Last updated: Jul 15, 2026
This Privacy Policy explains how MyLens (“MyLens”, “we”, “us”) collects, uses, shares, and protects your personal data when you use our website and services, and the choices and rights you have. MyLens acts as the data controller for the personal data described in this policy. If you have any questions, contact us at support@mylens.ai.
To generate visualizations and stories, your prompts and source content — including content from Google Drive files you choose to import — are processed by AI providers (listed below) via their business APIs. Your content is not used to train AI models — neither by us nor by our AI providers, whose API terms exclude training on customer data. Content is sent only for the purpose of generating your requested output.
MyLens uses Google APIs for sign-in (Google authentication) and, when you choose, for Google Drive so you can select files as sources for story generation. The disclosures below explain what Google user data we access, how we use it, when we share it, how we protect it, and how long we keep it. Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Depending on the features you use, MyLens may access the following Google user data:
We use Google user data solely to provide and improve user-facing MyLens features that you request:
We do not use Google user data to serve advertisements, to train generalized AI/ML models outside providing your requested output, to sell personal data, or for any purpose other than providing or improving MyLens features that interact with Google APIs. Your prompts and source content (including Drive files you import) are processed by our AI providers only to generate your requested output and are not used to train their models (see “AI Processing and Your Content”).
We share Google user data only as needed to run MyLens, with the types of parties below (also listed under “Our Service Providers”):
We do not sell Google user data. We do not transfer Google user data to third parties for their independent advertising or marketing purposes. Transfers are limited to service providers acting on our instructions under contractual confidentiality and data-protection terms.
Google user data is protected with the same controls as other MyLens account and content data: encryption in transit (TLS) and at rest, private-by-default object storage for imported files, authentication via Auth0, least-privilege access for our systems and staff, and monitoring for abuse and security events. Access tokens for Google APIs are handled through our auth stack and are not exposed in client analytics products. Workspace content, including imported Drive files, is private to your account and workspace by default.
Soft-deleted accounts and related content are hard-purged after a short recovery window (see “Data Retention”). Server logs that may incidentally include technical details about auth or import requests are deleted after 15 days.
When you first visit MyLens we show a cookie banner. Analytics and marketing cookies are not set until you consent; only strictly necessary cookies are active by default. Your choice is stored for 12 months in the ml_consent cookie together with a timestamp and the version of this policy, and is passed to Google services via Google Consent Mode v2.
You can change or withdraw your consent at any time, with effect for the future, by clearing the ml_consent cookie in your browser (the banner will reappear on your next visit) or by contacting us at support@mylens.ai. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.
Legal basis: Legitimate interest — always active, no consent required
Required to operate MyLens: signing you in securely, keeping your session, and remembering your cookie choices. The service cannot function without them.
| Cookie | Provider | Duration | Purpose |
|---|---|---|---|
ml_consent | MyLens | 12 months | Stores your cookie consent choices so they are respected on future visits. |
auth0, auth0_compat, did, did_compat | Auth0 (Okta) | Session to 3 days | Keeps you securely signed in and helps detect fraudulent login attempts. |
Legal basis: Consent
Help us understand how MyLens is used — which features are popular, where errors occur, and how performance can be improved. Set only after you consent.
| Cookie | Provider | Duration | Purpose |
|---|---|---|---|
_ga, _ga_* | Google Analytics | 13 months | Counts visits and measures how the site is used. |
mp_* | Mixpanel | 12 months | Measures product usage and feature adoption. |
_dd_s | Datadog | 15 minutes | Real User Monitoring session used to measure performance and errors. |
Legal basis: Consent
Used for advertising measurement and campaign attribution. Set only after you consent.
| Cookie | Provider | Duration | Purpose |
|---|---|---|---|
_gcl_au | Google Ads | 3 months | Links visits to advertising campaigns (conversion attribution). |
_cioanonid | Customer.io | 12 months | Anonymous visitor identifier for messaging and campaign attribution. |
tolt_referral | Tolt | 60 days | Attributes your signup to an affiliate referral partner. |
ml_pending_signup, ml_pending_upgrade | MyLens | 1 hour | Links signups and upgrades to the marketing campaign that referred you. |
Most browsers also let you block or delete cookies via their settings. Blocking strictly necessary cookies may prevent parts of MyLens (such as sign-in) from working.
We share personal data only with service providers that help us operate MyLens, under data processing agreements that restrict them to processing on our instructions. We do not sell or rent your personal information. Providers marked “consent-based” only receive data if you accept the corresponding cookie category.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting, database, file storage, and transactional email (SES) | United States |
| Auth0 (Okta) | Authentication and sign-in security (including Google Sign-In) | United States |
| Google (Sign-In & Drive) | Google account authentication and optional Google Drive file import for story sources | United States |
| Stripe | Payment processing and billing | United States |
| Google (Gemini / Vertex AI) | AI content generation | United States |
| OpenAI | AI content generation | United States |
| Anthropic | AI content generation | United States |
| Microsoft (Azure OpenAI) | AI content generation | United States |
| Datadog | Infrastructure monitoring and error tracking | United States |
| Mixpanel | Product analytics (consent-based) | United States |
| Customer.io | Product and marketing messaging (consent-based) | United States |
| Tolt | Affiliate program attribution (consent-based) | European Union |
We may also disclose information where required by law, to protect our rights, or as part of a corporate transaction (in which case this policy continues to apply to your data).
Our infrastructure is hosted in the United States (AWS), and most of our service providers are US-based. Where personal data of users in the European Economic Area, the United Kingdom, or Switzerland is transferred internationally, we rely on appropriate safeguards such as the EU–US Data Privacy Framework certification of the provider or Standard Contractual Clauses.
EU data residency on request: if you are in the European Economic Area, the United Kingdom, or Switzerland and prefer your account data and content to be stored within the European Union, email support@mylens.ai with your request. We will migrate your data to EU-based infrastructure and confirm when complete. Some processing by the service providers listed above may still occur outside the EU under the safeguards described here.
We protect your data with encryption in transit (TLS) and at rest, private-by-default file storage, delegated authentication via Auth0, least-privilege access controls, and continuous monitoring. Passwords are stored only as salted hashes. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the relevant authorities as required by law. Additional detail for Google Sign-In and Drive data is in “Google User Data”.
Depending on where you live (including under the GDPR and similar laws), you have the right to:
To exercise any of these rights, use the in-product controls or email support@mylens.ai. We respond within one month and may need to verify your identity first. You may also revoke MyLens access to your Google Account in your Google Account permissions settings.
MyLens is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
We may update this policy as MyLens evolves or the law changes. For material changes we will notify you (for example by email or an in-product notice) before the changes take effect. The “Last updated” date at the top always reflects the current version.
Questions or concerns about this policy or your data? Reach us at support@mylens.ai or via https://mylens.ai.