Privacy Policy

Last updated: August 31, 2026

This Privacy Policy explains how Juniper Software Solutions Ltd (company number 14709623), doing business as CalmLens ("CalmLens", "we", "us" or "our"), collects, uses and shares personal information through calmlens.com, the CalmLens portal, API, content-moderation service and media delivery network (together, the "Services").

CalmLens is primarily a service for businesses and developers. This policy distinguishes between information we process for our own purposes and content we process on a customer's instructions.

1. Who is responsible for your information?

For account, website, billing, support, security and service-usage information, Juniper Software Solutions Ltd is the controller.

For images, text, documents, websites and related data that a customer submits to the Services ("Customer Content"), we generally act as a processor or service provider on that customer's behalf. The customer decides why Customer Content is processed, which moderation policies apply, whether content is retained, and whether matching content is ignored, alerted on, hidden or purged. If your information was submitted by one of our customers, contact that customer first about your rights. We will assist the customer as required by applicable law.

2. Information we collect

Depending on how you use the Services, we may collect:

  • Account and identity information: name, email address, profile image, account identifiers and information received from an identity provider when you choose social sign-in.
  • Customer Content and moderation data: submitted or remotely fetched images, text, documents and websites; URLs and file metadata; extracted text, previews and transformed variants; classification scores, moderation results, configured policies and actions; and content-delivery settings. Customer Content may, by its nature, contain sensitive or special-category information.
  • Project and integration information: project configuration, API-key identifiers and hashes, webhook destinations, encrypted webhook credentials, delivery attempts and event records.
  • Usage and transaction information: metered use of uploads, storage, delivery, transformations, moderation, OCR and website ingestion; plan and subscription status; invoices and payment-related records. Stripe processes full payment-card details directly, and we do not store them.
  • Technical and security information: IP address, request and response metadata, timestamps, routes, device and browser information, authentication events, error reports and diagnostic data. We redact designated credentials and authentication headers from application request logs.
  • Communications: messages to support, privacy requests, feedback, and information submitted through contact or waitlist forms.
  • Cookies and preferences: authentication state, cookie choices, selected project, portal layout and other preferences described in our Cookie Policy.

We receive this information from you, your organisation or its end users, your chosen identity provider, our payment and infrastructure providers, and automatically when the Services are used.

3. How and why we use information

We use personal information to:

  • provide accounts, authentication, moderation, storage, transformations, CDN delivery, signed access, events and webhooks;
  • apply the customer's configured retention and flagged-content action;
  • operate, troubleshoot, secure and improve the Services;
  • meter usage, process subscriptions, collect payment and maintain financial records;
  • communicate about the Services, support requests, incidents and material changes;
  • prevent fraud, abuse, unlawful use and security threats; and
  • comply with law, enforce our Terms, and establish, exercise or defend legal claims.

Under UK and EEA data-protection law, our legal bases are performance of a contract, our legitimate interests in operating and securing the Services, compliance with legal obligations, and consent where we specifically request it. Where we rely on legitimate interests, we consider the impact on the people concerned. You may withdraw consent at any time without affecting earlier lawful processing.

We do not sell personal information. We do not share personal information for cross-context behavioural advertising, and we do not use Customer Content to target advertising.

4. Automated moderation

The Services use automated systems to generate category scores and moderation results. These systems can produce false positives, false negatives and incomplete results. A customer may configure the Services to ignore, alert, hide or purge content based on those results.

Customers are responsible for choosing appropriate thresholds and actions, testing the Services for their use case, providing any legally required notice, and providing human review or an appeal route where a decision may have a legal or similarly significant effect on a person. CalmLens does not decide the customer's purpose for processing Customer Content.

5. When we disclose information

We disclose information only as reasonably necessary for the purposes above, including to:

  • Cloudflare for edge hosting, security, storage, image processing and CDN delivery;
  • Google, including Firebase and Google Cloud, for identity services and OCR;
  • OpenAI for text and image moderation;
  • Stripe for subscriptions, invoicing and payment processing;
  • Sentry for error reporting and service diagnostics;
  • Upstash for service caching where enabled;
  • identity providers you choose to use, such as Google, Apple, Facebook or X, where offered;
  • destinations selected by the customer, including webhook endpoints and remote services the customer instructs us to contact; and
  • professional advisers, regulators, courts, law enforcement, a purchaser or successor where required by law or reasonably necessary to protect rights, safety, the Services or a corporate transaction.

These providers may process limited account, technical or Customer Content data according to their role. We do not authorise them to use personal information for their own advertising.

6. International transfers

We are based in the United Kingdom, and our providers may process information in the United Kingdom, European Economic Area, United States and other countries. Where required, we use recognised safeguards for international transfers, such as adequacy regulations or approved contractual clauses. Customers remain responsible for ensuring that their submission of Customer Content to the Services is lawful.

7. Retention and deletion

We keep information only for as long as reasonably necessary for the purposes described in this policy, including to provide the Services, meet legal and accounting obligations, resolve disputes and protect the Services.

Customer settings control much of the Customer Content lifecycle. Content configured not to be retained is deleted after processing unless it is hidden under a moderation policy. Retained or hidden content remains available until the customer deletes it, purges it through a moderation policy, or deletes the relevant account, subject to copies in caches and queues that expire through normal operations. Hiding content prevents normal delivery but is not deletion.

Account, billing, event, webhook, usage, security and support records are kept for the period needed to operate the account and meet the purposes above. When an account-deletion request is completed, we delete the account and associated projects and assets, except information we must retain by law or need for security, fraud prevention or legal claims.

8. Security

We use technical and organisational measures designed to protect information, including access controls, hashed API keys, encryption of stored webhook secrets, credential redaction in logs and restricted signed access for private assets. No internet service is completely secure, so customers must also protect account credentials and API keys and configure access appropriately.

9. Your responsibilities for Customer Content

Customers must have a lawful basis and all required rights, notices and consents before submitting Customer Content. Do not submit payment-card data, authentication secrets, health information or other specially regulated data unless you have confirmed that your use is lawful and the Services are appropriate for it. The Services are not offered as a substitute for a customer's own privacy, safeguarding, legal-compliance or human-review processes.

10. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete or receive a copy of personal information, restrict or object to processing, withdraw consent, or appeal a decision about a privacy request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.

You can export or delete account data from the portal or submit a request at calmlens.com/data-request. You may also email contact@calmlens.com. We may need to verify your identity and authority, and legal exceptions may apply.

UK residents may complain to the Information Commissioner's Office. EEA residents may complain to their local supervisory authority. We encourage you to contact us first so we can try to resolve the issue.

11. Children

The Services are intended for business users aged 18 or over and are not directed to children. A customer that submits information about children is responsible for the lawful basis, safeguards, notices and consents required for that processing.

12. Changes to this policy

We may update this policy to reflect changes to the Services, our providers or the law. We will change the date above and, where required, provide additional notice of material changes.

13. Contact us

Juniper Software Solutions Ltd (company number 14709623), 79 Duke of York Ave, Wakefield WF2 7DA, United Kingdom

Email: contact@calmlens.com