Privacy Policy

Last updated: May 21, 2026 · Version 1.0

This Privacy Policy explains what personal data Hooma Ltd collects when you use Setless, how we use it, who we share it with, and the rights you have over it. We collect the minimum data needed to run the service, never sell your data, and process it in line with UK GDPR, EU GDPR (where applicable), and US state privacy laws including CCPA. For questions, contact privacy@setless.app.

1. Who we are

This Privacy Policy is issued by Hooma Ltd ("we", "us", "our"), a company registered in England and Wales, registered office: 167-169 Great Portland Street, London W1W 5PF, United Kingdom.

We are the data controller for personal data you provide through the Setless service at setless.app.

You can contact our privacy team at privacy@setless.app.

We have not appointed a Data Protection Officer because we are not required to under UK GDPR. The privacy team owner is the point of contact for all data protection matters.

2. What data we collect

2.1 Account data

Email address, hashed password, display name (optional), profile picture (optional), account creation date, and authentication provider details if you sign in via Google.

2.2 Payment data

We use Stripeto process payments. We do not store full payment card numbers. We retain Stripe's customer reference ID, subscription status, invoice history metadata, and the last 4 digits of your card. Full card details are handled solely by Stripe under their terms.

2.3 Content you upload

Product images, brand assets, prompts, and any text descriptions you provide as part of using the Service.

2.4 Generated content

Images produced by the Service on your behalf, including associated metadata (scene, camera style, model used, generation parameters).

2.5 Usage data

IP address, browser type and version, device type, operating system, pages visited, actions taken in the product, timestamps, referring URL, language preference, and PostHog session identifiers.

2.6 Communications

Records of your communications with us via email, support chat, or feedback forms.

2.7 Cookies and similar technologies

See Section 10. We use first-party cookies for authentication and session management, and analytics cookies (PostHog) to understand product usage. We do not use advertising cookies.

3. How we use your data

We process personal data for the following purposes:

  • To create and manage your Account;
  • To provide the Service (run image generations, store your assets, deliver outputs);
  • To process payments and manage subscriptions;
  • To send transactional emails (account confirmations, receipts, security alerts);
  • To send product updates and marketing communications, where you have opted in or where permitted under soft opt-in rules;
  • To monitor and improve the Service, including analytics and feature usage tracking;
  • To detect, prevent, and respond to fraud, abuse, and security incidents;
  • To enforce our Terms and AI Content Use Policy;
  • To comply with legal obligations.

4. Legal basis for processing

Under UK GDPR and EU GDPR (where applicable), we rely on the following legal bases:

PurposeLegal basis
Providing the Service under the TermsContract (Art. 6(1)(b))
Processing paymentsContract (Art. 6(1)(b))
Transactional emailsContract (Art. 6(1)(b))
Marketing emails (opt-in)Consent (Art. 6(1)(a))
Analytics and product improvementLegitimate interest (Art. 6(1)(f))
Fraud prevention and securityLegitimate interest (Art. 6(1)(f))
Tax records, accountingLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interest, we have assessed that our interests do not override your rights and freedoms. You have the right to object — see Section 8.

5. Who we share data with

We share personal data only with the following categories of recipients, all of whom act as processors on our behalf under contractual terms compliant with UK GDPR:

ProviderPurposeLocation
StripePayment processingUSA
Firebase (Google)AuthenticationUSA
Cloudflare R2Image and asset storageGlobal (Cloudflare edge)
fal.aiAI image generationUSA
AnthropicAI text inference (Vision, Shoot Planner)USA
Google (Gemini)AI reference image generationUSA
ResendTransactional email deliveryUSA
PostHogProduct analyticsUSA (with EU option)
SentryError trackingUSA
DigitalOceanApplication hosting and databaseUSA / EU (region dependent)

We may also disclose personal data:

  • To comply with legal obligations, court orders, or lawful requests from public authorities;
  • To enforce our Terms and AI Content Policy;
  • To prevent fraud, abuse, or harm to our users or others;
  • In connection with a sale, merger, or reorganization of Hooma Ltd, subject to confidentiality protections.

We do not sell your personal data. We do not share personal data with advertising networks or data brokers.

6. International data transfers

Most of our processors are located in the United States. When we transfer your personal data outside the UK or EEA, we rely on:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission (and the UK equivalent IDTA) — for transfers to the US and other jurisdictions without an adequacy decision;
  • Adequacy decisions where they apply.

You may request a copy of the safeguards we use by contacting privacy@setless.app.

7. How long we keep data

Data categoryRetention period
Account dataUntil you delete your Account
Uploaded content and generated imagesUntil you delete them or 30 days after Account closure
Payment and invoice records7 years (UK tax law)
Server logs and security records90 days
Analytics data (PostHog)13 months
Support communications3 years after last interaction

When data reaches the end of its retention period it is deleted or anonymized. We may retain anonymized aggregate data indefinitely for analytics and product improvement.

8. Your rights

Under UK GDPR and EU GDPR you have the following rights:

  • Access — request a copy of the personal data we hold about you;
  • Rectification — request correction of inaccurate or incomplete data;
  • Erasure("right to be forgotten") — request deletion of your data, subject to legal retention requirements;
  • Restriction — request that we limit how we process your data;
  • Portability — request a copy of your data in a structured, machine-readable format;
  • Object — object to processing based on legitimate interest or for direct marketing;
  • Withdraw consent — for processing based on consent, you may withdraw at any time without affecting prior processing;
  • Lodge a complaint— file a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or your local supervisory authority in the EEA.

To exercise any of these rights, email privacy@setless.app. We respond within 30 days. We may ask you to verify your identity before acting on a request.

9. California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA") give you the following rights:

  • Right to know — what personal information we collect, use, disclose, and (if applicable) sell or share;
  • Right to delete — request deletion of personal information we have collected from you;
  • Right to correct — request correction of inaccurate personal information;
  • Right to opt out of sale/sharing — we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of, but the right is preserved;
  • Right to limit use of sensitive personal information — we do not process sensitive personal information for purposes beyond providing the Service;
  • Right to non-discrimination — we will not discriminate against you for exercising your rights.

To exercise these rights, email privacy@setless.appwith the subject "California Privacy Request" and include your account email so we can verify your identity.

Residents of Virginia, Colorado, Connecticut, Utah, and other US states with privacy laws have analogous rights. Contact privacy@setless.app to exercise them.

10. Cookies

We use the following cookies:

CookiePurposeType
SessionKeep you logged inStrictly necessary
CSRFPrevent cross-site request forgeryStrictly necessary
PostHogAnonymous product analyticsAnalytics (with consent)
StripeFraud prevention during checkoutStrictly necessary

You can disable non-essential cookies through our cookie banner or by adjusting your browser settings. Disabling strictly necessary cookies will impair core Service functionality.

11. Children

Setless is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact privacy@setless.app and we will delete it promptly.

12. Security

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit (TLS) and at rest, access controls, regular security reviews, and minimum-necessary data principles. No system is perfectly secure; if we become aware of a personal data breach affecting your data, we will notify you and the relevant supervisory authority where required by law.

13. Automated decision-making

The Service uses AI to generate images. These outputs are produced from inputs you provide and do not constitute automated decisions that produce legal or similarly significant effects on you under Art. 22 of UK GDPR. We do not use automated decision-making for credit scoring, hiring, or similar high-stakes decisions.

14. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email at least 30 days before they take effect, except where immediate change is required by law. The "Last updated" date at the top of this Policy reflects the latest revision.

15. Contact

For privacy questions or to exercise your rights, contact:

privacy@setless.app

Hooma Ltd
167-169 Great Portland Street, London W1W 5PF, United Kingdom

You also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office (ICO): ico.org.uk.