Privacy Policy
Last Updated: July 14, 2026
1. Data Controller
ShotMe.ee is operated by LihtneAI OÜ. Contact: oleg@lihtneai.ee.
2. Data We Process
- Uploaded photos: processed to create the result. Original uploads are not intentionally retained after the request is completed.
- Email address: used to connect paid credits, gallery access, payments, support, and secure account recovery.
- Generated images: paid results may be stored so the account holder can access their private gallery.
- Voice recordings: sent for transcription when a paid user chooses voice corrections and not intentionally retained after processing.
- Payment information: processed by Stripe. ShotMe.ee does not store full card details.
- Security data: IP address, browser information, rate-limit counters, pseudonymous identifiers, and request logs used to prevent abuse and diagnose failures.
3. Cookies and Local Storage
ShotMe.ee uses a secure, HttpOnly session cookie to protect paid credits and private gallery access. A pseudonymous cookie and local browser counter are used to enforce the free-trial limit. Session records normally expire after 180 days; anonymous free-trial records normally expire after 365 days.
4. AI Processing
Photo and audio inputs are sent to Google Gemini API only when needed to provide generation or transcription. Payment requests are handled by Stripe. These providers may process data under their own security and data-processing terms.
5. Retention and Security
Original uploads and voice inputs are kept only for request processing. Paid generated images and account data are retained until deletion is requested or the service establishes a shorter retention period. Secrets are stored outside public files, account routes require a protected session, and service traffic is encrypted with HTTPS.
6. Your Rights
You may request access, correction, export, or deletion of your personal data. Email oleg@lihtneai.ee with the subject "Data Deletion Request". We may ask you to verify control of the account email before releasing or deleting private data.
7. International Transfers
Some infrastructure and AI providers may process data outside the EEA using GDPR-compatible safeguards, including standard contractual clauses where applicable.
8. Contact
For privacy or security questions, contact oleg@lihtneai.ee.