In short
- An account needs a nickname and a name — they may be fictitious. We do not ask for a phone number; an email address is optional and used only for notifications.
- Data is stored on servers in Poland (EU). Files are encrypted, but not end-to-end: the server decrypts a file to show it to those you gave access.
- No advertising or analytics: only necessary cookies.
- You enter card or wallet details on the payment service page — we never receive them.
- You can access, correct, export and delete your data in the settings or through support.
A plain-language summary for convenience. The terms are in the text below.
1.General
The personal data controller is [company name], a company registered in the Emirate of [emirate], UAE, licence or registration number [licence or registration number] (“we”). Contacts are in section 13.
This policy covers data we receive through the lac.pics website, the personal account area, the lacuna app for Windows and the API.
We honour user rights to the extent provided by the EU General Data Protection Regulation (GDPR); they are described in section 10.
Terms are used as defined in the terms of service.
2.What data and why
We process only the data needed to run the service.
| Data | Purpose | Retention |
|---|---|---|
| Account: nickname, name, “about” text and avatar if you added them, language and settings | Sign-in, profile, upload settings | While the account exists |
| Login key — irreversible hashes only; we do not store the key itself | Checking the key at sign-in | While the account exists |
| Your email address, if you linked one: the address, the date it was confirmed, which emails to receive; a log of emails sent (the kind of email, time, delivery result); one-time confirmation codes — only as hashes | Emails about the free trial, payments, account security and your cards in Bugs & ideas (comments, status changes, team replies); confirming that the address is yours | The address — while it is linked (you can remove it in the settings; it is deleted together with the account); codes — up to 2 days; the sending log — 90 days; addresses whose owners pressed “This wasn’t me” or unsubscribed from all emails — only an irreversible hash, so that we do not write to them again |
| Sessions: browser and device (the User-Agent string), sign-in and last activity time | Keeping you signed in, showing your devices | Until sign-out, no longer than 30 days |
| API keys: name, permissions, expiry, key hash | Access for programs: your own scripts and programs, the lacuna app for Windows | Until revoked or expired |
| Computers with the app for Windows: the computer name, the lacuna and Windows versions the app reports, the time of its first and last contact with the server, whether it is connected now | Showing you and administrators where you are signed in; disconnecting a device; support and releasing updates | While the account exists; deleted together with the account |
| Installer downloads: time, version and your account if you were signed in to the website; otherwise only an IP address hash (HMAC with the server’s secret key; the address itself is not stored) | Counting downloads by version and day, protecting downloads from abuse | 90 days, at once when the account is deleted; daily counts without personal data are kept |
| Account block: the date and the reason, if an administrator chose to show it to you | Explaining why access is closed | While the account is blocked |
| API request log: method, path, response code, duration | Showing you your request history, finding errors and abuse | 30 days |
| Content: files and notes, titles, tags, original file names, size and type, access settings, view count, albums, favourites, subtitles | Storing and showing content according to your settings | Until you delete it, its expiry ends or the account is deleted |
| IP address hash — HMAC with the server’s secret key; the address itself is not stored in the database | Request limits, protection against guessing keys and passwords | Up to 24 hours |
| Viewer cookie for protected links (stored as a hash) and viewing permission | Not asking for the password again, enforcing one-time links | Permission up to 24 hours, cookie 30 days |
| Payments: number, plan, period, amount, currency, payment method, status, dates, the payment service’s reference and its payment notifications; notifications about a cryptocurrency payment may include the sender’s wallet address and the transaction hash | Payment, refunds, accounting, handling disputes | As long as tax and accounting rules require; after account deletion — without a link to it |
| Subscription history: plan, dates, changes | Showing and enforcing the subscription period | While the account exists |
| Free trial: plan, dates and hashes of the IP address and network it was started from (HMAC with the server’s secret key; the addresses themselves are not stored) | Giving the free trial once and not again to new accounts from the same address or network | Hashes — 30 days; the mark that the trial was taken — while the account exists, after its deletion — up to 30 days from the start of the trial |
| Invitations: who invited whom, invitation labels, showing your nickname in invitations | Running invitations | While the account exists; after its deletion — without a link to it |
| Reports: who reported (nobody for a report sent without an account), which content, reason, comment, decision | Moderation | As long as needed for moderation and handling repeat violations; when the reporter’s account is deleted, their identifier and comment are erased |
| Results of the automatic check of uploads: scores by category, time of the check, the checking service — without the images themselves | Protection against illegal content, moderation | While the content exists; scores behind a report — together with the report |
| Support requests and emails to us, including to abuse@lac.pics and support@lac.pics: correspondence, attachments, the sender’s email address. Emails are kept on our mail server and in the moderation console | Answering requests, handling complaints and requests | As long as needed to answer the request and handle related questions |
| Data export: a temporary snapshot of the archive contents and a download ticket | Exporting your data | Snapshot 60 minutes, service records 24 hours |
| Web server logs: IP address, time, request path, browser | Security and diagnostics | Up to 30 days |
We do not ask for a phone number, identity documents or bank card data. You may link an email address if you wish — for notifications only: it cannot be used to sign in or to recover the login key. Otherwise we only get your email address if you write to us.
Personal metadata is removed from images on upload: location, device serial numbers, XMP, IPTC and comments. For videos we keep one version — the one you uploaded (the app and the website compress it on your device beforehand) — repackaged without metadata: it is the one that is watched and the one that is downloaded if you allowed downloads. The original file is not kept on the server.
The app for Windows processes screenshots and recordings on your computer. Only files you upload yourself reach the server. If you turned on automatic upload (it is off by default), the app also uploads new screenshots. The app keeps its API key in Windows Credential Manager.
While the app is open, every minute or two and when its window opens it asks the server whether its key still works and reports its own version and the Windows version. This way a disconnected device or a blocked account reaches the app at once. No files are sent for this.
Video editing and compression and file conversion in the browser run on your device. A file reaches the server when you save it.
We do not analyse content for advertising or profiling and do not recognise faces — we do not establish who is shown. The check for illegal content is described in section 4.
3.Legal grounds
Performance of the agreement with you — the terms of service: account, content, links, sessions, API, subscription, invitations, export, support. This includes service security, request limits, moderation and protecting the free trial from repeated registrations: without them the service cannot be provided safely and fairly.
Obligations imposed on us by law: payment accounting, responses to lawful requests of state bodies.
Protecting our rights and handling disputes: the history of payments and report decisions.
Your choice: you make your public profile and content shared by link or publicly available to others yourself, and you can close access at any time.
4.How we process data
Processing is automated: collection, recording, organisation, accumulation, storage, updating, retrieval, use, transfer (provision, access), blocking, deletion and destruction.
Decisions to block an account or delete content after a report are made by a person, not an algorithm.
Uploaded images and videos may be checked automatically by an external processing service for illegal content — above all child sexual abuse material — and for violations of the sharing rules. The service receives a reduced copy of an image or a few frames of a video, not the original file and not the whole video, and returns only scores. We choose a processor that acts on our instructions, does not use the images for its own purposes and does not keep them after the check. If a score is high, the content is visible only to you until a moderator decides, and the moderator receives a report. The final decision is made by a person; you can contest it through support.
We do not sell data or use it for advertising.
5.Who sees your data
Other users and visitors — according to your settings:
- private content is visible only to you;
- unlisted content is visible to anyone with the link;
- public content may appear in the public feed and in your profile;
- the page of content shared by link or publicly shows its title, your name and nickname — they also appear in link previews in messengers and social networks;
- your profile — name, nickname, “about” text, avatar — is visible to signed-in users;
- your invitations show your nickname unless you turned this off.
A link recipient can save a copy, forward the link or record the screen. If you close access or delete content, copies kept by recipients and previews in external services remain.
Administrators see service data of accounts — for example the nickname, name, dates, storage used, payments and the API request log. An administrator can open content, including private content, only through the private review tool — to review a report, check a violation or comply with the law. Every opening is logged.
Payment services receive the data needed for the payment:
- Platega (platega.io) — the amount, order number, account identifier and nickname, which its anti-fraud system requires;
- Heleket (heleket.com) — the amount, currency and payment number;
- you enter card, account or wallet details on the payment service page. Payment services process data under their own rules, including outside the EU and the UAE.
Hosting: the servers that run lacuna and store files are provided by a hosting provider in Poland (EU). Files on the servers are stored encrypted.
Emails are sent by our own mail server in Poland (EU). An email is delivered to the mail service that handles your address (for example Gmail or Yandex Mail) and is then processed under its rules. We do not use third-party mailing services; if we start using one, we will update this policy.
The automatic checking service, when the check is on, receives reduced copies of uploaded images and video frames — to check them for illegal content (section 4).
hCaptcha (Intuition Machines, Inc.), when the “I am not a robot” check is on, receives the IP address and technical data about the browser and device during registration, sign-in after several failed attempts and reports sent without an account, to tell people from bots. Without hCaptcha a built-in check runs that sends nothing anywhere.
State bodies — only on the grounds and in the manner established by law.
6.Where data is stored
Servers and databases with personal data are located in Poland, in the European Union, where the GDPR applies. [to verify: the service also targets users in Russia — Russian language, rouble payments; storing Russian users’ data in Russia may be required]
Data leaves the EU only for payments — to the payment services — and, when hCaptcha is on, for the “I am not a robot” check: its servers are in the USA (section 5). Emails to a linked address are delivered to the mail service of that address, which may also be outside the EU. We choose an automatic checking service that processes data in the EU. Any other transfer abroad is made only on conditions permitted by applicable law.
8.How we protect data
Files are stored encrypted (AES-256-GCM); encryption keys are kept separately from the files.
The login key, API keys and link passwords are stored only as hashes.
Connections to the service are protected with HTTPS.
Administrator access is role-based, requires a second factor and is logged. The administration console is closed to all addresses except allowed ones.
Backups are encrypted.
If a breach occurs that may affect your data, we will notify the UAE Data Office where the law requires it and inform users in the service. Please report a suspected leak or vulnerability to support.
9.Retention and deletion
We keep data while it is needed for the purposes in section 2 and delete it when the purpose is achieved or you delete the data.
Deleted content becomes unavailable immediately; its files are removed from storage in the background.
Account deletion is in the settings and is confirmed with the login key and the nickname. Access closes immediately: sign-in, sessions, API keys, links and profile. Content, albums, favourites, keys and the request log are deleted in the background.
After account deletion the following remain: payment records — without a link to the account, for the period in section 2; the history of report decisions — without the reporter’s data; the free trial mark — up to 30 days from its start; the administrator action log and internal notes — as long as they are needed for security and handling violations.
Backups are kept for up to 28 days, pinned backups (for example, those made before a service update) for up to 30 days, and backups in the separate storage for up to 41 days. We keep a backup longer only if this is needed to investigate an incident or required by law. Until a backup is deleted, it contains data of deleted accounts and content.
Deletions of accounts and content are recorded in a separate journal — internal identifiers and times only. If a backup has to be restored, every deletion made after it was created is repeated from this journal before access opens.
10.Your rights
You can:
- access your data: learn what data we process and why, and get a copy;
- correct your data: the profile in the settings, anything else through support;
- delete your data: content and the account in the settings, anything else on request unless the law requires us to keep it;
- export your data in a machine-readable format — as an archive in the account settings;
- object to processing or ask us to restrict it, for example while we check your request;
- withdraw consent where processing is based on consent — this does not affect processing before withdrawal;
- complain to a supervisory authority: the UAE Data Office or, if you live in the EU, the data protection authority of your country.
Send your request through support in the account area — this way we immediately see it comes from the account owner. Without access to the account, write to [email for legal notices]; we may ask you to confirm that the account is yours.
We reply within 30 days. For complex requests the period may be extended — we will tell you why.
An export covers up to 1,000 files and 10 GB at a time. If you have more data, contact support.
11.Children
The service is not intended for persons under the age stated in clause 3.5 of the terms of service. If you learn that a child created an account without parental consent, write to us and we will delete the account.
12.Changes to this policy
We publish a new version on this page with its date. We announce material changes in the service in advance.
If new ways to sign in appear, for example with Google, Yandex, VK, Telegram, Discord or GitHub, we will describe here what data we receive from those services before they launch.
13.Contacts
- Controller
- [company name]
- Licence or registration number
- [licence or registration number]
- Emirate of registration
- [emirate]
- Address
- [address]
- [email for legal notices]
- Support
- in the lacuna account area — lac.pics/console