Privacy Policy
Last updated: 10 October 2026
What personal data LamaLama collects, why, who else sees it and how you stay in control. Short version: only what the app needs to work. No ads, no tracking, nothing sold.
1. Who is responsible
The data controller is Andrea D'Ambrosio, an individual based in Italy, who runs the LamaLama service at lamalama.video ( "LamaLama", "we", "us"). For anything about your data, write to legal@lamalama.video. We have not appointed a Data Protection Officer: the law doesn't require one for a service of this size.
LamaLama's code is open source. This policy covers only the hosted service at lamalama.video: if you run your own copy, you are the controller of the data it processes.
2. What we collect
Your account
- Name, email address and profile picture. With Google or GitHub sign-in they come from that provider; with an email link, only the email. You can change your name and picture in Settings.
- The access tokens Google or GitHub give us when you sign in with them, stored encrypted. We use them only to sign you in.
- Your sessions: when they start and expire, the IP address and the browser (user agent) they were opened from.
Your workspaces
- What you create or upload: screen recordings, brand kits, logos, product descriptions, video projects, exported videos and share links.
- Workspace members and invitations, including the email address of the people you invite.
- The workspace's AI provider key, if you add one, stored encrypted.
Screen recordings can show anything that was on screen, including other people's personal data. Please record only what you are allowed to share (see the Terms).
Technical data
- Server logs (IP address, requested page, time, errors), kept to run and protect the service.
- Counters that limit how often an action can be repeated, such as sign-in attempts, to stop abuse. They are tied to your IP address, your account or a hash of your email address.
- A few cookies and browser storage items, all necessary for the app to work. The Cookie Policy lists every one of them.
We don't use analytics, advertising or tracking tools, and we don't ask for special categories of data (health, religion, politics and so on).
3. Why, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating your account, signing you in, running your workspaces, processing and exporting your videos, sending sign-in links and invitations. | Performance of the contract with you: the Terms (Art. 6(1)(b)). |
| Keeping the service secure and available: sessions, logs, rate limits, preventing abuse and fixing errors. | Our legitimate interest in a secure, working service (Art. 6(1)(f)). |
| Answering reports of illegal content and requests from authorities, keeping records the law requires. | Legal obligations (Art. 6(1)(c)). |
| Defending or exercising legal claims. | Legitimate interest (Art. 6(1)(f)). |
Giving us your email address is necessary to have an account: without it we can't provide the service. Everything else you upload is up to you. We don't make decisions about you based solely on automated processing (Art. 22 GDPR) and we don't profile you.
4. AI features
LamaLama can analyse your recordings and draft scripts with Anthropic Claude, using the AI key the workspace adds ("bring your own key"). When you use these features, the relevant frames, text and product details are sent to Anthropic under that key and that account's terms. We don't send your content to any AI provider without a workspace key, and we don't use it to train models.
5. Who else processes your data
These providers process data on our behalf, under data processing agreements, and only to run LamaLama:
| Provider | What for | Where |
|---|---|---|
| Railway | Hosts the website and the background jobs that process videos. | Servers in the EU (Amsterdam, Netherlands). Company in the USA. |
| Neon | Database and file storage: your account, workspaces, recordings, logos and exported videos. | Servers in the EU (Frankfurt, Germany). Company in the USA. |
| Resend | Sends the emails: sign-in links and workspace invitations. | Sending from the EU (Ireland). Company in the USA. |
If you sign in with Google or GitHub, that provider processes your data as an independent controller under its own privacy policy, and your profile picture loads from its servers. The same applies to Anthropic when a workspace uses its own AI key.
Other workspace members see your name, email and picture and the content you share in the workspace. Anyone with a share link can watch that video. We disclose data to authorities only when the law requires it. We never sell or rent personal data.
6. Transfers outside the EU
Our data is stored on servers in the European Union. The providers above are US companies, so some data may be accessed from the United States, for example for support or maintenance. Those transfers rely on the EU–US Data Privacy Framework, where the provider is certified, or on the European Commission's Standard Contractual Clauses (Art. 45 and 46 GDPR). Write to us for a copy of the relevant safeguards.
7. How long we keep it
- Account and workspace content: until you delete it or your account.
- Sessions: until they expire (7 days) or you sign out.
- Sign-in links: 5 minutes. Invitations: 7 days.
- Server logs and database backups: up to 30 days.
- Data needed to answer a legal request or defend a claim: as long as that requires.
When you delete your account, we delete your profile, sessions, sign-in connections and the workspaces you own, with their files. In workspaces owned by others, the content you created stays with that workspace. Copies in backups disappear within 30 days.
8. How we protect it
- All traffic is encrypted with HTTPS.
- AI keys and sign-in tokens are encrypted at rest with AES-256-GCM.
- Sign-in links are single-use and stored only as a hash. There are no passwords to leak.
- Files are kept in private storage and reached only through short-lived signed links.
- Only the controller has administrative access.
If a breach puts your data at risk, we will notify the Italian supervisory authority and, where required, you (Art. 33 and 34 GDPR).
9. Your rights
Under the GDPR you can, free of charge:
- access your data and get a copy (Art. 15);
- have it corrected (Art. 16);
- have it deleted (Art. 17);
- restrict its processing (Art. 18);
- receive it in a machine-readable format (Art. 20);
- object at any time to processing based on our legitimate interest (Art. 21).
You can edit your profile and delete your account yourself in Settings. For anything else, write to legal@lamalama.video: we answer within one month and may ask you to confirm your identity.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live or work. In Italy it is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma.
10. Children
LamaLama is not meant for children: you must be at least 16 to use it. If you believe a child gave us personal data, write to us and we will delete it.
11. Google user data
When you sign in with Google we receive only your basic profile: name, email address and profile picture. We use it only to create your account and sign you in, and we don't transfer it to anyone except as described in this policy. LamaLama's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
12. Emails
We only send emails you ask for or need: sign-in links, invitations, and important notices about your account or these terms. No newsletters or marketing.
13. Changes
If this policy changes, we update the date at the top. For important changes, we tell you by email or in the app before they apply.



