Operator commitment
From Anara Heartsdale, the operator of Lanyard — in my own words:
"I have absolutely no reason or desire to see other people's groups, and the data will never be released to anyone."
What that means in practice:
Technical controls (encryption at rest, password-protected keys) back this up. But the commitment comes first, because trust in an SL community matters more than any server-side encryption scheme.
What we collect
Identity:
created_at (when you first attached the HUD) and last_seen_at (most recent request)Lanyards (group tags you save with the +Lanyard button):
Landmarks (teleport spots saved with the +Landmark button):
Auto-tag bindings (created automatically when you tap +Lanyard):
Your preferences:
Transient HUD↔server state:
Encryption material (binary):
Browser session (set in your browser, not stored server-side):
lanyard_session cookie — signed token holding your avatar UUID (and your DEK in password mode). 14 days, HTTP-only, SameSite=Lax. Cleared when you log out.See it all yourself: View my data renders every column of every table for your account.
What we don't collect
lanyard_key notecard you drop in for password-mode pairing)Lawful basis (GDPR)
Consent — by installing and using the HUD you actively choose what to save. No data is collected without an explicit +Lanyard or +Landmark action, or an explicit web-side preference change.
Your rights
Encryption
Lanyard labels, landmark labels, parcel names, notes, group UUIDs, and parcel keys are encrypted at rest in the database (AES-256-GCM via PyCryptodome). The encryption key lives in server environment variables, separate from the database file — so a leaked database backup is not readable on its own. Folder names, region names, and your avatar UUID are stored in plaintext (folder names because they're already user-chosen organizational metadata; region names so the auto-tag-switch lookup can run efficiently; your avatar UUID because every request needs it for routing).
The operator (administrator with server access) can technically still read your encrypted data because the server holds the decryption key — although per the commitment above, they don't.
If you want cryptographic protection instead of just the operator's word, you can turn on password protection. A key is derived from your password via PBKDF2 (600,000 iterations, SHA-256) and your data key is wrapped so only your password can unlock it. With password protection on, the operator cannot read your labels, notes, folder names, group UUIDs, or parcel keys — only publicly-fetched group names (already visible on world.secondlife.com) remain server-readable so auto-populating new groups still works. Trade-off: forgetting the password means permanent data loss; there is no recovery.
Where the data lives
A single SQLite database file on a Namecheap-hosted shared server in the United States. Not shared with any third party. No CDN, no analytics services, no backups beyond the operator's own occasional manual snapshots (which would be encrypted-at-rest the same as the live DB).
External requests we make on your behalf
When you save a lanyard, the server fetches the SL group's display name from world.secondlife.com (a public Linden Lab page) so we can show you a readable name instead of just a UUID. This is a one-time HTTP GET per group, with no avatar identifiers attached.
Contact
For data requests beyond what the self-service buttons cover, contact the operator in-world: Anara Heartsdale.