External LIGHTMASTER data handling

Technical release notice, prepared 7 October 2026. This page describes the separate external release implementation. The publisher must confirm the final privacy notice before opening registration and submitting for review. The existing publisher privacy policy currently describes the Sites version.

Account and authentication

The planned external version uses Auth0 Universal Login. Auth0 handles login credentials. LIGHTMASTER verifies the token signature, issuer, resource audience, lifetime and required permission. It derives an opaque stable profile ID from the verified issuer and subject. Email is not used as the ownership key. Sites identity headers are ignored.

Saved records and photos

The separate Cloudflare D1 database stores your goal, brief, equipment/room description, selected method, illustrative scene, composition, observations, steps, timestamps and revisions. Up to four photos can be explicitly selected in a panel session. Your browser resizes and re-encodes them to JPEG before upload; the separate private R2 bucket stores those bytes and the session stores their label, kind and ID. No bucket public access is required.

A photo attached in chat is not automatically imported into the panel. The host’s handling of chat and image understanding remains governed by the host’s policies. LIGHTMASTER has no microphone or paid model backend and does not automatically send email or a full conversation to the publisher.

Access and deletion

Every private record/photo operation is scoped to the verified profile. Removing a selected photo deletes its active stored bytes after the owned session update succeeds. Session-wide deletion and backup retention remain operational decisions that must be finalized before launch. No automatic expiry or immediate deletion from unspecified backups is promised.

Processors and requests

The proposed processors are Cloudflare for hosting/database/private photo storage and Auth0 for authentication. Their applicable regions, retention and publisher agreements need owner confirmation before launch. For access or deletion requests, contact support. Do not include authentication secrets.