Terms of Service
Last updated: August 26, 2026
Shotbase (we, us, or our) is responsible for the processing described in this Privacy Policy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use our macOS application, websites, account portal, public sharing service, and support channels (collectively, the Service).
1. A local-first service
Shotbase is designed to be local-first. Screenshots, recordings, project files, and editor state generally remain on your device. We do not automatically upload every capture. We process media in the cloud when you choose a cloud feature—for example, when you create a share link, upload a support attachment, or use web-page capture—and only as needed to provide that feature.
This Policy does not cover third-party services you use independently or the content practices of websites you choose to capture. Those services have their own notices and policies.
2. Information we collect
We collect the following information, depending on how you use the Service.
Account and profile information. When you create or use an account, we and our identity provider process information such as your name, email address, authentication identifier, sign-in method, connected sign-in account, and profile image. We also collect the profile and onboarding information you provide, including your handle, display name, intended uses, work role, and how you heard about Shotbase.
Device, trial, and security information. We collect information needed to provide access, protect accounts, and administer trial eligibility. This may include your device name, operating-system and app version, device model or family, public-key fingerprint, approximate city and country, and authentication and trial-eligibility events. We do not use a device serial number or a unique platform identifier for product analytics.
Service, sharing, and content information. We collect information about your use of the Service, including capture titles and descriptions, media type and size, timestamps, share-link identifiers, view counts, and reactions. We receive the media and thumbnails you choose to upload to create a public share link or use another cloud feature.
Billing information. We receive billing information from Stripe and from Service activity, including customer, checkout, subscription, invoice, plan, payment-status, and transaction identifiers.
Support information. If you contact us or submit feedback, we collect the feedback category and description, contact email, optional attachments, limited diagnostics, and support correspondence.
Product analytics and technical information. We collect product analytics such as account identifiers, the email and name of identified users, page views, named product events, plan and trial status, app version, release channel, and non-unique hardware details. We and our service providers may also collect IP address, browser and device information, log data, cookies, and local-storage values needed for authentication, security, or analytics.
Payment data. Payments are handled by Stripe. We receive billing and subscription status needed to administer your plan, but not your full payment-card number.
Capture content. The content of a capture can include personal, confidential, or sensitive information. We receive it only when you upload it or otherwise use a cloud feature. You control whether to create a public share link; anyone with that link can access the shared material while the link remains active.
Analytics limits. Our PostHog configuration uses named events and page views. It disables session replay, automatic element capture, page-leave capture, and surveys. We instruct our product not to send screenshot contents, recording contents, OCR text, private URLs, filenames, notes, free-text content, tokens, or other secrets in analytics events. Analytics may identify an authenticated user using the associated account identifier and include the user's name and email as account-level analytics properties.
3. How we use information
We use personal information to:
provide, authenticate, secure, maintain, and personalize the Service;
create and administer accounts, trials, device access, subscriptions, invoices, cancellations, promotions, and customer support;
host and deliver content that you choose to upload, including public share links;
process your feedback and optional diagnostic submissions;
monitor reliability, prevent fraud, enforce our Terms and usage limits, and protect users and the Service;
understand aggregate product use and improve features, performance, and communications; and
comply with legal obligations, enforce our agreements, and resolve disputes.
Where the GDPR or similar laws apply, we process personal data as necessary to perform our contract with you, pursue our legitimate interests in operating and securing the Service, comply with legal obligations, and, where required, with your consent. You may withdraw consent at any time; this does not affect earlier processing. We will identify the appropriate lawful basis where we seek consent.
4. How we disclose information
We disclose personal information only as necessary for the purposes above:
Identity and account management: Clerk processes authentication, verified email addresses, sign-in methods, sessions, and profile-image storage.
Application backend: Convex stores and processes account records, app configuration, share metadata, access controls, subscription state, and service operations.
Payments: Stripe processes checkout, payment methods, subscriptions, invoices, plan changes, cancellations, and payment failures.
Storage and delivery: Cloudflare R2 stores uploaded shared media and support uploads in private storage; authorized public-share delivery makes the selected shared media available through its public link.
Email: Resend sends transactional and support-related email.
Web-page capture: ScreenshotOne processes a URL that you submit to create a web-page capture.
Analytics: PostHog provides product analytics. Our current product analytics project is configured in the EU region.
Service providers: Hosting, security, infrastructure, professional advisers, and vendors acting on our instructions and subject to appropriate confidentiality and data-protection obligations.
Legal and corporate events: We may disclose information when reasonably necessary to comply with law, enforce or protect our rights and safety, prevent fraud or abuse, or in connection with a financing, merger, acquisition, reorganization, or sale of assets.
We do not sell your personal information. We do not use your capture content for targeted advertising. We do not authorize advertising networks to use your capture content.
5. Public sharing and your choices
Creating a share link makes the selected capture or recording accessible to anyone who has the link. Depending on the feature, the page may also display the title, description, creator handle, reactions, and view count. Do not use public sharing for material that should remain private. You can remove a share link through the Service; removal prevents future public access, though it cannot remove copies others already downloaded or recorded.
You can choose whether to upload content, provide optional feedback attachments, include diagnostics with support feedback, install or use optional local AI features, or use web-page capture. Local AI annotation is processed on your device; Shotbase does not send image content to a remote AI service for that feature.
6. Cookies and similar technologies
We use cookies, SDK storage, and similar technologies for authentication, security, account continuity, and analytics. For example, Clerk uses authentication/session technologies. PostHog uses analytics identifiers and the web application stores a small local-storage marker to avoid repeatedly identifying the same signed-in user; the analytics configuration supports a common cookie across Shotbase subdomains.
Where law requires consent before non-essential cookies or analytics technologies are used, we will obtain that consent and honor your choices.
You can also adjust browser settings to limit cookies, but doing so may prevent parts of the Service from working.
7. Retention
We retain information for as long as needed for the purposes in this Policy, including to provide the Service, maintain security, comply with law, resolve disputes, and enforce agreements.
Account, profile, device, and subscription information is generally retained while your account is active and deleted or de-identified after account deletion, subject to legal, fraud-prevention, backup, and recordkeeping needs.
Shared media and related sharing records are retained until you remove the share link or delete your account. Account deletion queues removal of associated shared media and upload artifacts.
Incomplete support uploads expire after 24 hours. Submitted diagnostics are deleted after 14 days, support attachments after 30 days, and remaining feedback-submission metadata after 180 days. Support-email mailbox copies are configured for deletion after 180 days.
Billing records may be retained longer where required for tax, accounting, fraud prevention, or legal compliance.
Analytics and provider logs are retained under the applicable provider configuration and our retention needs; we will not keep them longer than necessary for the stated purposes.
8. International transfers
We and our service providers may process information in countries other than where you live. When data-protection law requires a transfer mechanism, we will use an appropriate safeguard, such as an adequacy decision, standard contractual clauses, or another lawful mechanism. You may contact us at support@shotbase.com for information about the safeguards applicable to your information.
9. Security
We use reasonable technical and organizational measures designed to protect personal information. These include access controls, authenticated account access, signed upload and delivery flows, and private cloud-storage configurations. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please protect your account credentials and use care when creating public links.
10. Your privacy rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or portability of your personal information; to object to or restrict certain processing; and to withdraw consent. You may also have the right to complain to your local data-protection authority.
To make a request, use account controls where available or contact support@shotbase.com. We may need to verify your identity before acting. We will respond within the period required by applicable law. You may authorize an agent where applicable law permits; we may require proof of authorization and identity verification.
EEA, UK, and Swiss users. You may lodge a complaint with the supervisory authority in your habitual residence, place of work, or place of an alleged infringement.
California residents. Subject to applicable law, California residents may request to know, correct, or delete personal information and may be protected from discrimination for exercising those rights. We do not sell personal information. Contact us at support@shotbase.com.
11. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact support@shotbase.com so that we can investigate and take appropriate action.
12. Changes to this Policy
We may update this Policy from time to time. We will post the updated version and change the “Last updated” date. For material changes, we will provide additional notice where required by law. Your continued use of the Service after an update takes effect is subject to the updated Policy, to the extent permitted by law.
13. Contact us
Shotbase
Protaras, Cyprus
Privacy questions, requests, and general support: support@shotbase.com
