Privacy Policy
Last updated: July 14, 2026
1. Data Controller
ShotMind is operated under the ShotMind brand by Yuan Shuai. For all privacy-related inquiries, contact us at hello@shotmind.net.
2. Information We Collect
We collect the following types of information:
- Account Information: email address, display name, and a salted bcrypt hash of your password (we never store your password in plaintext).
- Content: clips or shots you choose to submit for analysis, and the thumbnails, descriptions, tags, and search metadata generated and returned to you for that analysis. The desktop client is used for import, clip selection, analysis, and search. Full local source videos remain on your device. Temporary clip copies used for desktop AI analysis are removed from cloud storage after successful analysis. The complete analysis results, thumbnails, and local searchable index for your private analyzed library are stored by default in the local library on your Mac. Except for temporary clips needed for submitted analysis, public example contributions, support materials you send us, or legal requirements, ShotMind does not keep your private shot library as a long-term cloud-searchable media library.
- Usage Data: cloud service request history, quota consumption, and feature usage to operate and improve the Service.
- Technical Data: IP address, browser type, device information, and request logs for security, rate limiting, and performance.
- Billing and Access Data: limited plan, account access, and quota status. If paid billing is enabled, full payment details such as card number, billing address, and tax ID will be collected and stored by Paddle and will not be accessible to us — see Section 4.
3. How We Use Your Information
- To provide and improve the video analysis service
- To authenticate your identity and secure your account
- To manage account access, quota, and payments if paid billing is enabled
- To communicate important service updates and quota warnings
- To detect and prevent fraud and abuse
- To comply with our legal obligations
Our legal bases for processing under GDPR are: performance of contract (providing the Service), legitimate interests (security, fraud prevention, service improvement), consent (optional product analytics and non-essential communications, which you can withdraw at any time), and legal obligations (tax records, law-enforcement requests).
4. Third-Party Services (Sub-processors)
We use the following categories of third-party services to operate ShotMind:
- Cloud infrastructure and object storage: Alibaba Cloud, used to run APIs, background jobs, and temporarily store the files needed for submitted analysis such as clips and thumbnails
- Database: Neon, used for accounts, credits, orders, cloud analysis task status, troubleshooting, and necessary service records. The complete analysis results, thumbnails, and local searchable index for your private analyzed library are stored by default in the desktop local library.
- AI analysis services: DashScope / Qwen; Google Gemini may be used as a fallback model provider when the primary service is unavailable
- Search service: Meilisearch, used for public examples and necessary service search surfaces. It is not the default search index for your private local library.
- Payments: Paddle, used as Merchant of Record for payments, invoices, tax, and refunds when paid billing is enabled
- Website, email, and error reporting: Vercel, Amazon SES, and Sentry, used to host the website, send service emails, and diagnose errors
- Optional product analytics: PostHog, used only after explicit acceptance for manually defined page views, button clicks, and account conversion events. Autocapture, session replay, heatmaps, and performance capture are disabled.
Authentication is handled by our own servers using industry- standard bcrypt password hashing and short-lived JWT access tokens. No third-party single-sign-on provider is used.
5. Data Storage and Cross-Border Transfer
Your data is processed and stored in multiple regions including Hong Kong (API server, temporary analysis file storage, public example and necessary service search surfaces), Singapore (primary database), the United Kingdom (payments, if paid billing is enabled), and the United States (web hosting, error tracking, transactional email, and optional product analytics after you accept). By using the Service, you consent to this cross-border transfer, which is carried out subject to appropriate safeguards (standard contractual clauses where applicable) as required by GDPR and the UK Data Protection Act.
6. Data Retention
Temporary clip copies used for desktop AI analysis are removed from active cloud storage after successful analysis. We retain account, credit, order, cloud task status, and necessary service records for as long as your account is active. Upon account deletion, we will delete the personal data, submitted temporary clips or shots, and any generated thumbnails or analysis results that remain in our server systems within 30 days. Backups containing deleted data are overwritten within 90 days. Public example contributions remain after account identity is removed, and transactional records (invoices) are retained for the period required by tax law. We may retain aggregated, anonymized usage statistics indefinitely for service improvement. If a valid legal hold, unresolved dispute, fraud investigation, or legal obligation applies, final deletion is paused until the hold reason is resolved or deletion is legally permitted.
After you allow optional analytics, the browser stores only allowlisted UTM parameters, the landing-page path, and the referring site hostname for up to 13 months. It does not retain query strings, email addresses, or payment identifiers. Withdrawing stops local capture immediately and queues deletion of the related PostHog history for signed-in accounts.
Local library and archives: The deletion above applies to data we hold on our servers. The ShotMind desktop app keeps a local library on your Mac — including analyzed shots, their AI analysis results, thumbnails, and search indexes — and you can export it as a local archive. These local files are stored on your own device and are under your control, not ours. Deleting your account removes the data we hold, but it does not reach into or delete the local library and archives on your device; you can keep or delete those yourself. Because they are yours to manage, you are responsible for backing them up and keeping them secure (for example, with macOS FileVault).
7. Your Rights
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and data ("right to be forgotten")
- Object to or restrict processing of your data
- Request data portability (export your data in a common format)
- Withdraw consent to non-essential processing at any time
- Lodge a complaint with your local data protection authority
To exercise these rights, contact us at hello@shotmind.net. We respond to verified requests within 30 days.
8. Cookies
We use essential cookies for authentication and session management. Optional PostHog analytics are off by default and initialize only after explicit acceptance. We send a random analytics identifier, not your email, name, ShotMind account ID, or payment transaction ID. Browser localStorage also holds language, theme, the consent choice, and the limited attribution described above. We do not use advertising or cross-site tracking cookies. Paddle payment flows may set their own cookies as described in Paddle's privacy policy.
Current choice: not chosen
Withdrawing stops optional analytics in this browser immediately. For signed-in accounts, historical PostHog data enters the deletion queue. Accepting again uses a new random analytics identifier.
9. Security
We implement industry-standard security measures including encrypted connections (TLS 1.2+), hashed passwords (bcrypt), encryption at rest for stored files, server-side access controls, and audit logging of sensitive operations. However, no system is 100% secure, and we cannot guarantee absolute security. If we discover a breach affecting your personal data, we will notify you and, where required, the relevant data protection authority without undue delay.
10. Children's Privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will delete it promptly. If you are a parent or guardian and believe we may have collected information about your child, please contact us at hello@shotmind.net.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced via email or in-app notification at least 14 days before they take effect.
12. Contact
For privacy-related inquiries, please contact us at hello@shotmind.net.