Privacy Policy

Last updated: 7 August 2026

In short

This site runs no analytics, no advertising and no tracking of any kind. It sets no cookies except one that exists for ten minutes while you sign in, and it stores no personal data on its servers at all — there is no database and no user accounts. Fonts are served from this site rather than from a third party.

The one thing worth knowing: to show current version and download information, your browser contacts GitHub directly. Section 3 explains that.

1. Who is responsible

lstwo
Email: contact@lstwomods.com

2. Hosting and server logs

The site is hosted on Cloudflare Workers (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). Every request necessarily reaches Cloudflare's servers, which process your IP address, the requested URL, the referring page, your browser's user agent and a timestamp.

Request logs are retained for a short period (currently up to 7 days) and are used only to diagnose errors and defend against abuse. They are not combined with any other data and are not used to profile visitors.

Legal basis: Art. 6(1)(f) GDPR. The legitimate interest is operating the site reliably and securely; without processing the IP address a web page cannot be delivered at all.

3. Data sent to GitHub while you browse

The mods on this site are distributed through GitHub. To show you the current version, the release history, download counts and each mod's README, your browser calls GitHub's API directly rather than going through this site's server. This happens automatically when you open a mod page, without any action on your part.

As a result GitHub, Inc. (a Microsoft company, USA) receives your IP address, your user agent and the fact that a particular mod's data was requested. I have no influence over what GitHub does with that information. See the GitHub Privacy Statement.

Mod descriptions may also embed images hosted on GitHub. Loading them transmits your IP address to GitHub in the same way.

Legal basis: Art. 6(1)(f) GDPR — the legitimate interest in showing accurate, current information about the mods instead of stale copies.

4. Downloads

When you download a mod, the release files are fetched through this site's own endpoint (/api/gh/asset/...), because GitHub's file servers cannot be read directly by a browser. That request passes through Cloudflare as described in Section 2, and this site's server then fetches the file from GitHub. No record of who downloaded what is kept.

The .zip file itself is assembled inside your browser. The files are never uploaded anywhere and the finished archive never leaves your device.

5. Signing in with GitHub (optional)

GitHub limits how many requests an IP address may make per hour. Signing in raises that limit so pages load and downloads work more reliably. It is entirely optional and nothing on this site requires an account.

If you choose to sign in:

  • You are redirected to GitHub, which asks for your permission. The authorisation is requested with no scopes at all, meaning the resulting access token can only read public information — it can never read your private repositories or write anything to your account.
  • This site receives an access token, which is passed straight to your browser and stored there. The token is never stored on the server.
  • Your browser then fetches your username, display name and avatar URL from GitHub to show them in the navigation bar. Your avatar image is loaded from avatars.githubusercontent.com, which transmits your IP address to GitHub.
  • Signing out deletes the token from your browser immediately. You can also revoke access at any time in your GitHub application settings.

Legal basis: Art. 6(1)(b) GDPR — carrying out a function you asked for. Insofar as consent is required, Art. 6(1)(a) GDPR, which you may withdraw at any time by signing out.

6. Cookies and browser storage

This site uses no tracking, advertising or analytics cookies. Two items are stored:

  • gh_oauth_state — a cookie set only when you start the sign-in process. It is cryptographically signed, marked HttpOnly and SameSite=Lax, expires after 10 minutes and exists solely to protect the login against cross-site request forgery.
  • lstwomods_gh_token — the GitHub access token from Section 5, held in your browser's local storage so you stay signed in between visits. It is removed when you sign out or clear your browser data.

Both are strictly necessary to provide a function you explicitly requested, so under § 25(2) no. 2 TDDDG they do not require consent, and this site therefore shows no cookie banner.

7. Transfers outside the EU

Cloudflare and GitHub are both based in the United States, so the processing described in Sections 2 to 5 may involve a transfer of your IP address to a third country. Both companies are certified under the EU–US Data Privacy Framework, which the European Commission recognised as providing an adequate level of protection in its adequacy decision of 10 July 2023. Standard Contractual Clauses under Art. 46(2)(c) GDPR apply in addition.

8. Your rights

Under the GDPR you have the right to:

  • access your data (Art. 15)
  • have inaccurate data corrected (Art. 16)
  • have your data erased (Art. 17)
  • restrict processing (Art. 18)
  • receive your data in a portable format (Art. 20)
  • object to processing based on legitimate interests (Art. 21)
  • withdraw consent at any time, without affecting processing already carried out (Art. 7(3))

In practice these requests will usually be short to answer: this site keeps no user records, so there is normally nothing held about you beyond short-lived server logs. Data connected to your GitHub account is held by GitHub, not by me, and is best addressed to them. Anything stored in your browser can be removed by signing out or clearing your browser data.

9. Right to complain

You may lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work (Art. 77 GDPR).

10. Changes to this policy

This policy may be updated when the site changes. The current version always applies and is dated at the top of the page.