Privacy Notice
Last updated: May 2026
ShotText is operated by Northern Story ("Northern Story", "we", "us"), based in Nunavut, Canada. Northern Story is the data controller for the personal data described below.
1. Data we collect
- Account data: email address, authentication identifiers (including Google sign-in), sign-in timestamps.
- Content data: screenshots and other images you upload, and the text, summaries, classifications, and tags derived from them.
- Usage data: requests, error logs, device and browser information, IP address, approximate location derived from IP.
- Billing data: handled by Paddle (see Section 3); we receive only your subscription status, plan, and partial payment metadata (e.g. last 4 digits, country) — never full card details.
- Support data: messages you send us and our replies.
2. How we use it (legal bases)
- To create your account and provide the Service — contract performance.
- To process screenshots through OCR and AI models on your behalf — contract performance.
- To secure the Service, prevent abuse, debug errors, and improve the product — legitimate interests.
- To send service emails (e.g. per-item summaries, account notices) — contract performance.
- To respond to support requests — legitimate interests.
- To comply with legal, tax, and accounting obligations — legal obligation.
3. Sharing
We share personal data with:
- Subprocessors that host the Service and run AI models (cloud hosting, OCR providers, large language model providers, email delivery providers).
- Paddle.com, our Merchant of Record for payments, subscription management, billing, tax compliance and invoicing. Paddle acts as an independent controller for billing data — see Paddle's Privacy Notice.
- Professional advisers (legal, accounting) where needed.
- Authorities where required by law or to protect our rights, users, or the public.
We do not sell your personal data and we do not use it to train third-party AI models.
4. International transfers
We are based in Canada and our subprocessors operate globally, including in the United States and the European Economic Area. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses or adequacy decisions) for transfers out of your region.
5. Retention
We keep account and content data for as long as your account is active. When you delete your account, we delete or anonymise the associated data within 30 days, except where retention is required by law (e.g. tax records kept by Paddle).
6. Your rights
Depending on where you live (including under Canadian PIPEDA, UK/EU GDPR, and US state privacy laws), you may have rights to access, correct, delete, restrict, port, or object to processing of your personal data, to withdraw consent, and to lodge a complaint with a supervisory authority (in Canada, the Office of the Privacy Commissioner). To exercise these rights, email info@northernstory.com. We will respond within 30 days.
7. Security
We use industry-standard technical and organisational measures, including encryption in transit (TLS), encryption at rest, access controls, and audit logging. No system is perfectly secure; please use a strong, unique password.
8. Cookies
We use essential cookies and local storage for authentication and session management. We do not use third-party advertising cookies. If we introduce analytics in future, we will update this notice and, where required, ask for your consent.
9. Children
ShotText is not directed at children under 13 (or under 16 in the EEA/UK) and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
10. Contact
Northern Story — info@northernstory.com.