Privacy policy
How byleandro.space handles information when you use its tools. Updated September 8, 2026.
Operator and contact
Leandro operates this independent project. For questions about your information or a feedback deletion request, email paulleandrolanot@gmail.com. Include enough detail to locate your feedback, but do not send passwords or private player records.
Your images and graphics
Card previews, deck graphics and background removal run in your browser. The application does not upload your selected photos to an image-processing API or save your editable graphics in a server account. Download work you want to keep before closing or reloading the page. Background removal downloads model assets from IMG.LY; that provider receives the network information needed to deliver those files.
Tournament imports
When you request a Challonge import, our server contacts Challonge to retrieve bracket data and returns it to your editor. The import code does not store the returned bracket in MongoDB. Only request data you are entitled to use and verify permission before publishing player names or photos.
Optional analytics and usage counts
If you accept analytics, the card tool stores a random browser identifier in local storage under leandro-tool-session-id and sends it to our usage endpoint. MongoDB records that identifier, first and last visit times, visit count and browser user-agent information. These are pseudonymous browser records, not verified people or an anonymous-only total. Counts can be affected by consent choices, different browsers and cleared storage.
Google Analytics loads only when configured and analytics has been accepted. Rejecting analytics prevents new automatic usage registration. Changing the choice to reject removes the local usage identifier and disables Google Analytics collection in the page; it does not automatically erase existing server records or previously created provider cookies. Browser settings can remove those cookies.
Preferences and advertising
The cookie-consent-v2 local-storage entry contains your analytics choice and decision time. The choice expires after 180 days. Open Cookie preferences at the bottom of any page to change it; every tool remains available when you decline. If storage is unavailable, optional analytics remains off.
Advertising is currently paused. No AdSense delivery script is loaded by this application. The publisher verification tag and ads.txt remain so the owner can verify the site. This analytics preference control is not a Google-certified advertising consent platform. Advertising requires a separate, verified consent integration and reviewed placements before it can resume.
Feedback and service protection
When you submit feedback, the server stores the selected category, title, message, optional contact information, page path, browser user agent and timestamps. A browser usage identifier is attached only if analytics is allowed. Feedback is not published in a public forum.
API rate limiting uses the request IP address and a time window in MongoDB to deter abuse; these rate-limit records have a short expiry and are removed by the database TTL mechanism. Hosting and upstream providers also receive ordinary network request information. Our application does not define an automatic deletion schedule for feedback or usage records; contact the operator about retention or deletion.
Third-party information
Hosting, MongoDB, Challonge, IMG.LY and optional Google Analytics process relevant requests under their own terms. Read Google’s privacy information for its services. Use your browser’s privacy controls to review or remove site storage.