Política de Privacidade

Última atualização: 24 de agosto de 2026

This is a first draft, not legal advice — see the caveat on our Terms of Service. Have it reviewed before relying on it, especially given real payment and personal data are involved.

This describes what STEALSHOT collects, why, and who else sees it.

What we collect

Account info. Email address, and if you sign in with Google: your name, avatar, and Google account id. If you sign in by email code, just the email.

Session and device info. When you sign in, we record the IP address, approximate location (country/city, from our own GeoIP lookup — not a third-party tracker), user agent, and device list, so the account page can show "where you're signed in" and so we can meter and trace abuse.

Activity. Logins, chat messages sent (not third-party-shared beyond the model call needed to answer them — see below), searches you run, films you play, favorites, board edits, and API/MCP calls (including what was sent) are logged with a timestamp, an IP-derived location, and the page/endpoint involved. This is what makes the daily chat/submission limits work and what we use to investigate abuse.

Billing. If you subscribe to Pro, Stripe collects and processes your payment details — we never see or store your card number. We keep your Stripe customer/subscription id, plan, billing interval, and renewal date so the account page can show your plan status.

Browser extension. If you install the STEALSHOT extension, it asks our server about the videos it sees on YouTube and X so it can tell you which are already in the library. Those lookups are logged the same way the activity above is: the platform, the video id and URL, whether we had it, and a timestamp — against your account if you have connected one, otherwise against a random id the extension generates at install, which identifies a browser rather than a person. We use it to decide what to add to the library next. We do not log video titles, page contents, anything from a tab you have not opened, or any site other than YouTube and X.

Cookies. A session cookie (ss_session) keeps you signed in; it stores a random token, not your identity directly (the identity lookup happens server-side). An anonymous cookie (ss_anon) is set only if you paste a submission before signing up, so it can be claimed once you do.

What we use it for

Running the Service: authenticating you, showing your saves/boards, metering chat and submission limits, answering chat questions, billing Pro subscriptions, and investigating abuse or security issues. We don't sell your data, and we don't use your chat messages or account data to train our own models beyond what's needed to answer your question in the moment.

Who else sees it

Data is processed by the vendors that run the Service. None of them get more than they need to do their job:

VendorWhat for
NeonPostgres database hosting — everything above lives here.
Cloudflare R2Video/frame file storage and CDN delivery.
GoogleOAuth sign-in, if you use it.
SMASHSENDSending magic-link sign-in codes.
Anthropic / OpenRouterRunning the chat assistant — your chat messages are sent to whichever is configured to generate a response.
StripePayment processing and subscription billing for Pro.

We may also disclose information if required by law, or to protect the security of the Service or its users.

Retention

Account and activity data is kept for as long as your account exists, plus a limited period after deletion for fraud/abuse investigation. Session records expire automatically after 30 days of inactivity.

Your rights

You can review and revoke your active sessions and API keys from your account page at any time, and you can sign out everywhere from there. To request a copy of your data or deletion of your account, email privacy@stealshot.com — we'll verify it's really you before acting on it.

Changes

We'll update this page as the product changes, with a new "last updated" date. Material changes will be called out, not buried in a diff.

Contact

privacy@stealshot.com