Privacy Policy
Version 1.0, effective 25 September 2026.
We collect as little as we can. Images you send for processing are handled in memory and deleted as soon as the result is returned.
1. Who is responsible
The controller of your personal data is JAUPIN Design LLC (Sharjah Media City (Shams) Free Zone Authority licence no. 2430614.01), Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, United Arab Emirates, United Arab Emirates, operating lassocut. For any question or request about your data, write to contact@lassocut.com. We answer within one month.
2. What we process, why, and for how long
| Data | Purpose | Legal basis | Kept for |
|---|---|---|---|
| Email address and GitHub or Google account identifier | Create and secure your account, send service and payment messages | Contract | While your account is open, then 30 days |
| API keys (stored only as a one-way hash, plus the last 4 characters) | Authenticate API calls | Contract | Until you delete the key or the account |
| Usage and credit history (dates, sizes, credits used, results sizes) | Count credits, show your history, prevent abuse | Contract | While your account is open, then 30 days |
| Purchase records (pack, amount, date, Stripe reference, business name and VAT number you give at checkout) | Deliver credits, keep accounting records, handle refunds | Contract and legal obligation | 5 years after the purchase |
| Images you send for processing and the results | Remove the background and return the result | Contract | Processed in memory and deleted as soon as the result is returned; not used for training |
Images you choose to send to /improve | Improve our models | Consent, given by sending them; you can withdraw it at any time | Until you ask us to delete them, and at most 24 months |
| Technical logs (IP address, time, endpoint, response code) | Security, rate limits, fraud prevention, troubleshooting | Legitimate interest in running a secure service | Up to 90 days |
| Messages you send us | Answer you | Contract or legitimate interest | 3 years |
We do not sell personal data, do not use it for advertising, do not profile you and make no automated decisions with legal effect. Photos may show people, but we only separate the subject from the background: we do not identify anyone and create no biometric identifiers.
Card details are entered on Stripe's payment page and never reach us.
3. Who else handles your data
We use these service providers, each bound by a data processing agreement:
- Supabase: database and sign-in (hosted in Frankfurt, Germany). DPA
- Modal Labs: image processing on GPU servers (United States). DPA
- Vercel: website hosting and request routing. DPA
- Stripe: payments and receipts; Stripe processes the transactions for us. DPA
- GitHub and Google: only when you choose to sign in with them; they tell us your email and account identifier.
We may disclose data when the law requires it, or to protect the Service and its users against fraud or abuse.
4. International transfers
lassocut is operated from the United Arab Emirates, and some providers are in the United States. Where data from the European Economic Area, the United Kingdom or Switzerland goes to a country without an adequacy decision, we rely on the EU-US Data Privacy Framework for certified providers (Stripe, Vercel, Google, GitHub) and on the European Commission's Standard Contractual Clauses in the providers' DPAs (Supabase, Modal). You can ask us for a copy of these safeguards.
5. Your rights
You can ask us to access, correct, delete or export your data, to restrict or object to its processing, and withdraw consent at any time without affecting past processing. Write to contact@lassocut.com; we may ask you to confirm your identity from your account email. Deleting your account deletes your keys and history, except records we must keep by law.
You can complain to a data protection authority, in particular in the country where you live or work (for example the UK ICO or an EU authority), and in the UAE to the UAE Data Office.
6. Browser storage
We do not use analytics, advertising or tracking cookies, so there is no cookie banner. When you sign in, your browser stores your session in local storage so you stay signed in; this is strictly necessary for the account you asked for, and it is removed when you sign out. Stripe's payment page, on stripe.com, uses its own cookies to process payments and prevent fraud.
7. Security
Connections are encrypted (HTTPS). API keys are stored only as hashes. Database access is restricted to our servers. If a breach puts your data at risk, we will inform you and the competent authorities as the law requires.
8. Children
The Service is for businesses and is not intended for anyone under 16.
9. Changes
We will publish any change here with a new version date, and tell account holders by email about important changes.