Privacy Policy
Last updated: 2 September 2026
1. Overview
Luttie is a colour grading tool that runs in your browser. This policy explains what we collect, why, who we share it with, how long we keep it, and what you can ask us to do with it. It covers luttie.app and the Luttie MCP server at luttie.app/api/mcp.
2. Your images
Where your images go depends on which feature you use. The difference matters, so it's spelled out rather than summarised.
Grading in the editor stays on your device. Curves, colour wheels, HSL, film effects, LUT preview and image export all run locally in your browser. Those images are never uploaded, and we cannot see them.
AI Grade uploads your image. When you use AI Grade — in the editor or through the MCP server — the image and your text prompt are sent to our server and on to OpenAI, which generates the grade. We do not store the image: it exists in memory for the length of the request and is not written to our database. OpenAI processes it under their own API terms.
Applying a LUT through the MCP server uploads your image. The apply_lut tool renders on our server and returns the result. The image is held in memory for the request and not stored.
Features you explicitly opt into store things for a fixed period. Sending a LUT to your phone, or exporting one over MCP, parks the LUT file behind a link that expires after 24 hours, after which it is deleted. Creating a shareable Pinterest-style grade link stores that image for up to 60 days.
3. Account data
If you create an account, authentication is handled by Clerk, which stores your email address, name, and sign-in method. We store your account identifier, your plan tier, and — if you generate one — a hash of each API key. We never store the key itself, which is why it is shown only once.
4. Payments
Payments are processed by Stripe. Card details go directly to Stripe and never reach our servers. We receive and store the resulting subscription state — your tier, and the Stripe customer identifier needed to manage or cancel it.
5. Usage data
We use a self-hosted Umami instance to count page views and basic events. It runs on our own infrastructure, is cookieless, and does not build a cross-site profile of you.
We also record product events — that a grade was exported, or a Pro feature was reached — so we can tell which features are worth keeping. For signed-in accounts these are stored against your account identifier. To rate-limit abuse on endpoints that work without an account, we store a hash of the IP address rather than the address itself.
Before you sign in, those same events are stored against two random identifiers kept in your browser: one for the device, one for the browser tab. They contain nothing about you, are never shared with anyone else, and let us see where people get stuck on the way to creating an account. If you then sign up, the device identifier is attached to your new account so that history becomes part of it. Clearing your browser storage discards both, and the next visit starts fresh.
6. Email
Transactional and product email is sent through Resend. Every non-essential email carries an unsubscribe link, and unsubscribing is permanent — we keep a suppression record so we don't email you again. If you reply to us, we store that message so we can answer it.
7. Who we share with
We do not sell your data, and we do not share it for advertising. We share only what a service needs to do its job:
- OpenAI — images and prompts sent to AI Grade
- Clerk — authentication and account records
- Stripe — payment processing
- Resend — email delivery
We may also disclose data where the law requires it.
8. How long we keep it
- Images sent to AI Grade or apply_lut — not stored; held in memory for the request only
- LUT handoff and MCP export links — 24 hours, then deleted
- Shared grade-link images — up to 60 days
- Account and subscription records — for as long as your account exists
- API key hashes — until you revoke the key or delete your account
- Product event records — retained while your account is active, for product analytics; events from before you signed up are kept for 12 months if no account claims them
- Email suppression records — kept indefinitely, so an unsubscribe stays honoured
9. Your choices
You can, at any time:
- Revoke an API key from the account menu, under Developer / MCP
- Unsubscribe from any non-essential email, via the link in it
- Ask for a copy of the data associated with your account
- Ask us to delete your account and its data
Email dom@luttie.app for access or deletion and we'll action it within 30 days. Deleting your account removes your account record, product events, and API keys; anonymised aggregate counts and email suppression records remain, since neither identifies you and the latter exists to keep us from emailing you again.
10. Cookies
Luttie does not use advertising or cross-site tracking cookies. Signing in sets a session cookie, which is required for the account to work. Your grading settings and saved projects are stored locally in your browser, not on our servers, as are the two random analytics identifiers described in section 5.
11. Children's privacy
Luttie is not directed at children under 13, and we do not knowingly collect their information. If you believe a child has given us data, email us and we'll delete it.
12. Changes
We may update this policy. Material changes will be reflected in the date at the top of this page, and we'll update it before a change takes effect rather than after.
13. Contact
Questions about this policy, or about data we hold on you, go to dom@luttie.app.