Privacy & data handling.
A plain-language explanation of the data used by this application.
What is stored
- Account information: your name, email address, account role and, if you use a password, its hash. Google and Apple sign-ins store a provider identity and the email shared by that provider. Provider passwords and access tokens are not stored.
- Project information: app names, template choices, screenshot copy, language variants, design settings and project timestamps.
- Files: images you upload and generated export files. Uploaded screenshots may contain personal information if you put it in them; use sample or anonymized app data.
- Access records: export history, authorized MCP connections and, where they already exist, historical orders and payment references. All current projects and exports are free.
Browser storage and cookies
The guest editor stores a draft in your browser so it can survive navigation. Clearing site data can remove an unsaved draft. Signing in uses an HTTP-only session cookie so the server can recognize your account. The included application does not add advertising trackers or a third-party analytics service.
How the application uses your data
Account data is used to authenticate you and restrict access to your projects. Project data is used to save designs, render screenshots and generate downloads. Historical order records are retained for receipts and refunds. Administrators of the installation can manage users and project metadata.
Where processing happens
If enabled by the operator, Google and Apple sign-in use Firebase Authentication to verify your identity. Your name, verified email and provider identifier connect to your ShotFleet account. Apple’s private relay email is supported. Connecting another sign-in requires your confirmation; matching email addresses are not automatically merged. Firebase and your chosen provider process sign-in information under their own privacy policies.
Saved projects and uploads are stored on the server running this installation. Screenshot rendering happens there using a browser rendering process. Actual hosting providers, countries, backups and log retention depend on the operator’s deployment configuration; those details must be disclosed by a public operator.
New checkout is disabled. For purchases made before the application became free, ShotFleet retains order references, totals, tax amounts, payment status and refunds; it does not store full card details. Polar processes historical payment information under its privacy policy. Installations using the legacy Stripe integration are also subject to Stripe’s privacy policy.
Connected editors
ShotFleet does not include a hosted AI chat or send designs to a model provider on its own. An external MCP client can read and edit the projects and permissions you authorize, including design text, uploaded assets and requested preview images. That client and its model provider have their own data policies.
MCP edits are saved as normal project revisions. Preview images are temporary and are not uploaded to object storage. Open editor sessions report the selected page, layers, language, size, zoom and unsaved state so your connected client can coordinate changes. Download links generated through MCP last five minutes. You can revoke a connection and its download links in MCP connections.
Retention and deletion
Saved projects and exports remain in the installation until its operator removes them. Archiving a project hides it from the active workspace; it is not a permanent deletion request. The included interface does not provide a complete account-erasure workflow. For a public service, the operator must publish a contact channel, retention period and process for access, correction and erasure requests.
Keeping your screenshots private
Project APIs, private uploads and completed downloads require authentication and ownership checks. Do not upload confidential data that you do not have permission to process. Protect your account and review your screenshots before publishing them to a public store listing.
Before a public launch
The deployment owner should complete this notice with accurate business and hosting information and verify applicable privacy obligations. The terms page explains the product’s usage and payment behavior.