NoLooky was built around a simple idea: software should not need to inspect your private photo library on somebody else's server in order to organise it.
Privacy-first does not mean the website processes no personal data. This Policy explains what stays local, what the website receives, why it is processed, and what rights you may have.
Privacy Summary
What stays local
- Photos and videos
- Thumbnails
- EXIF data and filenames
- AI detections/classifications
- Image hashes and duplicate groups
- Scan, sort, CSV, and undo reports
What the online service receives
- Account email
- Payment confirmation and Stripe references
- License key/device identifiers
- Device name and app version
- Support messages you send
Contents
- Data Controller
- Scope
- Core Local-Processing Promise
- Website Personal Data
- Purchase Data
- License Data
- Email Data
- Purposes and Legal Bases
- Cookies
- Recipients and Processors
- International Transfers
- Retention
- Security
- Your Rights
- Automated Decision-Making
- Children
- Data Breaches
- Changes
- Contact
1. Data Controller
Controller: [LEGAL COMPANY NAME], trading as [TRADING NAME]. Address: [REGISTERED ADDRESS], [COUNTRY]. Company number: [CVR / COMPANY NUMBER]. Privacy contact: [PRIVACY EMAIL].
[CONFIRM BEFORE PUBLICATION: complete controller identity, address, company number, and privacy contact details.]
2. Scope
This Policy covers the NoLooky website, user accounts, downloads, purchases, emails, licensing API, desktop app communications with the licensing API, support, and related service communications. It does not cover unrelated third-party services that you use independently.
3. Core Local-Processing Promise
Ordinary scanning, previewing, AI inference, duplicate detection, sorting, and report creation are local to your computer. NoLooky does not upload photos, videos, thumbnails, filenames, folder paths, EXIF metadata, image hashes, AI classifications, duplicate groups, reports, or facial/object data merely because you use the desktop app.
Local thumbnails, model files, caches, reports, and settings may be stored on your computer. You control the folders you select. Data may leave your device if you voluntarily send it to support, use third-party backup/sync tools, or if your operating system, antivirus, security, or other software processes it independently outside NoLooky's control.
4. Personal Data Collected Through the Website
The website may process your email address, account ID, password hash, account creation time, login/session data needed for authentication, password-reset token hashes and expiry times, legal acceptance timestamps and document versions, support communications, and essential session/cookie data.
Passwords are stored only as secure password hashes, not plaintext passwords. [CONFIRM BEFORE PUBLICATION: whether IP/security logs, optional names, or additional account fields are collected by hosting/server logs.]
5. Purchase Data
NoLooky may process Stripe Checkout session ID, payment intent ID, customer ID reference, payment status, amount, currency, customer email, purchase date, and associated account/license references. Stripe handles card details, and NoLooky normally does not receive full card numbers or CVC.
6. License Data
License activation and checks may process license key or protected reference, license type/status, device limit, stable random device ID, device name, app version, activation time, last-check time, and activation/check result.
The stable device ID is used to enforce device limits and support license activation. It is not intended as invasive hardware fingerprinting.
7. Email Data
NoLooky may send registration/welcome emails, purchase/license emails, password reset emails, service notices, security notices, and support replies. Marketing emails will be sent only where separately consented to or otherwise legally permitted. Transactional and security emails cannot always be opted out of while your account or service remains active.
8. Purposes and Legal Bases
| Purpose | Data | Legal basis |
| Account creation and login | Email, password hash, session data | Performance of contract; legitimate security interests |
| Software/license delivery | Account, license, download and activation records | Performance of contract |
| Payment processing | Stripe references, amount, currency, status, customer email | Performance of contract; legal obligations |
| Fraud and security | Session, payment, license and security records | Legitimate interests; legal obligations where applicable |
| Support | Messages and account/license details you provide | Performance of contract or legitimate interests |
| Marketing | Email and preferences | Consent where required |
| Accounting and tax | Purchase and transaction records | Legal obligation |
| Password resets | Email, reset token hash, expiry | Performance of contract; legitimate security interests |
9. Cookies
The website uses essential session/security cookies for login, CSRF protection, account access, admin access, and checkout flow continuity. Stripe may use payment-related cookies under its own policies during Checkout.
[CONFIRM BEFORE PUBLICATION: no analytics cookies appear in the current code. If analytics or non-essential cookies are introduced, add cookie consent and update this Policy.]
10. Recipients and Processors
Personal data may be processed by hosting providers, Stripe, email delivery providers, IT/security providers, professional advisers, and public authorities where legally required. [CONFIRM BEFORE PUBLICATION: hosting is DreamHost if accurate; confirm email provider and any additional processors.]
NoLooky does not sell personal information.
11. International Transfers
Hosting, Stripe, email, and support providers may process data outside the EEA. Where required, NoLooky should rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, or provider-specific transfer mechanisms. [CONFIRM BEFORE PUBLICATION: review provider documentation before publishing final wording.]
12. Retention
Account records are kept while the account is active and for a reasonable/legal period afterward. Purchase/accounting records are kept for statutory tax and accounting periods. Payment references are kept as needed for statutory, fraud, dispute, and support purposes. License and activation records are kept for the life of the license plus a reasonable dispute/security period. Password reset tokens expire quickly and are invalidated after use. Security logs, if collected, should be retained for a limited security period.
[CONFIRM BEFORE PUBLICATION: configure actual retention periods in internal policy and code where applicable.]
13. Data Security
NoLooky uses safeguards such as password hashing, HTTPS, prepared database statements, access controls, Stripe-hosted payment, webhook signature verification, CSRF protection, and local media processing. No system can be guaranteed perfectly secure.
14. Your Rights
Depending on your location, you may have rights to access, rectify, erase, restrict, object to processing, receive portability, withdraw consent where processing is based on consent, and complain to a supervisory authority. Identity verification may be required.
If the controller is Danish, the relevant authority may include the Danish Data Protection Agency. [CONFIRM BEFORE PUBLICATION: confirm controller country and supervisory authority.]
15. Automated Decision-Making
AI sorting occurs locally and is initiated/controlled by you. No account, payment, or legal decision by NoLooky is made based on photo classification. Fraud and payment providers such as Stripe may perform their own automated checks under their policies.
16. Children
NoLooky is not deliberately directed to children who cannot lawfully contract. Parent or guardian involvement is required where applicable law requires it.
17. Data Breaches
NoLooky will take reasonable steps to investigate security incidents and provide regulatory or user notifications where legally required.
18. Changes
NoLooky may update this Policy. Material changes will be communicated where legally required. The last-updated date above identifies the current version.
19. Contact
Privacy contact: [PRIVACY EMAIL].
[LEGAL COMPANY NAME], trading as [TRADING NAME], [REGISTERED ADDRESS], [COUNTRY], [CVR / COMPANY NUMBER].