Privacy Policy
What Luura collects, why, where it is stored, and how to get rid of it.
Last updated 18 September 2026
Who is responsible
The controller for the processing described here is Luura. You can reach us at [email protected].
We have not appointed a data protection officer, because we are not required to.
What this covers
This policy covers the Luura website, the Luura app for iOS and Android, and the web app guests use to join a roll. If you are a guest, the short screen you see before your first photo already tells you the essentials: your photos go to this roll only, the host and other guests can see them, and you can delete yours at any time. This page is the detail behind that.
What we collect
If you host a roll, we store the email address and name on your account, whatever you enter when you create a roll (its name, occasion, date, reveal time, guest limit, photos per guest and film look), which tier you chose, and notifications you have switched on.
If you are a guest, we store a record that you consented, the version of the consent text you agreed to, and the time you agreed. Your name is optional — if you join without entering one, we store no name. We store the photos you take in that roll. We store your email address only if you ask us to email you the photos, or if your account is the host's for that roll. We store the language you are using, so notifications and emails reach you in it.
For every photo we store the processed image, a small thumbnail and the times it was captured, uploaded and processed. The unprocessed original is stored separately and deleted automatically after seven days.
If you buy a plan, we store which plan, which app store you bought it through, the transaction and receipt reference the store returns, and whether it was a sandbox or production purchase. We do not receive or store your card or bank details — Apple or Google handle the payment.
We process IP addresses in memory to rate-limit requests and stop abuse. We do not write them to a table.
What we do not collect
- No analytics or tracking of any kind, from us or from anyone else. There is no Google Analytics, no advertising pixel, no session recording and no third-party tag on this site. We do not build a profile of you.
- No location data, no contacts, no calendar, and no access to your camera roll. The camera is used only while you are shooting a roll.
- No data about you from other sources, and no automated decision-making or profiling.
- No advertising, and nothing you give us is sold or shared for advertising.
Why we process it, and on what basis
- To run the roll you asked for — creating it, letting guests join, storing photos until the reveal, showing them afterwards, and taking the payment through the app store. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- To keep guests' photos hidden until the host reveals the roll, and to keep the consent record. Legal basis: your consent, Art. 6(1)(a) GDPR, which you can withdraw.
- To secure the service, rate-limit requests and prevent abuse. Legal basis: our legitimate interest in a working, abuse-free service, Art. 6(1)(f) GDPR.
- To keep invoices and purchase records. Legal basis: legal obligations under German commercial and tax law, Art. 6(1)(c) GDPR.
- To send you a notification or email you asked for — the photos, a reveal, a reminder. Legal basis: your request, and consent where required.
Who we share it with
We do not sell your data and we do not share it for advertising. We use a small number of service providers, each of which processes data only on our instructions:
- Hetzner (Germany) — servers and photo storage, in Nuremberg and Falkenstein.
- Brevo (France) — transactional email only, such as the email telling you a roll has been revealed.
- Apple and Google — in-app purchases, receipt verification, and push notification delivery for the app.
- Expo and the browser push services (Apple, Google, Mozilla) — delivering push notifications you have switched on.
Our photos and roll data are stored on Hetzner in Germany. Photo data never leaves Germany. Some of the providers above are not based in the EU — Apple, Google, Expo and the browser push services are not — so when a purchase is verified or a notification is delivered, data is transferred to the United States under those providers' standard contractual clauses and their EU-US Data Privacy Framework certifications.
How long we keep it
- Unprocessed photo originals: seven days, then deleted automatically. Only the processed image and its thumbnail remain.
- Photos and roll data on a Free roll: 30 days after the roll.
- Photos and roll data on Standard and Premium: kept until you delete them or delete the roll.
- Guest records and consent records: as long as the roll they belong to.
- Purchase records: as long as German commercial and tax law requires — ten years for accounting records and invoices, six years for other commercial correspondence (§ 257 HGB, § 147 AO).
- Backups: the database is dumped nightly, so a deletion you request may briefly still exist in a backup — up to 24 hours. Photo storage keeps version history, so a processing mistake cannot destroy a roll, and object locking is deliberately not enabled, so no retention lock holds a deletion back. Because that version history is kept, an earlier copy of a deleted file can outlive the deletion until the storage's own lifecycle removes it.
Deleting your photos
A guest does not need an account to delete. The link you were given when you joined leads to a page where you can delete your own photos, and you can do it while the roll is still open or after it has been revealed. A host can delete a whole roll, which deletes everyone's photos in it.
Deletion is carried out by a background job, not instantly, so allow a short time. It removes the photos themselves and the records about them.
Two honest limitations. Deletion cannot take back what people have already seen: once a roll is revealed, the other guests and the host may already have saved copies of your photos, and we cannot retrieve those. And if you are a guest, deleting your photos does not delete the host's account or the rest of the roll.
If you are a guest without an account
Guests are deliberately anonymous. We do not create an account for you, we do not ask you to log in, and unless you type one in we do not know your name. You are identified within a roll by a secret token in your link, which we store only as a hash. If you typed an email address to be sent the photos, that address is the only way we can contact you, and it is deleted with the rest of your guest record.
Cookies and local storage
The Luura website sets no tracking or advertising cookies. If you sign in as a host, the app stores a session cookie so you stay signed in; it is required for the service to work.
The guest web app keeps a little data in your browser's local storage so your roll survives a refresh and works offline. That data stays on your device until you clear it or the roll is deleted.
Children
Luura is not intended for children. You must be at least 16 to create a roll or take part in one. An event may include younger guests, but the host is responsible for them being there and should not be surprised by the roll's rules.
Your rights
Within the limits of the law, you have the right to ask what we hold about you, to have it corrected, to have it deleted, to restrict how we use it, to receive it in a portable form, to object to processing based on our legitimate interests, and to withdraw a consent you gave. To exercise any of these, write to [email protected].
If you are a guest, deleting your photos is the fastest route and does not need an account. If you believe we have handled your data badly, you can complain to a supervisory authority — in Germany, the authority responsible for the state where we are based.
Changes to this policy
If we change how we handle data, we will update this page and its date. If a change is significant, we will say so where you will see it — which, for guests, means the consent screen, because that is the moment you are being asked to agree.