Know what leaves your computer

Privacy & data handling

A practical account of the current website and plug-ins. Updated September 18, 2026.

This website

This static site has no sign-in, contact form, analytics script, advertising pixel, cookies, or browser-storage features. Images and styles are hosted with the site; loading a page does not fetch fonts or media from third-party services.

Any hosting provider may receive standard technical request information, including an IP address and browser details. Hosting-specific logging, retention, and operator contact information will need to be confirmed before public launch. This page does not claim that the eventual host collects no data.

Following external links takes you to sites with their own policies. This website does not accept photos, API keys, contributor credentials, or payments.

Alamy & Dreamstime publishing

Each FTP plug-in stores its credentials locally through Lightroom's encrypted password storage. They are separate from the other plug-ins. Original JPEGs, including any embedded metadata such as GPS, go directly to the selected agency.

FTP is unencrypted. Account credentials and image data can be exposed in transit. Local encrypted storage does not protect the network connection. Use the agency's HTTPS uploader if encrypted transfer is required.

Local upload history retains filenames and transfer states for duplicate checks. Local diagnostic logs contain stage names, counts, and batch indexes, not credentials, filenames, source paths, or raw server responses. There is no automatic upload of logs and no Expolumi-operated backend or analytics.

Removing a plug-in or published collection does not remove remote submissions. Agency processing and retention follow the agency's own policies.

Expolumi AI Photo Tagging

The plug-in sends a reduced JPEG preview to your configured Microsoft Foundry resource over HTTPS after consent. Embedded metadata is stripped, but identifying image content remains visible. Optional tip text and an enabled capture timestamp are also sent. Do not include information you are not authorized to share.

The resource endpoint and deployment name are local preferences. Your API key uses Lightroom's encrypted local storage. Expolumi does not operate a processing backend, receive the request, or keep a prompt/response archive through the plug-in.

Microsoft's data-processing terms and abuse-monitoring policies apply. A setting disabling stored completions is not a guarantee of zero retention. Processing location depends on the deployment type, not only the resource region.

Temporary preview files are normally deleted. A crash or deletion failure can leave Lightroom-AITagging* folders in the operating system's temporary directory. Close Lightroom before inspecting and removing only those plug-in temporary folders.

Your controls

  • Read the destination and consent prompt before sending an image.
  • Use Forget credentials or Forget key to clear locally stored access. This does not revoke credentials at the provider or erase backups.
  • Rotate compromised passwords or keys with the relevant service.
  • Review every AI suggestion and choose which fields to apply. Existing keywords are merged, not deleted.
  • Check metadata actually embedded in JPEGs before publishing, including location fields.
  • Review logs and screenshots for personal information before sharing them.

Encryption at rest cannot protect a compromised local account or malicious code in Lightroom. Credentials necessarily exist briefly in memory during use. The plug-ins do not guarantee secure memory or backup erasure.

Catalog changes may be written to disk independently by Lightroom's automatic metadata settings. Keep backups and check those settings before working with sensitive photos.