurisdiction, we rely on the European Commission's Standard Contractual Clauses (SCCs) and equivalent safeguards. Email and object storage run in the ap-southeast-1 (Singapore) region, so data in those services leaves the EU. Hosting and the database stay in the EU. PayPal and our infrastructure providers operate under SCCs and equivalent safeguards.

We operate from Indonesia, so the people who run the service reach the database from there. For data about people in Indonesia that leaves the country, we rely on the safeguards Law No. 27 of 2022 on Personal Data Protection (UU PDP) allows: a destination with adequate protection, or binding contractual safeguards with each provider.

7. Data retention

Account data is retained while your account is active. When you ask us to delete your account, we wait 30 days so you can cancel the request, then delete its personal data within a day once no subscription on the account is set to renew, except records we are required to keep for tax (typically 7 years) and active fraud investigations. License install records (instance ID, host fingerprint, the IP address that activated the install, activation and check-in times) are deleted once an install has not checked in for 12 months, and when your account is deleted. The record of your acceptance of the Terms is kept for as long as we may need to show the agreement existed. Website visit and portal page records keep the user agent for 30 days, then only the browser's name. The records are deleted after 13 months. The key behind a day's visitor identifiers is deleted the next day. Support messages, waitlist entries and discount requests are kept while the request is open and while we need them to serve you, and are deleted when you ask.

8. Your rights

Wherever you live, you may:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data. You can change your display name in the customer portal. For anything else, write to us.
  • Delete your account and the personal data we hold (subject to legal-retention exceptions). You can request this yourself under Settings in the customer portal, or by writing to us.
  • Export your data in a portable format.
  • Restrict or object to specific processing, and withdraw consent you gave, without affecting what was done before.
  • Lodge a complaint with your local data-protection authority.

Make any of these requests by email to privacy@lyeve.com, in English or Indonesian, from the address on your account. We may ask you to confirm the request from that address before acting on it. We respond within 30 days, and within 3 x 24 hours where Indonesian law requires it. Exports are sent as JSON.

9. Cookies

Marketing pages set no cookies and store nothing in your browser for analytics, so there is nothing to accept or decline. The customer portal sets HTTP-only cookies that are strictly necessary for signing in and for protecting forms, plus short-lived ones during a GitHub sign-in and a two-step sign-in. See the cookie policy for the full list.

10. Security

Passwords are hashed with argon2id (memory-hard, configurable cost). License JWTs are signed with Ed25519. The private key is held offline and rotated on a schedule. All traffic is TLS-only. We rotate session-signing keys quarterly and maintain a revocation list. Security disclosures: security@lyeve.com.

11. Children's data

LyEve is a service for businesses and developers and is not directed at anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data, contact privacy@lyeve.com and we will delete it.

12. Regional notes

  • Indonesia. This policy is our notice under UU PDP. If personal data we hold about you is breached, we will notify you and the authority within 3 x 24 hours, as that law requires.
  • EU, EEA and UK. You may complain to the data protection authority where you live or work. We notify the relevant authority of a breach within 72 hours.
  • United States. We do not sell or share personal information, and we do not use it for cross-context behavioral advertising. We honor requests from residents of every state the same way.
  • Brazil, Canada and elsewhere. The rights in section 8 apply to you too. Our privacy contact for LGPD and PIPEDA requests is privacy@lyeve.com.

13. Changes to this policy

We will notify active subscribers by email at least 14 days before material changes take effect. Continued use after that date constitutes acceptance.

This version took effect on 2026-10-08. It stopped keeping a visit identifier in your browser and recording your IP address with a visit, and it added two records: the campaign and referring website an account was created from, and the customer portal pages a signed-in customer opens. The previous version of 2026-10-06 stays readable.

14. Contact

Questions, requests, or complaints: privacy@lyeve.com.