Privacy
What Lychee Forge collects, why we hold it, where it lives, and what you can ask us to do with it. Written to be read, not to be survived.
Last updated: 2 August 2026.
Who is responsible
Lychee Forge is the controller of the data described here. If you want to ask about anything on this page, or exercise any of the rights below, write to nick@nickellis.net. A person reads that mailbox.
This website collects nothing on its own
The public pages — this one, the home page and the waiting list form — set no cookies, run no analytics, and load nothing from a third party. There is no tracking pixel and no advertising network. That is why you have not been asked to accept cookies: there are none to accept.
The only personal data this website receives is what you deliberately type into the waiting list form.
If you join the waiting list
We receive the name, work email, team name and message you enter. They are emailed to us and they are also stored in our database, as one row, so that the list has an order and we can tell you roughly where you are in it.
If you write to us again from the same address, the email reaches us with whatever you wrote, but the stored row keeps your original entry and your original place. So the stored record is your earliest enquiry from that address; anything later lives in our mailbox rather than in the database.
We use all of it only to answer your enquiry and, if it goes further, to set up an account. We do not add you to a mailing list and we do not pass it to anyone else. Our lawful basis is legitimate interests — responding to someone who has asked us to get in touch.
If nothing comes of the enquiry we delete both the stored row and the correspondence within twelve months. That deletion is a step a person runs, not an automatic job, and we would rather say so than imply a machine is doing it. Ask us sooner and we will delete it sooner — write from the address you used and we will remove the row and confirm.
If you use the application
Holding an account means we also hold:
- Your account details — the email address you sign in with, and your display name. Sign-in is by a one-time code sent to that address; we never see or store a password.
- The content you create — projects, requirements, comments, approval batches and everything else you put into a workspace.
- An audit trail— who changed what, and when. It is deliberately append-only and cannot be edited or deleted, because being able to show what was agreed and when it changed is the point of the product. See “Erasure” below for what that means in practice.
- Integration credentials, if you connect GitHub or Basecamp. Access tokens are encrypted before they are stored, are never logged, and are decrypted only at the moment a request is made.
Our lawful basis here is performance of a contract — we cannot provide the service without this data.
If you are asked to approve something
When a delivery team sends you an approval batch, we hold your email address, the decisions you record and any reasons you give. Your email address was given to us by the team you are working with, not collected from you.
The link you are sent carries a token that expires, and opening it sets one cookie so that your session survives the page. That cookie is strictly necessary, holds no tracking data, and is scoped to the approval pages only.
Cookies
Two, both strictly necessary, neither used for tracking: a sign-in session cookie set when you log in to the application, and the approval-portal cookie described above. The public website sets neither.
Where your data is held, and who else touches it
The database is hosted in the European Union — London — and is not replicated outside it. We use a small number of suppliers, each doing one job:
- Supabase — database and sign-in. Hosted in the EU.
- Vercel — application hosting.
- Resend — sending email, including approval requests and sign-in codes.
- Sentry — error reporting, so we find out when something breaks. Reports are stripped of secrets, approval tokens, cookies and request headers before they leave our servers.
Some of these are US companies and may process data outside the UK and EU. Where that happens it is covered by the standard safeguards those suppliers publish. We do not sell data to anyone, ever, and we do not use it to train anything.
Your rights
Under UK data protection law you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, or ask for it in a portable format. Write to nick@nickellis.net and we will answer within one month.
Erasure, honestly. We will delete your account and your content on request. We will not delete the audit trail of a project someone else is relying on, because that record is what makes an agreed scope provable and it is not ours alone to remove — but we will tell you exactly what is retained and why, and we will remove your identifying details from it wherever the record still makes sense without them.
If you think we have got something wrong you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first.
Security
Data is encrypted in transit and at rest. Access is separated by workspace at the database level, so one customer’s data cannot be read from another’s account. Integration tokens are encrypted with a key held outside the database. We report the changes we make to this page by updating the date at the top.