Privacy Policy
Last updated: February 17, 2026
1. Data Controller
The data controller is:
Sébastien Voerman — Cosmos Darkroom
Email: sebastien.voerman@gmail.com
2. Data Collected
We collect the following categories of data:
- Account data: email address, name, avatar (via NextAuth authentication — Google, Apple, or email)
- Usage data: images uploaded for processing, processing results, processing history, editor settings, presets
- Community profile data: display name, bio, profile slug, images published to the community gallery (Cosmos Feed)
- Payment data: processed exclusively by Stripe. We store no banking information (card numbers, IBAN, etc.) on our servers
- Technical data: IP address, browser type, operating system, device type, language preferences, authentication cookies
- Approximate geolocation data: coordinates (latitude/longitude) used solely for the night sky observation planner ("Tonight"), not permanently stored
- Analytics data: anonymized usage events via our internal tracker (/api/dx) and, with your consent, Google Analytics 4 (via Google Tag Manager)
3. Purpose and Legal Basis (GDPR Art. 6)
Your data is used for the following purposes, each relying on a specific legal basis:
- Contract performance (Art. 6§1(b)): provide the image processing service, manage your account, subscription, and credits
- Contract performance (Art. 6§1(b)): enable publishing on the community gallery
- Legitimate interest (Art. 6§1(f)): contact you for technical support and important Service notifications
- Legitimate interest (Art. 6§1(f)): improve the Service via our internal analytics tracker (aggregated and anonymized statistics)
- Consent (Art. 6§1(a)): audience analytics via Google Analytics 4 (only if you accept analytics cookies)
We never sell, rent, or transfer your personal data to third parties for commercial or advertising purposes.
4. Your Images — No Data Hosting
Important — Cosmos Darkroom is not a data hosting service:
- Your images are processed confidentially and are not shared with third parties
- They are not used to train our AI models without your explicit consent
- Uploaded images and processing results are stored temporarily on our servers solely to allow you to access and download them
- We do not guarantee the preservation, permanence, or integrity of your images
- Your images may be deleted at any time, without notice, for technical, maintenance, or capacity reasons
- You are solely responsible for backing up your original files and results
⚠️ Recommendation: Download your processing results as soon as they are available and always keep your original files on your own storage devices.
5. Public Content (Cosmos Feed / Cosmos Gallery)
If you publish content on the community gallery, the following elements are publicly visible to all users:
- Your display name and avatar
- Images you publish
- Your comments
Publishing to the gallery is voluntary. We reserve the right to remove any content deemed inappropriate. Deleting your account will result in deletion of your publications.
6. Data Retention
- Account data: retained as long as your account is active. Deleted upon request or after prolonged inactivity
- Images and results: temporary storage with no guaranteed duration. May be deleted at any time
- Payment data: retained by Stripe in accordance with their legal obligations
- Community content: retained while your account is active, deleted upon account closure
You may request deletion of your account and all your data at any time by contacting us via email.
7. Third-Party Services
We use the following third-party services for the operation of the Service:
- NextAuth: authentication (OAuth 2.0 via Google/Apple/email) — open-source library running on our infrastructure, no data transferred to third parties
- Stripe (Stripe Inc., USA): payment processing and subscription management — Stripe Privacy Policy
- Google Analytics 4 / Google Tag Manager (Google LLC, USA): audience analytics (with consent only) — Google Privacy Policy
- Infrastructure: hosted on technical infrastructure operated by the Publisher, located in France
7bis. International Transfers
Some sub-processors (Stripe, Google) are established in the United States. These transfers are governed by:
- The EU-US Data Privacy Framework for certified companies
- European Commission Standard Contractual Clauses (SCCs)
For more information, contact us at the address provided below.
8. Security
We implement appropriate security measures:
- Encrypted connections (HTTPS/TLS)
- Secure authentication via NextAuth (OAuth 2.0)
- Secure payments via Stripe (PCI DSS compliant)
- Data access restricted to authorized personnel only
Despite these measures, no system is infallible. We cannot guarantee absolute security of data transmitted or stored.
9. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: obtain a copy of your personal data
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure: request deletion of your data ("right to be forgotten")
- Right to portability: receive your data in a structured format
- Right to object: object to the processing of your data
- Right to restriction: request limitation of processing
To exercise these rights, contact us at:sebastien.voerman@gmail.com
You also have the right to file a complaint with your local data protection authority (in France: CNIL — www.cnil.fr).
10. Cookies
We use the following categories of cookies:
- Essential cookies (always active): NextAuth authentication session, language preferences (localStorage), cookie consent choice
- Analytics cookies (with consent): Google Analytics 4 via Google Tag Manager — anonymized audience measurement. These cookies are only activated if you click "Accept" on the consent banner
No advertising or commercial tracking cookies are used. You can change your consent choice at any time by deleting the "cookie_consent" key from your browser's local storage (localStorage) in your browser settings.
For more details, see our Cookie Policy.
11. Changes to This Policy
We reserve the right to modify this policy at any time. Any changes will be published on this page with an updated revision date.
12. Contact
For any questions about this policy or your personal data:
sebastien.voerman@gmail.com