← Back to ShotBorn
Beta
Privacy Policy
Last updated September 14, 2026
What changed on September 14, 2026: we now record a few product usage events and browser error reports (see Section 1, Technical data). Usage events linked to your account begin on September 28, 2026; until then they are recorded without any link to you.
This policy explains what ShotBorn collects, why, who sees it, how long we keep it, and what you can do about it. The operator named in Section 23 of the Terms is the data controller. Questions: hello@shotborn.com.
1. What we collect
Account
- Email address and a hashed password (we never store the password itself).
- A record of when you accepted the Terms, which version, and the IP address you accepted from. We keep this to prove consent.
- If you arrived through a link with campaign tags (utm_* or ref), those tags, so we know which link brought you. This is stored on your account only, never shared, and never involves a third-party tracker.
- Display name and avatar if you set one, plan, credit balance, and a ledger of every credit added or spent.
Content you create
- Prompts, settings, and reference files (images, video, audio) you submit for a generation.
- The generated images, videos, and text, and the job record (model, cost, timestamps, provider job id).
- Elements, characters, and workflows you save; media you import into the video editor and the exports you render.
- Audio you record for captions, which is sent to a transcription model, and the resulting text.
- Messages you exchange with the assistant features (Enhance, Studio Agent, Backroom), which are sent to a text model to produce the reply. We keep a usage record (tokens and cost) and, for Backroom, a per-account allowance; the chat content itself is processed to answer you and is not used for anything else.
Payments
Stripe handles checkout. We receive your Stripe customer id, subscription status, the plan or pack you bought, and invoice events. We never receive or store your full card number. Stripe may collect your billing address and tax location.
Technical data
- IP address, browser type, and request logs, used for security, rate limiting, abuse prevention, and debugging. Logs are kept for up to 90 days.
- A session cookie that keeps you signed in. It is signed, HttpOnly, and not readable by scripts.
- Browser local storage on your device for preferences such as the last tab you used and draft prompts. It never leaves your browser.
- Product usage events: page views of our landing page, and when you open a section of the app, open the sign-up form, or start a checkout. From September 28, 2026, for signed-in users these are linked to your account so we can see where ShotBorn is confusing or broken; before that date they are recorded without any link to you. For signed-out visitors they carry no identifier at all: no cookie, no stored ID, no IP address, no browser details. We collect these ourselves; nothing is sent to an analytics company. If your browser sends Global Privacy Control or Do Not Track, none are recorded.
- Error reports: if something breaks in your browser, the error message, the page, the app version and your browser type are sent to our server, linked to your account if you are signed in, so we can fix it. Email addresses and access tokens are removed before anything is stored.
Messages you send us
If you use the Contact page or email us, we keep the message and your reply address so we can respond.
2. What we do not collect
We do not run advertising trackers, third-party analytics, analytics pixels, or fingerprinting. We do not collect precise location. We do not knowingly collect data from anyone under 18.
3. Why we use it (and our legal bases)
- To run the service you asked for — creating your account, running generations, storing your library, billing (performance of a contract).
- To keep the service secure — rate limits, abuse detection, fraud prevention, enforcing the Terms (legitimate interest, and legal obligation where a law requires reporting).
- To communicate with you — password resets, receipts, service and legal notices (contract and legitimate interest). We do not send marketing email without a separate opt-in.
- To fix bugs — reading logs and, with your permission or when needed to resolve a support request, the specific job that failed (legitimate interest).
- To improve the product — understanding which features people use and where they get stuck (legitimate interest).
- To comply with the law — tax records, responding to lawful requests, copyright notices (legal obligation).
4. Who we share it with
We share data only with the companies we need to run ShotBorn, listed with their roles and locations on the AI Providers & Subprocessors page. In short:
- AI model routers and developers (OpenRouter, AtlasCloud, and the developers behind each model: OpenAI, Google, ByteDance, Kuaishou, MiniMax, Alibaba, xAI, Black Forest Labs, Microsoft, Ideogram, Meta, Runway, HeyGen, Anthropic, and others as added) receive your prompt, reference files, and chat messages so they can produce the output. They process it under their own terms. Some are located in China or Singapore.
- Infrastructure: Railway (hosting and database), Cloudflare R2 (file storage), Resend (email). Typefaces are served from our own servers.
- Payments: Stripe.
- Legal: authorities or third parties when required by law, to enforce the Terms, or to protect people from serious harm. Content involving the sexual exploitation of minors is reported to NCMEC as the law requires.
- Business transfer: if ShotBorn is sold or merged, your data moves with it under this policy.
We do not sell personal data and do not share it for cross-context behavioural advertising.
5. Where your data goes
ShotBorn is hosted in the United States. If you are in the EU, UK, or elsewhere, your data is transferred to the United States and, when you choose a model from a developer based there, to China or Singapore. Transfers rely on the providers' standard contractual clauses or equivalent safeguards where those apply, and on your request for the specific generation (Article 49(1)(b) GDPR) where they do not.
6. Public content
If you publish a generation to the public feed, other users can see the output, your display name, and the model used. Unpublish or delete it to remove it from the feed. Generated files are served from links that anyone with the exact link can open; do not share links to private generations you want to keep private.
7. How long we keep it
| Data | Kept |
| Account, library, generations, uploads, editor media | Until you delete them or your account |
| Consent record (Terms version, date, IP) | Life of the account plus 3 years |
| Request and security logs | Up to 90 days |
| Product usage events | 180 days |
| Browser error reports | Up to 90 days after the error was last seen |
| Billing records and invoices (via Stripe) | 7 years, as tax law requires |
| Copyright notices and abuse reports | 3 years |
| Database backups | Up to 30 days after deletion, then overwritten |
AI providers keep request data according to their own policies, typically 0 to 30 days for abuse monitoring; see the providers page for links.
8. Your rights and controls
- Export everything we hold about you: Settings → Your data → Export. You get a JSON file with your profile, ledger, jobs, elements, and file links.
- Delete your account and all content: Settings → Your data → Delete account. It cancels subscriptions, removes your files from storage, and signs out every device. This is immediate and cannot be undone. Billing records stay with Stripe as the law requires.
- Sign out everywhere: Settings → Your data → Sign out of all devices.
- Correct your email or display name in Settings, or ask us.
- Object or restrict processing based on legitimate interest, or withdraw consent, by emailing us. Withdrawing consent does not affect processing that already happened.
- Complain to your data-protection authority if you are in the EU/UK, or to your state attorney general in the US.
If you are a California resident, the rights above cover your CCPA/CPRA rights to know, delete, correct, and opt out; we do not sell or share personal information, and we will not discriminate against you for exercising a right. You can use an authorised agent by having them email us with proof of authorisation.
9. Security
Passwords are hashed with bcrypt. Sessions use signed HttpOnly cookies and can be revoked from every device at once. Uploads are checked by content, not just file name, before they are stored, and served with headers that stop the browser from executing them. Provider API keys are held only on the server and are never sent to your browser. Access to production is limited to the operator. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the relevant authorities as the law requires.
10. Children
ShotBorn is for adults. We do not knowingly collect personal data from anyone under 18, and never from anyone under 13. If you believe a minor has an account, email us and we will delete it.
11. Cookies and local storage
We use one strictly-necessary cookie (your session) and browser local storage for preferences. Neither is used for tracking or advertising, so no cookie banner is shown. Stripe sets its own cookies on its checkout pages under its policy. Product usage events use no cookies or local storage.
12. AI training
We do not use your prompts, uploads, outputs, or chats to train any model, and we do not license them to anyone for training. The model providers process your request to produce the output under their own terms; we choose routing services that do not train on API traffic by default, but we cannot control a provider's policy and you should read it if it matters to you.
13. Changes
We will post changes here and update the date above. For changes that reduce your rights or expand what we collect, we will email you or show an in-app notice at least 14 days before they take effect.
14. Contact
Email hello@shotborn.com or use the Contact page in the app. Operator and mailing address: see Section 23 of the Terms.
↑