Privacy Policy
Hlam app (hlam.app) · last updated September 2, 2026 · Русская версия
Data controller: Sergey Egorov (Cyprus). Contact: support@hlam.app.
1. What data we process
- Account: your email address (email sign-in) or the identifier provided by Apple / Google when you sign in with them. Passwords are stored only as an irreversible hash.
- Inventory data (item and place names, descriptions, tags, statuses): it is stored on our server only when you turn sync on, and you choose the storage mode. With end-to-end encryption on, the data is stored encrypted only — you alone hold the key, and we cannot read the content. If you chose storage without encryption, the data is stored on the server in readable form and is technically accessible to us — we use it solely to provide the service.
- Photos: stored in DigitalOcean Spaces object storage (EU, Frankfurt); encrypted when end-to-end encryption is on.
- Token balance and purchases: your AI-token balance and purchase records — which pack was bought, the platform (App Store / Google Play), the amount and the transaction identifier. We never receive or store card details — payments are handled by the payment platforms.
- Technical data: server request logs (without the content of your data), needed to keep the service running.
2. Photo recognition (AI)
When you start a recognition, the selected photo is sent to OpenAI (processor, USA) to detect the objects in it, together with the names of your existing tags so the AI can reuse them, and your interface language. The photo is used only to produce the response; per OpenAI's API terms, API data is not used to train models. Recognition runs only when you trigger it — photos are never sent anywhere automatically, and the app asks for your explicit consent before the very first recognition. You can withdraw that consent at any time in the app settings; the app will then ask again before the next recognition.
3. Country detection by IP
To operate the service correctly for your country (regional settings and compliance with applicable legal requirements), the server determines the country of the request IP: first via an offline database, and only if that misses — via an external IP geolocation service (iplocation.net, processor). The IP address is never stored: the check runs in server memory, and only the IP itself is sent out for a one-off country lookup.
4. Payments
Purchases are made via the App Store or Google Play and are processed by Apple / Google under their terms and privacy policies. We only receive the purchase confirmation.
5. Where and how long data is stored
The application server and database are hosted in the EU. Data is kept while your account exists. After account deletion, purchase records are anonymised (unlinked from the account) but retained as financial records of completed transactions.
6. Public share links
You can publish a snapshot of an individual item at a link like
hlam.app/s/…. When you publish, the following is sent to the server
in readable form and becomes visible to anyone who has the link: the item's
name, description, one photo and status — exactly what you see before
publishing. End-to-end encryption is not weakened: only this snapshot is
published in readable form; the rest of your inventory remains inaccessible to
us.
The snapshot is frozen — later edits to the item do not appear on the page. The link is valid for 90 days from publication (refreshing the link creates a new publication) and can be revoked in the app at any time; on revocation or expiry the page and the photo are deleted from the server. To report unacceptable content behind someone else's link, contact support@hlam.app — every public page carries a "Report" link.
7. Your rights
- Export: you can download all account data right in the app (Profile → data export).
- Deletion: at any time, in the app, you can wipe all server data while keeping the account (turning sync off) — see instructions — or delete the account entirely, including all data and photos — see instructions.
- You can also contact us at the address above with any request about your data (access, rectification, erasure, objection).
Processing complies with the GDPR (for EU users) and applicable data-protection law.
8. Security
All connections use TLS. When end-to-end encryption is on, inventory content and photos are encrypted on the device before upload. Server access is restricted.
9. Changes
If this policy changes materially, we will update this page and the revision date.