Privacy Policy
Effective Date: January 12, 2026
Last Updated: January 12, 2026
Your Privacy Matters: One Shotr is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI prompt engineering platform. Please read this policy carefully to understand our practices regarding your personal data.
Table of Contents
- Information We Collect
- How We Use Your Information
- Data Sharing and Third Parties
- Cookies and Tracking Technologies
- Data Security
- Data Retention
- Your Rights and Choices
- International Data Transfers
- Children's Privacy
- California Privacy Rights (CCPA)
- European Privacy Rights (GDPR)
- Changes to This Policy
- Contact Us
1. Information We Collect
We collect several types of information to provide and improve our Service. The information we collect falls into the following categories:
1.1 Information You Provide Directly
Account Information
- Registration data: Name, email address, password, and optional profile information
- Billing information: For paid subscriptions, we collect payment card information, billing address, and transaction history (note: full payment card details are processed and stored by our third-party payment processor, not by us)
- Profile preferences: Language settings, notification preferences, and platform preferences
User Content
- Input prompts: The rough ideas, draft prompts, and text you enter for optimization
- Generated prompts: The optimized prompts our system creates based on your inputs
- Saved prompts: Prompts you choose to save to your account for future use
- Feedback: Any feedback, ratings, or comments you provide about our Service
Communications
- Support requests: Information you provide when contacting customer support
- Survey responses: Information you provide in response to surveys or questionnaires
- Email communications: Records of our email correspondence with you
1.2 Information Collected Automatically
Usage Data
- Service usage: Features used, prompts generated, platforms selected, and interaction patterns
- Session information: Session duration, pages visited, actions taken within the Service
- Performance data: Load times, errors encountered, and system performance metrics
Device and Technical Information
- Device identifiers: Device type, unique device identifiers, operating system, and browser type
- Network information: IP address, Internet service provider, and general location (city/country level)
- Browser data: Browser version, language settings, and screen resolution
Analytics Data
- Traffic sources: How you found our Service (search engines, referral links, etc.)
- Engagement metrics: Click-through rates, conversion events, and feature adoption
- Aggregate statistics: General usage patterns and trends across our user base
1.3 Information from Third Parties
We may receive information about you from third-party sources, including:
- Social login providers: If you choose to sign up or log in using a social account (such as Google), we receive your profile information from that provider
- Payment processors: Transaction confirmation and fraud prevention data
- Analytics partners: Aggregated insights about user behavior and demographics
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Providing and Improving the Service
- Process your input prompts and generate optimized outputs
- Create and manage your user account
- Process payments and manage subscriptions
- Provide customer support and respond to inquiries
- Improve and optimize our prompt generation algorithms
- Develop new features and services
- Personalize your experience based on your preferences and usage patterns
2.2 Communications
- Send transactional emails (account confirmations, password resets, payment receipts)
- Provide service-related announcements and updates
- Send marketing communications (with your consent, where required)
- Request feedback and conduct surveys
2.3 Security and Compliance
- Detect, prevent, and investigate fraud and abuse
- Protect the security and integrity of our Service
- Enforce our Terms of Service and policies
- Comply with legal obligations and regulatory requirements
2.4 Analytics and Research
- Analyze usage patterns to improve the Service
- Conduct research on AI prompt engineering effectiveness
- Generate aggregated, anonymized insights and statistics
- Test new features and conduct A/B testing
2.5 Legal Bases for Processing (GDPR)
For users in the European Economic Area (EEA), we process your data based on the following legal grounds:
- Contract performance: Processing necessary to provide the Service you requested
- Legitimate interests: Processing for our legitimate business interests (improving services, preventing fraud, marketing)
- Consent: Processing based on your explicit consent (marketing communications, certain cookies)
- Legal obligation: Processing required by applicable law
3. Data Sharing and Third Parties
We do not sell your personal information. We may share your information in the following circumstances:
3.1 Service Providers
We work with third-party companies that help us operate and improve our Service. These providers have access to your information only to perform services on our behalf and are obligated to protect your data:
- Cloud hosting: Infrastructure and data storage services
- Payment processing: Secure payment transaction handling
- Analytics: Usage analysis and reporting
- Email services: Transactional and marketing email delivery
- Customer support: Help desk and support ticket management
3.2 AI Service Providers
To provide our prompt optimization service, we may use third-party AI services. When processing your prompts:
- Your input data may be sent to AI service providers to generate optimized outputs
- We select AI partners with strong privacy practices and data protection commitments
- We do not share personal account information with AI providers
3.3 Legal Requirements
We may disclose your information when required to do so by law, or when we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation or court order
- Protect and defend our rights or property
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of users or the public
- Protect against legal liability
3.4 Business Transfers
If One Shotr is involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website of any change in ownership or uses of your personal information.
3.5 With Your Consent
We may share your information for any other purpose with your explicit consent.
5. Data Security
We take the security of your personal information seriously and implement appropriate technical and organizational measures to protect it.
5.1 Security Measures
- Encryption: All data transmitted between your browser and our servers is encrypted using TLS/SSL
- Data encryption at rest: Sensitive data is encrypted when stored
- Access controls: Strict access controls limit who can access your data
- Regular audits: We conduct regular security assessments and vulnerability testing
- Secure infrastructure: We use reputable cloud providers with industry-standard security certifications
- Employee training: Our team receives regular training on data protection best practices
5.2 Password Security
Your account password is hashed using industry-standard algorithms. We never store your password in plain text and cannot retrieve it. If you forget your password, you must reset it.
5.3 Data Breach Response
In the event of a data breach that affects your personal information, we will:
- Notify affected users within 72 hours of discovery
- Report to relevant supervisory authorities as required by law
- Take immediate steps to secure our systems
- Provide information about steps you can take to protect yourself
Important: While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
6. Data Retention
We retain your information for as long as necessary to provide our Service and fulfill the purposes described in this Privacy Policy.
6.1 Retention Periods
- Account information: Retained while your account is active and for up to 30 days after deletion request
- User-generated prompts: Retained while your account is active; deleted upon account deletion
- Payment records: Retained for 7 years for tax and accounting purposes
- Usage logs: Generally retained for up to 2 years
- Support communications: Retained for up to 3 years
- Marketing preferences: Retained until you withdraw consent
6.2 Anonymized Data
We may retain anonymized, aggregated data indefinitely for analytics, research, and service improvement purposes. This data cannot be used to identify you.
6.3 Legal Requirements
We may retain certain information longer if required by law or if necessary to protect our legal rights or comply with legal obligations.
7. Your Rights and Choices
You have certain rights regarding your personal information. These rights may vary depending on your location.
7.1 Access and Portability
You can request a copy of the personal information we hold about you. We will provide this information in a structured, commonly used, and machine-readable format upon request.
7.2 Correction
You can update your account information directly through your account settings. If you believe any information we hold about you is inaccurate, you can request correction.
7.3 Deletion
You can request deletion of your account and personal information. We will delete your data within 30 days of your request, except where we are required to retain it for legal purposes.
7.4 Restriction and Objection
You can request that we restrict processing of your data or object to processing based on legitimate interests.
7.5 Marketing Communications
You can opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in our emails
- Updating your preferences in account settings
- Contacting us at support@oneshotr.com
7.6 How to Exercise Your Rights
To exercise any of these rights, please contact us at support@oneshotr.com. We will respond to your request within 30 days. We may need to verify your identity before processing certain requests.
8. International Data Transfers
One Shotr is based in the United States. If you access our Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our servers or service providers are located.
8.1 Transfer Mechanisms
When we transfer personal data outside the European Economic Area (EEA) or United Kingdom, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Binding Corporate Rules where applicable
- Adequacy decisions by relevant authorities
8.2 Data Protection Standards
Regardless of where your data is processed, we apply the same data protection standards as described in this Privacy Policy.
9. Children's Privacy
Our Service is not intended for children under 18 years of age.
We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at support@oneshotr.com. We will take steps to delete such information from our systems.
10. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
10.1 Your California Rights
- Right to Know: You can request information about the categories and specific pieces of personal information we've collected, the sources of that information, our business purposes for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You can request correction of inaccurate personal information.
- Right to Opt-Out: You can opt out of the "sale" or "sharing" of your personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
10.2 Categories of Information Collected
In the past 12 months, we have collected the following categories of personal information:
- Identifiers (name, email address, account ID)
- Commercial information (subscription history, transaction records)
- Internet activity (browsing history, usage data)
- Inferences (preferences, characteristics)
10.3 We Do Not Sell Your Personal Information
We do not sell your personal information as defined by the CCPA. We may share information with service providers who assist in operating our Service, but this is not considered a "sale" under California law.
10.4 Exercising Your Rights
To exercise your California privacy rights, please contact us at support@oneshotr.com. We will verify your identity before processing your request. You may designate an authorized agent to make a request on your behalf.
11. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR).
11.1 Your GDPR Rights
- Right of Access: Obtain confirmation of whether we process your data and access to that data
- Right to Rectification: Correct inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data in certain circumstances
- Right to Restriction: Request limitation of processing in certain circumstances
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
11.2 Data Controller
One Shotr is the data controller for personal information collected through our Service. For questions about our data practices, contact us at support@oneshotr.com.
11.3 Right to Lodge a Complaint
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first so we can address your concerns.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make changes:
- We will update the "Last Updated" date at the top of this page
- For material changes, we will provide notice through the Service or via email
- We encourage you to review this Privacy Policy periodically
Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
For privacy-specific inquiries, please include "Privacy Request" in your email subject line to help us route your inquiry appropriately.
We aim to respond to all privacy-related requests within 30 days.