Privacy Policy
Last updated: 2 August 2026
This policy explains how Thor Solutions Pvt Ltd handles personal data in lensdash (lensdash.app). It is maintained by us to answer common privacy questions about the service; it is not an independent audit or certification.
Who we are
Thor Solutions Pvt Ltd is the data controller for photographer accounts. For guest data inside a gallery, the photographer who created the gallery is the controller and we act as their processor. Contact: hello@thor.solutions.
Data we collect
Photographers: email address, password hash (managed by our authentication provider), studio name and branding you enter, plan and billing identifiers from our payment partners, and Google Drive authorisation tokens.
Photos: originals remain in your Google Drive. We store reduced-size derivatives (previews and indexing thumbnails) and numeric face descriptors — mathematical vectors derived from faces, not the faces themselves.
Guests: the selfie you take is used to compute a face descriptor for matching. If you choose to save your results we store your email address and a session reference so you can return to your photos.
Technical: standard server logs, IP address and error diagnostics needed to run and secure the service.
Biometric processing and consent
Face matching involves biometric processing. Selfie face embedding runs in your own browser; matching then compares that descriptor against descriptors for the gallery. Guests consent by choosing to take a selfie, and can simply close the page instead. Photographers must have a lawful basis and, where required, the consent of the people photographed.
How we use data
To operate your account, import and index photos you point us at, match guests to their photos, deliver downloads, take payment, prevent abuse, and provide support. We do not sell personal data and we do not use your photos or descriptors to train models for other customers.
Service providers
We rely on: Lovable Cloud (application hosting, database, authentication, storage), Google Drive (your own photo storage, accessed with your authorisation), Razorpay and Stripe (payments — card details go to them, never to us), and email delivery for account messages. Each processes data only to provide their service to us.
Retention
Gallery derivatives and face descriptors are kept while the gallery exists and are deleted when you delete the gallery or your account. Guest sessions, including a saved email, expire after 30 days. Account records and payment records are kept as long as needed for the account and for statutory accounting requirements.
Security
Data is transmitted over TLS and stored with per-account access rules enforced in the database. Gallery links are unguessable tokens and photo access is mediated server-side. Google Drive tokens are stored encrypted. No system is perfectly secure — please report concerns to us promptly.
Cookies
We use only the cookies and local storage needed to keep you signed in and to remember a guest gallery session. We do not run advertising trackers.
Your rights
You may request access, correction, deletion or a copy of your data, and withdraw Drive access at any time. Guests who want their selfie session or saved email removed can email us or ask the photographer. Write to hello@thor.solutions and we will respond within 30 days.
Changes
We will update this page when our practices change and revise the date above. Material changes affecting photographers will also be sent by email.