Legal

Privacy Policy

Last updated: January 2026

Zero-Logs Commitment

HideMyLens does not store filenames, EXIF metadata, processed images, or any record of your cleaning activity. Your photos are processed entirely in your browser. We cannot see them, and we cannot leak what we do not have.

1. What this policy covers

This policy describes what data HideMyLens collects, how we use it, who we share it with, and the rights you have over your data. It applies to our website, web application, and any related services at hidemylens.com.

2. The Zero-Logs Commitment (what we do NOT collect)

The following information is never stored on our servers, because it never reaches them in the first place:

  • The contents of your photos (pixels, file bytes).
  • Filenames of the photos you clean.
  • EXIF metadata extracted from your photos (GPS, camera model, timestamps, etc.).
  • Records of when, how often, or how many photos you have cleaned.
  • Thumbnails, previews, or derivatives of your photos.

All photo processing runs in your browser using the Web Crypto API, Canvas API, and open-source libraries (exifr, piexifjs). You can verify this by monitoring your browser's Network tab while using the tool — no upload requests are made.

3. What we do collect

Account information

If you create an account, we store:

  • Your email address (for sign-in and billing).
  • Your chosen display name.
  • Whether you have an active Pro subscription.
  • Your subscription ID and status (provided by our payment processor).
  • The date and time your account was created.

Guest rate-limiting

For users who use HideMyLens without an account, we enforce a one-free-photo limit using a hashed browser fingerprint. Your browser generates a fingerprint from non-identifying characteristics (screen size, installed fonts, etc.); that fingerprint is then hashed with SHA-256 before being sent to our server. We store only the hash and a counter, with no link to any identity. These records are automatically purged after 30 days.

Authentication sessions

When you sign in, our authentication provider (Supabase) issues a JWT-based session. The token is stored in an HttpOnly cookie. We do not maintain a separate session log.

Payment data

Subscription payments are processed by LemonSqueezy, our merchant of record. We do not receive or store your payment card details. LemonSqueezy's privacy policy applies to that data.

4. Why we collect it

We process the limited data above solely to:

  • Authenticate you into your account.
  • Determine whether you have Pro access.
  • Bill and manage your subscription (via LemonSqueezy).
  • Enforce anti-abuse limits on free usage.

5. Who we share it with

Data is shared only with service providers strictly necessary to operate the product:

  • Supabase — authentication and profile database.
  • LemonSqueezy — subscription billing.
  • Vercel — application hosting.

We do not sell personal data. We do not share data with advertisers. We do not use third-party analytics that identify individual users.

6. Cookies and tracking

HideMyLens uses only essential cookies required for authentication. We do not use advertising cookies, cross-site trackers, or marketing pixels.

7. Your rights

Under GDPR, CCPA, and similar regulations, you have the right to access, correct, export, and delete the personal data we hold about you. Because our data footprint is so small, most of these rights are satisfied by the self-service controls in your account settings. For account deletion or data export, email privacy@hidemylens.com.

8. Data retention

Account profiles are retained as long as your account is active. If you delete your account, we remove your profile immediately. Guest fingerprint hashes are purged after 30 days. Payment records required for tax and legal compliance may be retained by LemonSqueezy according to their policy.

9. Children's privacy

HideMyLens is not directed at children under 13. We do not knowingly collect personal data from children.

10. Changes to this policy

If we make material changes to this policy, we will notify you by email (if you have an account) and update the "Last updated" date at the top of this page. Privacy-reducing changes will require your affirmative consent before they apply to you.

11. Contact

For privacy questions: privacy@hidemylens.com.