Privacy Policy

Last updated: July 28, 2026

ShotKit (“we”, “us”, or “the service”) operates the website at https://shotkitapp.com and provides AI-powered product photography tools. This Privacy Policy explains what information we collect when you use ShotKit, how we use and share it, and the choices you have. By using ShotKit, you agree to the practices described here. For the rules that govern your use of the service, see our Terms of Service.

1. Information we collect

We aim to collect only what is needed to render images, enforce free-tier limits, prevent abuse, process payments, and respond to support requests.

  • Product images you upload. When you render a product photo, the image you upload is sent to our AI model provider (fal.ai) as a data URL so the render can be produced. We do not maintain a persistent public gallery of your uploads on the free tier; the result image is returned to your browser for you to download.
  • Usage and account data. When you create a lead (e.g. join a waitlist) we store the email address you submit. When you check out through Creem, Creem shares with us the information needed to fulfill your order (such as a transaction identifier and the plan purchased). We do not receive or store your full card number.
  • Automatic data. We collect an IP address and a browser fingerprint to enforce per-visitor free-tier limits and protect against abuse, plus standard request metadata (timestamps, the scene selected, and an approximate generation count) for capacity planning and analytics.
  • Anti-bot signals. We use Cloudflare Turnstile to distinguish real visitors from automated clients. The Turnstile token is verified server-side and is not linked to your identity.

2. How we use information

  • To generate and return the product images you request.
  • To enforce free-tier daily limits and paid entitlements, and to issue refunds or credits when a render fails.
  • To prevent fraud, abuse, and prohibited content (see our Acceptable Use Policy).
  • To send transactional messages about your order, and to respond to support requests you send us.
  • To improve scene quality, plan the service, and keep it secure.

3. How we share information

We do not sell your personal information. We share data only with the service providers that process it on our behalf, and where required by law:

  • fal.ai — receives the uploaded image and your written prompt to run the image model. fal.ai processes this data under its own terms as an independent controller.
  • Creem — acts as the merchant-of-record for paid transactions and processes your payment information directly. Creem shares with us only the order details needed to deliver your plan.
  • Cloudflare — provides bot protection (Turnstile) and edge delivery.
  • Infrastructure providers — hosting, databases, and logging services used to run ShotKit.

4. Content moderation

To keep the service safe and comply with our Acceptable Use Policy, prompt-based generation requests are screened through Creem’s Content Moderation API before an image is generated. Prompts that are flagged as prohibited are rejected and not sent to the model. See the Acceptable Use Policy in our Terms of Service for what is not allowed.

5. Data retention

Uploaded images are passed to the model and returned to you; we do not keep a persistent gallery of free-tier renders. We retain usage logs (IP, fingerprint, scene, timestamp) only as long as needed for abuse prevention and capacity analysis. Lead emails are kept until you request deletion. Records of paid transactions are retained as required for accounting and tax purposes.

6. Your rights

Depending on where you live, you may have the right to access, correct, or delete the personal information we hold about you, and to object to or restrict certain processing. To exercise any of these rights, contact us at help@shotkitapp.com. We will not discriminate against you for exercising these rights.

7. Children’s privacy

ShotKit is a business tool intended for merchants and brands. It is not directed at children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal data, contact us and we will delete it.

8. International transfers

Your information may be processed by providers located in countries other than your own. Where this involves a transfer out of your region, we rely on the safeguards those providers publish (such as standard contractual clauses) and on the fact that we limit the data shared to what each provider needs.

9. Security

We use reasonable measures to protect data — secrets are read at runtime rather than baked into the build, payments are handled by a PCI-scoped merchant-of-record, and access to backends is restricted. No method of transmission or storage is fully secure, and we cannot guarantee absolute security.

10. Changes to this policy

We may update this Privacy Policy as the service evolves. The “Last updated” date above reflects the most recent revision. Material changes will be reflected here; continued use after a change constitutes acceptance.

11. Contact us

Questions about this policy or your data? Email help@shotkitapp.com — this is our customer support address and matches the business details on file with our payment processor.