Lawful basis
Encryption at rest
No selling
Section 1
The data we collect
1.1 Information you provide directly
When you create a Lammah account, we ask for a username, an email address, a password, and your country of residence. Your password is hashed with a strong one-way algorithm before storage — we never see the plain text, and we cannot recover it for you if you forget it. Your email is used to verify your identity, to deliver security notifications, and to respond to support requests. Your country is used to tailor surf targeting and to comply with regional rules.
When you submit a website to the surf rotation, we store the URL, a short title, a description, the category you chose, and any targeting options you set. When you contact us through our contact page, we keep a copy of your message and our reply for up to twenty-four months so we can refer back to it if the same issue recurs.
1.2 Information collected automatically
Like most platforms, Lammah collects a small set of technical information every time you load a page. This includes your IP address (used for fraud detection and rate-limiting), your browser type and version, your operating system, the referring page, and a timestamp. We also record which sites you visit during a surf session — this is essential to the core function of the platform, because surf rewards are issued based on completed visits.
We use first-party cookies and a server-side session store to keep you logged in, to remember your surf preferences, and to detect automated abuse. We do not use third-party advertising cookies. We do not embed third-party analytics that profile you across the wider web.
1.3 Information from mining and engagement
The mining subsystem records your equipment, your gems, your ore inventory, your pool memberships, your expedition history, and the timestamps of every block you mine. This is gameplay state, not personal data in the traditional sense, but it is tied to your account and is included in any data export you request.
Section 2
Why we collect it
We do not collect data because we might find a use for it someday. Every category of data we record has a specific, documented purpose. If we cannot point to a reason, we do not keep the data — full stop.
- To deliver the service. Sessions, surf history, and balances are required for the platform to function at all.
- To prevent fraud. IP addresses, behavioural signals, and captcha records are essential to keeping the traffic pool human and the coin economy fair.
- To communicate with you. Your email is used for verification, security alerts, transactional notifications, and replies to your support requests.
- To comply with the law. Some records — particularly those related to financial transactions and abuse reports — are retained because the law requires us to.
- To improve the platform. Aggregated, anonymised statistics help us understand which features are used and where the experience breaks down. We never use individual-level data to make product decisions that could be made from anonymised aggregates.
Section 3
How long we keep data
Retention is the question privacy policies most often hand-wave, and it is the question we want to answer most directly. Different categories of data have different retention windows, and we have set each one to the shortest period that still allows us to deliver the service and meet our legal obligations.
- Account records (username, email, country): kept for the lifetime of your account, deleted within thirty days of a deletion request.
- Surf history: kept for ninety days in full granularity, then aggregated into daily summaries that we retain for twenty-four months.
- Anti-fraud signals and IP logs: kept for ninety days in raw form, then permanently deleted.
- Captcha records: kept for seven days, then deleted.
- Transaction ledger entries (coin transfers): kept for the lifetime of the account, because the ledger must remain verifiable.
- Mining gameplay state: kept for the lifetime of the account, then deleted with the account.
- Support correspondence: kept for twenty-four months after the last message, then deleted.
Section 4
Who can see your data
Access to your personal data is restricted to a small number of Lammah team members, and only on a need-to-know basis. A team member handling your support ticket can see the email address and account summary relevant to that ticket; they cannot see your password (no one can — it is hashed), they cannot see your session tokens, and they do not have carte blanche access to your surf history.
We use a small number of trusted infrastructure providers — a hosting provider for our servers and a managed database service — that necessarily process some data on our behalf. Each one is bound by a data processing agreement that contractually prohibits them from using your data for any purpose other than providing the service we have asked them to provide. We do not share personal data with advertising networks, data brokers, or analytics companies that build profiles across the web.
Section 5
Your rights
Depending on where you live, you may have specific legal rights over your personal data. We honour these rights for everyone, regardless of jurisdiction, because we believe they are good practice rather than legal minimums.
Right of access
Right to rectification
Right to erasure
Right to restrict
Right to portability
Right to object
To exercise any of these rights, write to support@lammah.click from the email address associated with your account. We will respond within thirty days, and we will never ask you to pay a fee to exercise a right that the law grants you for free.
Section 6
Cookies and tracking
Lammah uses first-party cookies for three purposes: to keep you logged in (session cookie), to remember your interface preferences (theme, sidebar state, last dashboard tab), and to detect abusive traffic patterns (rate-limit counters). These cookies are essential to the service and cannot be disabled without breaking core functionality.
We do not use third-party advertising cookies. We do not embed social-media buttons that track you across sites. We do not run third-party analytics scripts that profile you. The only third-party scripts that load on Lammah are those required to render captcha challenges, and those are loaded on-demand only when a captcha is presented.
Section 7
Security
We treat security as a continuous practice rather than a one-time checklist. Passwords are hashed with Argon2id. Sessions are signed and rotated regularly. Database access is restricted to a small group of team members and is logged. We run automated dependency scanning on every code change, and we patch critical vulnerabilities within hours of disclosure, not days.
No system is perfectly secure, and we will not pretend ours is. If we ever suffer a breach that affects your personal data, we will tell you — clearly, promptly, and without downplaying the scope. We would rather lose your trust by being honest than keep it by being evasive.
If you believe you have found a security vulnerability in Lammah, please report it responsibly to support@lammah.click with a clear description and a reproduction steps. We acknowledge every responsible disclosure within forty-eight hours and we credit researchers who help us improve.
Section 8
Children's privacy
Lammah is not designed for, and may not be used by, anyone under the age of thirteen. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact support@lammah.click and we will delete it immediately. For users between thirteen and eighteen, we require parental consent before an account can be created.
Section 9
International transfers
Lammah is a global platform, and your data may be processed in a country other than your own. When we transfer personal data across borders, we rely on appropriate safeguards — standard contractual clauses, adequacy decisions, or equivalent protections — to ensure your data receives a level of protection consistent with this policy. By using Lammah, you acknowledge that your information may be processed in any country in which we or our service providers operate.
Section 10
Changes to this policy
We will update this policy when the way we handle data materially changes. When we do, we will notify you by email — sent from support@lammah.click — at least thirty days before the changes take effect, and we will publish a clear changelog at the top of this page. We will never apply a policy change retroactively to data we have already collected under the previous policy.
Verification and security notifications about your account are sent from noreply@lammah.click. Transactional receipts, password reset links, and other automated messages are sent from noreply@lammah.click. Please add these addresses to your contacts so they are not caught by your spam filter.
Section 11
Contact us
If you have any question, concern, or request regarding this privacy policy or your personal data, we want to hear from you. Write to support@lammah.click or use the form on our contact page. A real person will read what you send, and we will respond within two business days.
