Privacy Notice
Last updated 26 August 2026
This notice explains what touchinggrass.lol collects, why, who else touches it, and what you can ask us to do about it.
1. Who is responsible for your data
The controller of your personal data is Luodaint LLC, 8 The Green #20373, Dover, DE 19901, United States. Privacy questions go to marc@luodaint.com and are answered by a person.
2. What we collect
From X, when you sign in
- your account identifier, handle, display name, and avatar URL;
- session information that keeps you signed in.
We do not receive your X password or your payment card numbers.
That you submit
- listing details: URL, name, tagline, and category;
- proof photos and optional GPX tracks;
- EXIF claims the browser reads (taken-at time and, if present, coordinates), which we store and do not display;
- flag reasons you write about someone else’s proof.
From payments
Stripe tells us that a checkout succeeded, the amount, and enough metadata to apply the bid, listing, or skip. Card numbers stay with Stripe.
That we generate about use
- server logs (IP address, user agent, timestamps) produced when your browser talks to our servers;
- page analytics via datafa.st when that script is enabled;
- vision-model verdicts on proof photos (grass, outdoors, original, NSFW, confidence, and a short reason).
3. Why we use it
- To run the leaderboard — sign-in, listings, bids, skips, proofs, flags, and rank. Basis: performance of our contract with you. ,
- To take payment — Stripe checkout and webhooks. Basis: contract. ,
- To keep the service secure — rate limits, logs, fraud and abuse prevention. Basis: our legitimate interest in a working product. ,
- To understand which pages are used — datafa.st analytics. Basis: legitimate interest in operating the site. ,
- To email you about your listing — idle and rot notices, when we have an email address. Basis: contract and legitimate interest in operational messages. ,
- To comply with law — tax and lawful requests. Basis: legal obligation. ,
4. Photos, location, and the vision model
Proof photos are the point of the game. Verified photos are public. Pending, rejected, and hidden photos are visible only to the listing owner (and to us, so we can operate moderation).
To decide whether a photo counts, we send it to OpenAI’s vision API and store the verdict. We do not use your photos to train general-purpose models, and we use API settings that forbid provider training where they exist.
If a photo’s EXIF includes GPS, we store those coordinates as a claimed location. We never render them. Do not upload a photo if you do not want a public picture of that place, even without a pin on a map.
5. Cookies and analytics
We set a session cookie so the service knows you are signed in, plus short-lived cookies needed for X sign-in. Those are strictly necessary.
When analytics is configured, the site loads datafa.st to measure page views. We do not use advertising cookies and we do not sell personal information.
6. Who else processes it
We do not sell your personal data. We use these processors:
- Cloudflare — hosting, database, cache, photo storage, and transactional email. ,
- Stripe — checkout and payment records. ,
- OpenAI — vision checks on proof photos. ,
- X Corp. — sign-in. ,
- datafa.st — website analytics, when enabled. ,
We may also disclose data where the law requires it, to defend legal claims, or in a merger or sale of the business, in which case we will tell you before your data becomes subject to a different notice.
7. International transfers
We are a United States company. Cloudflare, Stripe, OpenAI, and X process data in the United States and other countries. Where we transfer personal data out of the European Economic Area or the United Kingdom to a country without an adequacy decision, we rely on the providers’ Standard Contractual Clauses and similar safeguards.
8. How long we keep it
- Account, listings, bids, proofs, and flags — while the listing or account exists, and as needed to run public rank history. ,
- Billing records — as long as tax and accounting law requires, typically seven years. ,
- Server logs — a short operational period, then discarded or aggregated. ,
- Backups — deleted data can remain in backups until those backups expire. ,
To ask us to delete an account or a proof, email marc@luodaint.com.
9. How we protect it
- Traffic between you and the site is encrypted in transit. ,
- Photos are stored in a private object store; only verified proofs are served publicly. ,
- Claimed coordinates are never shown in the interface. ,
- Card details never touch our servers. ,
No system is perfectly secure. If a breach is likely to risk your rights, we will notify you and any required authority without undue delay.
10. Your rights
Subject to local law — especially if you are in the European Economic Area or the United Kingdom — you can ask to access, correct, delete, or export your personal data, to restrict or object to some processing, and to withdraw consent where we relied on it. Email marc@luodaint.com. We will respond within one month.
If you are in California or another US state with a comprehensive privacy law, you may request to know, delete, or correct personal information. We do not sell personal information and we do not share it for cross-context behavioural advertising.
11. Children
The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has used the site, contact us and we will delete the account.
12. Changes
We update this notice when the product changes. The date at the top is the current version. If a change materially affects how we handle your personal data, we will say so on this page before it takes effect.
13. Contact and complaints
Luodaint LLC
8 The Green #20373
Dover, DE 19901
United States
Email: marc@luodaint.com
If you are in the European Economic Area or the United Kingdom and you think we handled your data badly, you can complain to your local supervisory authority. We would rather you told us first.
The Terms of Service govern use of the service alongside this notice.