ShowShot

Privacy Policy

Last updated: August 28, 2026

ShowShot is a product of Workado LLC. It records your screen and camera, edits what you recorded, and hosts a watch page for the people you send it to. This policy explains exactly what we hold, where it sits, and what leaves your machine. In this policy, "we" and "us" mean Workado LLC. Questions go to [email protected].

The short version. Recording and editing run inside your browser, and your footage is not uploaded until you publish a share link. Transcription is the one exception: when you are signed in, the audio of a take is sent to Google's Gemini speech models to be transcribed, then discarded. We do not sell your data, we run no advertising trackers, and we do not train models on your recordings.

1. What we collect

Information you give us

Information we collect automatically

2. What never leaves your device

ShowShot is built so the heavy work happens locally:

A recording leaves your device only when you publish a share, upload a file, or use a feature that needs a cloud model.

3. Where published videos are stored

Publishing writes your video, its poster image, and a small manifest into object storage on Cloudflare under a slug that belongs to that share. Comments, reactions, view events, and notification email addresses are stored separately in our database, not in the public storage bucket.

4. What we send to AI providers

Each AI feature calls one provider, and only the input that feature needs. Nothing is sent in the background and no feature runs unless you start it.

FeatureProviderWhat is sent
AI editor, scripts, transcript cleanupOpenRouterYour prompt and the project text it needs, such as the transcript or scene list
Transcription and speaker labelsGoogle (Gemini)The audio track of the take being transcribed, for the duration of the request
Privacy check, vision snapOpenRouterSingle still frames sampled from your timeline
Voice generation and voice cloningElevenLabsThe text to speak, and for a clone the audio samples of the voice being cloned
Avatar videoHeyGenYour footage or photo for the avatar, the script, and the consent record HeyGen requires
AI video generationKIE.aiYour prompt and any source clip or image you attach
Transactional emailResendRecipient address and message content
Hosting, storage, databaseCloudflarePublished files, account records, comments, analytics
PaymentsStripeCard details are entered on Stripe's own checkout page and never reach us; we keep the amount, the currency and the receipt id
Referral payoutsPayPalOnly if you ask for a payout: the PayPal address you give us, and the amount

Content is sent for the duration of the request and for that request only. We do not use your recordings, transcripts, or uploads to train models, ours or anyone else's. Providers process the request under their own terms, so review theirs if a feature matters to your compliance position.

Your own key versus our managed key

Two modes are possible, and they route your data differently:

5. Voice cloning, avatars, and consent

Both features are gated on a consent step, and the person whose voice or face is being used has to be the one who gives it.

6. Viewers, comments, and lead data

When you send someone a watch page, we handle their data on your behalf. In data protection terms you are the controller of that viewer data and we are your processor. We use it to run the watch page and to report engagement back to you, never for our own marketing.

7. Data we ask you not to send

ShowShot is a general product and is not built for regulated categories. Please do not record or upload protected health information, payment card data, government identifiers, children's records, or anything else covered by HIPAA, PCI DSS, GLBA, FERPA, or COPPA. The privacy check tool can help you blur what slipped into frame, but it is an assistant and not a guarantee: review every video before you publish it.

8. How we use your information

9. Keeping and deleting data

10. Your rights

You can change your account details in Settings, delete any share at any time, and ask for a copy of your data or its deletion at [email protected]. Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to your local regulator. We answer requests within 30 days.

11. Google user data

The way ShowShot uses information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Your Google profile is used only to create and identify your ShowShot account. It is not transferred to others except as described here, is not used for advertising, and is not used to train models. You can disconnect ShowShot at any time from your Google account permissions page.

12. Security

Traffic is encrypted in transit, passwords are hashed, stored API keys are encrypted at rest and revealed only to their owner, and access to production systems is limited. No service can promise perfect security, so use a strong unique password and think before you publish.

13. Children

ShowShot is not intended for children under 13 and we do not knowingly collect their personal data. Write to us if you believe a child has given us data and we will remove it.

14. International transfers

Our providers operate globally, so your data may be processed outside your own country, including in the United States. We rely on the standard contractual protections those providers offer.

15. Changes

If we make a meaningful change we will update the date at the top of this page, and for significant changes we will tell you by email before they take effect.

16. Contact

Questions, requests, or complaints: [email protected]. ShowShot is operated by Workado LLC, Arizona, United States.