Privacy
Last updated 2 August 2026
This is a template, not legal advice. Have a lawyer review it before you rely on it. It does describe how the product actually behaves today, which is the part most policies get wrong.
What we collect
- Account data — email and a hashed password, or your OAuth identifier.
- Onboarding answers — the six questions at signup, plus the segment we derive from them. Used to prioritise the roadmap.
- Screenshots you export — source captures and rendered output, so sets can be re-rendered.
- Usage events — page views, exports, and errors. No third-party ad trackers.
What we do not collect
Screenshots you only preview. In the studio, captures are read locally in your browser with an object URL and are never transmitted. If you never export, we never receive them. That is a property of how the studio is built, not a promise we ask you to take on trust.
Processors
- Supabase — authentication, database, file storage.
- Anthropic — screenshot copy generation with Claude Fable 5. We send a short text description of what a screen contains. We do not send your images.
- Stripe — payments. Card details never reach our servers.
- Vercel — hosting and logs.
Retention
Projects and exports are kept until you delete them or close your account. Deleting your account removes both within 30 days. Files you have already downloaded are yours and unaffected.
Your rights
Access, export, correction and deletion, from Settings or by emailing privacy@shipshot.app. If you are in the EEA or UK, the GDPR applies and our lawful basis is contract performance for account data and legitimate interest for product analytics.