A plain-language account of the data behind the tool.
This policy explains what ShotToPrompt processes when you create an account, use account credits to analyze a video, purchase more credits, or contact us. An active signed-in account with at least one Analysis Credit is required to use the analyzer.
Video analysis
When you upload a video, it travels directly to temporary private Cloudflare R2 storage. Kie.ai's Gemini endpoint reads it through a short-lived signed URL and receives a maximum 15-second analysis range, after which the temporary object is deleted. ShotToPrompt does not write the video to its Postgres database.
When you submit a supported direct video-file link, the validated URL and a maximum 15-second time range are sent to Kie.ai. ShotToPrompt does not download the linked video through Vercel or its Worker and does not store the raw URL in Postgres or analytics. The URL exists transiently in the processing request and Cloudflare Queue message. Kie.ai and its upstream model provider process both workflows under their applicable terms and privacy practices; do not submit confidential material or media you are not authorized to process. YouTube and other social-video page links are not currently supported.
Data we store
- A random browser identifier stored in a first-party, HTTP-only cookie and a one-way hash of that identifier in the database.
- Daily usage counts and a rotating HMAC of the server-observed network address. The raw address is not stored in the product database, and the HMAC changes each UTC day.
- Operational metadata: a generic source label, source type, media type, file size when uploaded, requested duration or link start time, processing status, model name, token counts, estimated model cost, and timestamps. We do not retain the original source filename or raw public video URL.
- The generated analysis, including prompts, shot and action-beat timeline, evidence and uncertainty labels, visual description, and notes.
- Your optional helpful/not-helpful rating, selected reason, and—only if you join the early-access offer experiment—your email address and offer identifier.
- If you contact us: your name if supplied, email address, message, timestamps, and an anonymous browser hash used for abuse prevention.
- If you create an account: your name, verified email address, optional profile image, authentication provider identity, session records, and security metadata such as session timestamps, browser user agent, and network address observed during sign-in.
- If you start or complete a purchase: the checkout, order, transaction, product and customer identifiers supplied by Creem; purchase email; amount, currency, tax-related country information where supplied; payment, refund, or dispute status; credit grants and usage ledger; and a one-way hash of your recovery key. ShotToPrompt does not receive or store your full card number.
Why we process it
We process this data to provide the requested analysis, maintain the account credit ledger, enforce request and service-capacity limits, troubleshoot failures, protect the service from abuse, measure the product funnel, improve output reliability, respond to messages, and notify people who explicitly join an early-access offer. We do not sell personal information.
Cookies
ShotToPrompt sets necessary first-party cookies named stp_visitor and, for the Cloudflare media pipeline, stp_media_visitor. When you sign in, the authentication service sets a necessary ShotToPrompt session cookie. It also sets stp_entitlement across ShotToPrompt subdomains so the media Worker can recognize the credit account attached to the current signed-in user; current account-access tokens expire after 30 days and are revoked from the current browser when you sign out. These cookies are HTTP-only and SameSite=Lax and are used for authentication, limits, credit entitlement, matching feedback to an analysis, recording an intentional pricing-interest click, and abuse prevention—not advertising or cross-site tracking. When you start an analysis, the site also sets and immediately deletes a short-lived stp_cookie_probe cookie to confirm that required first-party cookies work. If they are blocked, the analyzer explains what must be enabled without asking you to enable analytics. We do not use Vercel Web Analytics.
For visitors in the EEA, United Kingdom, Switzerland, or when the visitor's country cannot be determined, Google Analytics 4, PostHog, and Microsoft Clarity load product analytics only after “Allow analytics” is selected. In other regions, pseudonymous product analytics and masked session recordings may load automatically without advertising storage; they can be turned off at any time through “Analytics choices” in the footer. A browser Global Privacy Control signal is honored automatically as an analytics opt-out. The regional decision is derived from Vercel's country-level request header and cached in local browser storage for up to 24 hours; ShotToPrompt does not receive precise location from this check. Declining or disabling analytics does not prevent use of the analyzer.
Abuse prevention
When you ask to start an analysis, Cloudflare Turnstile may check browser and network signals to help distinguish legitimate use from automated abuse. The check runs before ShotToPrompt issues a private upload URL or queues a linked video. ShotToPrompt validates the short-lived response but does not store the Turnstile token or send it to Google Analytics. Cloudflare may process ordinary security data under its privacy practices. The check does not run merely because you read the site.
Kie.ai or its upstream Gemini content-safety filters may reject a submitted video. ShotToPrompt records a generic operational error code and anonymous usage identifiers to enforce limits, but does not retain the rejected video, raw public URL, safety category, or detailed safety response in product analytics.
Analytics events
A single pseudonymous registration event is recorded when an account is created so registrations can be counted across products. Where browser analytics is enabled under the regional rule or by your choice, we measure steps such as selecting or rejecting an upload, starting or completing an analysis, encountering an error code, copying a prompt, choosing a model tab, viewing pricing, starting or returning from checkout, and confirming a purchase. Google Analytics and PostHog may receive coarse file type or size buckets, latency, shot and action-beat counts, selected output model, and the offer identifier. PostHog uses a product-scoped pseudonymous account identifier for signed-in activity and does not record sessions; Microsoft Clarity receives only coarse event names and masked interaction recordings. The entire analyzer workspace—including uploaded media, filenames, prompts, and generated results—is explicitly masked or excluded. These services do not receive uploaded video bytes, original filenames, full generated prompts, contact messages, IP-derived HMACs, storage keys, signed URLs, email addresses, names, or payment identifiers. Advertising storage, advertising user data, and advertising personalization remain disabled; the current MVP does not load AdSense or advertising cookies.
Retention
Our current operational targets are 14 days for analysis runs and generated results, two days for anonymous visitor and network usage rows, and 90 days for aggregate cost reservations, contact messages, result feedback, early-access emails, and anonymous daily pricing-interest totals. Account and session data is retained while the account is active; expired sessions and access tokens are removed during routine service activity. Purchase, refund, dispute, tax, and credit-ledger records may be retained for up to seven years where needed for accounting, fraud prevention, legal claims, and tax obligations. Entitlement records may remain while credits are valid and for a limited reconciliation period afterward. Kie.ai currently states that its model-task log records are retained for up to two months; security logs and provider backups may persist for a limited additional period under infrastructure-provider practices.
Service providers and disclosure
Kie.ai and its upstream Gemini model provider process uploaded or directly linked video for the analysis you request. Creem provides checkout, payment processing, receipts, tax handling, refunds, and payment-dispute events. Google provides optional OAuth sign-in and returns the verified account details you approve; Resend delivers requested Magic Link emails when that method is enabled. Google Analytics and PostHog process page and coarse product-event data, and Microsoft Clarity processes coarse event names plus masked interaction recordings, only when enabled under the regional rule or by your choice; account emails, recovery keys, generated content, and payment identifiers are never sent as readable product analytics. Neon hosts the Postgres records described above. Vercel hosts the website but does not carry linked video bytes. Cloudflare Turnstile provides the analysis-start security check; Cloudflare Workers, Queue, and private R2 storage coordinate media jobs; Cloudflare R2 also hosts public example and brand assets requested directly by your browser. These providers may keep ordinary security logs under their practices. We may disclose information when required by law or to protect the service and its users.
Your choices
You can avoid submitting a video, sign out to revoke the current browser's account access, clear ShotToPrompt cookies, or ask us to delete an identifiable account, contact message, or analysis record. Include the account or message email and an analysis identifier if available. For a purchase request, include the account email and Creem order identifier; some transaction records must be retained where law requires. Because other usage identifiers are pseudonymous, we may not be able to reliably identify a record without that information.
Advertising changes
If advertising is enabled later, this policy and the site's consent controls will be updated before ad tags are served where required. Google advertising cookies are not part of the current MVP.
Contact
Privacy requests can be submitted through the contact form or sent to support@shottoprompt.com. This policy may change as the product or its providers change; the effective date above will be updated when material changes are published.