Legal

Privacy Policy

Version 1.0, effective 25 September 2026.

We collect as little as we can. Images you send for processing are handled in memory and deleted as soon as the result is returned.

1. Who is responsible

The controller of your personal data is JAUPIN Design LLC (Sharjah Media City (Shams) Free Zone Authority licence no. 2430614.01), Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, United Arab Emirates, United Arab Emirates, operating lassocut. For any question or request about your data, write to contact@lassocut.com. We answer within one month.

2. What we process, why, and for how long

DataPurposeLegal basisKept for
Email address and GitHub or Google account identifierCreate and secure your account, send service and payment messagesContractWhile your account is open, then 30 days
API keys (stored only as a one-way hash, plus the last 4 characters)Authenticate API callsContractUntil you delete the key or the account
Usage and credit history (dates, sizes, credits used, results sizes)Count credits, show your history, prevent abuseContractWhile your account is open, then 30 days
Purchase records (pack, amount, date, Stripe reference, business name and VAT number you give at checkout)Deliver credits, keep accounting records, handle refundsContract and legal obligation5 years after the purchase
Images you send for processing and the resultsRemove the background and return the resultContractProcessed in memory and deleted as soon as the result is returned; not used for training
Images you choose to send to /improveImprove our modelsConsent, given by sending them; you can withdraw it at any timeUntil you ask us to delete them, and at most 24 months
Technical logs (IP address, time, endpoint, response code)Security, rate limits, fraud prevention, troubleshootingLegitimate interest in running a secure serviceUp to 90 days
Messages you send usAnswer youContract or legitimate interest3 years

We do not sell personal data, do not use it for advertising, do not profile you and make no automated decisions with legal effect. Photos may show people, but we only separate the subject from the background: we do not identify anyone and create no biometric identifiers.

Card details are entered on Stripe's payment page and never reach us.

3. Who else handles your data

We use these service providers, each bound by a data processing agreement:

  • Supabase: database and sign-in (hosted in Frankfurt, Germany). DPA
  • Modal Labs: image processing on GPU servers (United States). DPA
  • Vercel: website hosting and request routing. DPA
  • Stripe: payments and receipts; Stripe processes the transactions for us. DPA
  • GitHub and Google: only when you choose to sign in with them; they tell us your email and account identifier.

We may disclose data when the law requires it, or to protect the Service and its users against fraud or abuse.

4. International transfers

lassocut is operated from the United Arab Emirates, and some providers are in the United States. Where data from the European Economic Area, the United Kingdom or Switzerland goes to a country without an adequacy decision, we rely on the EU-US Data Privacy Framework for certified providers (Stripe, Vercel, Google, GitHub) and on the European Commission's Standard Contractual Clauses in the providers' DPAs (Supabase, Modal). You can ask us for a copy of these safeguards.

5. Your rights

You can ask us to access, correct, delete or export your data, to restrict or object to its processing, and withdraw consent at any time without affecting past processing. Write to contact@lassocut.com; we may ask you to confirm your identity from your account email. Deleting your account deletes your keys and history, except records we must keep by law.

You can complain to a data protection authority, in particular in the country where you live or work (for example the UK ICO or an EU authority), and in the UAE to the UAE Data Office.

6. Browser storage

We do not use analytics, advertising or tracking cookies, so there is no cookie banner. When you sign in, your browser stores your session in local storage so you stay signed in; this is strictly necessary for the account you asked for, and it is removed when you sign out. Stripe's payment page, on stripe.com, uses its own cookies to process payments and prevent fraud.

7. Security

Connections are encrypted (HTTPS). API keys are stored only as hashes. Database access is restricted to our servers. If a breach puts your data at risk, we will inform you and the competent authorities as the law requires.

8. Children

The Service is for businesses and is not intended for anyone under 16.

9. Changes

We will publish any change here with a new version date, and tell account holders by email about important changes.