FilmGrainLab › Privacy

Privacy Policy.

Short version: your photos never leave your device. We store your e-mail address so you can sign in, and one cookie to keep you signed in.

Last updated: 1 October 2026

Who is responsible

FilmGrainLab is operated by GranularityLabs, 6017 Ålesund, Norway (“we”). We are the data controller for the personal data described below. Contact: [email protected].

Your photos

Photos you open in FilmGrainLab are processed locally in your browser, using your device’s graphics card. They are not uploaded to our servers and we cannot see them.

What we collect

  • E-mail address. When you create an account or sign in, so we can send you a sign-in link and identify your account.
  • Account activity. When your account was created, when you last signed in and how many times you have signed in.
  • Subscription status. If and when paid plans are introduced: whether your subscription is active, the plan, and when the paid period ends. Payments are handled by our payment provider (see below); we do not receive or store your card details.
  • Technical logs. Our hosting provider processes your IP address and basic request data (browser, time, page) to deliver the site and protect it against abuse.

We do not use advertising or analytics trackers.

Cookies

We use one cookie, fgl_session. It keeps you signed in and is strictly necessary for the service you asked for, so it is set without a consent banner. It is an HttpOnly, signed cookie that contains your e-mail address and an expiry time, and it expires 30 days after you sign in or when you sign out. We do not use cookies for tracking.

Why we process your data

  • To provide your account and the service (performance of a contract, GDPR art. 6(1)(b)).
  • To keep the service secure and prevent abuse, including blocking accounts (legitimate interest, art. 6(1)(f)).
  • To handle payments and meet accounting obligations if paid plans are introduced (contract and legal obligation, art. 6(1)(b) and (c)).

Who we share data with

We use these service providers (processors) and share only what they need:

  • Cloudflare: hosting, content delivery and storage of account records.
  • Resend: sends the sign-in e-mails (receives your e-mail address and the message).
  • Paddle (only if paid plans are introduced): payment processing as merchant of record. Paddle handles your payment details and is an independent controller for that data under its own privacy policy.

We do not sell your data. Some providers are based in or transfer data to the US; they rely on the EU–US Data Privacy Framework or standard contractual clauses.

How long we keep it

  • Account data: until you ask us to delete your account.
  • Sign-in links: valid for 15 minutes and usable once.
  • Session cookie: 30 days.
  • Accounting records (if paid plans are introduced): as long as the law requires.

Your rights

You can ask us for access to your data, to correct it, to delete it, to restrict or object to processing, and to receive a copy in a portable format. To use any of these rights, e-mail [email protected] from the address on your account. You can also complain to your data protection authority; in Norway that is Datatilsynet.

Changes

If we change this policy in a meaningful way we will update the date above and, for significant changes, tell signed-in users.