Privacy Policy
Last updated: August 7, 2026
1. Controller
ShotStudio is operated by PRIMECODE SOLUTIONS SRL, CUI 50939602, Trade Register No. J2024044285005, registered office Str. Gramont 38, Sector 4, Bucharest, Romania. It is the data controller for the processing described here. Contact: primecodesolution@gmail.com.
2. What we collect
- Waitlist data: the email address you submit, your language, where the signup form appeared, consent version and timestamps, signup timestamps and count, invitation status, and a keyed one-way identifier used to prevent duplicate records.
- Account data: your email address, name, sign-in provider, private-beta access status and invitation claim when you authenticate.
- Your content: projects, uploaded screenshots and images, and rendered exports.
- Usage data: timestamps of saves, exports and agent (MCP) requests, plus trial status, subscription status, point balances, per-tool point usage and transaction references.
- Payments: handled entirely by Polar as merchant of record. We receive the transaction reference and subscription purchased, never your card details.
3. Why we process it
- To provide the service (contract): storing and syncing projects, managing trials and subscriptions, enforcing point allowances, rendering exports and applying successful payments.
- To operate the waitlist (consent): recording your request, selecting and sending private-beta invitations, and sending limited ShotStudio product updates. You can withdraw consent at any time by contacting us.
- Security and abuse prevention (legitimate interest): authentication, rate limits, fraud prevention.
- We do not sell personal data and we do not use advertising trackers.
4. Processors we use
- Google Firebase / Google Cloud: waitlist processing, secure invitation-link generation, authentication, database, file storage, functions and hosting (primary application region: europe-west1, Belgium).
- Resend: transactional delivery of waitlist confirmations and private-beta invitations, including delivery, bounce and complaint handling.
- Modal: cloud GPUs that render exports (United States). Project data is processed transiently for the render and not retained there.
- Polar: payment processing as merchant of record (see Polar's privacy policy).
- Google Analytics for Firebase: usage statistics, loaded only after you consent via the cookie banner (see Google's privacy policy).
Transfers outside the EEA rely on the processors' standard contractual clauses and equivalent safeguards. We may change processors; this page always lists the current ones. We do not sell personal data and we do not use automated decision-making that produces legal effects.
5. Retention
- Projects and uploads are kept until you delete them. Deleted projects go to a trash and are permanently removed after 30 days.
- Waitlist records are kept until the private-beta and launch process ends, you withdraw consent, or the address is no longer needed. Revocation, bounce, complaint and claim timestamps may be kept as a minimal suppression and security record.
- Transactional email delivery metadata is normally removed after 90 days; deduplication records for provider webhooks are removed after 180 days.
- Unclaimed or ineligible authentication records may be removed periodically. Anonymous accounts are not used for new private-beta access.
- Database backups are retained for up to 30 days for disaster recovery.
- Transaction records are retained as required by tax and accounting law.
6. Your rights
Under the GDPR you can request access, rectification, erasure, portability of your data, and object to or restrict processing. Write to primecodesolution@gmail.com and we will respond within 30 days. You can also lodge a complaint with the Romanian supervisory authority (ANSPDCP) or the authority in your country of residence.
To leave the waitlist or stop product updates, email us from the address you submitted with the subject “Remove me from the ShotStudio waitlist”.
7. Cookies and local storage
Strictly necessary storage runs without consent: authentication state, abuse protection, and local copies of projects (IndexedDB) in your browser. Firebase App Check may process technical signals to distinguish genuine requests from automated abuse. Google Analytics cookies are set only after you choose "Allow analytics" in the cookie banner; choosing "Essential only" (or ignoring the banner) never loads analytics. You can change your mind any time by clearing this site's data in your browser. We use no advertising or cross-site tracking cookies.
8. Security
All traffic is encrypted (TLS). Data access is isolated per account, agent tokens are stored hashed, and payment data never touches our servers. No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we notify affected users and authorities of breaches as required by the GDPR.
9. Children
The service is not directed at children under 16.
10. Changes
We may update this policy; the date above reflects the current version. Material changes will be announced in the product.