← Blockshot
Privacy Policy
Last updated [DATE]
Before this goes live: fill in every highlighted value,
confirm the sub-processor list matches what you actually deploy, and have it reviewed. This draft
describes the data the software genuinely collects today — if you add analytics, marketing email or
a support tool later, this page has to change with it.
This policy explains what Blockshot collects, why, and who else sees it.
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]
is the data controller. Contact us at [SUPPORT EMAIL].
What we collect
- Account
- Your email address and display name, received from Amazon Cognito when you sign in. We never
receive your password. If you sign in with Google, we also keep the web address of your Google
profile picture so it can be shown on your account — the address only, never a copy of the
image, and your Google password is never seen by Cognito or by us.
- Your work
- The scene documents you save: object positions, camera moves, timing and the scene name. These
are stored as versions, so an earlier state of a project can be restored.
- Prompts
- The descriptions you type, and the scene they are applied to, are sent to an AI provider to
produce a layout. We do not store your prompt text after the request completes.
- Usage and billing
- For each generation: which action, which model, token counts, what it cost us, and what we
charged you in credits. This is what makes a billing question answerable.
- Device signal
- A value computed in your browser from characteristics of your device — screen size, timezone,
language, graphics rendering. We store only a salted hash of it, never the value itself, and use
it for one purpose: detecting the same machine collecting the free credits again and again. It is not used
for advertising, is not shared with anyone, and is not joined to any data outside this service.
Blocking it does not affect how the app works for you.
- Technical
- IP address (stored as a salted hash alongside sessions and coupon redemptions), browser user
agent, and server logs.
- Saved clips
- Exported clips are produced in your browser and are not uploaded unless you choose to
save one to your project library. A clip you save is stored encrypted, is readable only
through a short-lived link issued to you, and is deleted automatically after
[30] days. You can delete one yourself at any time. We do not
watch, analyse or use saved clips for any purpose other than showing them back to you.
- Payments
- Razorpay handles payment. We receive the payment identifier, amount and status. We never
receive or store your card number, UPI ID or bank details.
Why we use it
- To run the service — sign you in, save and load your projects, generate
layouts. (Performance of our contract with you.)
- To meter and bill — track credits, settle what a generation cost, take
payment. (Contract, and our legal obligation to keep financial records.)
- To keep the service usable — rate limits, abuse detection, and stopping one
machine collecting the free credits repeatedly. (Our legitimate interest in not having the free
credits farmed.)
- To support you — answer questions, correct balances, investigate faults.
(Contract and legitimate interest.)
We do not use your content to train AI models, and we do not sell your data or share it for
advertising. We do not send marketing email unless you ask for it.
Who else processes it
- Amazon Web Services
- Hosting, database, file storage, sign-in (Cognito) and email. Region
[AWS REGION].
- Anthropic
- The AI provider that generates layouts. Your prompt and current scene are sent to it. Anthropic
does not train on data submitted through its API.
- Helicone
- An AI gateway that sits in front of the provider for cost tracking and rate limiting, when
enabled. Requests pass through it, which includes your prompt.
[Remove this entry if you deploy without HELICONE_API_KEY set.]
- Google
- Analytics for the website: page views, roughly where in the world a visit came from, and which
pages lead to which. Not the contents of your scenes, which never reach it.
- Razorpay
- Payment processing. Subject to their own privacy policy.
How long we keep it
- Projects and scenes — until you delete them or close your account. Deleted
projects are archived rather than immediately erased, and removed within
[30] days.
- Saved clips — [30] days from the day they are
saved, then deleted automatically.
- Usage and credit records — retained while your account is open and for
[8 years] afterwards, because financial records must be kept.
- Sessions — until they expire or you sign out.
- Device and IP hashes — [12] months.
- Server logs — [30] days.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of
it. Write to [SUPPORT EMAIL] and we will respond within
[30] days. You can also export any project from the studio at any time
without asking us — File → Save .json.
If you are in a jurisdiction with a supervisory authority for data protection, you may complain to
it. [If you serve users in India, name your Grievance Officer and their contact
details here, as the DPDP Act requires.]
Cookies
We set one cookie of our own: an opaque session identifier that keeps you signed in. It is
httpOnly, so no script can read it, and it carries no information about you.
Google Analytics sets its own cookies to count visits and to tell a returning visitor from a new
one. We use it to see which pages people arrive on and where they stop, not to build a profile of
you: we do not send it your name, your email or anything you type into the studio, and there is no
advertising or remarketing tag on this site. Blocking it changes nothing about how the product
works. Google's handling of that data is covered by
their privacy policy.
The studio also uses your browser's local storage to keep a copy of your current scene so you do
not lose work offline; that copy never leaves your device.
Security
Traffic is encrypted in transit. Sessions are server-side and can be revoked. Device and IP values
are stored as salted hashes rather than in the clear. API keys are held in AWS Parameter Store and
never reach your browser. No system is perfectly secure, and we will tell you promptly if a breach
affects your data.
Children
The Service is not directed at children and we do not knowingly collect their data.
Changes
If we change this policy in a way that materially affects you, we will tell you by email or in the
app before it takes effect.