Privacy notice
Version 1.0. Last updated .
This notice explains what personal data Shotcup collects when you visit shotcup.dev, create an account or use the API, the MCP server and the SDK; why we use it; how long we keep it; who helps us process it; and the rights you have. We keep it short and specific to how the service actually works.
Who we are
Shotcup is a trading name of the operator below, based in the United Kingdom ("we", "us"). We are the controller of the personal data described here: we decide why and how it is used.

Need this in text (for example for a screen reader)? Email privacy@shotcup.dev.
For anything about your data, email privacy@shotcup.dev. For everything else, email support@shotcup.dev.
What we collect
- Your account: your email address and the user id of our sign-in provider, Clerk. Clerk also holds your sign-in methods and, if you sign in with an outside account such as GitHub or Google, the basic profile that service shares (such as your name and picture). We never see your password.
- Account settings: your plan, whether you opted into overage and your spend cap, and whether you objected to product analytics.
- API keys: a SHA-256 hash of each key, its name and its first characters. The key itself is shown to you once and never stored.
- What you run: the code and files you send, the output, the files your code writes (artifacts), timings and resource figures, and which surface and client a run came through (for example the REST API, or an MCP client by its self-reported name). Arguments and results of tool calls are kept only when you turn recording on for a key or a run. Your code and files may contain personal data; you decide what you send.
- Usage counters: how many runs you started and the compute time they used per minute, day and month, to apply your plan's allowance and, if you opt in, to record overage for billing.
- Abuse limits: counters of sign-ups, key creations and demo runs per network. We store a keyed hash of your network address, not the address itself.
- Product analytics about your account: events such as "run completed" or "key created", with your internal account id, plan, outcome, counts, sizes and durations. They never contain your email address, your network address, your location, or the content of your code, files, output or tool calls.
- Website measurement: anonymous counts of page views and landing-page demo use (see Cookies and your consent choice).
- Logs: our own logs hold ids, counts, sizes, durations and error classes, never your code, files, output or tool data. Our hosting provider's request logs record the network address, browser or client, time and path of each request for a short period.
- Payments (once paid plans are on sale): payments are handled by Stripe and its reseller Onelink, which collect your payment details, billing address and tax information themselves (see Payments). We receive your subscription status, plan, country and the references that link a payment to your account, never your full card details.
- Messages: what you write to us by email, including abuse and security reports, and our replies.
Why we use it and our legal bases
UK data protection law (and, for people in the European Economic Area, the EU GDPR) requires a legal basis for each use of personal data. Ours are:
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service: your account, sign-in, running your code, storing runs, files and artifacts, applying your plan's limits | Account, settings, API keys, what you run, usage counters | Contract: we need it to provide what you signed up for |
| Billing for paid plans and overage, and keeping accounting records | Account, settings, usage counters, subscription data from Stripe | Contract; legal obligation for the records tax law requires |
| Keeping the service secure and available, preventing fraud and abuse, enforcing the acceptable use policy | Abuse-limit counters, logs, account and run records, reports | Legitimate interests: protecting the service, our users and others |
| Understanding how the API and MCP server are used, to fix problems and improve the product | Product analytics about your account | Legitimate interests: improving the service. You can object at any time (see below) |
| Counting visits to our public pages and use of the landing-page demos | Anonymous page views and demo events | Consent where your region requires it; elsewhere legitimate interests, with an opt-out |
| Answering your messages and requests | Messages and the account they concern | Legitimate interests: helping you; contract where the message is about your account |
| Complying with the law: answering lawful requests, handling reports of illegal content, defending legal claims | Whatever the matter needs | Legal obligation; legitimate interests for legal claims |
We do not use your data for advertising, we do not sell it, and we do not share it for cross-context behavioural advertising. We do not use your code, files or output to train AI models. We make no decisions about you based solely on automated processing that have legal or similarly significant effects; automatic limits apply the same published rules to every account.
Your right to object to product analytics
You can object to product analytics about your account at any time, without giving a reason. Send PATCH /api/v1/me with { "analyticsOptOut": true } using your API key or a signed-in session, or email privacy@shotcup.dev. From then on no analytics event about your account is created or sent. GET /api/v1/me shows the current setting. Objecting does not affect the service.
How long we keep it
A run, its output, source, recorded tool calls and artifact links are kept for your plan's run history, fixed when the run starts, and then deleted:
- Free: 1 day
- Pro: 7 days
- Scale: 30 days
- Platform: 90 days
- Uploaded input files: 24 hours after upload, whether used or not.
- Saved sandboxes and their files: until you delete them or close your account.
- Your account, settings, API key hashes and usage counters: while your account is open. When you close it, we delete them within 30 days, apart from what we must keep by law.
- Abuse-limit counters: deleted when their window ends, at most 1 day.
- Product analytics events and website measurement: up to 12 months.
- Hosting request logs: a short period set by our hosting provider, then deleted.
- Billing records: as long as tax and accounting law requires, which in the UK is usually six years.
- Messages: as long as we need to deal with them, and up to two years afterwards.
- Accounts disabled for breaking the acceptable use policy: their records are kept as evidence for as long as the case and any legal claim need.
To close your account, email support@shotcup.dev from the address on the account. Deleted data can remain in our providers' backups for a limited time until they are overwritten.
Who processes data for us
These providers process personal data on our behalf, only on our instructions and under data processing terms with us:
| Provider | What for | Where |
|---|---|---|
| Vercel | Hosts the website, the API and the MCP server, and keeps short-lived request logs | Functions in Frankfurt, Germany; content delivery worldwide; Vercel Inc. is in the United States |
| Convex | Database and file storage: accounts, key hashes, runs, sources, files and artifacts | European Union (Ireland); Convex, Inc. is in the United States |
| Clerk | Sign-in, sign-up and sessions; holds your email address and sign-in methods | United States |
| Fly.io | Runs the sandbox machines that execute your code | Frankfurt, Germany; Fly.io, Inc. is in the United States |
| PostHog | Product analytics and service metrics, sent from our servers only | EU Cloud (Frankfurt, Germany); PostHog, Inc. is in the United States |
| Fastmail | Email: the messages you send to our addresses and our replies | EU data region (Netherlands), with a replica and backups in the United States; Fastmail is in Australia |
International transfers. Most of the data is stored in the European Union, but several of these providers are based in, or keep copies or support staff in, countries outside the UK and the European Economic Area, mainly the United States. Where personal data leaves the UK or the EEA, or can be accessed from outside them, we rely on the safeguards in each provider's data processing terms: the UK-US data bridge (the UK Extension to the EU-US Data Privacy Framework) where the provider is certified under it, or standard contractual clauses (the European Commission's clauses with the UK Addendum, or the UK International Data Transfer Agreement). You can ask privacy@shotcup.dev for more information about these safeguards.
Payments. Paid plans are sold through Stripe Managed Payments. For the payment itself, Onelink (Sold through Link, LLC, a Stripe company) and Stripe act as independent controllers under their own privacy policies (Stripe privacy policy), not as our processors.
We may also disclose personal data where the law requires it, to protect the rights and safety of others, or to a company that takes over the service (see the terms), which would continue to use it under this notice.
How we protect it
All traffic to Shotcup uses HTTPS. API keys are stored only as hashes and network addresses used for abuse limits only as keyed hashes. Your code runs in isolated sandboxes with strict limits, and access to production systems is limited to the people who run the service. If a personal data breach puts your rights at risk, we will tell the Information Commissioner's Office and, where the law requires, you. Report a security issue to security@shotcup.dev.
Your rights
You have the right to:
- get a copy of your personal data and information about how we use it (access);
- have inaccurate data corrected (rectification);
- have your data deleted (erasure);
- ask us to limit how we use it (restriction);
- receive the data you gave us in a machine-readable format (portability);
- object to processing based on our legitimate interests, including product analytics;
- withdraw consent at any time, where we rely on it.
Some rights depend on the legal basis and have exceptions. To use any of them, email privacy@shotcup.dev. It is free. We may ask you to confirm your identity, usually by writing from the email address on your account. We answer within one month, or tell you within that month if we need up to two more months for a complex request.
Residents of US states with privacy laws, such as California, have similar rights to know, correct and delete their data, and we honour them in the same way. We do not sell or share personal information as those laws define it.
Complaints
If you are unhappy with how we handle your data, please tell us first at privacy@shotcup.dev: we acknowledge complaints within 30 days and tell you what we will do.
You can also complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint or on 0303 123 1113. If you live in the European Economic Area or Switzerland, you can also complain to the data protection authority where you live or work.
Children
Shotcup is a tool for software developers and is not directed at children. You must be 18 or older to create an account, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, email privacy@shotcup.dev and we will delete it.
Changes to this notice
We update this notice when the service or the law changes. Each version has a number and a date at the top of this page. If a change materially affects how we use your data, we tell account holders by email or in the dashboard before it takes effect.
Contact
Privacy: privacy@shotcup.dev. Everything else: support@shotcup.dev. By post: to the operator at the address under Who we are.