Privacy Policy

Last updated: September 12, 2026

1. What we collect

2. How we use it

For credit purchases, we also keep payment references, purchased credits, balances, refunds and related account records. Stripe processes card payments; we do not store your full card number or security code.

Only to run the Service: to sign you in, store your work, generate the content you ask for, publish to the platforms you connect, and keep the Service secure. We do not sell your data, and we do not use your content to train AI models.

3. Where it lives

Your data is stored in Google Firebase (Firestore and Cloud Storage). The application server runs on Railway, and traffic may pass through Cloudflare. Some generated assets are automatically deleted after a retention period (currently about 15 days for generated ad images and card images).

4. Who else processes it

Stripe processes one-time credit payments and receives the information needed to process those payments.

We share nothing with anyone else, and nothing for advertising purposes.

5. Cookies and tracking

The Service uses authentication state (Firebase) to keep you signed in. There are no third-party advertising or analytics trackers.

6. Retention and deletion

Saved libraries share 100 MB per account unless support grants additional space. We record file sizes and upload information to enforce storage limits. Deleting saved files removes unreferenced copies from storage; a copy shared by another saved folder remains until it is no longer referenced. Failed cleanup is retried.

Temporary generation references have a separate 100 MB limit and expire after 24 hours. Files hosted by AI providers follow their own expiry periods. Keep a downloaded copy of work you need to retain.

Media download links can be accessed by anyone who has the link. Reference links are shared with the AI provider when needed for a generation request. Avoid sharing download links to private work.

Your account data is kept while your account is active. Generated assets are cleaned up automatically on a rolling basis. To delete your account and its data, email [email protected] from your account's email address and we will remove it within a reasonable time, except where retention is required for legal or security reasons.

7. Security

Access to data is restricted by per-account security rules (each account can only read and write its own data), provider secrets are kept server-side only, and connections use encrypted transport (HTTPS). No system is perfectly secure, so keep your login credentials and API keys private.

8. Your choices

You can disconnect any linked platform at any time from the app's settings, ask us for a copy of your data, or ask for deletion (section 6). If you believe data is held about you in error, contact us.

9. Changes

We may update this policy from time to time; the "Last updated" date above reflects the current version. Meaningful changes will be visible here before they take effect.

10. Contact

Privacy questions: [email protected].

© 2026 ShineStudio. All rights reserved. · Terms of Service