LANYARD

← back

Lanyard Privacy

What we store and why

Operator commitment

From Anara Heartsdale, the operator of Lanyard — in my own words:

"I have absolutely no reason or desire to see other people's groups, and the data will never be released to anyone."

What that means in practice:

  • I will not read your data. Not your lanyard labels, not your landmark notes, not your folders, not your parcel names. Not to debug, not out of curiosity, not for any reason.
  • I will not share, sell, trade, or give your data to anyone — no analytics vendors, no ad networks, no "partners," no one.
  • I will not use your data to monitor you. Where you teleport, which groups you hold, who you're affiliated with — none of that is my business.
  • If I ever need to touch the database for maintenance (schema migration, backup, data recovery at your explicit request), I will do it without inspecting content.
  • If you want that commitment backed by cryptography so it doesn't rely on trust at all, the password-protection feature makes it technically impossible for me to read your labels, notes, or folder names even if I wanted to.

Technical controls (encryption at rest, password-protected keys) back this up. But the commitment comes first, because trust in an SL community matters more than any server-side encryption scheme.

What we collect

Identity:

  • Your Second Life avatar UUID and display name — sent automatically by the SL simulator with every HUD request, can't be faked
  • Account timestamps: created_at (when you first attached the HUD) and last_seen_at (most recent request)

Lanyards (group tags you save with the +Lanyard button):

  • SL group UUID, your custom label, the auto-resolved group name, optional note, optional folder, favorite flag, favorite-order, added-at timestamp

Landmarks (teleport spots saved with the +Landmark button):

  • Region name, parcel UUID, parcel name, the exact x/y/z position you were standing in, your custom label, optional note, optional folder, favorite flag, favorite-order, created/updated timestamps

Auto-tag bindings (created automatically when you tap +Lanyard):

  • An "auto-tag anchor" row per parcel (region, parcel UUID, parcel name, position) so the HUD knows to switch your tag when you arrive there
  • An "assignment" row linking each anchor to one or more lanyards

Your preferences:

  • theme — which color scheme the HUD and website use (midnight, rose, forest, mono, plum, sunset)
  • tp_mode — whether teleports happen via RLV (HUD-driven) or SL Map (browser-driven)
  • tp_chat_channel — the in-world chat channel (if any) where you've enabled the HUD to listen for TP commands
  • speak_notes — whether the HUD whispers a lanyard's note when it auto-activates on parcel arrival
  • hud_locked — whether the HUD is RLV-locked to your avatar
  • onboarded — a flag tracking whether you've seen the first-time explainer whisper
  • ignored_update_version — the version number you dismissed an update prompt for
  • prompt_lanyard_* / prompt_landmark_* — six toggles for whether the HUD pops a text-entry box for name / folder / note before saving

Transient HUD↔server state:

  • pending_tp_* — the next region/x/y/z the HUD should teleport to. Written when you click TP on the website, cleared the instant the HUD's next status poll consumes it.

Encryption material (binary):

  • key_mode (server / password), key_salt, dek_encrypted (your data-encryption key, wrapped by either a server master key or a key derived from your password), and password_verify_hash if you set a password

Browser session (set in your browser, not stored server-side):

  • lanyard_session cookie — signed token holding your avatar UUID (and your DEK in password mode). 14 days, HTTP-only, SameSite=Lax. Cleared when you log out.

See it all yourself: View my data renders every column of every table for your account.

What we don't collect

  • Real-world identity, email, IP-based tracking, analytics, fingerprinting
  • Any data about other people on a parcel or region
  • SL group memberships beyond ones you explicitly save as lanyards
  • Anything from groups you've never bound to a parcel
  • Chat content (the chat-TP channel listener filters to your own avatar key — only your own commands on that channel are seen, and only the command line itself, never adjacent chat)
  • Inventory contents (other than the optional lanyard_key notecard you drop in for password-mode pairing)

Lawful basis (GDPR)

Consent — by installing and using the HUD you actively choose what to save. No data is collected without an explicit +Lanyard or +Landmark action, or an explicit web-side preference change.

Your rights

Encryption

Lanyard labels, landmark labels, parcel names, notes, group UUIDs, and parcel keys are encrypted at rest in the database (AES-256-GCM via PyCryptodome). The encryption key lives in server environment variables, separate from the database file — so a leaked database backup is not readable on its own. Folder names, region names, and your avatar UUID are stored in plaintext (folder names because they're already user-chosen organizational metadata; region names so the auto-tag-switch lookup can run efficiently; your avatar UUID because every request needs it for routing).

The operator (administrator with server access) can technically still read your encrypted data because the server holds the decryption key — although per the commitment above, they don't.

If you want cryptographic protection instead of just the operator's word, you can turn on password protection. A key is derived from your password via PBKDF2 (600,000 iterations, SHA-256) and your data key is wrapped so only your password can unlock it. With password protection on, the operator cannot read your labels, notes, folder names, group UUIDs, or parcel keys — only publicly-fetched group names (already visible on world.secondlife.com) remain server-readable so auto-populating new groups still works. Trade-off: forgetting the password means permanent data loss; there is no recovery.

Where the data lives

A single SQLite database file on a Namecheap-hosted shared server in the United States. Not shared with any third party. No CDN, no analytics services, no backups beyond the operator's own occasional manual snapshots (which would be encrypted-at-rest the same as the live DB).

External requests we make on your behalf

When you save a lanyard, the server fetches the SL group's display name from world.secondlife.com (a public Linden Lab page) so we can show you a readable name instead of just a UUID. This is a one-time HTTP GET per group, with no avatar identifiers attached.

Contact

For data requests beyond what the self-service buttons cover, contact the operator in-world: Anara Heartsdale.