Privacy Policy
1. Who we are and what this covers
DS-GN is a product of LightLeap Labs LLC.
This policy explains how LightLeap Labs LLC (DS-GN, we, or us) handles personal information through the DS-GN website, documentation, waitlist, dashboard accounts, and support channels. It does not cover applications you build with our packages; you are responsible for how those applications handle their users’ information.
Legal and privacy questions and requests: LightLeap Labs LLC, 2501 Chatham Rd, Suite N, Springfield, IL 62704, USA; support@ds-gn.com.
2. Information we collect
The @ds-gn/ui and @ds-gn/tokens packages do not collect or send any information to us. They contain no telemetry or install scripts and make no requests to DS-GN; components load only resources you supply, such as an image URL. npm handles package downloads under its own privacy policy, and we see only the aggregate download counts npm publishes.
When you create a dashboard account, we collect your name, email address, and password. We store a hash of your password, never the password itself. We also keep email-verification records and the personal organization and Free plan created for your account.
When you sign in, we keep session records that include your IP address and browser user agent. We also keep an activity log of organization events, such as renaming the organization or changing member roles.
When you join the waitlist, we collect your email address, the page you signed up from, verification records, and any utm_source, utm_medium, utm_campaign, and utm_content tags on the page where you submit the form. We do not retain campaign tags in your browser or carry them across pages.
When you contact us, we receive your email address and whatever you send. Issues you open on GitHub are public. Do not include passwords or other secrets in support requests or GitHub issues.
Our hosting provider processes IP addresses, browser details, and request timestamps to deliver the services, rate-limit requests, and protect forms from automated abuse.
3. How we use information
We use this information to create and secure accounts, verify email addresses, operate the dashboard, run the waitlist, respond to requests, send service messages, prevent abuse, fix problems, and meet legal obligations. We use campaign tags to measure which channels bring people to the waitlist.
We use your waitlist email to confirm your signup and to send availability updates about the @ds-gn-cli/create CLI and future paid plans. Every update of this kind will include an unsubscribe link.
4. Cookies and browser storage
Dashboard: a session cookie keeps you signed in, and your theme choice is saved in local storage (ll-theme). Blocking the session cookie prevents sign-in.
Documentation: your theme choice is saved in local storage (lightleap-docs-theme).
Website: we do not store campaign tags in cookies, local storage, or session storage. Tags on the current page URL may accompany a waitlist submission. Cloudflare Turnstile processes browser and network signals to protect the waitlist form. Approved reviewers of pre-release pages may receive a preview-access cookie.
The website uses Plausible Analytics to count page views and two events: clicks on the dashboard sign-up button and waitlist signups. Events are tagged with the page or link involved and any campaign tags, never your email address. Plausible does not use cookies or other persistent identifiers and does not store IP addresses; it counts unique visitors with a hash of the IP address and browser user agent combined with a salt that is deleted every 24 hours, and it stores data in the European Union. The documentation site and the dashboard do not use analytics, and we do not use advertising or social media tracking pixels.
You can clear cookies and local or session storage in your browser settings. Content blockers can also block Plausible.
5. Who receives information
We use service providers to run DS-GN: Cloudflare for hosting, content delivery, rate limiting, and abuse protection; Neon for database storage; Resend for email delivery; Plausible for website analytics, as described in section 4; and Stripe, as described below. Providers receive the information needed for their role, and some also process it under their own privacy policies.
We create a customer record for your account’s organization with Stripe, our payment processor, normally when the organization is created; if that step fails, the record is created when you start a checkout. The record contains your email address and your organization’s name, which starts out based on your name or email address. We use it for customer segmentation and to prepare billing for future paid plans. Free accounts are not asked for payment details.
Organization administrators can see member information and organization activity. Information you post publicly, including GitHub issues, can be seen by others. We may disclose information when required by law, to protect rights and security, or as part of a business transfer subject to applicable protections.
We do not sell personal information, and we do not share it for cross-context behavioral or targeted advertising.
6. Retention, deletion, and security
We keep account information, session records, and your organization’s activity log while your account exists. We keep waitlist entries, including signups that were never confirmed, until you ask us to remove them or we close the waitlist. We keep support email as long as needed to handle your request and for our records. Cloudflare keeps dashboard request logs for up to 7 days.
To delete your account, email the contact address above from the address on the account. We will delete your account, sessions, personal organization and its activity log, and the organization’s Stripe customer record. Backups and records we must keep by law may persist for a limited time, and Stripe may retain some data under its own legal obligations.
We use safeguards designed to protect personal information, but no system is completely secure. Use a strong, unique password and report suspected account compromise to the contact address above.
7. Your choices and rights
You can ask us to access, correct, or delete your personal information, or to remove you from the waitlist, by writing to the contact address above. We may need to verify your identity before acting, and an authorized agent can make a request for you with proof of your authorization. We respond within 45 days. If we decline a request, you can reply to ask us to reconsider. Legal obligations may limit what we can delete.
Every marketing email we send will include an unsubscribe link. Service messages, such as email verification, are sent regardless.
We do not sell or share personal information, so there is no sale or sharing to opt out of, including through Global Privacy Control signals.
8. Where we process information, and children
DS-GN is offered to people in the United States, and our database is hosted in the United States. Plausible stores website analytics in the European Union, and Cloudflare serves requests from data centers around the world.
Accounts and the waitlist are for people 18 and older. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact us so we can delete it.
9. Changes to this policy
We update the effective date and version whenever this policy changes. For material changes, we will give additional notice, such as an email to account holders or a notice on the website, and obtain consent where the law requires it.