LX MAPPER
Privacy notice

Last updated 28 July 2026

This notice describes what the software actually does. It has not been reviewed by a lawyer. If you take paying customers or users in the EU, have it checked before you rely on it.

Who is responsible

LX MAPPER is operated by TEBANI Mehdi at https://myhostlife.space. For any question about your data, write to no-reply@myhostlife.space.

What is collected

Only what the service needs to work:

DataWhy
Email addressIdentifies your account, and is how approval and password-reset messages reach you.
PasswordStored only as a hash (Argon2id or bcrypt). It cannot be read back, including by the operator.
Name, organisation, countryOptional. Used to decide what access level your request should get.
Your projectsThe .lxp files you save — drawings, imported layers, elevation data.
Sign-in recordsTime and IP address of your last sign-in, and failed attempts, to stop password guessing.
Administrative logApprovals, tier changes and deletions, so account decisions can be traced.

There is no analytics, no advertising, no tracking pixels and no third-party scripts on this site. Nothing you draw or upload is looked at, and nothing is sold or shared.

Cookies

One cookie, LXSESSID, which keeps you signed in. It holds a random session identifier and nothing else, is not readable by JavaScript, is restricted to this site, and disappears when you sign out or close the browser. There are no other cookies, so there is nothing to consent to.

Services the map contacts

Map tiles and lookups come from other providers. Your browser talks to them directly, so they can see your IP address and the area you are looking at. Your account details are never sent.

ServiceUsed for
EsriSatellite and street basemaps
GoogleHybrid satellite basemap
OpenStreetMap, CARTO, OpenTopoMapStreet and topographic basemaps
Mapbox3D terrain and elevation tiles
Nominatim, BANAddress search
OSRMRoute calculation
OpenTopography, Open-MeteoElevation data, when you request it

The geological sheets are served from this site, not from a third party.

Where it is kept, and for how long

Everything is stored on the hosting account behind https://myhostlife.space. Your account and projects are kept while the account exists. Failed sign-in records are cleared after a day. Password-reset and email-confirmation links expire and stop working on their own.

What you can ask for

A copy of your data, a correction, or deletion of the account and everything in it. You can edit your own details and change your password on the account page, and export any project as an .lxp file from inside the app at any time. For anything else, write to no-reply@myhostlife.space. Deletion removes the account, its projects and its stored files; entries in the administrative log are kept, since they record a decision rather than describe you.

Security

The site is served over HTTPS. Passwords are hashed and never stored in readable form. Sign-in is rate-limited. Project files are held outside the public web directory, so they cannot be fetched by guessing a URL. No system is perfect — keep your own copy of work that matters, which the export button in the app is there for.