Skip to content
Shotcup

Privacy notice

Version 1.0. Last updated .

This notice explains what personal data Shotcup collects when you visit shotcup.dev, create an account or use the API, the MCP server and the SDK; why we use it; how long we keep it; who helps us process it; and the rights you have. We keep it short and specific to how the service actually works.

Who we are

Shotcup is a trading name of the operator below, based in the United Kingdom ("we", "us"). We are the controller of the personal data described here: we decide why and how it is used.

Operator name and postal address, shown as an image

Need this in text (for example for a screen reader)? Email privacy@shotcup.dev.

For anything about your data, email privacy@shotcup.dev. For everything else, email support@shotcup.dev.

What we collect

  • Your account: your email address and the user id of our sign-in provider, Clerk. Clerk also holds your sign-in methods and, if you sign in with an outside account such as GitHub or Google, the basic profile that service shares (such as your name and picture). We never see your password.
  • Account settings: your plan, whether you opted into overage and your spend cap, and whether you objected to product analytics.
  • API keys: a SHA-256 hash of each key, its name and its first characters. The key itself is shown to you once and never stored.
  • What you run: the code and files you send, the output, the files your code writes (artifacts), timings and resource figures, and which surface and client a run came through (for example the REST API, or an MCP client by its self-reported name). Arguments and results of tool calls are kept only when you turn recording on for a key or a run. Your code and files may contain personal data; you decide what you send.
  • Usage counters: how many runs you started and the compute time they used per minute, day and month, to apply your plan's allowance and, if you opt in, to record overage for billing.
  • Abuse limits: counters of sign-ups, key creations and demo runs per network. We store a keyed hash of your network address, not the address itself.
  • Product analytics about your account: events such as "run completed" or "key created", with your internal account id, plan, outcome, counts, sizes and durations. They never contain your email address, your network address, your location, or the content of your code, files, output or tool calls.
  • Website measurement: anonymous counts of page views and landing-page demo use (see Cookies and your consent choice).
  • Logs: our own logs hold ids, counts, sizes, durations and error classes, never your code, files, output or tool data. Our hosting provider's request logs record the network address, browser or client, time and path of each request for a short period.
  • Payments (once paid plans are on sale): payments are handled by Stripe and its reseller Onelink, which collect your payment details, billing address and tax information themselves (see Payments). We receive your subscription status, plan, country and the references that link a payment to your account, never your full card details.
  • Messages: what you write to us by email, including abuse and security reports, and our replies.

Why we use it and our legal bases

UK data protection law (and, for people in the European Economic Area, the EU GDPR) requires a legal basis for each use of personal data. Ours are:

Purposes of processing and their legal bases
PurposeDataLegal basis
Providing the service: your account, sign-in, running your code, storing runs, files and artifacts, applying your plan's limitsAccount, settings, API keys, what you run, usage countersContract: we need it to provide what you signed up for
Billing for paid plans and overage, and keeping accounting recordsAccount, settings, usage counters, subscription data from StripeContract; legal obligation for the records tax law requires
Keeping the service secure and available, preventing fraud and abuse, enforcing the acceptable use policyAbuse-limit counters, logs, account and run records, reportsLegitimate interests: protecting the service, our users and others
Understanding how the API and MCP server are used, to fix problems and improve the productProduct analytics about your accountLegitimate interests: improving the service. You can object at any time (see below)
Counting visits to our public pages and use of the landing-page demosAnonymous page views and demo eventsConsent where your region requires it; elsewhere legitimate interests, with an opt-out
Answering your messages and requestsMessages and the account they concernLegitimate interests: helping you; contract where the message is about your account
Complying with the law: answering lawful requests, handling reports of illegal content, defending legal claimsWhatever the matter needsLegal obligation; legitimate interests for legal claims

We do not use your data for advertising, we do not sell it, and we do not share it for cross-context behavioural advertising. We do not use your code, files or output to train AI models. We make no decisions about you based solely on automated processing that have legal or similarly significant effects; automatic limits apply the same published rules to every account.

Your right to object to product analytics

You can object to product analytics about your account at any time, without giving a reason. Send PATCH /api/v1/me with { "analyticsOptOut": true } using your API key or a signed-in session, or email privacy@shotcup.dev. From then on no analytics event about your account is created or sent. GET /api/v1/me shows the current setting. Objecting does not affect the service.

How long we keep it

A run, its output, source, recorded tool calls and artifact links are kept for your plan's run history, fixed when the run starts, and then deleted:

  • Free: 1 day
  • Pro: 7 days
  • Scale: 30 days
  • Platform: 90 days
  • Uploaded input files: 24 hours after upload, whether used or not.
  • Saved sandboxes and their files: until you delete them or close your account.
  • Your account, settings, API key hashes and usage counters: while your account is open. When you close it, we delete them within 30 days, apart from what we must keep by law.
  • Abuse-limit counters: deleted when their window ends, at most 1 day.
  • Product analytics events and website measurement: up to 12 months.
  • Hosting request logs: a short period set by our hosting provider, then deleted.
  • Billing records: as long as tax and accounting law requires, which in the UK is usually six years.
  • Messages: as long as we need to deal with them, and up to two years afterwards.
  • Accounts disabled for breaking the acceptable use policy: their records are kept as evidence for as long as the case and any legal claim need.

To close your account, email support@shotcup.dev from the address on the account. Deleted data can remain in our providers' backups for a limited time until they are overwritten.

Who processes data for us

These providers process personal data on our behalf, only on our instructions and under data processing terms with us:

Providers that process personal data for Shotcup
ProviderWhat forWhere
VercelHosts the website, the API and the MCP server, and keeps short-lived request logsFunctions in Frankfurt, Germany; content delivery worldwide; Vercel Inc. is in the United States
ConvexDatabase and file storage: accounts, key hashes, runs, sources, files and artifactsEuropean Union (Ireland); Convex, Inc. is in the United States
ClerkSign-in, sign-up and sessions; holds your email address and sign-in methodsUnited States
Fly.ioRuns the sandbox machines that execute your codeFrankfurt, Germany; Fly.io, Inc. is in the United States
PostHogProduct analytics and service metrics, sent from our servers onlyEU Cloud (Frankfurt, Germany); PostHog, Inc. is in the United States
FastmailEmail: the messages you send to our addresses and our repliesEU data region (Netherlands), with a replica and backups in the United States; Fastmail is in Australia

International transfers. Most of the data is stored in the European Union, but several of these providers are based in, or keep copies or support staff in, countries outside the UK and the European Economic Area, mainly the United States. Where personal data leaves the UK or the EEA, or can be accessed from outside them, we rely on the safeguards in each provider's data processing terms: the UK-US data bridge (the UK Extension to the EU-US Data Privacy Framework) where the provider is certified under it, or standard contractual clauses (the European Commission's clauses with the UK Addendum, or the UK International Data Transfer Agreement). You can ask privacy@shotcup.dev for more information about these safeguards.

Payments. Paid plans are sold through Stripe Managed Payments. For the payment itself, Onelink (Sold through Link, LLC, a Stripe company) and Stripe act as independent controllers under their own privacy policies (Stripe privacy policy), not as our processors.

We may also disclose personal data where the law requires it, to protect the rights and safety of others, or to a company that takes over the service (see the terms), which would continue to use it under this notice.

Cookies and your consent choice

Whether you see a banner depends on where you visit from, as your network's country tells us (we use the country our hosting provider reports and no other location service). In the European Economic Area, the United Kingdom, Switzerland and Quebec, and whenever we cannot tell, a banner asks on your first visit whether we may measure your visit; Reject and Accept are equal choices, and Preferences lets you decide per category. There, measurement is based on your consent. Elsewhere, including the United States, there is no banner: measurement is on until you switch it off, and a Global Privacy Control signal from your browser switches it off. There are two categories:

  • Strictly necessary (always on): the sign-in cookies Clerk sets on the account pages (sign-in, sign-up and the dashboard) to keep you signed in, and the c15t cookie that stores your consent choice.
  • Measurement (where a banner shows, off unless you allow it): our servers count anonymous page views and use of the landing page's demos and send these counts to our analytics provider, PostHog (EU project). A page view records which page, the host of the site that linked to it, the browser family and the country; a demo event records which demo and its outcome. These events carry no name, email, account or address and get a new random identifier each time; nothing for measurement is stored on or read from your device apart from your choice. Where a banner shows, no such event is sent without your consent; elsewhere none is sent once you have switched measurement off. Page views by known search-engine and other crawlers, which are programs rather than people, are counted without asking.

Your choice is stored in the c15t cookie and in your browser's local storage on shotcup.dev for up to a year, together with the time of the choice and a random identifier the consent tool creates. It stays in your browser: we keep no copy of it on our servers. You can change or withdraw it at any time with Cookie settings at the bottom of every page; withdrawing works for every later visit and does not affect what was measured before. There are no advertising cookies and no tracking scripts. The domain that serves run artifacts (shotcup.page) shows no banner and sets no cookies at all.

Events about how an account uses the API and the MCP server are not covered by the banner: they are product analytics under our legitimate interests, which you can object to as described above.

How we protect it

All traffic to Shotcup uses HTTPS. API keys are stored only as hashes and network addresses used for abuse limits only as keyed hashes. Your code runs in isolated sandboxes with strict limits, and access to production systems is limited to the people who run the service. If a personal data breach puts your rights at risk, we will tell the Information Commissioner's Office and, where the law requires, you. Report a security issue to security@shotcup.dev.

Your rights

You have the right to:

  • get a copy of your personal data and information about how we use it (access);
  • have inaccurate data corrected (rectification);
  • have your data deleted (erasure);
  • ask us to limit how we use it (restriction);
  • receive the data you gave us in a machine-readable format (portability);
  • object to processing based on our legitimate interests, including product analytics;
  • withdraw consent at any time, where we rely on it.

Some rights depend on the legal basis and have exceptions. To use any of them, email privacy@shotcup.dev. It is free. We may ask you to confirm your identity, usually by writing from the email address on your account. We answer within one month, or tell you within that month if we need up to two more months for a complex request.

Residents of US states with privacy laws, such as California, have similar rights to know, correct and delete their data, and we honour them in the same way. We do not sell or share personal information as those laws define it.

Complaints

If you are unhappy with how we handle your data, please tell us first at privacy@shotcup.dev: we acknowledge complaints within 30 days and tell you what we will do.

You can also complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint or on 0303 123 1113. If you live in the European Economic Area or Switzerland, you can also complain to the data protection authority where you live or work.

Children

Shotcup is a tool for software developers and is not directed at children. You must be 18 or older to create an account, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, email privacy@shotcup.dev and we will delete it.

Changes to this notice

We update this notice when the service or the law changes. Each version has a number and a date at the top of this page. If a change materially affects how we use your data, we tell account holders by email or in the dashboard before it takes effect.

Contact

Privacy: privacy@shotcup.dev. Everything else: support@shotcup.dev. By post: to the operator at the address under Who we are.