SHOT.MOV
English

Privacy Policy

Last updated: September 17, 2026

1. Overview

This policy describes what data Shot.mov (“we”, “us”) collects when you use our AI image and video generation service, how we use it, and the choices you have. The short version: we collect only what the Service needs to work, we do not sell your data, and we do not run advertising or tracking networks.

2. Data We Collect

  • Google account profile. When you sign in with Google we receive your name, email address, profile picture, and Google account identifier. We use them to create and identify your account. We never see your Google password.
  • Prompts and generated media. The text prompts you submit and the images and videos generated from them. Depending on the image features available to your account, a newly generated still may appear as a temporary candidate; when an image is labeled Temporary, only an image you explicitly keep is stored in your gallery. Other generated images, videos, and uploaded images are stored when created or uploaded.
  • Uploaded images. Images you upload to the Service as generation inputs.
  • Usage and quota records. Records of your generations and how much of your generation allowance they consumed, plus basic technical logs (such as timestamps, the IP address you signed up from, and error information) we use to keep the Service reliable and prevent abuse.
  • Publication and moderation records. If Community publishing becomes available and you publish, we record the account, shot, time, and notice revision associated with that choice. A report about a public shot records the reporting account, the target shot and its owner, the selected reason, timestamps, and resulting moderation actions.
  • Share-link records. If member share links become available and you create one, we record the link, when it was created, rotated, or revoked, the account, shot, time, and notice revision of your acknowledgement, aggregate view counts, and any reports about it with the same details as a feed report.
  • Payment records. When you buy a plan or Dedicated Queue we keep the product selection, model-specific slot quantity, price, and the payment provider’s charge reference and status. Payment itself happens on the provider’s hosted page — we never see or store your wallet keys or payment credentials. Payment records are kept for accounting even after account deletion, detached from your identity.

3. Cookies

If you accept a referral invitation, we remember its code in a first-party httpOnly cookie for up to 30 days, removing it after successful sign-in or when you choose to continue without an invitation. We record who invited whom, the first qualifying payment and the plan time each reward added. The inviter sees how many invited members joined and were rewarded, but not your name, email, payment amount or creations. Attribution and accounting records survive account deletion with user references removed, to prevent duplicate rewards.

If you open a signup pass link and choose Join, we remember that link in a first-party httpOnly cookie for up to one day, removing it once the sign-in it started has used it. An account records which signup pass link or code it took a pass through and when, what the pass granted, and what it paid for; these records survive account deletion with user references removed. A sign-in identity that took a pass is remembered by a keyed fingerprint rather than its identifier, also after account deletion, so it cannot take another pass.

We use an httpOnly session cookie so you stay signed in. It lives for up to 30 days and contains only a session identifier. We do not use advertising or cross-site tracking cookies.

4. How We Use Your Data

We use the data above to:

  • operate the Service and deliver your generations;
  • enforce generation quotas, safety rules, and our Terms of Service;
  • diagnose failures and improve the Service — which may include analysing prompts and generated content to develop and improve our features and models.
  • make content public only when you choose to publish it, operate that public access, prevent report abuse, and moderate public surfaces.

We do not sell personal data, and we do not share it with ad networks or data brokers.

5. How Your Content Is Processed

To fulfil a generation request, your prompt — and, for video, the image it is based on — is sent to our AI infrastructure partners, who run the generation on our behalf and solely for that purpose. Their transient copies of your content expire within about 24 hours, and prompt-preparation results may be cached for up to one hour to make repeated requests faster, then destroyed. The still-image candidates that the Service labels Temporary remain in that transient provider storage unless you explicitly keep one by liking it, marking it as Legend, pinning it, downloading it, moving it to a folder, or using it to make a video. At that point we copy it into our own object storage. Merely viewing a candidate, disliking it, or repeating its prompt does not save it. Other generated images, videos, and images you upload are copied to our storage as part of their normal creation or upload flow.

6. Data Retention

To prevent repeated free trials, we retain a protected fingerprint of each sign-in identity for the lifetime of the trial offer, including after account deletion. It contains no profile, email address, or media, and is not used to restore a deleted account. Separate protected signup-IP fingerprints enforce a rolling 24-hour signup limit; expired entries are removed by routine cleanup.

We keep your account data, media you explicitly keep, uploaded media, videos, and usage records for as long as your account exists. Still-image candidates labeled Temporary normally expire with our AI infrastructure partner within about 24 hours and are then removed from the Recent candidates surface. Operational logs are kept only as long as needed for reliability and security purposes.

Publication-choice records are kept with the shot and its moderation history. Report records may outlive deletion of the reported shot or the reporter’s account: the deleted shot and reporter are no longer linked, while a detached reference to the content owner may remain so repeated safety and enforcement issues can be reviewed. These limited records are retained only as reasonably necessary for safety, enforcement, disputes, and legal duties.

7. Deleting Your Data

You can delete individual generations from your gallery at any time, and you can delete your account and its gallery content from your account page. You can also request deletion by emailing support@shot.mov from the address linked to your account. Either way, deleted data is queued for removal and purged from our systems within 30 days, except for the limited payment, safety, enforcement, dispute, and compliance records described in this policy. Those records may be kept longer and detached from the deleted account or content where feasible.

8. Public Sharing, Member Share Links, and Moderation Records

Community publishing is not available today.

Content in an ordinary member gallery is private and is not placed in the official Shot Feed. Community publication is a separate use of the selected content and account information.

  • Publishing is a separate choice for each shot. Creating, liking, marking as Legend, pinning, downloading, or creating a share link does not publish a shot to Community.
  • When you publish, the selected media, its prompt, and your public handle become available through Community, its permalink, and its media delivery routes. Anyone can view and share them without signing in.
  • Before your first publication under this notice, we will show a concise notice separately from general account acceptance and require an affirmative action. We record the account, shot, time, and notice revision. A material revision must be acknowledged before you can publish another shot.
  • You can unpublish from the same publishing controls. Public delivery stops on the next request, while the generation remains private in your gallery unless you delete it. Unpublishing does not erase reporting or moderation records and cannot recall copies that other people already made.

Community publication notice revision: community-publication-v1

Member share links are available for general-audience shots. 18+ share links are available to accounts that pass the checks below.

If member share links become available and you create one, the link and what happens to it are a separate use of the selected shot and of your account. This section says what a viewer receives, what we record, and how long we keep it.

  • A link page shows the finished image or video, a generic AI-generated label, a download, and a way to report it. It never shows the prompt, any input image, who made the shot, internal or provider identifiers, or the other outputs made alongside it.
  • A general-audience shot opens for anyone who has the link: no Shot.mov account is needed to view or download it, and because a link can be passed on, whoever holds the address can open it. Only an 18+ shot asks the viewer to sign in before showing more than a blurred preview.
  • An 18+ shot shows a blurred preview to anyone who has the link, and says what is still needed to see the shot itself. The shot itself is shown only to a signed-in viewer whose account currently carries the 18+ verification that already gates making 18+ content on Shot.mov and has turned off Blur 18+ shared shots, and only while the account that shared it carries that verification too. The preview is blurred on the server before it is sent, so the shot's detail never leaves Shot.mov.
  • A shot has at most one active link. Rotating a link invalidates the old address before the new one works, and revoking a link stops new access immediately, although it cannot recall a file someone already downloaded. Sharing a temporary still keeps it in your gallery, the same as downloading it. A downloaded file is delivered as it is, with no added mark and no embedded provenance data: the AI-generated label lives on the page, and any disclosure a later use needs is for the person using the file to add.
  • The link record, its history, and any reports about it are kept after you revoke or rotate the link, delete the shot, or delete your account. The deleted shot or account is detached from those records rather than the records being erased, and we keep them for 365 days after the link stops, or longer while a legal hold applies. The media itself follows the retention of the shot: it is never kept for the link, and revoking a link does not delete your copy.
  • You see how many times your link was viewed, never who viewed it. Product analytics receive aggregate counts only, never link addresses, prompts, media, or viewer identities.
  • Any signed-in viewer can report a shot from its link page. Reports go to the same queue as feed reports: Shot.mov operations is responsible for it and targets an initial review within 7 calendar days after receipt.
  • If your shot is quarantined or its link is revoked by moderation, you can appeal by emailing support@shot.mov.
  • We do not disclose link, viewer, or report records to anyone on request. They are preserved and disclosed only under a legal process that binds us, and a legal hold can keep a record beyond its normal retention.
  • Before your first share link under this notice, we will show a concise notice separately from general account acceptance and require an affirmative action. We record the account, shot, time, and notice revision. A material revision must be acknowledged before you can create another link.

Member share-link notice revision: share-links-v1

Shot.mov operations is responsible for the report queue. We target an initial review within 7 calendar days after receipt. Automated safeguards may hide a shot sooner, and urgent safety reports are prioritized. This target covers initial review, not final resolution or an individual response.

Reporter account details are used to deter report abuse and support moderation. They are not shown publicly or to the person who posted the shot.

For an appeal or a safety concern that needs context, email support@shot.mov.

9. Security

Your data is transmitted over encrypted connections and stored in access-controlled infrastructure. No system is perfectly secure, but we design the Service so that your content is accessible only to you, to the systems that operate it, and through a public route only after an authorized publication choice.

10. Children

The Service is not directed to anyone under 18, and we do not knowingly collect data from them. If you believe someone under 18 has created an account, contact us and we will delete it.

11. Changes to this Policy

We may update this policy as the Service evolves. If a change is material, we will give reasonable notice — for example on the website or by email — before it takes effect. The date at the top of this page always reflects the latest revision. A material change to the Community publication notice also changes its revision and must be acknowledged before another shot can be published. The same applies to the member share-link notice: a material change changes its revision and must be acknowledged before another link can be created.

12. Contact

Questions about this policy or your data? Email support@shot.mov.