Legal document
Privacy Policy
Last updated: 8 September 2026 · Version 1.0 · GDPR compliant
This is an English translation of our French Privacy Policy, provided for convenience. In case of any discrepancy, the French version prevails.
1. Data controller
LCM LLC ("we", "our")
A limited liability company under United States law
Delaware, United States
Contact: privacy@tatua.fr
2. Data collected
We collect the following categories of data:
- Identification data: email, name (optional), profile picture (Google OAuth only)
- Payment data: processed by Stripe, we do not store card details
- Usage data: prompts entered, designs generated, credits used, sign-in dates
- Technical data: IP address, device type, browser, country
- Images you send us: for the try-on and editing tools. They are hosted with our storage provider and stay attached to your account. They are not published, not shown to another user, and not resold. You can ask for them to be deleted at any time by writing to support@tatua.fr from your account address.
- Cookies: sign-in session, preferences, analytics (see section 7)
3. Purposes of processing
| Purpose | Legal basis | Retention |
|---|---|---|
| Creating and managing the account | Performance of the contract | Lifetime of the account + 3 years |
| Generating AI designs | Performance of the contract | Lifetime of the account |
| Billing and payments | Legal obligation | 10 years (accounting) |
| Customer support | Legitimate interest | 3 years |
| Email marketing | Consent | Until unsubscribed |
| Usage measurement (Microsoft Clarity) | Consent | 13 months |
| Targeted advertising (Meta, TikTok) | Consent | 13 months |
| Improving the Service (AI) | Legitimate interest + consent | Anonymised after 12 months |
| Security (logs) | Legitimate interest | 12 months |
4. Recipients (processors)
We share certain data with technical providers, all contractually bound by a Data Processing Agreement:
- Netlify Inc. (USA): web hosting · DPF certified
- Stripe (USA): payment processing · PCI-DSS Level 1
- Replicate (USA): AI generation · does not store images after processing
- Cloudinary (USA/EU): image storage and CDN · EU region available
- Brevo (FR): transactional and marketing email · EU hosting
- Google LLC (USA): Google OAuth (sign-in) · DPF certified
- Microsoft (Ireland/USA): Microsoft Clarity, usage measurement and session replay, with consent
- Meta Platforms (USA): advertising pixel, with consent
- TikTok (USA/IE): advertising pixel, with consent. After consent, the email address may be sent to TikTok in hashed form (SHA-256) for advertising matching; a SHA-256 hashed email is also sent server-side for measuring advertising conversions
For transfers outside the EU, we rely on the European Commission's standard contractual clauses and on the EU-US Data Privacy Framework where applicable.
5. Your GDPR rights
Under the GDPR, you have the following rights:
- Right of access: obtain a copy of your data
- Right to rectification: correct inaccurate data
- Right to erasure ("right to be forgotten"): delete your data
- Right to restriction of processing
- Right to portability: retrieve your data in a structured format
- Right to object to processing
- Right to withdraw your consent at any time
- Right to give instructions about your data after death
To exercise your rights: privacy@tatua.fr. Reply within one month at most.
You may also lodge a complaint with the CNIL (France), the APD (Belgium), the FDPIC (Switzerland), or the CAI (Quebec).
6. Security
We put technical and organisational measures in place to protect your data:
- TLS 1.3 encryption for all communications
- Hashed passwords (PBKDF2 + unique salt) · Google OAuth with no password
- Session cookies HttpOnly + Secure + SameSite
- HSTS, CSP, X-Frame-Options enabled
- Data access limited to what is strictly necessary
- Regular security audits
- Daily encrypted backups
7. Cookies and trackers
We use three categories of cookies:
7.1 Essential cookies (no consent required): sign-in session (tatua_session), UI preferences, OAuth security.
7.2 Analytics cookies (consent required): Microsoft Clarity (usage measurement and session replay).
7.3 Advertising cookies (consent required): Meta Pixel, TikTok Pixel to measure campaign effectiveness. After consent, the account email address may be sent to TikTok in hashed form (SHA-256) for advertising matching; a SHA-256 hashed email is also sent to TikTok server-side for measuring advertising conversions.
You can change your cookie preferences at any time through the "Manage cookies" link below, or block cookies in your browser settings.
8. Uploaded images (Try-On, Image-to-Tattoo, Extract, Coverup)
8.1 The images you send us are passed to our generation provider for processing, then hosted with our image storage provider so that you can find them again in your space.
8.2 They stay attached to your account for as long as it exists. They are not published, not shown to another user, not resold, and not used for advertising. They serve only to produce your results.
8.3 You can ask for them to be deleted at any time by writing to support@tatua.fr from your account address. We delete them and confirm it to you.
8.4 Only the result (the generated design) is kept in your private gallery if you choose to save it.
9. Changes
We may change this policy to reflect legal or technical changes. You will be notified by email of any substantial change.
10. DPO contact
For any question about your data: privacy@tatua.fr