How micro-LEAN handles your data
Updated 7 October 2026 · Operator: Christopher Guiffre
micro-LEAN works in your browser without an account. If you sign in, create a share link or contact us, some information is stored on our servers. This notice explains those choices.
Process work
Without an account: your workspace is saved in this browser’s local storage. It is not sent to our server unless you create a share link or choose to send feedback. Export a backup if you need a copy on another device.
With an account: your email identifies your workspace. Your process content is synced to our server so you can use another device. The sign-in session is held in an HTTP-only cookie; the server stores the session ID, time and a limited browser device string so you can see and revoke devices. Sessions expire after up to 90 days.
Deleted processes: synced work remains in Trash for 30 days before permanent removal from the workspace.
Sharing
Creating a share link stores a snapshot of the selected process on our server. Anyone with the link can open a copy. Guest links expire after 7 days; signed-in owners can choose an expiry up to 90 days and revoke them. Expired links are removed automatically; revoked links are removed 7 days later. Earlier links created before 6 October 2026 expire 30 days after creation. A share email is sent only when you choose to send it.
Contact and feedback
Website contact messages store the email address you enter, your selected inquiry type, message, time, consent time and any permitted referral tag. We use them to reply; if you specifically choose Pro launch updates, we may also send one launch update. Sending this form places the request in our admin inquiry queue; it does not automatically send you an email. Please do not include confidential client or process data.
In-app feedback stores your note, stage, optional rating and optional “how you found us” answer. If you are signed in, your email is stored with that note. A user can ask us to remove a contact message or feedback through the privacy contact form. Account deletion removes the matching account email from feedback and website inquiry entries, as well as deleting the cloud workspace, owned share links and sessions. The inquiry message and type remain until we remove them on request or when no longer needed to handle the inquiry. An inquiry submitted from another email must be requested separately.
Referral counts
When a link contains a supported ?ref= tag, the browser can keep that short tag. Starting a process sends a one-time first-party count with the date and tag; it contains no process content or email. If you sign in, the tag may also be saved with the account. We do not use advertising pixels or third-party analytics scripts.
Network and service records
As with other web services, our host and server can process IP address, request time, browser information and requested pages to deliver the site and protect it from abuse. The app uses short-lived rate-limit records; we do not use this information for cross-site advertising. We do not sell personal data or use cross-site trackers. A browser Do Not Track signal does not change this first-party operation because no third-party tracking is active.
Service providers and AI
Railway hosts the app and its database. Resend delivers sign-in codes and share emails when requested. These providers process data needed to provide their services. micro-LEAN does not automatically call an AI model with your process data. Build files are downloaded for you to review and decide whether to send to another tool. Stripe is not connected and we do not collect payment details today. If payments launch, this notice will be updated before checkout.
Retention, security and choices
Cloud work remains until you delete your account. Session records last up to 90 days unless revoked sooner. Rate-limit records contain no process content and are removed after one day. Referral start counts are kept as aggregate service measurements. Contact and feedback records are retained as needed to respond and improve the product; ask for deletion when you no longer want us to keep a message. Access to stored work is limited by account sign-in; share links are bearer links, so treat them like a document you send to someone.
You can remove local work through the app and your browser, revoke shares from your account panel, sign out of every device, or delete your account in the app. Use the contact form for access or deletion questions. We may need to verify your request before acting.
Changes
We will update this page when handling changes and show the new date. Material changes may also be announced in the app.