Last Updated & Effective Date: October 1, 2026
Lycoris is built on an offline-first foundation. We do not require accounts, do not run analytical telemetry, and do not maintain any central servers or databases that collect your personal identity, gaming library, financial receipts, or gameplay hours. You maintain 100% data sovereignty.
This Privacy Policy explains how Lycoris ("the Application", "we", "us", or "our"), an open-source personal gaming library and ROI tracking application, handles information. Unlike typical SaaS applications, Lycoris executes and stores its primary database exclusively on your physical client device.
We believe the best privacy guarantee is not having your data in the first place. Lycoris does NOT collect:
When you use Lycoris to track your gaming library and calculate cost-per-hour return on investment (ROI), the following records are generated and stored exclusively within your device's sandboxed local storage using Hive NoSQL boxes (games_vault and settings_box):
This data remains strictly on your device unless you explicitly initiate a cloud backup or export a JSON file.
Lycoris offers an optional, user-initiated cloud backup feature powered by the official Google Drive API. Please read our exact permission boundaries below.
If you choose to enable cloud backups in Lycoris Settings, the application will prompt you to authenticate with your Google Account via Google Sign-In.
Lycoris requests only a single, restricted Google Drive scope:
https://www.googleapis.com/auth/drive.file (DriveApi.driveFileScope)
The drive.file scope grants Lycoris access ONLY to files and folders that have been created directly by the Lycoris application. Under this scope:
Lycoris/ at the root of your Google Drive.lycoris_vault_backup.json containing your exported game library data and delta timestamps.Lycoris's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
To provide box art, release dates, and game summaries, Lycoris connects to the Internet Database of Video Games (IGDB v4) via a stateless Cloudflare Worker proxy:
| Endpoint | Data Transmitted | Data Retained by Proxy |
|---|---|---|
/games Proxy |
Search keywords (e.g. "Hollow Knight") and IGDB numeric IDs. | None. The worker is completely stateless. It caches Twitch OAuth tokens server-side to prevent API rate limits, but does not log search queries, client IPs, or library contents. |
You have absolute control over your information at all times:
Lycoris/ folder, and moving it to the Trash.Lycoris does not knowingly collect or solicit personal information from children under the age of 13. Since the application does not collect personal data from any user, it is fully compliant with the Children's Online Privacy Protection Act (COPPA) and equivalent international regulations.
We may update this Privacy Policy from time to time. Any modifications will be posted to this page with an updated "Last Updated" date. Continued use of the application following any changes constitutes acceptance of the revised terms.
If you have any questions, concerns, or requests regarding this Privacy Policy or the security practices of Lycoris, please contact us or open an issue on GitHub: