Back to home

Privacy Policy

How Hotel Lobby AI handles your account, reference photos, generated videos, payments, cookies, and privacy requests.

Last updated: 2026-10-03

1. Scope and contact

This policy explains how the operator of Hotel Lobby AI handles personal information when you browse our pages, use the Studio, create an account, buy credits, or contact support. In this policy, "we" and "our" refer to that operator. Contact us at support@hotellobby-ai.net about this policy or a privacy request. You do not need an account to email us.

Hotel Lobby AI is an independent service that uses third-party providers to generate media. This policy describes our handling of information. Providers and external websites also have their own privacy notices and contractual terms.

2. Information we process

The information involved depends on which features you use:

  • Account and sign-in information: your name, email, profile image if provided, account identifiers, email verification status, authentication records, and session records. Password sign-in uses a stored password hash. Third-party sign-in can provide a name, email, profile image, provider account identifier, and authentication tokens needed for that sign-in.
  • Reference photos and generation records: the two photos you submit, or their image URLs, the selected model, resolution and aspect ratio, generation instructions, task and provider identifiers, timestamps, status and error information, generated video links, and credits used or returned. Photos may contain personal information about you or other people. If you submit prompts or other media through an available generation feature, that request content is also processed.
  • Payments and credits: order identifiers, pack details, amounts and currencies, transaction and payment status, payment-provider identifiers, payer information returned by the provider, invoice references, and credit grants, consumption, and returns. Checkout providers handle payment credentials; we do not collect full card numbers or card security codes through the Studio.
  • Support communications: messages, ticket titles, attachments, replies, and contact details you choose to send.
  • Technical and usage information: IP addresses, browser and device information, request and session metadata, and diagnostic information used to deliver and protect the service. Account creation also records the signup IP address and, when available, a referral-source value. Optional analytics, advertising, or chat services may process additional usage information as explained below.

You can read and copy public prompt examples without submitting photos, creating an account, or buying credits. Ordinary website requests still involve technical information, and any enabled third-party scripts may operate on those pages.

3. How photos and videos are processed

Choosing a photo in the Studio prepares a resized copy in your browser. Submitting a generation request sends the selected photos and settings to our service. We send the reference images or their hosted URLs, the Studio's generation instructions, and a reference performance video to the AI provider handling the task.

The current video workflow uses Kie.ai, or fal.ai where the selected generation path requires it. When Kie.ai handles the request, inline photos are uploaded to its file service so the generation system can access them. The images may also be sent to fal.ai if a supported request is routed there after a confirmed submission rejection. Our task records retain reference image information or URLs and the provider's result information so you can view task history and we can reconcile status and credit charges.

AI processing uses the visual features in your photos to create a performance. Upload only images you have permission to process, including appropriate permission from depicted people or a child's legal guardian. Avoid submitting identity documents, confidential records, intimate photos, or other sensitive material.

Selecting a replacement photo, clearing an upload slot, closing the page, or downloading the video does not delete photos or task information already submitted. A provider may retain its own copies under its applicable terms. We do not promise that providers keep no data or never use submitted material for model improvement. See Kie.ai's privacy notice and fal.ai's privacy notice; provider processing also depends on the applicable service agreement.

4. Why we use information

We use information to create and authenticate accounts; submit and deliver generation tasks; show task history; process purchases and maintain credit balances; return credits for confirmed failures; respond to support and privacy requests; diagnose service problems; prevent unauthorized access, abuse, and payment fraud; and meet applicable legal obligations. Where enabled, analytics help us understand site usage, and advertising services deliver and measure ads.

Where data-protection law requires a legal basis, we rely on performance of a contract for account, generation, and purchase functions; legitimate interests for proportionate service security, troubleshooting, and support where permitted; legal obligations for required accounting and legal records; and consent where required for optional tracking or another processing activity. You can contact us about these bases or withdraw consent where processing relies on it. Withdrawal does not undo earlier lawful processing.

5. Who receives information

Information is disclosed as needed for the function you use:

  • AI and file providers: Kie.ai and fal.ai, as applicable, receive generation inputs and settings, host media, and return task status and outputs. Their downstream infrastructure and model providers may be involved in fulfilling the request.
  • Hosting and storage: Cloudflare provides hosting infrastructure. Uploaded files and site assets may use configured Cloudflare R2 storage; generated videos may remain on provider-hosted storage.
  • Authentication, payments, and email: if you choose third-party sign-in, its provider exchanges the information needed for login. The provider shown at checkout, such as Stripe, Creem, or PayPal when offered, receives purchase and customer information. Configured email services, such as Resend or Cloudflare Email, process the address and message needed for verification, password reset, or other service communications.
  • Optional analytics, advertising, and chat providers: Google Analytics, Plausible, Google AdSense, Crisp, or Tawk may receive the information described in the next section when enabled.
  • Authorized service administrators: relevant account, task, transaction, or support information may be accessed to operate the service, investigate problems, handle complaints, and resolve your requests.

We may also disclose relevant information when required by law or reasonably necessary to protect rights and service security. If the service is transferred as part of a business transaction, information may be transferred with it, subject to applicable privacy obligations and any required notice.

6. Media links and sharing

Your task-history and download endpoints require your account and check task ownership. That access control does not make the underlying media URL private. Provider-hosted or publicly hosted photo, attachment, or video URLs can be accessible to anyone who obtains the link. Do not treat an unlisted media URL as confidential storage.

Publishing or sending an output lets the recipient or platform copy and process it under their own rules. A deletion request to us cannot remove copies downloaded by others or published on another platform. Contact those recipients separately where necessary.

7. Cookies, browser storage, and optional services

Authentication cookies maintain sessions and support sign-in. Browser storage can retain interface preferences, such as sidebar state. Where available, a referral-source cookie can supply the source recorded when an account is created. Blocking required cookies can prevent sign-in from working.

The following optional integrations operate only when enabled for the site:

You can use browser settings to restrict cookies and storage, and use available provider controls. These controls may have different effects and do not necessarily stop all requests to a provider. Where applicable law requires consent or an opt-out mechanism, the relevant requirements apply to those integrations; this policy does not itself obtain consent. We do not represent that a site-wide cookie-preference control is currently available.

8. Retention and deletion

There is currently no fixed, site-wide automatic deletion schedule for account, generation, transaction, or support records. Retention is assessed by the purpose of the record: account operation; access to generation history and unresolved tasks; support and dispute handling; security investigations; and applicable accounting or legal requirements. Purchased credits do not expire, but this does not guarantee permanent availability of stored media.

Provider media and logs have separate retention rules. Kie.ai's current retention guidance describes generated-media retention of 14 days and log retention of two months. Those periods concern Kie's service, may change, and do not set the retention period for our task records, uploaded reference photos, or another provider's files. Download results promptly rather than relying on a provider link as a backup.

To request account closure or deletion of photos, videos, or associated records, contact us with the account email and any relevant task identifiers. There is currently no self-service account or generation deletion control. We will assess the request and explain any information that must remain for a legal obligation, an unresolved transaction, a dispute, or a security need. Deletion from our records does not by itself confirm deletion from provider storage, backups, or copies held by others; tell us if your request concerns those copies too.

9. Your privacy rights and choices

You can update available profile fields in your account and choose whether to submit photos or use optional third-party sign-in. Depending on applicable law, you may have rights to access or obtain a copy of personal information, correct it, request deletion, restrict or object to processing, receive portable data, or withdraw consent. You may also have rights concerning sale, sharing, or targeted advertising where those activities and local rules apply.

Email support@hotellobby-ai.net or open an account support ticket to make a request. We may ask for information reasonably needed to verify identity or authority, and will respond within the period required by applicable law. Do not send your password or full card details. If your photo was submitted by someone else, you can contact us without an account and provide the relevant link or other information that helps us locate it.

You may complain to your local data-protection authority where applicable. Exercising a privacy right does not remove any protection you have under consumer or data-protection law.

10. International processing and security

Our infrastructure and providers may process information in countries other than the one where you live, where privacy laws may differ. Transfers are subject to applicable legal requirements. Contact us if you need information about the providers or transfer arrangements relevant to your request; using the site is not, by itself, a substitute for a legally required transfer safeguard.

Account authentication and task-ownership checks help protect access to service records. No internet transmission or storage system can be guaranteed secure, and publicly accessible media URLs have the limitations described above. Use a strong password, protect your sign-in account, and report suspected unauthorized access promptly.

11. Children

The service is not intended for children under 13, and users must meet applicable local age requirements. If you believe a child has provided personal information without the necessary authorization, contact us so we can investigate and handle removal as required. A parent or guardian's permission to upload a child's photo does not authorize exploitative or otherwise prohibited content.

12. Changes and questions

We will post updates on this page with a revised date and provide additional notice of material changes where required. If new processing requires consent, that consent must be obtained separately. For privacy questions, contact support@hotellobby-ai.net.