Skip to main content

Privacy Policy

Version 2.0 · Effective 20 July 2026

This Policy explains how Shoodio processes personal data, including data used for asset and shoot compliance checks. It should be read with our Terms of Service and Ethical AI standards.

1. Controller and contact

The controller is Puristo GmbH, Waldbach 51, 4816 Gschwandt bei Gmunden, Austria, commercial register FN 346897v, Landesgericht Wels.

  • Privacy enquiries and data-subject requests: info@shoodio.ai
  • Safety and model-identity reports: safety@shoodio.ai
  • Austrian supervisory authority: Ă–sterreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria

2. Scope and roles

This Policy applies to the Shoodio website, account, Studio, Help Center, billing and compliance portal. For ordinary account and platform operations, Puristo GmbH is the controller. If an organisation uses Shoodio to process personal data on its own instructions, the contractual data-processing terms determine whether Shoodio acts as processor for that activity.

Shoodio model images may depict synthetic identities or identities supplied under contractual rights. An image that represents a real partner can be personal data even if the production process is generative. We therefore protect identity material regardless of the technical production method.

3. Data we process

Account and organisation data

  • email address, display name, language, profile settings and any profile image you upload;
  • password verifier, authentication identifiers, sessions and MFA status;
  • organisation, freelancer or business-verification details;
  • workspace membership, roles and audit events.

Production data

  • uploaded product, apparel, accessory and location images;
  • prompts, product metadata, canvas configuration and selected model, pose or action;
  • generated images and videos, thumbnails, file hashes and provenance;
  • support communications and feedback.

Compliance and safety data

  • asset category, visible-text/OCR facts and policy reason codes;
  • platform, adult-only, product-only and under-18 eligibility;
  • location viability, perspective, lighting and scene-safety facts;
  • shoot manifests, compliance decisions, policy versions and confidence status;
  • strikes, Security Holds, appeals, user statements, admin revisions and report evidence.

We classify submitted content and requested use. We do not infer or store a user’s political opinion, religious belief or other special-category trait merely because an uploaded item contains a slogan or symbol.

Billing and technical data

  • plan, credit balance, transaction references, invoices and tax information received from the merchant of record;
  • IP address, device/browser information, timestamps, security events, error logs, request IDs and service performance;
  • cookie consent and language preference.

We do not receive or store full payment-card details.

4. Purposes and legal bases

PurposeMain legal basis
Account, workspace, generation and customer supportPerformance of contract, Art. 6(1)(b) GDPR
Asset and whole-shoot review needed to provide a protected production servicePerformance of contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f)
Model-identity, platform and fraud protectionLegitimate interests in preventing abuse and securing partners, Art. 6(1)(f)
Security Hold, evidence preservation and legal noticesLegitimate interests; legal obligation where applicable, Art. 6(1)(c) and (f)
Billing, tax and accountingPerformance of contract and legal obligation, Art. 6(1)(b) and (c)
Essential service messagesPerformance of contract or legitimate interests
Optional marketingConsent, Art. 6(1)(a)
Aggregated performance and cost analysisLegitimate interests in operating and improving the service

Where we rely on legitimate interests, we balance platform, brand and model protection against the user’s rights. You may object as described below. Consent can be withdrawn at any time without affecting earlier lawful processing.

5. How automated compliance review works

The system evaluates an uploaded asset and, at Shoot, the exact intended context. It may use the image, visible text, asset metadata, model age category, selected pose/action, location and final prompt. Deterministic policy rules and visual-language analysis produce approval, product-only, adult-only or rejection. The decision is bound to the exact file and context.

The expected consequences are a blocked upload or shoot, a usage restriction, a T2 strike, or—in narrowly defined zero-tolerance cases—an immediate Security Hold pending authorised review. An uncertain automated result by itself does not create a serious strike or permanent ban.

Eligible asset restrictions can receive an Enhanced Review using the unchanged asset and the user’s statement. Security Holds, account terminations and similarly significant access decisions have a free human correction route. You can express your view, contest the result and obtain an authorised review. We provide meaningful reasons while withholding detection details that would undermine security.

We do not automatically inspect every resulting image or video after an approved generation. The customer reviews final outputs before publication.

6. Recipients and processors

We disclose data only as necessary to:

  • cloud database, authentication and hosting providers;
  • encrypted media storage and content-delivery providers;
  • image/video generation, asset-processing and compliance-analysis providers;
  • payment and merchant-of-record services;
  • transactional email, customer support and security-monitoring services;
  • professional advisers, authorities or courts where legally required;
  • a successor in a merger, financing or sale subject to appropriate confidentiality.

Generation and analysis providers receive only the assets, prompts and parameters needed for the requested operation. Cost records contain identifiers and amounts, not prompt, OCR or image content. We do not sell personal data.

We do not use customer uploads, prompts or outputs to train general-purpose AI models, and we configure contracted processors not to use service data for their own model training where the service permits such controls.

7. International transfers

We prefer European processing where commercially and technically available. Some processors may operate in the United Kingdom, United States or other countries. Transfers outside the EEA rely on an adequacy decision, approved Standard Contractual Clauses and, where appropriate, supplementary technical and organisational safeguards. Contact us for relevant transfer information or a copy of applicable safeguards, subject to redaction of confidential security terms.

8. Retention

We keep data only as long as necessary for the stated purpose:

DataStandard period
Account and workspace dataWhile the account is active, then deletion/recovery workflow subject to legal duties
Profile images uploaded before mandatory reviewRemoved from profile display; the prior storage pointer remains in a restricted audit record until reviewed, replaced or deleted with the account. The source file can remain at its existing storage address during that period.
Normal uploads and generated contentAccording to the selected plan or earlier user deletion
Raw T1/T2 rejected uploadEncrypted and private for 14 days; if Enhanced Review approves an exact recommit, only for that 14-day recommit window (no more than 21 days from the original review)
Raw T3 evidenceNormally 6 months, longer only for a legal hold, investigation or legal claim
Structured compliance cases, decisions and appeal statementsUp to 24 months
Active T2 strike12 months; limited event history may remain within the 24-month compliance record
Authentication and security logsNormally up to 90 days, longer for an active incident
Support and model-misuse reportsNormally up to 24 months
Billing, tax and accounting recordsStatutory period, generally 7 years in Austria and longer where law requires

Hash-based records may be retained without the underlying image where needed to prevent repeated evasion. Deletion from active systems may be followed by limited encrypted backup retention until routine overwrite.

9. Cookies and local storage

Essential technologies keep you signed in, protect sessions, store language and consent choices, prevent fraud and remember the Landing theme. Optional analytics or marketing technologies are used only under the consent settings shown to you. Payment checkout may set essential anti-fraud cookies. You can change non-essential choices through Cookie Settings; browser blocking of essential cookies may prevent sign-in or payment.

10. Security and access controls

We use encryption in transit, encryption at rest where supported, row-level data controls, least-privilege service roles, short-lived signed media access, MFA for sensitive capabilities, append-only compliance history, audit logs, rate limits and incident procedures. Sensitive rejected assets are separated from the normal library. No security method guarantees absolute protection.

Admin access to compliance evidence is restricted by role and, for sensitive actions, MFA. Admin decisions and revisions are logged. Dangerous previews are not loaded into general-purpose lists.

11. Your rights

Subject to the GDPR and applicable exceptions, you can request:

  • access to and a copy of your personal data;
  • correction of inaccurate data;
  • deletion or restriction of processing;
  • portability of data you provided where applicable;
  • objection to processing based on legitimate interests;
  • withdrawal of consent;
  • information about and human intervention in a qualifying automated decision.

Use account export/deletion tools or email info@shoodio.ai. We may verify identity and authority before responding. We normally respond within one month. You may complain to the Austrian Data Protection Authority or the authority where you live or work.

These privacy rights are separate from the paid Enhanced Review of an asset. Exercising a GDPR right or contesting a significant account restriction through the human channel does not cost a credit.

12. Children and under-18 model productions

The service is not offered to account holders under 16 and we do not knowingly collect their account data. Under-18 model identities in the catalog are production assets subject to enhanced protection; they do not mean the account holder is a child. If you believe a child has submitted personal data, contact us for prompt investigation.

13. Legal notices and safety reports

When you report misuse, we process your contact details, the reported URL or files, statement and evidence to investigate and communicate the outcome. We may disclose necessary details to the affected rights holder, service provider or authority, but avoid revealing the reporter where law and fair process permit. Do not include unrelated personal data.

14. Changes

The version and effective date are shown above. We will give reasonable notice of material changes where possible. Material changes to contractual compliance processing may require renewed acceptance before Studio use; legal information, export, deletion and logout remain available.

Questions or requests: info@shoodio.ai · Safety reports: safety@shoodio.ai