Privacy Policy
Last updated: 27 July 2026
This policy explains how Interiørlab processes personal data in accordance with the Norwegian Personal Data Act and the GDPR. It is provided in good faith and is not legal advice.
1. Data controller
The data controller is Ramin Esfandiari. Contact: ramin.esfandiari@manaconsulting.no.
2. What we collect
- Account data: email, name and login IDs (Google/Apple) from the authentication provider.
- Uploaded photos of rooms and AI-generated images you create.
- Payment data: handled by Stripe. We never store card numbers – only order ID and status.
- Usage logs: credit ledger, generation logs and technical telemetry.
- Cookies / local storage: required for login, language choice and theme.
3. Legal basis
- Performance of a contract (GDPR art. 6(1)(b)) – to deliver the service.
- Legitimate interest (art. 6(1)(f)) – security, operations and product improvement.
- Consent (art. 6(1)(a)) – where we ask explicitly, e.g. optional analytics.
- Legal obligation (art. 6(1)(c)) – e.g. accounting law for payments.
4. How we use the data
We use your data to deliver the service, process payments, prevent abuse and improve the app. Uploaded photos are not used to train AI models without your explicit consent.
5. Sub-processors
- Supabase – authentication, database and image storage.
- Stripe – payment processing.
- AI model providers (via the Lovable AI Gateway) – image generation and analysis.
- SerpAPI / Google Lens – optional product search in images.
- Cloudflare – hosting and edge runtime.
6. Retention
Photos and account data are kept while your account is active. When you delete your account we remove personal data within 30 days, except data we are legally required to retain (e.g. accounting records for 5 years).
7. Sharing
We never sell personal data. Data is only shared with the sub-processors listed above, or when required by law or a public authority.
8. International transfers
We prefer EU/EEA hosting. Where transfers to third countries occur (for some AI providers), transfers are safeguarded by the EU Standard Contractual Clauses (SCCs) or equivalent mechanisms.
9. Your rights
You have the right to:
- access your personal data,
- have inaccurate data corrected,
- have data erased (“right to be forgotten”),
- restrict or object to processing,
- request data portability,
- lodge a complaint with the Norwegian Data Protection Authority (datatilsynet.no).
10. Security
We use Row-Level Security in the database, encryption in transit (TLS) and encryption at rest at our sub-processors. Access is restricted and logged.
11. Children
The service is not directed at children under 16. Guardians who believe a child has signed up should contact us so we can delete the account.
12. Changes
We may update this policy. Material changes will be announced in the app at least 14 days before they take effect.
13. Contact
Privacy inquiries: ramin.esfandiari@manaconsulting.no.