Skip to content

Hotel Lobby AI / Field notes

Privacy Policy

Hotel Lobby AI is operated by Nitor as an individual. This policy explains how photos, creations, account information and payment records are handled. For privacy requests, contact support@hotellobbyai.me or use Support tickets.

Photos and creations

The generator prepares your selected photos in the browser. It attempts orientation correction, converts readable inputs to JPEG and removes EXIF metadata before upload. Prepared photos are used as references for the requested preview and, when available, its animation. The application has no feature that trains a personal model from your photos or publishes your private creation to a public gallery.

Media access is restricted to the owning account or the signed anonymous browser identity that created it. After an anonymous creation is claimed by an account, the previous anonymous identity does not retain independent access. A private URL is not intended to be a permanent public share link.

Input photos expire after 24 hours. Preview and output-video assets expire after 7 days. Expired assets stop being readable through the application; scheduled cleanup removes stored objects. Delete now revokes access immediately and requests physical deletion, with cleanup retries if storage is temporarily unavailable. Backups and downstream provider retention require separate production review; we do not promise instantaneous erasure from every external system.

Accounts, orders and support

The application can store an account identifier, email, session records, creations, a credit ledger and order records. Those records support access, accounting, fraud prevention and recovery. Photo expiry does not delete your entire account or accounting history. The account-record and accounting-retention schedule remains under review.

Google authentication supplies account information for enabled sign-in. Email authentication and email delivery are separate services and should not be assumed active merely because Google sign-in works. Waffo Pancake processes checkout and subscription information; the application does not store full card numbers.

Service providers

Cloudflare provides the deployed database (D1), private object storage (R2) and Turnstile verification. The current image and video integrations use fal for ByteDance Seedream 4.5 Edit and Higgsfield for Genjutsu Motion Transfer v1.0. In a real generation, prepared photos, the selected template, assembled instructions and necessary reference media can be transmitted to these providers. See the model disclosure.

SeeAPI image, video and text moderation has been integrated and tested with fictional AI media and fixed test text. SeeAPI receives the assembled generation instructions and temporary access to the media needed for review: prepared photos, template background or reference media, the preview and the generated video. These links allow the provider to fetch specific files; they do not make the storage bucket public.

Before a real image or video generation, Waffo Pancake also checks the exact assembled text instructions. This text check does not send photos or videos to Waffo. Only an explicit pass permits generation; a rejection or unavailable check prevents it. The application records a prompt fingerprint, a request identifier and a limited decision record, without copying the prompt into the review audit log. Waffo describes this interface as stateless and says it does not retain the original prompt after returning the decision. See its prompt scan documentation.

Results awaiting review are held in private quarantine and cannot be viewed or downloaded by users. Quarantine copies expire after one hour; terminal review triggers their cleanup. An expired copy or unavailable review does not authorize release of the result. This application-side limit does not establish a deletion deadline for copies processed by an external provider.

The SeeAPI privacy policy does not specify moderation-media retention, training use or a media-deletion process. These provider terms remain under review. We do not promise that external providers never retain or train on uploads. No additional visual-review provider has been connected. The current image/video NSFW checks do not establish coverage of visual violence, gore, hate symbols, identity permission or copyright.

Provider processing locations, contractual safeguards and retention terms remain under review. No original performer footage, private user photo or unapproved test output is used as public marketing media. Read the acceptable use policy for safety reporting.

Cookies, local storage and analytics

Essential browser state supports sign-in, anonymous ownership, security and your privacy preference. These functions are distinct from optional analytics. Abuse controls use a salted IP hash in application usage records; infrastructure may process connection information to deliver requests. Do not interpret that implementation detail as a promise that all infrastructure logs have been anonymized.

When configured, Google Analytics measures permitted page and interaction events. Microsoft Clarity is limited to designated public informational pages; creation, account, administration, authentication and generator pages are excluded from its recordings. Photo, video and sensitive form areas carry masking markers as an additional precaution. Business events use an allowlist and do not contain photos, email, names, keys, signed media URLs or private creation identifiers.

Ahrefs Web Analytics measures visits and basic interactions on designated public pages. It does not load on creation, account, administration or authentication pages, or URLs containing query parameters or fragments. Its default service uses no cookies; our integration still respects the analytics preference below. Google's privacy information and Ahrefs' privacy policy describe their processing.

For EEA, UK and Switzerland visitors, and when the region is unknown, optional scripts remain unloaded until analytics consent is granted. Other recognized regions use the initial behavior described in the privacy choices control and can reject analytics. Advertising storage, advertising user data and personalization remain denied. The application does not load analytics at all when the corresponding ID is missing.

Use Privacy choices in the footer to reject or withdraw analytics. Withdrawal stops event dispatch, clears recognized analytics cookies and reloads the document when necessary to unload third-party listeners. The preference is retained for up to 180 days. With consent, local event deduplication keeps bounded hashed event keys for up to 30 days; these keys are not sent as private IDs. Browser storage restrictions can limit preference persistence or cross-tab deduplication.

Contact and requests

The operator is Nitor, an individual operating under the Hotel Lobby AI brand. For privacy, access, account deletion or complaint requests, contact support@hotellobbyai.me. The email address has been configured, but delivery testing and the request-handling process remain pending. No response deadline has been agreed. Do not include passwords, verification codes, payment credentials or private photos in your initial message.

You can use Delete now for a creation you own. That action is separate from deleting an account or requesting the removal of accounting records. Read the terms and refund policy for the current product rules.

Last updated: October 2, 2026.

Local photo draft

Prepared JPEGs can be saved in this browser for up to 24 hours to restore the two selected photos. Original EXIF is removed before that save. Use Clear local photos on a shared device. Submitting a preview uploads the prepared images; it is not an entirely local workflow. Local drafts do not restore expired server assets or extend retention.

Last updated: