Privacy policy

Version du 12 septembre 2026.

1. Qui est responsable

Jimmy Leroy, entrepreneur individuel — 1 chemin rural derrière les Meix, 21130 Magny-Montarlot, France — SIRET [à compléter].
Contact pour toute question ou demande liée à tes données : leroyjimmy805@gmail.com.

2. Le principe : tes créations ne passent pas par nous

Lazarus est un pack de fichiers et un panneau web qui tourne dans ton navigateur. Tes photos, tes prompts, tes datasets, tes LoRA et tes rendus restent sur ton ordinateur ou sur l'infrastructure de calcul que tu loues toi-même (RunPod ou autre). Nous n'y avons pas accès, nous ne les stockons pas, nous ne les utilisons pas pour entraîner quoi que ce soit.

Les réglages de Lazarus Control (serveurs, identités, brouillons, historique des jobs) sont enregistrés dans le localStorage de ton navigateur, sur ta machine.

3. Ce que nous collectons

Quand tu achètes : nom, adresse e-mail, adresse de facturation, pays, montant, date, statut du paiement, numéro de commande. Le paiement est traité par Shopify et son prestataire de paiement : nous ne voyons jamais ton numéro de carte complet, seulement le type de carte et les quatre derniers chiffres.

Quand tu écris au support : ton adresse e-mail, le contenu de ton message et les pièces jointes que tu envoies.

Quand tu visites le site : données techniques de fonctionnement et de sécurité gérées par Shopify (adresse IP, type de navigateur, pages vues, horodatages), ainsi que les cookies décrits plus bas.

4. Pourquoi, et sur quelle base légale

  • Exécution du contrat : traiter la commande, envoyer le lien de téléchargement, répondre au support.
  • Obligation légale : conserver les pièces comptables et fiscales.
  • Intérêt légitime : sécurité du site, prévention de la fraude, mesure d'audience minimale.
  • Consentement : cookies non essentiels et, le cas échéant, e-mails commerciaux. Tu peux le retirer à tout moment.

Nous ne vendons aucune donnée personnelle et nous ne faisons pas de profilage publicitaire.

5. Qui d'autre voit ces données

  • Shopify (Shopify International Limited, Dublin, Irlande) : hébergement de la boutique, traitement des commandes, envoi des e-mails de commande, paiement.
  • Les autorités, uniquement sur demande légale valable.

Si tu connectes un service de calcul comme RunPod, c'est ton compte chez ce fournisseur : sa propre politique s'applique et nous ne sommes pas partie à cette relation.

6. Combien de temps

  • Commandes et pièces comptables : 10 ans, durée légale de conservation en France.
  • Échanges avec le support : 24 mois après résolution.
  • Journaux techniques et de sécurité : 90 jours environ, gérés par Shopify.

7. Transferts hors Union européenne

Shopify peut traiter certaines données en dehors de l'Union européenne. Ces transferts reposent sur les garanties prévues par le RGPD, notamment les clauses contractuelles types de la Commission européenne.

8. Cookies

Le site utilise les cookies strictement nécessaires au fonctionnement de la boutique et du panier, déposés par Shopify. Les cookies non essentiels ne sont déposés qu'avec ton accord et peuvent être refusés aussi simplement qu'acceptés.

9. Tes droits

Tu disposes d'un droit d'accès, de rectification, d'effacement, de limitation, d'opposition et de portabilité, ainsi que du droit de définir des directives sur le sort de tes données après ton décès. Écris à leroyjimmy805@gmail.com : nous répondons sous un mois.

Tu peux aussi introduire une réclamation auprès de la CNIL (3 place de Fontenoy, 75007 Paris — cnil.fr).

10. Mineurs

Lazarus est réservé aux personnes majeures. Le produit ne doit jamais servir à produire des contenus sexualisés impliquant des mineurs ou des personnes présentées comme telles. Si nous apprenons qu'un mineur a passé commande, la commande est annulée et les données supprimées.

11. Sécurité

Le site et le paiement s'appuient sur l'infrastructure de Shopify : transmission chiffrée (TLS), accès administrateur restreint, journalisation. Aucun service connecté à Internet ne peut garantir une sécurité absolue. En cas de violation de données présentant un risque, nous informons les personnes concernées et la CNIL dans les délais prévus par le RGPD.

12. Modifications

Cette politique peut évoluer avec le service ou la réglementation. La version en ligne porte toujours sa date de mise à jour.


English version — Lazarus is sold as a one-off digital download. Sections below that mention accounts or subscriptions apply only where such features exist.

Effective date: 12 September 2026

Last updated: 12 September 2026

This Privacy Policy explains how Jimmy Leroy (sole trader / entrepreneur individuel) ("we", "us", "our") collects, uses, stores and discloses personal information when you use Lazarus and our related website, software and services (the "Service").

Data Controller / Operator

Jimmy Leroy (sole trader / entrepreneur individuel)

1 chemin rural derrière les Meix, 21130 Magny-Montarlot, France

SIRET: [to be completed]

France

Privacy contact: leroyjimmy805@gmail.com

1. Our Privacy Principles

We design the Service around the following principles:

  • collect only information reasonably necessary to operate the Service;
  • minimise storage of generation content;
  • do not sell private Customer Content;
  • do not use private Customer Content to train our generative AI models without express opt-in consent;
  • do not build a biometric identification database from uploaded faces;
  • protect connected service credentials;
  • give users reasonable control over their information; and
  • comply with applicable data-protection laws.

2. Information We Collect

2.1 Account Information

When you register, we may collect:

  • name or username;
  • email address;
  • password authentication information;
  • account identifier;
  • country or approximate region;
  • subscription status; and
  • account preferences.

Passwords should be stored using industry-standard one-way password hashing where password authentication is operated directly by us.

2.2 Billing Information

Payments may be processed by a third-party payment processor.

We may receive information such as:

  • customer name;
  • billing address;
  • transaction identifier;
  • subscription plan;
  • payment status;
  • payment date;
  • partial payment-card information such as card type and last four digits; and
  • tax information where necessary.

We do not intentionally store full payment-card numbers when payments are handled by a compliant third-party payment processor.

2.3 Customer Content

When you use AI features, you may provide:

  • images;
  • photographs;
  • video;
  • audio;
  • prompts;
  • text;
  • workflow settings;
  • reference images;
  • character or identity references;
  • generated outputs; and
  • other files.

Customer Content may contain personal information about you or other people.

Because some features involve faces or likenesses, Customer Content may contain facial information or other characteristics associated with an identifiable individual.

We do not use uploaded facial information to create a general-purpose biometric identification database or to authenticate individuals.

2.4 Connected Service Information

If you connect a third-party compute provider such as RunPod, we may process:

  • API credentials or access tokens;
  • account or endpoint identifiers;
  • pod or server identifiers;
  • deployment status;
  • job status;
  • usage information; and
  • technical information necessary to establish and maintain the connection.

Sensitive API credentials must be encrypted at rest and protected using access controls.

We do not intentionally expose connected-service credentials to other customers.

2.5 Device and Technical Information

When you access the Service, we may automatically receive:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • timestamps;
  • pages or features accessed;
  • error information;
  • security events;
  • session identifiers; and
  • approximate geographic information derived from IP address.

We use this information primarily for security, operation, troubleshooting and service improvement.

2.6 Support Communications

If you contact us, we may retain:

  • your contact details;
  • the contents of your request;
  • files voluntarily attached to the request; and
  • our response.

Do not send passwords, private API keys or unnecessary sensitive material through support channels.

3. How We Use Personal Information

We may process personal information to:

  • provide the Service;
  • create and administer accounts;
  • authenticate users;
  • execute AI-generation requests;
  • communicate with connected compute services;
  • process subscriptions and payments;
  • provide customer support;
  • maintain security;
  • detect abuse, fraud and unauthorised access;
  • troubleshoot errors;
  • maintain service reliability;
  • comply with legal obligations;
  • enforce our Terms of Service;
  • investigate prohibited use;
  • protect users and third parties;
  • maintain financial and tax records;
  • improve the Service using appropriately minimised usage information; and
  • communicate important changes to the Service.

We will not materially repurpose private Customer Content for an unrelated purpose without an appropriate legal basis and, where required, notice or consent.

4. AI Training

Private Customer Content is not used to train our proprietary generative AI models unless the user separately and affirmatively opts in.

Consent to training will not be bundled into acceptance of the general Terms of Service.

Declining optional training will not prevent access to ordinary paid Service functionality unless a particular optional feature inherently requires such processing and this is clearly explained beforehand.

Where third-party models or services are selected by you, their own privacy and data-use practices may apply.

You should review the terms of third-party services before connecting them.

5. How AI Generation Is Processed

Our Service is designed to minimise our possession of Customer Content.

Where supported by the selected configuration:

  • you submit a request through our interface;
  • the Service prepares the required workflow or command;
  • the request is transmitted to your connected compute environment, such as your RunPod instance;
  • AI processing occurs within that environment;
  • the resulting output is returned to you; and
  • unnecessary temporary copies within our own infrastructure are deleted.

Our systems may temporarily cache data where technically necessary to transfer a file, complete a job, recover from an immediate error or maintain system security.

Temporary generation content held by our infrastructure should ordinarily be deleted within 24 hours after processing unless:

  • you explicitly choose a feature requiring longer storage;
  • additional retention is reasonably necessary to investigate a security incident or abuse;
  • the information must be preserved by law; or
  • you ask us to retain it.

Persistent galleries or cloud libraries, if introduced, will clearly disclose their storage behaviour separately.

6. Uploaded Images of Other People

You should only provide images or information concerning another person where you have a lawful basis to do so.

The Service is not intended to establish whether you have obtained required consent.

Under our Terms, users are prohibited from using the Service for non-consensual intimate imagery, unlawful impersonation, child sexual exploitation, fraud and other unlawful identity-based uses.

If we receive a valid privacy or legal complaint concerning uploaded material, we may investigate, restrict processing, preserve necessary evidence or delete information where appropriate.

7. Legal Bases Under the GDPR

Where the EU General Data Protection Regulation applies and we act as a controller, we rely on one or more of the following legal bases.

Contract

We process information where necessary to provide the Service you requested, administer your account, connect your infrastructure, process subscriptions and provide support.

Legitimate Interests

We may process limited information where necessary for legitimate interests such as:

  • protecting account security;
  • preventing fraud;
  • troubleshooting;
  • maintaining service reliability;
  • defending legal claims; and
  • understanding basic service performance.

We consider the impact on individuals before relying on legitimate interests.

Legal Obligation

We process information where necessary to comply with obligations relating to areas such as tax, accounting, law enforcement requests and regulatory requirements.

Consent

We rely on consent where required, including for certain non-essential cookies, optional marketing communications and any optional programme involving use of Customer Content for AI training.

You may withdraw consent at any time without affecting processing that was lawful before withdrawal.

8. Business Customer Data

Where a business customer submits personal data through Customer Content and instructs us to process that information solely on its behalf, data-protection law may treat that customer as the controller and us as its processor.

In those circumstances we will:

  • process the data only on documented instructions except where law requires otherwise;
  • require appropriate confidentiality from personnel with access;
  • maintain appropriate security safeguards;
  • provide reasonable assistance regarding data-subject requests;
  • provide reasonable assistance with legally required security and breach obligations;
  • use subprocessors subject to appropriate protections;
  • delete or return relevant data at the end of processing where required; and
  • make information reasonably necessary to demonstrate compliance available as required by applicable law.

Business customers requiring a separate Data Processing Agreement may contact leroyjimmy805@gmail.com.

9. Sharing Personal Information

We may disclose information to service providers that assist us in operating the Service, including providers of:

  • cloud hosting;
  • authentication;
  • database infrastructure;
  • payment processing;
  • transactional email;
  • security monitoring;
  • customer support;
  • error monitoring; and
  • infrastructure management.

These providers should receive only information reasonably necessary for their function.

A current list of material subprocessors should be maintained at:

https://lazarusai.shop/policies/privacy-policy

or may be requested from leroyjimmy805@gmail.com.

10. Customer-Directed Third-Party Services

You may instruct the Service to transmit information to a third-party account controlled by you, such as RunPod.

Where you independently select, configure and control that account, the third-party provider may process data according to its own agreement with you.

You are responsible for reviewing the provider's privacy, security and regional-hosting options before using it for sensitive material.

11. International Data Transfers

The Service may involve processing in more than one country.

Where personal information is transferred internationally, we will use protections required by applicable law.

For data protected by the GDPR, these may include:

  • an adequacy decision;
  • approved Standard Contractual Clauses;
  • another legally recognised transfer mechanism; or
  • another applicable lawful basis.

If you intentionally select a particular third-party infrastructure region, information may be transmitted to that region at your direction.

12. Cookies and Similar Technologies

We may use essential technologies necessary for:

  • login sessions;
  • account security;
  • fraud prevention;
  • user preferences; and
  • basic operation of the Service.

Where applicable law requires consent, non-essential analytics, advertising or marketing cookies will not be activated until the required consent has been obtained.

Users must be able to reject optional cookies as easily as accepting them where applicable law requires this.

Withdrawal of optional-cookie consent will not disable essential account functionality.

Details of individual cookies should be made available through leroyjimmy805@gmail.com.

13. Analytics

We may collect limited analytics necessary to understand performance and improve the Service.

Where reasonably possible, analytics information should be minimised, aggregated or pseudonymised.

We do not use private Customer Content for advertising profiles.

We do not sell personal information to data brokers.

14. Marketing

We may send service-related messages necessary to administer your account.

Marketing communications will be sent only where permitted by applicable law.

Where required, we will obtain consent before sending electronic marketing.

You may unsubscribe from marketing communications at any time.

Unsubscribing from marketing does not prevent essential account, billing, security or legal notices.

15. Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy.

Unless a longer period is required by law or reasonably necessary for security or legal claims, our target retention periods are:

Temporary generation files: normally no more than 24 hours on our infrastructure.

Operational and security logs: normally up to 90 days.

Account information: while the account remains active and normally deleted or anonymised within 30 days following account deletion, subject to required records.

Support communications: normally up to 24 months after resolution.

Billing, accounting and tax records: for the period required under applicable financial and tax law.

Security, fraud and legal records: for as long as reasonably necessary to investigate or defend the relevant matter.

Information may remain for a limited additional period in encrypted backups until those backups are overwritten according to normal backup cycles.

16. Account Deletion

You may request deletion of your account through an e-mail to leroyjimmy805@gmail.com or by contacting leroyjimmy805@gmail.com.

Deletion does not necessarily require us to erase information that:

  • must legally be retained;
  • is necessary to establish, exercise or defend legal claims;
  • relates to fraud or security incidents that require retention;
  • has already been irreversibly anonymised; or
  • must otherwise lawfully be retained.

We will not retain information indefinitely merely because it might become useful later.

17. Your Privacy Rights

Depending on where you live, you may have rights concerning your personal information.

These may include the right to:

  • obtain information about processing;
  • access your information;
  • correct inaccurate information;
  • request deletion;
  • restrict certain processing;
  • object to certain processing;
  • receive eligible information in a portable format;
  • withdraw consent;
  • object to direct marketing; and
  • lodge a complaint with a data-protection authority.

Not every right applies in every circumstance.

To exercise a privacy right, contact:

leroyjimmy805@gmail.com

We may need to verify your identity before fulfilling a request.

We will not discriminate against you for exercising a privacy right.

18. European Users

Users protected by the GDPR may contact the competent supervisory authority if they believe their information has been processed unlawfully.

If our principal EU establishment is in France, the relevant supervisory authority will generally be:

Commission Nationale de l'Informatique et des Libertés (CNIL)

We encourage you to contact us first so that we have an opportunity to address your concern.

If applicable law requires us to appoint an EU representative or Data Protection Officer, their contact information will be published in this Policy.

20. Security

We use technical and organisational safeguards appropriate to the risks of the Service.

Our security programme should include measures such as:

  • encrypted transmission using modern TLS;
  • encryption or equivalent secure protection for stored secrets and API credentials;
  • one-way password hashing;
  • role-based or least-privilege administrative access;
  • separation of production credentials;
  • authentication controls;
  • logging of sensitive administrative actions;
  • timely software and dependency updates;
  • security monitoring;
  • protected backups where backups are used; and
  • procedures for responding to security incidents.

No system connected to the internet can be guaranteed completely secure.

If we become aware of a personal-data breach, we will investigate and provide notifications where required by applicable law.

21. API Keys and Secrets

Third-party API credentials are treated as sensitive information.

We will not intentionally:

  • display secret API credentials publicly;
  • include them in public URLs;
  • expose them to other customers;
  • sell them;
  • use them for purposes unrelated to providing the requested integration; or
  • retain them after they are no longer reasonably needed.

Users should revoke a connected credential immediately if they believe it has been compromised.

22. Children's Privacy

The Service is for adults aged 18 and older.

We do not knowingly permit minors to create accounts.

The Service must not be used to process sexualised content involving minors.

If we learn that a minor has improperly created an account or supplied personal information, we may delete the account and associated information.

Contact leroyjimmy805@gmail.com to report concerns involving a minor.

23. Automated Decision-Making

We do not use account data to make decisions producing legal or similarly significant effects about users solely through automated processing unless this is clearly disclosed and legally permitted.

Automated systems may be used to identify potential fraud, abuse or security threats.

Where a significant enforcement decision is based on an automated signal, we may review additional information before final action where reasonably appropriate.

24. Law Enforcement and Legal Requests

We may preserve or disclose information where we reasonably believe doing so is required by applicable law, a valid legal process or an enforceable governmental request.

Where legally permitted and reasonably appropriate, we may notify the affected user.

We may challenge requests that we reasonably believe are invalid, excessive or unlawful.

25. Corporate Transactions

If the Service or Provider is involved in a merger, acquisition, financing, restructuring or sale of assets, personal information may be transferred as part of that transaction subject to applicable law.

Any successor handling personal information will remain subject to applicable privacy obligations.

26. Changes to This Policy

We may update this Privacy Policy when our Service, processing practices or legal obligations change.

The current version will display its effective date.

If a change materially affects how we use personal information, we will provide additional notice or request consent where required by law.

27. Contact Us

Questions, complaints and privacy requests may be sent to:

Jimmy Leroy (sole trader / entrepreneur individuel)

1 chemin rural derrière les Meix, 21130 Magny-Montarlot, France

France

Privacy: leroyjimmy805@gmail.com

Security: leroyjimmy805@gmail.com

General support: leroyjimmy805@gmail.com