Privacy Policy

What StoreShots collects, what it never collects, and where the things you make actually live.

Last updated: 24 August 2026.

Before you read this

This policy is written in plain English by the person who built StoreShots, describing what the software actually does. It is not legal advice, and it has not been reviewed by a lawyer. If you need it to satisfy a specific legal requirement, have someone qualified check it.

The short version

Your screenshots stay on your device. StoreShots builds every design in your browser, including the finished PNGs and the ZIP you download. Nothing you make is uploaded, backed up, or synced anywhere.

The only personal data that reaches a server is what is needed to sign you in and to take a payment: your Google account identity, and your Stripe customer record. We never see a card number.

Your screenshots and designs

The screenshots you drop in, the designs you build from them and the name you give your set are stored in your browser’s own IndexedDB database, on the device you used. That local copy is the original and it is always written first, whether or not you are signed in.

On a Studio or Publisher plan they are also synced to our servers, so that your work survives a cleared browser and follows you to another device. That means the screenshots themselves are uploaded — to Google Cloud Storage, in a folder keyed to your account — along with the design, the captions, the set name and any translations. This happens automatically as you work, a moment after each change is saved locally. Only your own account can read them; the storage rules refuse everyone else.

Signed out, or on the free and Pro plans, nothing is uploaded.Your work stays in the browser exactly as it always has, and the same two consequences follow, which cut against us as much as for us: clearing your browser’s site data deletes it permanently and we cannot restore it, and it does not follow you to another device.

Screenshots are stored under a fingerprint of their own contents, which is how the same picture used on several slides is stored once. We do not look at them, they are not used to train anything, and they are not shared with anyone. Delete a project and its design is removed from our servers, along with every screenshot no other project of yours still uses — a picture shared by two projects survives until the last one goes.

You can delete everything yourself. Your account menu has a Delete account button: it cancels any subscription, removes every project and screenshot we hold for you, and deletes the account itself. It also clears the copy in this browser. There is nothing to email us about and no waiting period — press it and it is gone.

Signing in

Signing in is handled by Google, through Firebase Authentication. We receive the email address, display name and account identifier on that Google account. We do not receive your Google password and we cannot act on your Google account.

You only need an account in order to subscribe. Everything the free tier does works signed out.

Payments

Subscriptions are processed by Stripe. Card details are entered on Stripe’s own checkout pages and never reach StoreShots — we never see, receive or store a card number. Your email address is passed to Stripe so it can create your customer record and send receipts. Stripe’s own privacy notice governs what Stripe does with all of that.

On our side we store, against your account identifier, only: your Stripe customer id, the subscription’s status, the plan (“tier”) it grants, the price id, and when the current period ends. That is what tells the app what you have paid for. No name, no address, no card data.

AI features

Caption translation is on. When you pick languages and press Translate, the captions of that set — the text you typed, and nothing else — are sent to our server and on to OpenAI, which returns the translations. Your screenshots are not sent, your project name is not sent, and nothing is sent unless you press that button. We do not keep a copy of the captions on our side; the translations come back to your browser and are stored there with the rest of your work. OpenAI handles what it receives under its own API terms, which at the time of writing do not use API data to train their models.

AI image generation is on — backgrounds, icons and banners. When you press Generate, the words you typed are sent to our server and on to OpenAI, which returns an image. If you attach a reference picture, that picture is sent too, and only then: we never send a screenshot you did not attach, and nothing is generated in the background or without you pressing the button. OpenAI handles what it receives under its own API terms, which at the time of writing do not use API data to train their models.

Generations are kept, until you remove them. An image takes minutes rather than seconds to make, so the work happens on our server and not in your browser — which means we keep a record of it: the words you typed, when you asked, and the finished image, stored against your account in Google Cloud Storage. That record is what lets you close the app and come back to a picture that was not ready when you left, and it is listed in the generation panel where you made it. Remove one there and both the record and the image are deleted. A reference picture you attach is stored only for as long as the generation runs and is deleted the moment it finishes, whether it succeeded or failed.

Analytics

There is no analytics product here. StoreShots records a handful of product events — a design applied, an export finished, an upgrade prompt shown, a crash caught — and writes them to your browser’s developer console and nowhere else. They are not sent to us and not sent to anyone. There are no advertising cookies, no third-party analytics scripts and no cross-site tracking. The one request StoreShots makes to a third party in normal use is for a font you have chosen yourself — see “Fonts” below.

The only browser storage StoreShots uses is the IndexedDB database holding your own designs, and the sign-in state Firebase Authentication keeps so you are not signed out on every visit.

Fonts

The typefaces StoreShots ships with are served from this site, like the rest of the app. If you choose a different typeface for a screenshot, that font is fetched from Google Fonts at the moment it is needed — which means your browser makes a request to fonts.googleapis.com and fonts.gstatic.com, and Google sees your IP address and which font was asked for. Nothing about your designs, your account or your screenshots is sent with it, and it happens only if you pick a font we do not ship. Google’s own privacy notice governs what Google does with that request.

Server logs

The app is hosted on Firebase, and its billing functions write log entries when you start a checkout, open the billing portal, or when Stripe notifies us of a change. Those entries contain your account identifier and Stripe’s own reference ids — deliberately not your email address, your name, or anything about your designs. Google records ordinary web-server request logs for the hosting itself, as any host does.

How long it is kept

Designs live in your browser until you delete them or clear your site data — that is entirely in your hands and needs nothing from us. Generated images and the record of each generation live against your account until you remove them from the generation panel, or until you delete your account, which removes them along with everything else. The account and subscription record lives in our database for as long as you have an account; ask us to delete it and we will. Stripe keeps its own billing records to its own schedule, which we do not control and cannot delete on your behalf.

Your rights, and how to use them

Email [email protected] to get a copy of the account data we hold, correct it, or have it deleted. Deleting the designs themselves does not need us at all: they are on your device, and clearing this site’s data removes them.

Depending on where you live you may have further rights over this data — for example under the UK/EU GDPR or the CCPA. Ask, and we will do what applies.

Changes to this policy

If what the app does changes, this page changes with it, and the date at the top moves. The version you are reading is the current one.

Who runs StoreShots

StoreShots is operated by [COMPANY LEGAL NAME], [REGISTERED ADDRESS]. Questions about this notice, or anything above, go to [email protected].