Last updated 2026-08-22
Privacy policy
This policy explains how Lightloom handles account, payment, moderation and video-generation data. We use it to provide the service, protect it from abuse, meet legal obligations and support users.
What we collect
Prompts and generation records. When you submit a generation, we store the prompt, selected settings, moderation result, provider task id, status, credit charge, cost snapshot and output-storage key. Text typed but never submitted stays in your browser.
Google account data. If you sign in, we receive your verified email address, Google account identifier, display name and profile image. We store an app-owned user id, those profile fields, your credit balance and account timestamps in Cloudflare D1. New accounts start with 0 credits.
Purchases and output. We store the selected credit pack, price, currency, purchase and provider order ids, webhook events and resulting ledger entries. Creem receives payment details; we do not receive complete card numbers. Completed clips are stored in Cloudflare R2 for authenticated delivery.
Technical data. IP address, browser user agent and request timestamps may be processed for hosting, fraud detection, rate limiting, security and abuse prevention. Google Analytics also processes page views, referral information, device and browser details, approximate location derived from IP address and interactions with the site so we can understand aggregate usage.
Who else processes your data
MiniMax. After moderation and an atomic credit reservation, MiniMax receives the allowed prompt and generation settings and returns the generated clip. Its API processes that material under its own terms. Completed clips are copied into Lightloom’s private Cloudflare storage for authenticated delivery.
Google. Google authenticates the account and returns the verified profile fields described above. We do not persist Google access or refresh tokens. Google Analytics also measures site usage under measurement ID G-E3NFXQ72N9 and processes analytics data under Google’s own terms and privacy policy.
Cloudflare. Hosting, storage, security, asynchronous workflow execution and asset delivery. Requests pass through Cloudflare’s network; account, purchase and generation records are stored in D1, and completed clips are stored in R2.
Creem. Creem is the merchant of record for credit purchases. It receives your email, selected product, checkout metadata and payment details. Creem also screens every submitted prompt through its Moderation API before generation; a flagged, denied or unavailable moderation result is not sent onward to MiniMax.
What we don't do
We do not sell your data, persist Google access or refresh tokens, or run third-party advertising trackers. We do not trust a credit balance stored in a browser cookie; the current ledger-backed balance is read from D1.
Cookies
Signing in creates an encrypted Auth.js session cookie that may last up to 30 days. The cookie identifies the app-owned user; the current credit balance is reloaded from D1 rather than trusted from the cookie. Google Analytics may set or read analytics cookies to distinguish visits and measure site usage. Cloudflare may also use necessary security cookies or similar signals when serving and protecting the site.
Retention and deletion
Completed clips may be deleted from R2 30 days after creation, so you should download anything you need to keep. Account, prompt, generation and ledger records remain while the account is active and may be kept longer where reasonably needed for support, fraud prevention, disputes or legal obligations. Purchase and payment-event records may be kept for the period required for tax, accounting and chargeback handling.
Questions or deletion requests about data held directly by us can be sent to contact@h3video.net. We will verify the request and explain any records we must retain. Independent processors may also retain data under their own policies or legal obligations.
Content moderation and abuse reports
Every submitted prompt is screened through the Creem Moderation API before it reaches our model provider. We record the moderation decision, the request status and the account behind each generation so that abuse can be investigated and so that we can answer payment and legal enquiries.
The content rules themselves — the six prohibited categories, how we review requests, and what happens when an account breaks the rules — are set out in our Terms of Service and restated in the Acceptable Use Policy. To report content or an account that breaks those rules, or to request removal of content that depicts you, email contact@h3video.net. We review every report and normally respond within five business days.
Children
This site is not intended for anyone under 13, and we do not knowingly collect their data.
Changes
If this policy changes materially, we will update the date at the top of this page. Continuing to use the site after that means you accept the revised policy.