Privacy Policy

Last updated: Jul 15, 2026

This Privacy Policy explains how MyLens (“MyLens”, “we”, “us”) collects, uses, shares, and protects your personal data when you use our website and services, and the choices and rights you have. MyLens acts as the data controller for the personal data described in this policy. If you have any questions, contact us at support@mylens.ai.

Information We Collect

  • Account information: your name, email address, password (stored as a salted hash — never in plain text), and optional profile details such as your field of work and how you found us. If you sign in with Google, we receive your Google account identifier, name, email, and (if available) profile photo via our authentication provider — see “Google User Data”.
  • Content you create: prompts, stories, visualizations, and documents or links you upload as sources. This includes files you choose to import from Google Drive, which we download into your workspace for story generation. Your content is private to you and your workspace by default.
  • Payment information: handled by Stripe. We store a Stripe customer reference and your subscription status; we never see or store full card numbers.
  • Usage and device information: how you interact with features, pages visited, and technical data such as browser type. Analytics data is collected only with your consent (see “Cookies and Consent”).
  • Log data: our servers record request logs including your IP address for security, abuse prevention, and troubleshooting. These logs are automatically deleted after 30 days.
  • Communications: messages you send us, feedback you submit in the product, and workspace invitations you send (which include the invitee’s email address).

How We Use Your Data and Legal Bases

  • To provide MyLens — creating your account, generating your content, importing sources you select (including from Google Drive), processing payments, and providing support (performance of a contract).
  • To secure the service — authentication, fraud and abuse prevention, monitoring, and debugging (legitimate interest).
  • To improve the product — consent-based analytics about feature usage and performance (consent).
  • To communicate with you — transactional emails about your account and, with your consent, product news and marketing (contract / consent).
  • To meet legal obligations — tax, accounting, and responding to lawful requests (legal obligation).

AI Processing and Your Content

To generate visualizations and stories, your prompts and source content — including content from Google Drive files you choose to import — are processed by AI providers (listed below) via their business APIs. Your content is not used to train AI models — neither by us nor by our AI providers, whose API terms exclude training on customer data. Content is sent only for the purpose of generating your requested output.

Google User Data

MyLens uses Google APIs for sign-in (Google authentication) and, when you choose, for Google Drive so you can select files as sources for story generation. The disclosures below explain what Google user data we access, how we use it, when we share it, how we protect it, and how long we keep it. Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Data Access

Depending on the features you use, MyLens may access the following Google user data:

  • Google Sign-In (authentication): basic profile information from your Google account used to create or sign in to MyLens — typically your name, email address, Google account identifier, and profile photo URL if available. We receive this through our authentication provider (Auth0). We do not access your Gmail, Contacts, Calendar, or other Google products for sign-in.
  • Google Drive (source import): when you connect Drive and pick files to use as sources, we access only the files you select — including file name, type, size, and other metadata needed to import them, plus the raw file contents we download so they can be stored in your workspace and used for story generation. We do not browse or continuously sync your entire Drive; access is limited to files you explicitly choose in the product.
  • Aggregated / anonymized Google user data: we do not create separate advertising or profiling datasets from Google user data. Any operational metrics (for example, that a Drive import succeeded or failed) are used only to operate and improve the import feature and are not sold or used for ads.

Data Use

We use Google user data solely to provide and improve user-facing MyLens features that you request:

  • Authentication: to identify you, create or link your MyLens account, and keep you signed in securely.
  • Google Drive sources: to download the files you select into our systems as workspace sources, extract text or other content as needed, and use that content as input to AI-assisted story and visualization generation — the same way we treat other sources you upload (PDFs, links, etc.).

We do not use Google user data to serve advertisements, to train generalized AI/ML models outside providing your requested output, to sell personal data, or for any purpose other than providing or improving MyLens features that interact with Google APIs. Your prompts and source content (including Drive files you import) are processed by our AI providers only to generate your requested output and are not used to train their models (see “AI Processing and Your Content”).

Data Transfer / Sharing

We share Google user data only as needed to run MyLens, with the types of parties below (also listed under “Our Service Providers”):

  • Authentication provider (Auth0 / Okta): processes Google Sign-In and passes account identifiers (such as email and Google user ID) to MyLens so we can create and secure your session.
  • Cloud infrastructure (Amazon Web Services): stores imported Drive file copies and related workspace data in our private storage and databases.
  • AI providers (for example Google Gemini / Vertex AI, OpenAI, Anthropic, Azure OpenAI): receive content derived from sources you import — including text or other material from Drive files you selected — only to generate the stories and visualizations you request.
  • Monitoring and support tools (for example Datadog): may process limited technical logs related to import or auth failures; we do not use these tools to sell or advertise based on Google user data.

We do not sell Google user data. We do not transfer Google user data to third parties for their independent advertising or marketing purposes. Transfers are limited to service providers acting on our instructions under contractual confidentiality and data-protection terms.

Data Protection

Google user data is protected with the same controls as other MyLens account and content data: encryption in transit (TLS) and at rest, private-by-default object storage for imported files, authentication via Auth0, least-privilege access for our systems and staff, and monitoring for abuse and security events. Access tokens for Google APIs are handled through our auth stack and are not exposed in client analytics products. Workspace content, including imported Drive files, is private to your account and workspace by default.

Data Retention and Deletion

  • Google Sign-In data: account identifiers (email, Google user ID, name) are retained for as long as your MyLens account remains active, so we can keep you signed in and recognize returning users.
  • Google Drive files you import: copies we download are stored as workspace sources for as long as they remain in your account (or until you delete the source or the related workspace content). We do not keep a separate indefinite archive of Drive files beyond what is needed for the sources you imported.
  • Deletion: you can remove imported sources from MyLens at any time. You can delete your entire account from account settings (Danger Zone), which erases your personal data and content — including imported Drive file copies — from our systems and, where applicable, from our service providers as described elsewhere in this policy. You can also revoke MyLens’s access to your Google Account at any time in your Google Account permissions; after revocation we can no longer access new Drive data, and existing imported copies remain until you delete them or your account in MyLens.

Soft-deleted accounts and related content are hard-purged after a short recovery window (see “Data Retention”). Server logs that may incidentally include technical details about auth or import requests are deleted after 15 days.

Cookies and Consent

When you first visit MyLens we show a cookie banner. Analytics and marketing cookies are not set until you consent; only strictly necessary cookies are active by default. Your choice is stored for 12 months in the ml_consent cookie together with a timestamp and the version of this policy, and is passed to Google services via Google Consent Mode v2.

You can change or withdraw your consent at any time, with effect for the future, by clearing the ml_consent cookie in your browser (the banner will reappear on your next visit) or by contacting us at support@mylens.ai. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.

Strictly necessary

Legal basis: Legitimate interest — always active, no consent required

Required to operate MyLens: signing you in securely, keeping your session, and remembering your cookie choices. The service cannot function without them.

CookieProviderDurationPurpose
ml_consentMyLens12 monthsStores your cookie consent choices so they are respected on future visits.
auth0, auth0_compat, did, did_compatAuth0 (Okta)Session to 3 daysKeeps you securely signed in and helps detect fraudulent login attempts.

Analytics

Legal basis: Consent

Help us understand how MyLens is used — which features are popular, where errors occur, and how performance can be improved. Set only after you consent.

CookieProviderDurationPurpose
_ga, _ga_*Google Analytics13 monthsCounts visits and measures how the site is used.
mp_*Mixpanel12 monthsMeasures product usage and feature adoption.
_dd_sDatadog15 minutesReal User Monitoring session used to measure performance and errors.

Marketing

Legal basis: Consent

Used for advertising measurement and campaign attribution. Set only after you consent.

CookieProviderDurationPurpose
_gcl_auGoogle Ads3 monthsLinks visits to advertising campaigns (conversion attribution).
_cioanonidCustomer.io12 monthsAnonymous visitor identifier for messaging and campaign attribution.
tolt_referralTolt60 daysAttributes your signup to an affiliate referral partner.
ml_pending_signup, ml_pending_upgradeMyLens1 hourLinks signups and upgrades to the marketing campaign that referred you.

Most browsers also let you block or delete cookies via their settings. Blocking strictly necessary cookies may prevent parts of MyLens (such as sign-in) from working.

Our Service Providers (Subprocessors)

We share personal data only with service providers that help us operate MyLens, under data processing agreements that restrict them to processing on our instructions. We do not sell or rent your personal information. Providers marked “consent-based” only receive data if you accept the corresponding cookie category.

ProviderPurposeLocation
Amazon Web ServicesCloud hosting, database, file storage, and transactional email (SES)United States
Auth0 (Okta)Authentication and sign-in security (including Google Sign-In)United States
Google (Sign-In & Drive)Google account authentication and optional Google Drive file import for story sourcesUnited States
StripePayment processing and billingUnited States
Google (Gemini / Vertex AI)AI content generationUnited States
OpenAIAI content generationUnited States
AnthropicAI content generationUnited States
Microsoft (Azure OpenAI)AI content generationUnited States
DatadogInfrastructure monitoring and error trackingUnited States
MixpanelProduct analytics (consent-based)United States
Customer.ioProduct and marketing messaging (consent-based)United States
ToltAffiliate program attribution (consent-based)European Union

We may also disclose information where required by law, to protect our rights, or as part of a corporate transaction (in which case this policy continues to apply to your data).

International Data Transfers

Our infrastructure is hosted in the United States (AWS), and most of our service providers are US-based. Where personal data of users in the European Economic Area, the United Kingdom, or Switzerland is transferred internationally, we rely on appropriate safeguards such as the EU–US Data Privacy Framework certification of the provider or Standard Contractual Clauses.

EU data residency on request: if you are in the European Economic Area, the United Kingdom, or Switzerland and prefer your account data and content to be stored within the European Union, email support@mylens.ai with your request. We will migrate your data to EU-based infrastructure and confirm when complete. Some processing by the service providers listed above may still occur outside the EU under the safeguards described here.

Data Retention

  • Account data and content: kept while your account is active. When you delete your account, your personal details are erased and your content is deleted, including uploaded files, Google Drive imports, and copies held by our service providers.
  • Server logs: deleted after 15 days.
  • Billing records: retained as required by tax and accounting law.
  • Consent records: your cookie choice is stored for 12 months.

Protecting Your Data

We protect your data with encryption in transit (TLS) and at rest, private-by-default file storage, delegated authentication via Auth0, least-privilege access controls, and continuous monitoring. Passwords are stored only as salted hashes. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the relevant authorities as required by law. Additional detail for Google Sign-In and Drive data is in “Google User Data”.

Your Privacy Rights

Depending on where you live (including under the GDPR and similar laws), you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Delete your data — you can delete your account yourself at any time from account settings (Danger Zone), which erases your personal data from our systems and our service providers;
  • Export your data in a portable format;
  • Request EU data residency — ask us to store your account data and content in the European Union (see “International Data Transfers”);
  • Withdraw consent at any time (see “Cookies and Consent”), without affecting prior processing;
  • Object to processing based on legitimate interest, and restrict processing in certain cases;
  • Complain to your local data protection authority.

To exercise any of these rights, use the in-product controls or email support@mylens.ai. We respond within one month and may need to verify your identity first. You may also revoke MyLens access to your Google Account in your Google Account permissions settings.

Children’s Privacy

MyLens is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.

Updates to This Policy

We may update this policy as MyLens evolves or the law changes. For material changes we will notify you (for example by email or an in-product notice) before the changes take effect. The “Last updated” date at the top always reflects the current version.

Contact Us

Questions or concerns about this policy or your data? Reach us at support@mylens.ai or via https://mylens.ai.