← Back to ShotBorn
Beta

Privacy Policy

Last updated September 14, 2026

What changed on September 14, 2026: we now record a few product usage events and browser error reports (see Section 1, Technical data). Usage events linked to your account begin on September 28, 2026; until then they are recorded without any link to you.

This policy explains what ShotBorn collects, why, who sees it, how long we keep it, and what you can do about it. The operator named in Section 23 of the Terms is the data controller. Questions: hello@shotborn.com.

1. What we collect

Account

Content you create

Payments

Stripe handles checkout. We receive your Stripe customer id, subscription status, the plan or pack you bought, and invoice events. We never receive or store your full card number. Stripe may collect your billing address and tax location.

Technical data

Messages you send us

If you use the Contact page or email us, we keep the message and your reply address so we can respond.

2. What we do not collect

We do not run advertising trackers, third-party analytics, analytics pixels, or fingerprinting. We do not collect precise location. We do not knowingly collect data from anyone under 18.

3. Why we use it (and our legal bases)

4. Who we share it with

We share data only with the companies we need to run ShotBorn, listed with their roles and locations on the AI Providers & Subprocessors page. In short:

We do not sell personal data and do not share it for cross-context behavioural advertising.

5. Where your data goes

ShotBorn is hosted in the United States. If you are in the EU, UK, or elsewhere, your data is transferred to the United States and, when you choose a model from a developer based there, to China or Singapore. Transfers rely on the providers' standard contractual clauses or equivalent safeguards where those apply, and on your request for the specific generation (Article 49(1)(b) GDPR) where they do not.

6. Public content

If you publish a generation to the public feed, other users can see the output, your display name, and the model used. Unpublish or delete it to remove it from the feed. Generated files are served from links that anyone with the exact link can open; do not share links to private generations you want to keep private.

7. How long we keep it

DataKept
Account, library, generations, uploads, editor mediaUntil you delete them or your account
Consent record (Terms version, date, IP)Life of the account plus 3 years
Request and security logsUp to 90 days
Product usage events180 days
Browser error reportsUp to 90 days after the error was last seen
Billing records and invoices (via Stripe)7 years, as tax law requires
Copyright notices and abuse reports3 years
Database backupsUp to 30 days after deletion, then overwritten

AI providers keep request data according to their own policies, typically 0 to 30 days for abuse monitoring; see the providers page for links.

8. Your rights and controls

If you are a California resident, the rights above cover your CCPA/CPRA rights to know, delete, correct, and opt out; we do not sell or share personal information, and we will not discriminate against you for exercising a right. You can use an authorised agent by having them email us with proof of authorisation.

9. Security

Passwords are hashed with bcrypt. Sessions use signed HttpOnly cookies and can be revoked from every device at once. Uploads are checked by content, not just file name, before they are stored, and served with headers that stop the browser from executing them. Provider API keys are held only on the server and are never sent to your browser. Access to production is limited to the operator. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the relevant authorities as the law requires.

10. Children

ShotBorn is for adults. We do not knowingly collect personal data from anyone under 18, and never from anyone under 13. If you believe a minor has an account, email us and we will delete it.

11. Cookies and local storage

We use one strictly-necessary cookie (your session) and browser local storage for preferences. Neither is used for tracking or advertising, so no cookie banner is shown. Stripe sets its own cookies on its checkout pages under its policy. Product usage events use no cookies or local storage.

12. AI training

We do not use your prompts, uploads, outputs, or chats to train any model, and we do not license them to anyone for training. The model providers process your request to produce the output under their own terms; we choose routing services that do not train on API traffic by default, but we cannot control a provider's policy and you should read it if it matters to you.

13. Changes

We will post changes here and update the date above. For changes that reduce your rights or expand what we collect, we will email you or show an in-app notice at least 14 days before they take effect.

14. Contact

Email hello@shotborn.com or use the Contact page in the app. Operator and mailing address: see Section 23 of the Terms.