Privacy Policy

Last updated: February 27, 2026

1. Overview

Luster AI ("we," "our," "us") operates a real estate photo enhancement platform available via web application at tryluster.ai and through our mobile application for iOS and Android (collectively, the "Service"). This Privacy Policy explains what personal data we collect, how we use and share it, how long we keep it, and what rights you have regarding your data.

By using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.

2. Information We Collect
2.1 Account & Authentication Information

When you create an account or sign in, we collect:

Email address — collected when you sign up via magic link (email one-time password) or social login.
Name (optional) — provided by Google, Apple, or Facebook if you choose to sign in with those services. You may decline to share your name through Apple's "Hide My Email" feature.
User identifier — a unique ID (UUID) generated by our authentication provider, Supabase.
Authentication tokens — temporary access and refresh tokens used to keep you signed in. On mobile, these are stored using your device's secure storage (iOS Keychain / Android Keystore). On web, they are managed by the Supabase client library.

We support sign-in through email magic links, Google OAuth, Apple Sign In, and Facebook OAuth. When you use a social login provider, we receive only the information you authorize that provider to share (typically email and display name). We do not receive or store your social media passwords.

2.2 Photos & Image Data

When you use our enhancement service, we collect:

Original photos — the images you upload for enhancement, stored securely on Cloudflare R2 cloud storage.
Enhanced output photos — the AI-enhanced versions of your images.
File metadata — original filename, file size (bytes), and MIME type (e.g., image/jpeg). We do not extract or separately store EXIF metadata (camera model, GPS coordinates, timestamps) from your original uploads, although this metadata may be present in the original file as uploaded.

EXIF & location data:
We strip all metadata — including GPS location, camera model, date/time, and device identifiers — from every enhanced output image before storing it. Original uploaded images retain whatever metadata was present at the time of upload. You can delete originals at any time.

HEIC conversion:
If you upload photos in Apple's HEIC format (common on iPhones), we automatically convert them to JPEG before processing.

Photo ownership:
You retain full ownership of all photos you upload and all enhanced outputs generated from them.

2.3 Payment & Transaction Information

We offer credit packs for purchasing photo enhancements. Payment processing is handled entirely by third-party payment processors:

Web: Stripe processes payments. Your credit card details are submitted directly to Stripe and are never sent to or stored on our servers.
iOS: Apple's App Store processes payments via RevenueCat. Your payment method is managed by Apple.
Android: Google Play processes payments via RevenueCat. Your payment method is managed by Google.

What we store:
We store only your credit balance (an integer count) and transaction identifiers for deduplication purposes. We do not store credit card numbers, bank account details, billing addresses, or any other financial account information on our servers.

2.4 Device & Technical Information

When you use our Service, we may automatically collect:

• IP address — collected in server access logs for security and debugging purposes.
• User agent string — your browser or app version identifier, collected in server access logs.
• Device type and operating system — collected by our crash reporting service (Sentry) when errors occur.
• App version — collected for crash reporting and compatibility.
• Network connectivity status — the mobile app checks whether your device is online to provide appropriate error messages. This information is not transmitted to our servers.

2.5 Usage & Service Data

To operate the Service, we track:

• Job processing records — status (queued, processing, succeeded, failed), timestamps, enhancement style selected, and processing duration.
• Job audit events — a log of status transitions for each enhancement job (e.g., created, started, completed, failed) used for debugging and customer support.
• Credit transactions — records of credit deductions and refunds (e.g., credits refunded when a job fails).
• Project/shoot organization — names and groupings you create to organize your photos.

We do not use advertising trackers, behavioral analytics platforms, or sell your data to third parties.

2.6 Crash Reports & Diagnostics

We use Sentry for crash reporting and performance monitoring. When an error occurs, Sentry may collect:

• Error messages and stack traces
• Device type, operating system, and app version
• User identifier (to correlate errors to accounts for support purposes)
• Breadcrumbs (a sequence of recent actions leading to the error, such as which screens were visited)
• Performance traces (a sample of request durations and response times)

We configure Sentry with sendDefaultPii: false and actively filter sensitive fields (passwords, tokens, API keys, credit card numbers, SSNs) before any data is transmitted. Session replay masks all text and user inputs. In production, only 20% of performance traces and 10% of sessions are sampled.

3. Mobile App: Device Permissions & Local Data
3.1 Device Permissions

The mobile app may request:

• Camera
• Photo Library (read)
• Photo Library (write)
• Haptic feedback / vibration

All permissions are requested at the point of use and can be revoked at any time through your device's Settings app.

3.2 Data Stored on Your Device

• Authentication tokens — stored using iOS Keychain / Android Keystore via Supabase SDK.
• Listings cache — stored locally via AsyncStorage and cleared when you sign out.
• Temporary image files — cached in the app's private directory and managed by the operating system.

When you sign out, all locally cached data including listings and session tokens are cleared. Photos saved to your device camera roll remain under your control.

4. How We Use Your Information

We use the information to:

• Provide the Service
• AI image processing
• Process payments
• Maintain and improve the Service
• Security
• Communicate with you

We do not send marketing emails unless you opt in.

5. Automated Processing & AI

Our core service uses OpenAI's gpt-image-1 model to enhance real estate photos.

• Only image pixels and a generic style prompt are sent.
• No personal information is transmitted to OpenAI.
• Outputs are processed automatically with no human review.
• Metadata is stripped from enhanced outputs.

This processing does not involve profiling or legally significant automated decisions.

6. Third-Party Services & Data Sharing

We do not sell, rent, or trade your personal information.

Third-party services used:

• Supabase — Authentication & database hosting
• OpenAI — AI image processing
• Cloudflare R2 — Photo storage
• Stripe — Web payment processing
• RevenueCat — Mobile purchase management
• Sentry — Crash reporting
• Railway — Application hosting
• Google, Apple, Facebook — Social login

Each provider’s privacy policy link should be displayed as a clickable external link.

7. Data Storage & Security

Security measures include:

• HTTPS/TLS encryption
• Encryption at rest
• JWT authentication
• Signed URLs (1-hour validity)
• HMAC-SHA256 webhook verification
• Native mobile secure token storage
• API rate limiting
• Ownership verification on every request

Primary infrastructure is hosted in the United States.

8. Data Retention

Display as a clean table on your site:

Data TypeRetention PeriodDeletionAccount informationUntil account deletionContact usOriginal photosUntil deleted by userDelete in-appEnhanced photosUntil deleted by userDelete in-appJob recordsUntil account deletionDeleted with accountCredit balanceUntil account deletionDeleted with accountServer logs30 daysAutomaticCrash reports90 daysAutomaticLocal mobile cacheUntil sign-outSign out or uninstall

9. Your Rights

You may have rights to:

• Access
• Correction
• Deletion
• Data portability
• Restriction
• Objection
• Withdraw consent

California residents:
• We do not sell personal information.
• We do not share for behavioral advertising.
• No discrimination for exercising rights.

EEA residents:
• Contract performance
• Legitimate interest
• Consent

You may lodge complaints with your local authority.

10. Cookies & Tracking Technologies

Web: Essential authentication cookies only.
No advertising cookies.
No behavioral tracking.

Mobile: No cookies.
NSPrivacyTracking: false.

11. Children's Privacy

Not directed to children under 16 (or 13 where applicable).
We do not knowingly collect data from children.

12. International Data Transfers

Data is processed in the United States.
Transfers may occur across jurisdictions.
Standard Contractual Clauses may apply where required.

13. Changes to This Policy

We may update this Privacy Policy.

We will:
• Update the “Last updated” date
• Notify users for material changes

Continued use constitutes acceptance.

Contact

Evil Genius Labs LLC
Email: dev@evilgeniuslabs.info