Legal

Privacy Policy

A plain account of the information processed by darkrm's current service.

On this page

  1. Controller and bases
  2. What we collect
  3. Photographs and generation
  4. Third parties
  5. Retention and deletion
  6. Cookies and local storage
  7. Your rights
  8. Information to complete

Last updated: 24 August 2026

Deployment hold: this Privacy Policy is not final until [LEGAL OPERATOR NAME], [CORRESPONDENCE ADDRESS] and [SUPPORT EMAIL] are replaced with verified details.

1. Data controller and lawful bases

[LEGAL OPERATOR NAME], an individual trading as darkrm, is the data controller for personal information processed to operate darkrm. The correspondence address is [CORRESPONDENCE ADDRESS].

We rely on contract where processing is necessary to provide the service you request, including account operation, storing photographs and saved work, generation requests, Voice settings, usage allowances and core workspace functions. We may rely on legitimate interests, subject to balancing them against your rights and interests, for service security, abuse and fraud prevention, diagnostics, reliability, cost and usage monitoring, and privacy-focused aggregate analytics. Consent will be used for genuinely optional processing, such as future marketing communications or future non-essential tracking. We may also process or retain information where necessary to comply with a legal obligation.

2. What we collect

darkrm processes the information needed to provide its current photographer workspace. This can include your email address and sign-in identifier from Google, a display name when supplied by the sign-in provider, signed-session information, uploaded photographs, image dimensions and stored file path, the context and controls you enter for a photograph, saved titles, captions, hashtags and draft versions.

If you use Your Voice, the service processes the preferences, writing sample, selected interests, goals, choices and summary you provide. It also records usage and credit information associated with generation requests. If you submit an early-access email address through the launch-interest feature, the application stores the address and submission source.

3. Photographs, context and generated content

Before upload, the browser processes a selected JPEG, PNG or WebP image into a resized JPEG. The current upload path accepts that JPEG and stores it in service storage with a database record containing the user account, file path, JPEG type, width and height. The original source file is not the file sent by the browser's upload request.

When you ask darkrm to prepare content, the service sends the resized photograph and relevant information needed for that request to the OpenAI API. This may include your selected context, location or venue, target audience, photo vibe, platform, caption style and length, relevant earlier draft text and completed Voice-profile information. darkrm uses the Responses API with store: false, so it does not ask OpenAI to retain response application state.

darkrm does not use photographs, context or generated output to train its own models. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in to data sharing. OpenAI also states that standard API usage may create abuse-monitoring logs that retain inputs and outputs for up to 30 days, unless retention is required for longer by law. darkrm does not have Zero Data Retention configured in this repository and does not claim it.

darkrm saves generated titles, captions and hashtags with the photograph's draft versions so you can review, edit and return to them. Platform choices influence the generation request only. darkrm does not connect to or post to social accounts in the current service.

4. Third-party services and international processing

The public website uses the standard Ahrefs Web Analytics script. The current implementation has no Ahrefs conversion or cookie feature configured. Ahrefs states that standard Web Analytics is cookie-free by default and does not collect or store personal data or persistent identifiers by default. The implementation also uses Bootstrap files from the jsDelivr CDN. Google is the sign-in route currently exposed in the interface.

OpenAI processes generation requests as described above. The authentication code contains support for Apple and Facebook sign-in when configured, but those providers are not currently presented in the public interface and are not described here as active account options. The repository does not identify the hosting provider.

Personal information may be processed outside the UK by service providers. Where data-protection law requires safeguards for an international transfer, the operator will use safeguards required by that law. The applicable provider contracts, processing locations and transfer arrangements have not been verified in this repository.

5. Retention, deletion and exports

The application stores account records, sign-in identities, photographs, saved drafts, Voice-profile records, launch-interest entries and usage records in a SQLite database, with uploaded image files stored by the application. A photograph can be deleted from its workspace. That action deletes its database record and associated saved drafts, and attempts to remove its stored image file from active application storage.

The following are intended retention targets. The current repository does not show automated retention jobs, an account-deletion workflow, export tooling or backup rotation. These targets must be implemented and operationally verified before this policy is treated as final.

  • Account information: while the account is active, then target removal from active systems within 30 days of a verified deletion request, except where retention is required for legal, fraud-prevention or security purposes.
  • Photographs: while stored in your gallery. A user-initiated photograph deletion is supported now; backups should expire through normal rotation within 30 days after deletion from active systems.
  • Saved drafts, generated content and supplied context: while saved to the account, then deleted with the relevant content or account where technically linked.
  • Voice and profile settings: until changed, removed or the account is deleted.
  • Launch-interest records: target a maximum of 12 months, unless the person becomes a user, there is an ongoing relevant relationship, or earlier removal is requested.
  • Application and security logs: target 90 days under normal circumstances, with longer retention where reasonably needed to investigate abuse, fraud, security incidents or legal claims.
  • Generation usage and cost telemetry: target 12 months for service monitoring, cost analysis, abuse prevention, reliability and product analysis. The telemetry code records usage, cost and request metadata, not generated caption text.

You may request account deletion, access to your personal information or a copy of relevant account content at [SUPPORT EMAIL]. We may verify the request and account ownership where necessary. There is no self-service deletion or export feature, and no verified manual procedure, in the current implementation.

6. Cookies, local storage and analytics

darkrm uses a signed, HTTP-only essential session cookie called darkrm_session to keep an authenticated session. The current code sets a maximum lifetime of 14 days. It also uses local storage for theme preference, Voice-profile progress and selected Voice information, and uses local or session storage for launch-prompt state. These browser-storage items support the site experience.

Ahrefs Web Analytics is distinct from the essential session cookie. The standard Ahrefs script currently used by darkrm is cookie-free by default and is described by Ahrefs as privacy-focused aggregate analytics without persistent identifiers. No consent is claimed or collected for optional marketing or non-essential tracking because those features are not active in the current implementation.

7. Security

The code includes signed session handling, account-scoped access checks for photographs and API routes, and standard HTTP security middleware. These implementation details are not a guarantee of security. Hosting arrangements, backups, incident procedures and encryption practices require operational verification.

8. Your rights and children

UK users may have rights under data-protection law, including rights to ask for access, correction, deletion, restriction, objection, portability and, where relevant, withdrawal of consent. To make a request, contact [SUPPORT EMAIL]. darkrm is intended for adults aged 18 and over. It is not intended for children under 18 and does not knowingly seek to collect their personal information.

No ICO registration number is displayed because no valid registration has been confirmed.

9. Contact and information to complete

For now, the only published route is the Contact page, which itself says that contact details and a secure form are still to be configured.

Owner review required before final privacy use: establish the legal operator and working support mailbox, complete the ICO fee self-assessment and register if required, implement and verify account-deletion/export handling and retention jobs, confirm backup rotation, hosting and transfer arrangements, and verify provider terms and contracts.

© darkrmThe photographer's assistant.
FeaturesFAQTermsPrivacy