Privacy Policy
This policy explains what information Shapesoda (“we”, “us”) collects when you use the Shapesoda website, API and MCP server (together, the “Service”), why we collect it, and what you can do about it. The Service is operated by Individual Entrepreneur Ali Mameday, 15 Pavstos Buzand St, Kentron district, Yerevan 0018, Armenia, which is the data controller for the personal data described here.
The short version: we collect as little as we can. We need your email address to run your account. We do not keep the images you upload, and we never use them to train models.
1. What we collect
- Account data. Your email address, and the date your account was created. If you sign in with Google, we receive your email address and the fact that Google has verified it. We do not receive or store your Google password, contacts or profile photo.
- Sign-in codes. When you sign in by email we send you a one-time code. We store only a keyed hash of the code, for at most 10 minutes.
- Credits and payments. Your credit balance, purchases and spending limit. Payments are processed by our online reseller and Merchant of Record (named at checkout), which acts as an independent controller for the payment data you give it. We receive the payment status (for example, “paid”, amount, date) but never your full card details.
- API keys. If you create API keys, we store only a keyed hash and a short prefix so you can recognise the key.
- Usage metrics. For each processed image: time, processing duration, file size in bytes, pixel count, the number of credits charged, and a cryptographic hash (SHA-256) of the image, which lets us avoid charging you twice for the same picture. These records do not contain the image itself.
- Technical data. IP address and request metadata (such as time and user agent), used for security, rate limiting and abuse prevention. Our servers keep operational logs for a limited time.
2. Your images
- Images you open in the editor are processed in memory on our servers for the duration of your editing session and are discarded when the session ends.
- For the API and MCP server, files are held only in short-lived temporary storage in memory: uploads for up to 10 minutes, results for up to 1 hour, then they are deleted automatically.
- We do not write your images or results to disk or to a database, do not look at them, and do not use them to train machine-learning models.
3. Why we use your data
- To provide the Service: create and secure your account, sign you in, process images, track credits (performance of a contract).
- To keep the Service safe: prevent fraud, bots and abuse, enforce rate limits (legitimate interests).
- To send you service emails, such as sign-in codes and important account notices. We do not send marketing email without your consent.
- To comply with legal obligations, for example tax and accounting rules for payments.
4. Cookies
We use a single first-party session cookie (ss_session) to keep you signed in. It is HttpOnly and is not used for tracking. During Google sign-in we set a short-lived cookie (up to 10 minutes) that protects the sign-in flow against forgery. We do not use advertising or analytics cookies. If bot protection is enabled, Cloudflare Turnstile may use its own technical signals to tell humans from bots, as described in Cloudflare’s privacy policy. Your theme and language choices are stored locally in your browser and never sent to us.
5. Third parties we rely on
| Provider | Purpose | Data involved |
|---|---|---|
| Railway | Hosting of servers and database | All data described above, stored and processed on our behalf |
| Resend | Sending sign-in emails | Your email address and the one-time code |
| “Continue with Google” sign-in (optional) | Your email address and verification status, returned by Google at your request | |
| Cloudflare Turnstile | Bot protection on the sign-in form (if enabled) | IP address and browser signals needed for the check |
| Payment reseller (Merchant of Record, named at checkout) | Reseller and Merchant of Record for credit packs: checkout, payment, tax, invoices, refunds | Payment details you give the provider; we receive payment status |
We do not sell your personal data. These providers may process data outside your country, including in the United States; where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
6. How long we keep data
- Images: see section 2 (minutes to at most one hour).
- Sign-in codes: up to 10 minutes. Session cookies: up to 30 days, or until you sign out.
- Account data and usage metrics: while your account is active. When you delete your account, they are deleted, except a one-way hash of your mailbox that we keep so the free credit cannot be claimed again.
- Payment records: as long as tax and accounting law requires.
- Server logs: up to 30 days.
7. Your rights
Depending on where you live (for example under the GDPR or UK GDPR), you may have the right to access your data, correct it, delete it, receive a copy in a portable format, object to or restrict certain processing, and withdraw consent. To exercise any of these, email us at [email protected] from the address linked to your account. You can also complain to your local data protection authority.
8. Security
We use encryption in transit (HTTPS), store only hashes of sign-in codes, session tokens and API keys, isolate image processing in separate processes, and limit access to production systems. No system is perfectly secure, but we work to protect your data and will notify you of a breach where the law requires it.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
10. Changes
We may update this policy. If the changes are significant, we will notify you by email or in the Service before they take effect.
11. Contact
Individual Entrepreneur Ali Mameday, 15 Pavstos Buzand St, Kentron district, Yerevan 0018, Armenia — [email protected]