Privacy Policy
Last updated: 2026-08-09
1. Data controller
The data controller for personal data processed through shotium.com and api.shotium.com is Shotium, operated by an independent developer. Contact for all privacy matters: [email protected]. Payment data is processed by Waffo.com Limited as an independent controller (see Section 5).
2. What we collect, why, and on what legal basis
- Account data — your GitHub account ID and email address, collected at sign-in. Purpose: authentication and account management. Legal basis: performance of a contract.
- API keys — stored only as SHA-256 hashes; we cannot recover the plaintext. Purpose: authenticating API requests. Legal basis: performance of a contract.
- Render metadata — requested URLs, template parameters, timestamps, and outcome. Purpose: providing the service (caching), billing, abuse prevention. Legal basis: performance of a contract and our legitimate interest in securing the service.
- Usage and billing records — monthly usage counters, subscription state, and a credit ledger. Purpose: quota enforcement and billing integrity. Legal basis: performance of a contract and legal obligations.
- Server logs — IP address and user agent may appear in transient infrastructure logs (rotated automatically). Purpose: security and troubleshooting. Legal basis: legitimate interest.
We do not sell personal data, run third-party analytics scripts, or use advertising trackers. We do not use your rendered content or API inputs to train AI models.
3. Retention
- Account data, usage counters, credit ledger, and render metadata (URLs, parameters, timestamps): kept while your account exists; deleted or anonymised after account deletion, except records we must keep for legal or billing-integrity reasons.
- Rendered images: stored in Cloudflare R2 for up to 30 days for caching, then deleted automatically.
- Database backups: retained for 30 days, then deleted automatically.
4. Cookies
We use a single strictly necessary, encrypted session cookie for sign-in. No cross-site tracking, no advertising cookies, no consent banner required.
5. Recipients & sub-processors
- Oracle Cloud (US-East) — application and database hosting.
- Cloudflare — CDN/security in front of the site, and R2 object storage for rendered images and encrypted backups.
- GitHub — OAuth sign-in (GitHub sends us your account ID and email; governed by GitHub's privacy statement).
- Waffo.com Limited (Hong Kong) — payments, invoicing, taxes, and payment support as merchant of record and independent controller; we never see or store card numbers. See Waffo's privacy policy.
6. International transfers
Our infrastructure is located in the United States; payment processing is operated from Hong Kong. Where our providers process personal data of EEA/UK residents, transfers are covered by their standard contractual clauses and equivalent safeguards; transfers inherent to the service you explicitly request are additionally covered by Art. 49(1)(b) GDPR.
7. Your rights
Subject to applicable law (including GDPR if you are in the EEA/UK), you have the right to access, rectify, delete, and export your personal data, to restrict or object to certain processing, and to lodge a complaint with your local supervisory authority. To exercise any right — including full account deletion — email [email protected] from your account email. We respond within 30 days.
8. Security
All traffic is encrypted in transit (TLS). API keys are stored as hashes. Rendered images live in private storage accessed via the API only. Access to production systems is restricted to the operator via key-based authentication.
9. Children
The service is not directed to children under 16, and we do not knowingly collect their data.
10. Changes
We may update this policy from time to time; material changes are announced on this page with an updated date. Questions: [email protected].