Privacy & Storage Notice
Last updated 31 August 2026
This notice explains what Lust.ai records about you, why, and what you can do about it. It covers the cookie and browser-storage disclosure required by PECR as well as the information required by the UK GDPR.
1. Who is responsible
[TRADING NAME — required before this site is public], [POSTAL ADDRESS — required; a PO box is not sufficient in the UK], is the data controller for the personal data described here. Contact: [email protected].
2. What we collect
- Your account — the username you sign in with, and a bcrypt hash of your password. The password itself is never written to disk and cannot be recovered from the hash.
- Your session — a signed cookie proving you are signed in. It holds your username and an expiry time, nothing else, and it lasts 12 hours.
- Server logs — your IP address and the time of each request, which the web server records by default. An IP address is personal data under the UK GDPR, which is why it is listed here.
- Prompts and generated images — what you asked for, the settings used, and the resulting files. These are stored so the gallery persists and so a generation can be repeated.
- Refused prompts — where a prompt is blocked for referring to a minor, we record the prompt, the account, the IP address and the time. See section 5.
- Failed sign-in attempts — counted per IP address, in memory only, to enforce a lockout. This is discarded when the server restarts.
We do not use analytics, advertising, tracking pixels, or any third-party script. There is no third party receiving your browsing behaviour.
3. Why we can process it (lawful basis)
- Contract — running the account and delivering the Service you asked for.
- Legitimate interests — keeping the Service secure, preventing abuse, and enforcing the acceptable use policy. We consider this proportionate because the data involved is minimal and is not used for any other purpose.
- Legal obligation — retaining records of refused prompts, and responding to lawful requests.
4. Cookies and browser storage
Strictly-necessary storage does not require your consent, but it does have to be disclosed. This is the complete list of what is stored in your browser:
session— an HttpOnly, SameSite=Lax cookie holding your signed session token. Strictly necessary; without it you cannot stay signed in. Expires after 12 hours or when you sign out.genDefaults— a localStorage entry remembering your last generation settings, so the form is not blank each visit. A preference, kept until you clear your browser data.vastSshConfig— a localStorage entry remembering the GPU connection details you last entered, so you do not retype them.- The age confirmation, in localStorage, so the notice is not shown on every page.
None of these are used for advertising or shared with anyone. Clearing your browser storage removes all of them; you will simply be signed out and the form will return to its defaults.
5. How long we keep things
- Generated images and their prompts — until you delete them. Deleting an image from the gallery removes both the record and the file.
- Refused-prompt records — kept indefinitely at present, because their whole purpose is to evidence that the Service refuses this class of request. If that ever changes, this notice changes with it.
- Server logs — as long as the host keeps them.
- Account — until the account is removed.
6. Who else sees your data
Image generation does not happen on this server. Prompts are sent over an encrypted SSH tunnel to a rented GPU machine, which runs the model and returns the image. That machine is supplied by a third-party compute marketplace and may be located outside the UK and the EEA. The operator of that machine has physical access to it.
Nothing is sold, and nothing is shared for advertising. We disclose data only where the law requires it.
7. Security
Passwords are hashed with bcrypt at cost 12. Session tokens are signed with HMAC-SHA256 and compared in constant time. Sign-in attempts are rate limited per address. Access is restricted to a private network rather than the public internet.
No system is perfectly secure, and this one is operated by an individual rather than a staffed organisation. Do not put anything into it that you could not afford to have exposed.
8. Your rights
Under the UK GDPR you can ask for a copy of your data, ask for it to be corrected or erased, object to processing based on legitimate interests, ask for processing to be restricted, and ask for your data in a portable form. Write to [email protected].
If you are not satisfied with the response, you can complain to the Information Commissioner's Office (ICO), ico.org.uk.