Who is responsible?
Lomelio is operated by YMDevs, LLC (United States). Its sole employee is the formally appointed Data Protection Officer. Contact: ymeghzifene@hotmail.com. Lomelio serves adult professional sellers in France and Spain.
Accounts and saved data
Sign in with Google, an email and password, or a one-time email link. Firebase supplies your account identifier, verified email and any profile name. Passwords are handled by Firebase Authentication and are never stored in Lomelio records or logs. Verification, sign-in and recovery emails are sent by Firebase. An email-link request stores your email on this device to complete sign-in. It is reused only for 24 hours and removed after successful sign-in; clearing site data also removes it. Google sign-in gives no access to Gmail or Drive. Firebase manages sign-in sessions in your browser. Your language preference is stored on your device. Saved fiches, reduced product and evidence photos, dates, parcel presets and the professional contact details you enter are stored in your private account. Test and production spaces are separate. Unsaved photos and drafts remain in memory and may be lost when you close or reload the page. Original photo metadata is removed during JPEG conversion.
Optional dictation
The microphone starts only when you tap it and grant permission. Where available, your browser or device speech service processes audio under its own terms. Otherwise, a recording of up to 25 seconds is sent through the Lomelio server to OpenAI for transcription (gpt-4o-mini-transcribe). Lomelio does not store recordings. The transcript is automatically applied as a correction when dictation ends or you stop the recording. You can cancel or undo a correction, or type instead. Simple explicit price, quantity and saved-parcel commands run locally; other corrections send the transcript and editable fiche fields to OpenAI, without resending photos.
AI analysis and review
Completing the selected photos automatically sends reduced images and the requested language to GPT-6 Luna (OpenAI) through the Lomelio backend. A correction sends the correction text and relevant editable draft fields; photos are not resent. Do not photograph people, identity documents, payment data or unrelated private information. When a manufacturer or EU responsible person is missing a name, postal address or contact detail, Luna can use OpenAI web search with public brand/product/model information. The instructions exclude seller personal data from search queries. Public sources used for a suggestion are shown in the fiche. A known company or brand may be prefilled as an unverified candidate; this does not confirm its legal role. AI suggestions can be wrong; you must review them. Ordinary fields and parcel values may contain labelled best guesses or defaults; measure and confirm the actual parcel before use. Safety information, legal contacts and documents still require evidence. A brand is not automatically a manufacturer or an EU responsible person, and a visible CE mark is not a compliance assessment. Saved contact records are not automatically verified in TikTok.
Providers, purposes and locations
Google provides Firebase Authentication, Hosting, Firestore, Cloud Storage, server functions, App Check/reCAPTCHA Enterprise and Google Fonts. Account fiches and private objects are configured in Paris. Hosting, identity and security services are not restricted to Paris. OpenAI processes reduced product photos and fiche fields with GPT-6 Luna and, when needed, voice recordings for transcription. Lomelio calls the standard OpenAI API; EU-only AI processing is not configured. Company operations may access necessary data from Thailand and the United States. Technical requests may include IP addresses, device/browser information and security signals. We process data to deliver the requested service, protect it, prevent abuse, answer support requests and meet applicable legal obligations. We have no advertising pixels or analytics SDK and do not sell your data. See Firebase privacy information and OpenAI API data controls. OpenAI API data is not used for model training by default. Responses use store:false; this does not remove all provider retention, including applicable abuse monitoring. We do not promise zero retention.
Retention and deletion
We retain saved account content until you delete it or your account. The backend does not deliberately log photo contents, AI responses or contact details; infrastructure retains technical security and service logs under its configured policies. Deletion removes active records and private objects; recovery copies may remain for the configured backup or soft-delete period, currently up to seven days. Interrupted deletions are retried by maintenance. Original camera photos, downloaded exports, correspondence and any TikTok-side records are separate. Old fiches stored by earlier releases stay on their original device and are not automatically assigned to a Lomelio account.
Your choices and rights
In My account, export your test and production data, manage saved contacts and parcels, sign out or delete your Lomelio account. Deleting Lomelio does not delete your Google account. Contact ymeghzifene@hotmail.com to request access, correction, erasure, restriction, portability or object where applicable. The DPO handles requests within applicable time limits and may verify your identity proportionately. You may contact the CNIL, AEPD or your local authority.
TikTok and test mode
The current account release saves drafts and supports clearly labelled simulations. It does not yet publish real products or discover real LIVE rooms. Test mode never sends a listing to TikTok, but photo analysis still uses OpenAI. Connecting a shop redirects you to TikTok to authorize Lomelio. We store access and refresh tokens, their expiry dates, seller identity, authorized shop IDs, names, markets and private shop identifiers in a server-only record linked to your Lomelio account. This supports your shop connection and selection; tokens are not returned to the browser. Disconnecting removes that record from Lomelio; revoke the TikTok authorization separately in Seller Center. Deleting your Lomelio account also removes the connection. Current permissions cover shop authorization, product reading/modification and logistics; this release does not publish products, read buyer/order data or discover real LIVE rooms.