Privacy
What we do with your data.
Numeri sets one cookie to keep you signed in. Three third-party scripts can load: Microsoft Clarity and Google Analytics, if and only if you accept them, and Google's sign-in button, on the sign-in screen only, for those who choose to continue with Google. The one thing you should read before uploading anything: your product photograph is processed outside the European Union.
Last updated 24 September 2026. Controller: Odratta, a French SARL.
The short version
Three things, then the detail.
Cookies
One cookie, and one question
The cookie keeps you signed in. The question is whether we may measure how the site is used, with Microsoft Clarity and Google Analytics. Nothing loads until you say yes, and you can change your mind.
Transfer
Your photo goes to the US
Rendering happens at WaveSpeed AI, outside the European Union. it is how the service works. The detail is below.
Metadata
EXIF is stripped
Every uploaded image is re-encoded on our server. Colour profile, comments and GPS coordinates are destroyed before anything else happens.
Collected
What we hold, and why.
If a field is not needed to run your account or to make your video, we do not ask for it.
Your account
- Email address
- Required: your login, and where the video lands
- Sign-in code
- Never stored in clear: a SHA-256 hash, valid 10 minutes
- Name, company, country
- Optional, declared by you, for invoicing
- WhatsApp number
- Optional: only so we can help you use Numeri, never for ads. Remove it from your account at any time
- IP address at sign-up
- Required: proof of registration, abuse prevention
Your content
- The product photograph you upload
- Re-encoded on arrival, EXIF and GPS destroyed
- The intermediate studio image
- Produced automatically, never shown for approval
- The delivered video
- Yours to download
- Optional note
- Kept with the job
Billing
- Payment card number
- Never reaches us, our payment provider handles it
- Payment provider identifiers, amounts, status
- Stored, with the payment method label only
- Allowance history
- Stored, to show what you used
Technical records
- Audit log: sign-ins and code requests
- With the IP address and browser, for security and abuse prevention
- Session IP and user agent
- Recorded when the session opens; a session lasts 30 days at most
- Failed renders
- To learn from outages
- Web server logs
- Kept for intrusion monitoring, rotated by size
Help requests, Business enquiries and chat conversations keep your IP address hashed with a secret, never in clear. The audit log, session records, the sign-up record and sign-in code requests keep it as received. How long each of these is kept is set out under How long we keep it.
Processors
Nine companies touch your data.
No CDN, no font host, no embedded player. Two analytics providers, Microsoft Clarity and Google Analytics, and only with your consent — still nine companies, because Google is already in the table below. One sign-in provider, Google, whose button loads on the sign-in screen only, and does nothing until you press it, and whose Analytics measures the site if you accepted it. The site's content security policy blocks outbound requests to every other third party outright.
- WaveSpeed AI, renders the image and the video, writes the replies of Numeri Bot, the virtual assistant of the chat, and reads your description in Automatic mode to write the film plan
- Outside the EU
- Dodo Payments, Inc., sells and collects purchases started on or after 18 September 2026, as merchant of record: it hosts the payment page, collects any applicable tax and issues your invoice
- United States (with affiliates in the United Kingdom and India); data protected by Dodo Payments' standard contractual clauses
- Stripe Payments Europe, Limited, collects subscriptions started before 18 September 2026
- Ireland, EU; may also process in the United States
- Mollie B.V., collects subscriptions started before 8 September 2026
- Netherlands, EU
- OVH SAS, hosts the server
- France, EU
- Resend, sends transactional email
- Outside the EU
- Brevo (Sendinblue SAS), holds our contact list, including a WhatsApp number if you left one, and sends marketing email
- France, EU
- Google (Sign in with Google, and Google Analytics), only if you choose that button: hands us your email address and your name, and learns that you signed in to Numeri; and, if you accepted usage analytics, runs Google Analytics on the site
- Google Ireland Ltd, EU; may be processed outside the EU
- Microsoft (Clarity), records how the site is used, only if you accept
- May be processed outside the EU
WaveSpeed AI, and the transfer outside the EU
Product photographs are processed by our rendering provider, WaveSpeed AI, which operates the AI models used to generate your image and your video, on servers outside the European Union. WaveSpeed AI is the only provider we send your photographs and your videos to outside the European Union.
The chat in the corner of the site is answered by Numeri Bot, our virtual assistant, an AI. To write each reply, the messages of that conversation, the page you are on and your browser language are sent to WaveSpeed AI's language model service, outside the European Union; if you are signed in, so is a short summary of your own account (credit balance, plan, number of videos). Your photographs, your videos and your email address are never sent. When Numeri Bot cannot answer, it gives you the team's contact, and the team can read the conversation.
In the studio's Automatic mode, our AI reads the description you write and looks at your photos to write the film plan. For that, your description, the length and format you picked, your browser language and a reduced copy (768 px) of up to two of your photographs are sent to WaveSpeed AI's language model service, outside the European Union. Your email address and your account details are never sent. We do not keep your description. The plan our AI writes can be used for two hours, then it is deleted automatically; if you press Generate, it becomes part of that video's record, like the other settings of the video, and it is included when you export your data.
One other item leaves the Union, and we would rather say it here than let you find it in the table: your email address, each time Resend sends you a transactional message : the code that signs you in, a receipt, or a notice that a payment did not go through. Nothing else crosses the border, except your chat messages to Numeri Bot and, in Automatic mode, your description with its reduced photos (above), and the usage analytics you may have accepted (see Cookies): Microsoft and Google may process analytics data outside the Union. Mollie, OVH and Brevo are all established in the European Union; so is Stripe's European entity, although Stripe may also process payment data in the United States. Dodo Payments, the merchant of record for purchases made from 18 September 2026, is established in the United States and processes your billing details there and in India.
For rendering, we do not upload your file to them. We hand over a signed URL, valid for one hour, that grants access to that single file, and WaveSpeed AI fetches it from our server. The result is then pulled back to us. The provider's output URL is never handed to you, and never made public.
Google, if you sign in with it
“Continue with Google” is optional; the email code does the same job. If you use it, Google's script loads on the sign-in screen, Google confirms who you are and hands us two things: your email address and the name on your Google account. We ask for nothing else, no contacts, no calendar, no files, and we never receive your Google password. Google, for its part, learns that you signed in to Numeri, under Google's own privacy policy.
Dodo Payments, Stripe, Mollie, and your card
We never see a card number. Since 18 September 2026, new subscriptions and one-time purchases are sold by Dodo Payments, Inc., acting as merchant of record: you are redirected to a payment page hosted by Dodo Payments, which charges you, collects any applicable tax, issues your invoice and keeps your billing details and payment method under Dodo Payments' own privacy policy. Subscriptions started earlier stay with the provider that opened them: you are redirected to a payment page hosted by Stripe, or by Mollie for a subscription started before 8 September 2026; there is no payment iframe, no payment SDK and no payment script in our pages. What we keep on our side is the provider's identifiers, the amount, the currency, the status, and the label of the payment method, “Visa” for instance, never the number itself. Stripe contracts with you through Stripe Payments Europe, Limited, in Ireland, and may also process payment data in the United States under Stripe's own privacy policy. Mollie is established in the European Union.
Retention
How long we keep it.
These are the periods the service actually applies today. Where nothing deletes a record automatically yet, we say so, rather than print a period we do not enforce.
Your content
- The product photograph you upload
- 30 days after upload, then the file is deleted
- The intermediate studio image
- 90 days after it is made, then the file is deleted
- The delivered video
- 365 days after it is made, then the file is deleted. Download it before then
- Your data export
- 7 days after it is prepared, then the file is deleted
Only the file is deleted. The record of the render stays with your account: its date, its settings, the optional note or prompt you wrote, and what it cost.
Your account
- An open account
- Kept while the account is open. An account is not closed or deleted for inactivity
- A closed account
- Anonymised 30 days after closure. Your files are not deleted at closure: they follow the periods above
- Sign-in code
- Valid 10 minutes. Deleted as soon as it is used, or replaced by the next code you request
- An email address that asked for a sign-in code but never opened an account
- Kept in our contact list at Brevo. No automatic deletion yet
- Sessions
- The cookie lasts 30 days at most. The session record, with its IP address and user agent, has no automatic deletion yet
Billing
- Invoices and accounting records
- 10 years, French commercial code, art. L123-22. They are kept after an account is closed
- Payment records: provider identifiers, amounts, status
- Kept with the accounting records
Messages and technical records
- Help requests, Business enquiries, chat conversations
- No automatic deletion yet
- Audit log
- No automatic deletion yet
- Failed render records
- No automatic deletion yet
- Record of the emails sent to you
- No automatic deletion yet
- Application logs
- No automatic deletion yet
- Rate-limit counters
- 24 hours
- Web server access logs
- Rotated by size: the last five files are kept, none for more than 90 days
- Your cookie choice
- 6 months, on your own device
A record with no automatic deletion yet is not beyond reach: you can still ask us to erase it, see Access, correct, export, erase. Accounting records, and material under an abuse report, a payment dispute or a legal request, are the exceptions.
Legal basis
Why we are allowed to.
There is no profiling and no advertising here. Two things rely on your consent, and only those: marketing email if you asked for it, and usage analytics if you accepted them.
- Your account, the renders, sending you the result
- Performance of a contract, art. 6.1.b
- Subscription, invoicing, dunning
- Performance of a contract, art. 6.1.b
- Keeping accounting records 10 years
- Legal obligation, art. 6.1.c
- Security logs, rate limiting, abuse prevention
- Legitimate interest, art. 6.1.f
- Transactional email
- Performance of a contract, art. 6.1.b
- Marketing email, if you asked for it
- Consent, art. 6.1.a : withdrawable at any time
- Helping you on WhatsApp, if you left a number
- Consent, art. 6.1.a : withdrawable at any time
- Usage analytics (Microsoft Clarity and Google Analytics), if you accepted them
- Consent, art. 6.1.a : withdrawable at any time
Cookies
One cookie, plus the ones you accept.
One cookie keeps you signed in and needs no consent. Everything else in this section only exists if you accepted usage analytics.
- Name
- nmr_s
- Purpose
- Keeps you signed in
- Lifetime
- 30 days at most
- Attributes
- HttpOnly · Secure · SameSite=Lax
This cookie is strictly necessary to the service you asked for to sign you in to your account, so it falls under the consent exemption of the ePrivacy directive.
The browser also stores a form draft locally on your own machine. It never reaches us.
Usage analytics, only if you accept
With your consent we use two providers, and one single yes covers both. Google Analytics 4 counts visits, pages and the steps of the sign-up, and nothing else: advertising signals and ad personalisation are switched off in our configuration, so nothing here feeds Google Ads. Microsoft Clarity to see how the site is used: where people click, how far they scroll, and anonymised replays of sessions. Clarity masks the text you type by default. It is published by Microsoft, and the data it collects may be processed outside the European Union. Nothing from Clarity is loaded, and none of the cookies below is set, until you press “Accept” on the banner. Continuing to browse is not consent. Your choice, yes or no, is kept on your device for six months.
- _clck
- Clarity user ID for this site · first-party · up to 1 year
- _clsk
- Links the page views of one session · first-party · 1 day
- CLID, MUID, ANONCHK, MR, SM
- Set by Microsoft on its own domains (clarity.ms, bing.com) · third-party
_ga,_ga_<stream>- Google Analytics visitor and session IDs · first-party · up to 2 years · deleted when you refuse
Your current choice:
If your browser sends the Global Privacy Control signal, we treat it as a refusal and never show the banner.
Your rights
Access, correct, export, erase.
You may request access to your data, correct it, have it erased, take it elsewhere, restrict how it is used, or object to a given use. Where a processing rests on your consent, marketing email, usage analytics. You can withdraw it at any time: the unsubscribe link in every marketing email, and the “Change my choice” button in the Cookies section.
Two of these are built into the application and take effect without writing to anyone: you can request a full export of your data, which arrives by email, and you can close your account from your settings.
What closing an account does
You are signed out everywhere at once. Thirty days later the account is anonymised: your email address, name, company, country, WhatsApp number and sign-up IP address are erased, and your contact is removed from our mailing list provider. That delay exists so that a closure made by mistake, or by someone who took over your session, can still be undone, and so that a dispute can still be handled.
Your files, the photograph, the intermediate image and the video, are not deleted at closure: each is deleted when its own period ends, as set out under How long we keep it.
Invoices are kept for 10 years. That is a legal obligation, and those records cannot be erased.
One reservation: where material is the subject of an abuse report, a payment dispute or a legal request, we keep it and the records around it for as long as that investigation or obligation lasts. See the acceptable use policy.
Odratta has not appointed a data protection officer and is not required to. The person to write to is the company's manager. If you believe your rights are not respected, you may lodge a complaint with the French supervisory authority: CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
Still reading?
The terms of service cover what the product does, what it does not promise, and how the subscription works.