Legal

Privacy policy for Lampo

DeutschThe German version is the binding one.

Lampo is a tool for reviewing videos. This policy says which personal data we process on the website lampo.video and in the Lampo Cloud service (app.lampo.video, media.lampo.video), why, on what legal basis, for how long and who receives it.

In short: We process your videos and notes only to provide the service. Speech recognition runs on our own servers in Germany.

1. Controller

nprompt UG (haftungsbeschränkt), Güglinger Str. 16, 70435 Stuttgart, Germany
Email: hello@lampo.video · represented by its managing director Philip Verropoulos · Legal notice

Data protection officer: we are not required to appoint a data protection officer (§ 38 BDSG) and have not appointed one. Write to hello@lampo.video with any question about data protection.

2. Who is responsible for what

  • We are the controller for accounts, billing, the emails we send ourselves, the website and the security of the service (sections 3.1–3.3, 3.6–3.11).
  • Our customers are the controllers for what they put into their workspaces (videos, notes, drawings, voice notes, files) and for what their review links record about visitors (sections 3.4 and 3.5). We process this as a processor under Art. 28 GDPR on the basis of our data processing agreement, which applies to business customers together with the terms. That includes the analysis within a workspace (Insights, who watched a video): we make it only for the customer and don't use it for purposes of our own. If you open a review link as a client of one of our customers, please ask whoever sent you the link about your data; we help them answer.

3. What we process

3.1 Visiting the website and the app

  • Hosting. The app runs on servers of Hetzner Online GmbH in Germany (data centre in Falkenstein). The website lampo.video is a set of static files that Cloudflare Workers serves from Cloudflare's network, with request logging switched off (see the Cloudflare paragraph).
  • Cloudflare. Requests to app.lampo.video and lampo.video pass through the network of Cloudflare, Inc. (reverse proxy, protection against attacks, TLS encryption, DNS). Cloudflare processes the IP address, the address requested, browser details and times, and passes the visitor's IP address on to our server. Videos are not delivered through Cloudflare: media.lampo.video connects directly to our server. Legal basis: Art. 6 (1) (f) GDPR (secure, fast operation). Cloudflare is our processor here (Cloudflare's data processing addendum) and keeps these data only as long as delivery and protection against attacks need them. We have no request logs sent to us by Cloudflare and keep none.
  • Server logs. Our web server keeps no access log. The app logs no IP addresses, no access tokens, passwords or email addresses; it logs its start, warnings, failed background tasks and, for server errors, a reference with technical details. Of the requests, it logs only an agent's tool calls over MCP, one line each: the workspace, the agent's session id, the tool, how long it took and how it ended, so that a missed note can be traced. Never what a tool was given or answered: no note text, no names, no file names. Email recipients appear in the log only as a non-reversible hash. Logs are overwritten continuously (at most five files of 10 MB) and kept nowhere else. Legal basis: Art. 6 (1) (f) GDPR (running the service and keeping it secure).
  • Abuse protection. To limit sign-ins, password attempts, sending email and the like, the app holds IP addresses (for IPv6 the /64 network) briefly in memory; they are not stored and are gone at the latest with a restart. Legal basis: Art. 6 (1) (f) GDPR.

3.2 Your account

  • Data: name, email address, password (only as a scrypt hash), optionally a profile picture, language and appearance settings, memberships and roles in workspaces, API tokens (only as a hash), connected apps (OAuth), sign-in times. Optionally, if you turn on sign-in alerts: a coarse device description ("Safari on iPhone") in the alert email.
  • Last active: when you were last active, to the hour (your own sessions only, never a review link or an API token). We keep it as the operator to run the service (Art. 6 (1) (f) GDPR); it is in your own data export, and workspace admins don't see it.
  • Purpose and legal basis: running the account and the contract (Art. 6 (1) (b) GDPR).
  • Retention: as long as the account exists. Sign-ups whose address is not confirmed within 7 days are deleted. Confirmation and password links work for 24 hours or 60 minutes and are kept as a hash for a week to tell "used" from "expired". An account that no longer belongs to any workspace is deleted.

3.3 Billing

  • Data we keep: which workspace has which plan, the trial and its end, the subscription's status, the customer and subscription IDs at Stripe, billing name, billing email and country as Stripe tells us.
  • At Stripe: payment details (card, SEPA etc.), billing address, tax ID, invoices. You enter these directly on Stripe's pages; we never see card details.
  • Legal basis: Art. 6 (1) (b) GDPR (contract), Art. 6 (1) (c) GDPR (tax and commercial retention).
  • Retention: as long as the workspace exists; after that, what tax and commercial law require (§ 147 AO, § 257 HGB): books and records 10 years, accounting vouchers such as invoices 8 years, business letters 6 years, each from the end of the calendar year.

3.4 Content in workspaces (processing on behalf)

Videos and their versions, notes, drawings, screenshots, voice notes and their transcripts, attached files, playbooks and a workspace's history. We process them only to provide the service to the customer: storing them, making previews and playback copies, running speech recognition and automatic checks on our own servers, and showing them to the people and agents the customer gives access to. Retention: until the customer deletes them or the workspace is deleted; for backups see 3.11.

Customers can send videos through a link to people without an account. A review link records for the customer:

RecordedNot recorded
that someone opened the link or one of its videos, and when (once per visitor per half hour)IP addresses (held briefly in memory only, to count a visit once and to set limits)
the name a visitor typed, if they typed onetracking cookies, browser fingerprints, the browser, the device, the location
which hundredths of a version played, how often and for how longwhere exactly someone paused, scrubbed or looked; anything outside the review page
notes, replies, approvals and downloads

To tell visitors apart, the review page stores a random id once in the browser (local storage). The server keeps only a key derived from it, a different one for every link. The page records the same for everyone, whatever "Do Not Track" or "Global Privacy Control" says. The records belong to the link (at most 200 visitors, 500 videos and 50 playbacks per video) and stay until the customer deletes the link or the video; a revoked link keeps its records.

The random id is strictly necessary for the function the visitor uses: finding their notes and progress under their name again (§ 25 (2) no. 2 TDDDG); it serves no other purpose. The review page links this policy. The records are the customer's data: the customer decides how long they stay, and they are deleted at the latest with the workspace.

Embed links. A customer can also put one video on a page of their own website with an Embed link: Lampo's player in a frame on that page. Its visitors load the player and the video from our server, which sees their IP address like any request (3.1). The player shows the video and nothing else, sets no cookie and keeps nothing in the browser. When someone plays the video, the link records that it was played, when and which hundredths, as above, but never with a name. The page around the player is the customer's: what it collects is theirs to answer for.

3.6 Emails

We send the emails the service needs: address confirmation, password reset, invites, welcome, notices about your account (password or address changed, a new sign-in – only if turned on, account disabled) and, for a workspace's owners and admins, notices about the plan (e.g. three days before the trial ends and when it ends). No newsletter, no advertising, no tracking pixels: the emails load nothing.

  • Sent through Resend (EU data centre). Until sent, messages wait encrypted in a queue on our server.
  • Notices go to confirmed addresses only.
  • Legal basis: Art. 6 (1) (b) GDPR. The notices about the plan and the trial are part of performing the contract too; they don't advertise anything further.

3.7 Push notifications (if you turn them on)

If you allow notifications in the browser or the installed app, they go through the push service of the browser's maker (Apple, Google, Mozilla or Microsoft). The content is end-to-end encrypted (RFC 8291); the push service sees only its size and timing. The legal basis is your consent (Art. 6 (1) (a) GDPR), which you give by allowing them in the browser; you can withdraw it at any time by turning notifications off in Lampo or in the browser. On the push services in the USA, see section 4.

3.8 Services customers connect themselves

At a customer's request, data goes to services they connect: when publishing, to YouTube (Google) or through Zernio to Instagram and Facebook; to AI agents and their providers that a member connects to their workspace through MCP and OAuth (e.g. ChatGPT, Claude). This happens only when the customer sets it up and triggers it; those providers' privacy notices apply. We pass the data on the instructions of the customer, who is the controller for it.

3.9 Cookies and local storage

On the website (lampo.video) we set one cookie and keep one setting in your browser:

NamePurposeDuration
cc_cookieyour choice in the website's cookie settings182 days
lampo.theme (local storage)the appearance you chose for the website (system, light or dark)until you clear it

Both serve only what you ask the website to do (§ 25 (2) no. 2 TDDDG). In the cookie settings (Cookie settings at the foot of every page) you can switch a category for analytics on or off; it is off unless you switch it on. No analytics service is connected to it, so switching it on sets nothing more. If one is added, this policy names it and the website asks you again. The cookie settings are made with the open-source library CookieConsent (Orest Bida, MIT licence), served from this website like all its files.

In the app (app.lampo.video) we set only what the service needs (§ 25 (2) no. 2 TDDDG):

NamePurposeDuration
__Host-vr_sessionstay signed in30 days
vr_devicerecognise this device, so sign-in alerts come only for new devices and failed attempts elsewhere don't lock you out365 days
vr_signuprecognise the browser you signed up in when you confirmuntil confirmed
vr_g_…a password-protected review link is unlocked in this browser30 days
cc_cookieyour choice in the app's cookie settings182 days

The app has cookie settings of its own, like the website's: necessary (the cookies above), payments and analytics (off; nothing is connected to it). The choice on lampo.video and the one in the app are kept apart: each asks for what it uses.

On the billing page (Settings → Billing) the payment form is Stripe's. It loads Stripe.js from Stripe's servers only once you allow payments in the app's cookie settings. Stripe then sets its own cookies to prevent fraud, and refusing payments later removes them:

NamePurposeDuration
__stripe_midStripe: recognise the browser, to prevent fraud1 year
__stripe_sidStripe: the same, for this visit30 minutes

The address search in the payment form is Stripe's, part of payments too; its suggestions come from Google, which receives what you type into it. The legal basis for both is your consent (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR): without it the app loads neither Stripe.js nor the address search, and you can withdraw it at any time in the app's cookie settings. On Google and Stripe in the USA, see section 4.

The browser's local storage holds language, appearance and view settings, cached data of a signed-in person's account (cleared on sign-out) and, on review pages, the random visitor id (3.5). vr_device is strictly necessary because it protects your account: it tells your devices apart from someone else's sign-in attempts (§ 25 (2) no. 2 TDDDG).

3.10 When you write to us

Emails to hello@, security@ and conduct@lampo.video are forwarded by Cloudflare (email routing) to our team's mailbox, which is hosted by Google Workspace (Google Ireland Limited). We process them to answer (Art. 6 (1) (b) GDPR where a contract is concerned, otherwise (f)) and delete them when settled and no retention duty applies.

3.11 Backups

We back up the data every night, encrypted, to storage (a Storage Box) of Hetzner Online GmbH in Germany. Backups are overwritten on a fixed schedule: 14 daily, 8 weekly and 12 monthly. Deleted data can therefore remain in backups for up to twelve months; it is not restored from them except when recovering from an outage. Legal basis: Art. 6 (1) (b) and (f) GDPR (providing the service reliably; Art. 32 GDPR).

4. Recipients

RecipientForWhereBasis
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germanyservers, backupsGermanyprocessing on behalf
Cloudflare, Inc., San Francisco, USAreverse proxy, DNS, email routing, serving the websiteworldwide, USAprocessing on behalf; Data Privacy Framework, plus standard contractual clauses
Plus Five Five, Inc. ("Resend"), San Francisco, USAsending emailEU data centre; company in the USAprocessing on behalf; Data Privacy Framework, plus standard contractual clauses
Google Ireland Limited, Dublin, Ireland (with Google LLC, USA)our team's mailbox (3.10)EU, USAprocessing on behalf; Data Privacy Framework
Stripe Payments Europe, Limited, Dublin, Ireland (with Stripe, Inc., USA)payments, tax, invoicesEU, USAour processor for billing, an independent controller for fraud prevention and its own legal duties; Data Privacy Framework
Google LLC, USA (through Stripe's address search)address suggestions while you type in the payment formUSAyour consent (3.9); Data Privacy Framework
push services of Apple, Google, Microsoft, Mozillaonly if turned on (3.7)incl. USAyour consent (3.7); see below
services connected by customers (3.8)at the customer's requestdepends on the providerthe customer's instructions

Transfers to third countries. Where data go to the USA, we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework: Cloudflare, Resend, Google, Stripe, Apple and Microsoft are certified under it. Cloudflare and Resend also agree the Commission's standard contractual clauses with us. Push messages through Mozilla's service go to the USA on the basis of your consent (Art. 49 (1) (a) GDPR) when you allow notifications in Firefox; their content is end-to-end encrypted, but the USA does not offer the same level of protection as the EU in every respect.

5. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future. Write to hello@lampo.video. You change your name, address and password yourself in Lampo (Settings → Profile), where you also download your data and delete your account. A workspace's owner deletes it in Settings → Workspace.

You can complain to a supervisory authority, for example the one responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

6. Further information

  • Obligation to provide data: without name, email address and password we cannot run an account; everything else is optional.
  • No automated decision-making within the meaning of Art. 22 GDPR. Analysis within a workspace (e.g. which clients watched a video) helps the customer work on their videos; we don't use it to evaluate personal aspects of anyone (no profiling).
  • Changes: we update this policy when the service changes. The version published here applies. As of: 6 October 2026.