Last updated 28 July 2026
Who is responsible
LX MAPPER is operated by TEBANI Mehdi at https://myhostlife.space. For any question about your data, write to no-reply@myhostlife.space.
What is collected
Only what the service needs to work:
| Data | Why |
|---|---|
| Email address | Identifies your account, and is how approval and password-reset messages reach you. |
| Password | Stored only as a hash (Argon2id or bcrypt). It cannot be read back, including by the operator. |
| Name, organisation, country | Optional. Used to decide what access level your request should get. |
| Your projects | The .lxp files you save — drawings, imported layers, elevation data. |
| Sign-in records | Time and IP address of your last sign-in, and failed attempts, to stop password guessing. |
| Administrative log | Approvals, tier changes and deletions, so account decisions can be traced. |
There is no analytics, no advertising, no tracking pixels and no third-party scripts on this site. Nothing you draw or upload is looked at, and nothing is sold or shared.
Cookies
One cookie, LXSESSID, which keeps you signed in. It holds a random session
identifier and nothing else, is not readable by JavaScript, is restricted to this site, and
disappears when you sign out or close the browser. There are no other cookies, so there is
nothing to consent to.
Services the map contacts
Map tiles and lookups come from other providers. Your browser talks to them directly, so they can see your IP address and the area you are looking at. Your account details are never sent.
| Service | Used for |
|---|---|
| Esri | Satellite and street basemaps |
| Hybrid satellite basemap | |
| OpenStreetMap, CARTO, OpenTopoMap | Street and topographic basemaps |
| Mapbox | 3D terrain and elevation tiles |
| Nominatim, BAN | Address search |
| OSRM | Route calculation |
| OpenTopography, Open-Meteo | Elevation data, when you request it |
The geological sheets are served from this site, not from a third party.
Where it is kept, and for how long
Everything is stored on the hosting account behind https://myhostlife.space. Your account and projects are kept while the account exists. Failed sign-in records are cleared after a day. Password-reset and email-confirmation links expire and stop working on their own.
What you can ask for
A copy of your data, a correction, or deletion of the account and everything in it. You can edit
your own details and change your password on the account page, and
export any project as an .lxp file from inside the app at any time.
For anything else, write to no-reply@myhostlife.space.
Deletion removes the account, its projects and its stored files; entries in the administrative
log are kept, since they record a decision rather than describe you.
Security
The site is served over HTTPS. Passwords are hashed and never stored in readable form. Sign-in is rate-limited. Project files are held outside the public web directory, so they cannot be fetched by guessing a URL. No system is perfect — keep your own copy of work that matters, which the export button in the app is there for.