Privacy Policy
Version 0.15 · 1 October 2026
1. Controller and scope
The controller responsible for CamLuma is Individual Entrepreneur Nikoyan Vachagan Arturi, registration and tax number 20309749, registered address Avan 6th, 28, Yerevan, Armenia. For privacy matters, contact support@camluma.com. The Public Offer is available at https://camluma.com/legal/public-offer; the separate Consent to Personal Data Processing is at https://camluma.com/legal/consent-to-processing. Cookies and similar technologies are covered by section 14 of this Policy. All documents are listed at https://camluma.com/legal.
This Policy covers the CamLuma website, accounts, website photo processing and support. Telegram has its own service and data environment. Dodo Payments is separately responsible for the payment processing, fraud prevention, tax and other purposes it determines under its own privacy policy. If we process a business customer’s photographs solely on its documented instructions, the applicable processor agreement governs that activity; this Policy still covers our own account, billing and security purposes.
2. Information we handle
Account information includes your email address, account identifier, language, account creation and verification records, authentication data managed by Supabase in Seoul, South Korea, and session information. A copy of your email and account information is also stored in CamLuma/AutoCanon’s application database on our backend server in Frankfurt, Germany. We do not need your plain-text password for support and will never ask you to send it.
Image information includes the photograph you submit, people and other information visible in it, processing parameters and the resulting image. Images may contain personal or sensitive information about you or another person. File metadata can also contain information; do not assume that every item of embedded metadata is removed unless the interface confirms it.
Service records include edit balances, trial use, plan and renewal status, payment and subscription identifiers, amount and currency, transaction dates and acceptance timestamps. For each generation, we keep its identifier, file type and size, status, source of the edit used, error code or text, timing, and relevant storage and expiry metadata. We record the time when Terms are accepted. Registration-source information is described in sections 9 and 14.3.
Technical information may include IP address, browser and device information, session and request logs and security events handled by our hosting, authentication and communications providers. After optional analytics consent, PostHog also receives the analytics data described in section 6.
Support information includes your email address, messages, any attachments you choose to send, and the records needed to resolve your request. Do not send full card details, passwords or unnecessary sensitive documents. Dodo collects the payment details required by its checkout; CamLuma does not receive or store your full card number.
We receive information from you, your browser, authentication and payment providers and other providers needed to perform your request. If another account holder uploads a photograph of you, that person is the source of the image; you can contact us about it even if you do not have an account.
3. Purposes and legal grounds
We use account and service data to create and secure your account, verify email, provide processing and history, manage edit entitlements, deliver transactional messages and support you. Where the GDPR or UK GDPR applies, the legal basis for processing necessary to provide the contract with you is performance of that contract or steps you request before entering it.
We use necessary billing and related records to reconcile payments, handle refunds, satisfy legal accounting and tax duties and deal with claims. The relevant bases are performance of the contract, compliance with an applicable legal obligation, or our legitimate interests in accurate records and establishing or defending legal claims, as appropriate to the specific activity.
We use proportionate technical and access information to secure the service, prevent abuse and fraud, troubleshoot failures and enforce permitted-use rules. Where applicable, we rely on our legitimate interests in safe and reliable operation, balanced against individuals’ rights, or an applicable legal obligation. This does not authorise optional analytics without the choice described below.
For optional PostHog analytics, our basis is consent. You can decline or withdraw it without losing access to paid features. Consent withdrawal does not make earlier lawful processing unlawful.
Registration-source attribution records which partner link brought a user to CamLuma. Our Cookie settings classify the narrowly limited first-party registration-source cookie as Strictly necessary; it is set without optional analytics consent, as described in section 14.3 of this Policy. Where legitimate interests are available under applicable law, we rely on our interest in accurately attributing registrations and maintaining partner records for the associated account entry, subject to necessity, balancing and your applicable right to object. This data-protection basis does not replace any cookie consent required by applicable law. We do not use the source for cross-site tracking or analytics or disclose it to partners or other third parties for their own purposes.
For photographs depicting people other than the account holder, the account holder’s contract is not by itself a contract with every depicted person. The applicable basis and any additional sensitive-data condition must be established for that use: for example, an appropriately documented consent, lawful representation, a justified legitimate interest where permitted, or processing on a business controller’s instructions. We require uploaders to have the necessary authority and provide relevant privacy information. We do not infer consent from a person merely appearing in an image.
Armenian and other applicable laws may require specific consent, notices or permissions. Our separate Consent to Personal Data Processing (https://camluma.com/legal/consent-to-processing) covers the specified account, photo and service purposes where consent is the applicable legal basis. It does not cover optional PostHog analytics, advertising, public use of private photographs or model training. Accepting the Public Offer or acknowledging this Policy does not waive privacy rights, authorise every transfer or change a processing activity’s actual legal basis.
Providing an email and the selected image is necessary for the corresponding account and processing functions. You may choose not to provide them, but we cannot provide those functions without the necessary data. Optional analytics is not required to use CamLuma.
4. What happens to a photograph
Your browser sends the photograph over HTTPS to our website server. It is temporarily handled in server memory and sent over HTTPS to our processing backend, which sends it with the effect instructions to BytePlus ModelArk. The active model is Dola Seedream 5.0 Pro. The configured model-processing region is Asia Pacific, Johor, Malaysia.
CamLuma does not deliberately save your original upload to its persistent image storage or application database. It is handled in memory during the request; memory release is controlled by the runtime and is not guaranteed to occur at an exact instant. This statement concerns CamLuma’s handling, not an assurance that the external AI provider keeps no data.
The provider returns a generated image. We return it to your browser and save successful website results to private DigitalOcean Spaces storage in Frankfurt, Germany, for the period below. There are no separate server thumbnail files. Your browser may cache a displayed or downloaded image locally.
CamLuma does not separately create facial recognition templates, compare faces to identify a person or maintain a facial identity database. The face mode changes a prompt; the complete image is still processed by the external model. We do not claim to control or independently audit every internal operation of that model.
5. AI provider use and retention
The CamLuma BytePlus API account is activated; requests are handled according to the account’s tariffs. Data Collaboration Rewards and Model Generation Quality Diagnostics are disabled. CamLuma does not opt submitted photographs or outputs into those data-sharing or model-improvement programmes and does not use them to train its own models.
BytePlus Content Filter is enabled. Under the provider’s ModelArk data-processing documentation, inputs and outputs that trigger its filter may be retained for content-safety purposes for up to 180 days in Malaysia. The documentation reviewed for the service does not identify a single fixed retention period for every other API request. We therefore do not promise zero retention or immediate provider deletion.
We can receive privacy requests and work with the provider under the applicable contractual and legal procedures. CamLuma does not currently have an API control that independently deletes every provider-side copy. Provider safety retention and legally required retention must be considered when answering a request. Google Gemini is not an active provider for the processing described in this Policy.
6. Optional analytics
PostHog Cloud US, United States, is used for product analytics and error tracking only after you opt in to analytics. This consent requirement applies to browser events and to server-side analytics events and error reports sent to PostHog. Before consent, or after rejection or withdrawal, those optional transmissions are disabled. Session Replay is disabled; photographs and session contents are not recorded.
After consent, the current integration can send page views, actions, browser and device properties, registration and account events, payment-flow events and technical error context. It identifies a signed-in user by their Supabase account ID and email. IP-related and approximate location data depend on the project configuration. Image files, image contents and signed image links are excluded from analytics; passwords and full payment details must not be captured.
You can withdraw analytics consent at any time in Cookie settings. Withdrawal stops further optional collection, including server-side transmissions to PostHog, and removes the PostHog cookies and localStorage used by CamLuma from that browser. This browser action does not automatically delete records already held in PostHog. To request deletion of those records, email support@camluma.com; we handle deletion manually within the applicable legal deadlines. Where applicable law requires erasure following withdrawal without a separate request, that duty applies and we do not make a second request a condition of exercising it. Withdrawal does not affect the lawfulness of earlier processing or itself close your account. Records held on a separate valid legal basis are assessed separately. We do not currently run third-party advertising pixels or a marketing email programme. The registration-source cookie is separate from analytics; see section 14.3. Withdrawal of analytics consent does not itself remove its account record, without prejudice to applicable deletion and objection rights.
7. Recipients and processing locations
We disclose data only for relevant service, support, security and legal purposes. Our providers may use authorised subprocessors under their applicable arrangements. A chosen hosting region does not necessarily limit all support access, logs or subprocessors to that country.
Recipient | Purpose and data | Processing location |
|---|---|---|
DigitalOcean | Backend hosting; application database, including account email; saved results and backend backups | Frankfurt, Germany |
BytePlus ModelArk | Input image, selected effect instructions, generated output and content-safety checks | Johor, Malaysia |
Supabase | Authentication, email, protected password data and sessions | Seoul, South Korea |
Resend | Verification and password-reset email; recipient email and message contents | United States and relevant provider infrastructure under its service terms |
Dodo Payments Inc | Checkout, subscriptions, transaction documents, taxes, fraud checks and refunds | United States; other locations under Dodo’s privacy notice |
PostHog Cloud US | Account ID, email, product analytics and errors only after separate analytics consent | United States |
Google Workspace | Support email, reply address, messages and attachments | International Google and subprocessor infrastructure, subject to applicable account and data-location terms |
One authorised CamLuma manager currently has technical access to saved results for support, fault investigation, security and deletion requests. Access must be limited to what the task requires. Authorised provider personnel may have access under their service arrangements. We do not maintain a public gallery. We may disclose necessary information to legal advisers, competent authorities or other parties when legally required or necessary to establish, exercise or defend a legal claim, with applicable safeguards.
If the business is reorganised or transferred, any disclosure must be necessary, protected and consistent with applicable law; we will give any required notice. A business transfer does not grant unrestricted permission to repurpose private photographs.
8. International transfers
The service involves processing and possible access outside your country, including the operator’s activity in Armenia and the provider locations above. Data protection rules may differ between those countries.
International transfers must comply with the law applicable to the relevant route. Where required, this includes an applicable adequacy decision or appropriate contractual safeguards and any necessary additional measures, together with relevant Armenian requirements. The safeguards for a particular provider depend on its contracting entity and applicable data-processing terms; a region setting or acceptance of this Policy alone does not replace them.
Contact support@camluma.com for information about the applicable safeguards, subject to legitimate redaction of confidential terms. We do not treat acceptance of this Policy as a blanket consent that replaces required transfer safeguards.
9. Retention and deletion
Original images are handled transiently in CamLuma server memory as described above. Provider-side content safety retention is separate from CamLuma’s storage schedule.
Saved website outputs are scheduled for deletion 30 days after successful storage. Cleanup normally runs hourly and at backend startup, removing the image object and then its history record. If storage deletion fails or the backend is unavailable, deletion is retried after service resumes. There is no object version history enabled for these images. Output files in Spaces are not included in the Droplet backup.
Account records and edit balances are retained while needed to operate your account. When you request closure, we delete or anonymise data no longer required, while retaining the minimum necessary to resolve outstanding purchases, honour legal duties or establish or defend claims. Financial and tax records are retained for the applicable statutory periods. We do not retain all photographs merely because a payment record must be kept.
Support correspondence is kept while a request remains open and, where necessary, to resolve an identified follow-up issue or claim. Attachments no longer needed are removed. Acceptance records are kept only for the period needed to evidence the relevant agreement or permission and address an applicable legal claim; a photograph is not required merely as proof of accepting Terms.
PostHog product analytics has no fixed automatic event-deletion period in our current configuration. Previously collected personal analytics remains until removed through a manual deletion operation or applicable user-data or project deletion. We limit retention to the disclosed purpose and applicable law; this is not permission to retain identifiable analytics indefinitely. Requests sent to support@camluma.com are handled manually. Section 6 explains withdrawal, browser cleanup and any legal duty to erase without a separate request. PostHog Logs is not used, and its advertised retention period does not describe our analytics events.
Backend error logs contain the user identifier and error text; original images and base64 image data are not written to these logs. Logs are stored in the server’s system journal, with size- and disk-based rotation rather than a fixed age limit. Generation records in the application database are separate from the image files and history records; they currently have no automatic age-based deletion. Their purpose is operation, balance reconciliation, fault investigation and justified claims handling. We must delete or irreversibly anonymise records once no longer needed for a lawful purpose; limited incident or legal-preservation records may be retained separately when justified.
The referral source copied to the account at registration is retained while the account exists, rather than expiring with the 30-day browser cookie. It is deleted or irreversibly anonymised earlier when the attribution purpose ends or an applicable deletion request or objection requires it, subject to any separately justified minimum record for a legal duty or partner-payment claim. Withdrawing analytics consent does not itself remove this independent account entry.
Dodo maintains the buyer’s payment documents and its own required transaction records under its privacy notice. CamLuma retains the limited transaction references, amounts, dates and entitlement records described in section 2 to reconcile access, refunds and disputes, and any minimum records it must keep under applicable law. A record is deleted or anonymised when those purposes and applicable retention or claim periods end. The fact that Dodo issues invoices does not mean CamLuma keeps no account-linked payment metadata.
DigitalOcean backend backups are made daily and retained for seven days. They may contain account, balance, transaction and image metadata, but not the image files in Spaces. The current Supabase configuration does not include scheduled project backups. Data awaiting backup rotation remains protected and unavailable for ordinary use; applicable deletion requests are reapplied if a backup is restored.
User downloads, shared links and browser caches are not all under CamLuma’s control. Deletion from our service does not delete copies another person independently holds. Legal preservation duties may require limited additional retention; we will explain the applicable exception where permitted.
10. Security and access links
We use HTTPS, authenticated account access, private image storage and time-limited signed access links. No security measure is a guarantee against every incident. Protect your account and do not publish signed image links.
A signed link functions as a temporary access credential: anyone who obtains it may retrieve the image while the link and file remain valid. The current signing configuration can leave a link valid for up to seven days from issue. The ordinary unsigned storage address does not grant public access. Where required by law, we will notify affected people and competent authorities of relevant security incidents.
11. Your choices and rights
Depending on the law that applies, you may request access, a copy, correction, deletion, restriction, portability or information about recipients and transfers; object to relevant processing; withdraw consent; and complain to a competent data protection authority. Where US state law gives additional opt-out, appeal or authorised-agent rights and applies to CamLuma, we will provide them. We do not penalise a user for exercising a protected privacy right.
Email support@camluma.com, preferably from the account email, and describe the request and relevant account or image. We may request proportionate information to confirm identity or authority, particularly for another person’s or a child’s photograph. We do not require unnecessary identity documents as a default.
You can request deletion of a result, saved results, your account or other personal data by emailing support@camluma.com. We handle these requests manually within the deadlines required by applicable law. We may retain the minimum information required for a continuing lawful purpose, including payment and tax duties or justified legal claims, and explain the applicable exception. Relevant provider-held data is addressed within the applicable legal and contractual arrangements. Your separate Telegram account is not automatically deleted. Subscription cancellation and refunds are covered by sections 7.5 and 15 of the Public Offer.
We respond within the deadlines required by applicable law. Under the GDPR and UK GDPR this is generally one month, with a permitted extension for complexity or multiple requests if the required notice is given. Other laws may set different periods. Our ordinary support response target is not a substitute for these deadlines. You may complain to your competent authority, including the Armenian Personal Data Protection Agency, an EEA supervisory authority where applicable, or the UK Information Commissioner.
12. Children and automated processing
Accounts are for adults aged 18 or over. Authorised adults may submit ordinary photographs of children under the Terms. This does not remove the child’s privacy rights. Contact us if a minor created an account or if an image of a child was uploaded without proper authority.
AI generation and content filtering are automated. A filter may prevent a particular processing request, and support can review a reported problem within the limits of the provider’s controls. CamLuma does not use image processing to determine a person’s creditworthiness, employment, identity or eligibility for essential services, or to make similarly significant decisions about them.
13. Policy changes
We will update this Policy when practices materially change, identify the new date and version, and provide appropriate notice. If a new use requires consent, we will request it before that use. An update does not itself authorise retroactive model training, advertising use of private images or other incompatible purposes.
14. Cookies and similar technologies
14.1. Storage and your choices
CamLuma uses cookies and similar browser storage for sign-in, requested preferences, consent choices, registration-source attribution and optional analytics. This section forms part of our Privacy Policy.
Cookie settings include Strictly necessary storage, including the registration-source cookie in section 14.3, and optional Analytics. The referral cookie is set before the optional choice when its stated conditions are met. Analytics is off until you opt in; refusal does not restrict registration or paid features. You can change the analytics choice at any time. Browser controls can block or delete storage; blocking authentication cookies may prevent account functions.
14.2. Cookies and storage periods
Storage or name | Purpose | Duration |
|---|---|---|
Supabase authentication | Necessary sign-in and session security | Standard @supabase/ssr cookie Max-Age: 400 days, refreshed when rewritten; may end earlier on sign-out or browser deletion. This is not the access-token lifetime. |
LOCALE_COOKIE | Remember your requested language | 1 year |
EFFECT_COOKIE | Remember your selected effect | 1 year |
FACE_MODE_COOKIE | Remember your selected face mode | 1 year |
COOKIE_CONSENT | Remember optional-storage choices | 180 days; choices may be renewed or requested again after a material change. |
PostHog ph_… cookies | Optional analytics after consent; PostHog Cloud US, United States | Standard posthog-js cookie lifetime: 365 days from setting or renewal. Removed when analytics consent is withdrawn. |
PostHog ph_… localStorage | Optional analytics after consent; PostHog Cloud US, United States | No browser-imposed expiry; removed on consent withdrawal or browser cleanup. This is separate from server event retention. |
Registration-source cookie | Strictly necessary category in our settings; one partner code from ?ref= to attribute a registration only | 30 days; set only on the first visit via a referral link, not overwritten or extended by later visits. At registration the source is copied to the account; separate retention applies. |
The stated authentication and PostHog cookie lifetimes reflect the standard SDK settings used by CamLuma. Session-cookie expiry is separate from access-token validity and may be refreshed; browser limits can shorten persistence. localStorage has no inherent automatic expiry. The 180-day consent choice has a separate lifetime: optional collection requires a current valid consent, even if a technical identifier could otherwise last longer.
14.3. Analytics and registration source
After separate analytics consent, PostHog Cloud US in the United States receives account ID, email, usage events and error information described in section 6, including authorised browser and server events. Session Replay is disabled. Browser traffic is routed through CamLuma’s /ingest proxy to us.i.posthog.com. Using our proxy does not change the recipient or US processing location. Accepting the Public Offer or the general Consent to Personal Data Processing does not activate analytics.
You can withdraw analytics consent at any time in Cookie settings. Withdrawal stops further optional collection, including server-side transmissions to PostHog, and removes the PostHog cookies and localStorage used by CamLuma from that browser. This browser action does not automatically delete records already held in PostHog. To request deletion of those records, email support@camluma.com; we handle deletion manually within the applicable legal deadlines. Where applicable law requires erasure following withdrawal without a separate request, that duty applies and we do not make a second request a condition of exercising it. Withdrawal does not affect the lawfulness of earlier processing or itself close your account. Records held on a separate valid legal basis are assessed separately.
Our Cookie settings classify the registration-source cookie as Strictly necessary for our registration-source attribution process. It is one first-party HttpOnly cookie containing only a partner code. It is set only on a first visit through a URL containing ?ref=, lasts 30 days and is not overwritten or extended by later visits. Its sole use is to record, at registration, which partner link brought you to CamLuma; it does not track activity across other websites and is not used for analytics or shared with partners or other third parties for their own purposes. It is handled within the service infrastructure described in this Policy. At registration, the code is copied to users.referral_source in the account. Cookie expiry or browser deletion does not remove that separate account entry; its retention and your applicable deletion or objection rights are described in section 9 of this Policy. Analytics settings do not control this cookie. This classification does not mean that the cookie is needed to edit a photo or create an account without referral attribution.
14.4. Payment pages and changes
Dodo’s hosted checkout and customer portal are separate services and may use their own necessary or optional storage under their own notices and controls. The CamLuma cookie choice is not a promise to control all storage on those separate pages.
We will update this Policy and the consent interface if the storage purposes or providers change. A new optional purpose will not be enabled solely because we revised this page. Questions: support@camluma.com.
Related documents: https://camluma.com/legal/public-offer · https://camluma.com/legal/consent-to-processing