Privacy Policy

A plain-language account of the data behind the tool.

Effective August 4, 2026

This policy explains what ShotToPrompt processes when you use the video analyzer or contact form. The service does not require an account.

Video analysis

When you submit a video, its bytes and MIME type are sent to Google's Gemini API so Gemini can analyze the visual and audio content and return a structured result. ShotToPrompt does not write the uploaded video to local disk or its Postgres database. Google processes the request under its applicable API terms and privacy practices; do not upload confidential or sensitive footage that you are not comfortable sending to this processor.

Data we store

  • A random browser identifier stored in a first-party, HTTP-only cookie and a one-way hash of that identifier in the database.
  • Daily usage counts used to enforce the free limit.
  • Operational metadata: a generic file label derived from media type, file size, reported duration, processing status, model name, and timestamps. We do not retain the original source filename.
  • The generated analysis, including prompts, shot timeline, visual description, and notes.
  • Your optional helpful/not-helpful rating, selected reason, and—only if you join the early-access offer experiment—your email address and offer identifier.
  • If you contact us: your name if supplied, email address, message, timestamps, and an anonymous browser hash used for abuse prevention.

Why we process it

We process this data to provide the requested analysis, enforce the daily allowance, troubleshoot failures, protect the service from abuse, measure the anonymous product funnel, improve output reliability, respond to messages, and notify people who explicitly join an early-access offer. We do not sell personal information.

Cookies

ShotToPrompt sets one first-party cookie named stp_visitor. It is HTTP-only, SameSite=Lax, and lasts for up to one year. It is used for the anonymous daily limit, matching feedback to its analysis, and contact-form abuse prevention—not advertising or cross-site tracking. Vercel Web Analytics collects aggregated page, referrer, device, and anonymous product-event data without analytics cookies. Custom events do not include uploaded files, original filenames, full generated prompts, or email addresses. The current MVP does not load AdSense or advertising cookies.

Retention

Our current operational targets are 30 days for analysis runs and generated results, 32 days for daily usage rows, and 90 days for contact messages, result feedback, and early-access emails. Expired live-database rows are removed during routine service activity. Security logs and provider backups may persist for a limited additional period under infrastructure-provider practices.

Service providers and disclosure

Google Gemini processes uploaded video for the analysis you request. Neon hosts the Postgres records described above. Vercel hosts the service, transmits requests, provides cookieless aggregate analytics, and may keep ordinary security logs. We may disclose information when required by law or to protect the service and its users.

Your choices

You can avoid submitting a video, clear the ShotToPrompt cookie in your browser, or ask us to delete an identifiable contact message or analysis record. Include the email used in your message or an analysis identifier if available. Because usage identifiers are pseudonymous, we may not be able to reliably identify a record without that information.

Advertising changes

If advertising is enabled later, this policy and the site's consent controls will be updated before ad tags are served where required. Google advertising cookies are not part of the current MVP.

Contact

Privacy requests can be submitted through the contact form. This policy may change as the product or its providers change; the effective date above will be updated when material changes are published.