Privacy

Privacy Notice

1. Scope and contact

This notice explains how AnchorLens processes information when you create an account or use the image-reconstruction experiment. For privacy questions or requests to access, correct, or delete your personal information, contact us at privacy.anchorlens@gmail.com.

2. Account and usage information

For members, AnchorLens processes your full name, username, email address, authentication records, terms-and-privacy consent record, account identifier, daily allowance, and generation-usage timestamps. Supabase manages authentication credentials and stores passwords in protected hashed form; AnchorLens does not receive or store a readable copy of your password.

3. Uploaded images and descriptions

Your uploaded image, selected anchor and mask, and scene description are processed automatically through the AnchorLens server and sent to OpenAI to produce a reconstruction. The AnchorLens application does not intentionally save this content to its own database or reuse it to build a user profile. The application operator does not routinely inspect uploaded images or generated results.

Processing by infrastructure and AI providers is still necessary to deliver the request. OpenAI and the hosting provider may temporarily process or retain request data under their own service, security, abuse-prevention, and legal requirements. OpenAI states that API data is not used to train its models by default, but that API inputs and outputs may generally be retained for up to 30 days unless a different approved retention arrangement applies. Do not upload confidential information, sensitive personal data, or images you are not authorized to process.

4. Statistics and service improvement

AnchorLens may use limited technical and aggregate statistics—such as the number of reconstruction requests, success or error rates, quota usage, and general service performance—to operate, secure, evaluate, and improve the application. These statistics are not intended to include the content of your uploaded image or scene description. Per-account generation timestamps remain linked to an account while needed to enforce its allowance; reports used for general statistics should be aggregated or de-identified where practical.

Similarity measurements such as MSE, PSNR, and SSIM are currently calculated in your browser and are not intentionally sent to or stored in the AnchorLens database.

5. Guest API keys

A guest OpenAI API key is transmitted to the AnchorLens server only to perform the requested generation. The application does not intentionally write it to a database, file, browser storage, or API response. Hosting infrastructure still processes the request in transit. Use a restricted project key, monitor its usage, and revoke it if you believe it has been exposed.

6. Purposes and legal grounds

Account and request information is processed to provide the service you request, authenticate users, deliver reconstructions, enforce allowances, respond to support requests, and administer the account. Security, abuse prevention, reliability monitoring, and limited aggregate service statistics are processed for the operator's legitimate interests in protecting and improving AnchorLens, provided those interests are not overridden by applicable privacy rights. Information may also be processed when necessary to comply with law. The operator should confirm these legal grounds for the countries in which the service is offered before launch.

7. Service providers and international processing

AnchorLens relies on Supabase for authentication and database services, OpenAI for image processing, Cloudflare Turnstile for bot protection, and the configured hosting provider for website delivery and server functions. These providers receive only the information needed for their role and process it under their own terms and privacy commitments. Depending on provider configuration and user location, information may be processed outside your country, including outside the European Economic Area, subject to the safeguards offered by the relevant provider.

8. Retention and deletion

Account profiles and linked usage records are retained while the account is active and for as long as reasonably necessary to operate, secure, or comply with legal obligations. Deleting an authentication user is configured to delete the related AnchorLens profile and usage records. Uploaded images, masks, descriptions, generated images, guest API keys, and browser-calculated metrics are not intentionally retained in the AnchorLens database. Temporary copies and technical logs controlled by service providers follow the providers' applicable retention periods.

9. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of personal information, receive a portable copy, or lodge a complaint with a data-protection authority. You may request account deletion through the contact route above. You may also use guest access with your own API key instead of creating an account, although the image request must still pass through the configured service providers.

10. No sale, security, and changes

AnchorLens does not sell personal information or use uploaded images for advertising or unrelated profiling. Reasonable technical and organizational safeguards are used, but no internet service is risk-free. This notice may be revised when the application, providers, or legal requirements change; the effective date identifies the current version. Material changes should be presented to users where required.