ShadowTeck

Privacy Policy

Last updated: August 2026

This Privacy Policy explains what personal data ShadowTeck ("we", "us") collects when you use our AI video generation service, why we collect it, who we share it with, and the rights you have over it - including the rights EU/EEA and UK users have under the General Data Protection Regulation (GDPR).

Who we are

ShadowTeck is operated by VLAHOV TECH, obrt za usluge, vl. Franko Vlahov (a Croatian sole-proprietorship trade business registered in Croatia), VAT ID HR97659127676, personal identification number (OIB) 97659127676, which is the data controller for the personal data described in this policy, registered at Stjepana Radića 46, 22000 Šibenik, Croatia.

Information we collect

We collect the following categories of personal data:

  • Account data - email address, a hashed password (we never store or see your plaintext password), and, if you sign in with Google or Apple, the provider-issued identifier used to link that account.
  • Content you submit - text prompts, uploaded reference images (your personal asset library), and the videos and thumbnails generated for you.
  • Usage & billing data - your credit balance and transaction history, generation history (model used, settings, status, cost), subscription plan and status.
  • Payment data - handled entirely by Stripe; we receive only a customer/subscription reference, never your card number.
  • Communications - if you use the contact form (which doesn't require an account) or email us, we collect the name, email, and message you provide.
  • Technical data - your session cookie (needed to keep you signed in), and, on our two unauthenticated forms (contact, forgot password), your IP address and browser signals processed by Cloudflare Turnstile for bot protection.

How we use it, and on what legal basis

  • Performance of our contract with you - operating your account, generating and storing your videos, tracking and spending credits, processing subscription and top-up payments.
  • Legal obligation - keeping records Stripe or tax law require us to keep.
  • Legitimate interest - securing the service (fraud/abuse prevention, bot protection on public forms), responding to support requests, and improving reliability. Where we rely on legitimate interest, we've weighed it against your rights and it doesn't override them.
  • Consent - where we ask separately, such as the EU 14-day withdrawal-right waiver you confirm before subscription checkout, or analytics (see below) - nothing runs there until you accept the banner.

We don't sell your personal data, and we don't use it for third-party advertising.

Third parties we share data with

We use the following processors to run the service. Each receives only what it needs to do its job, under its own terms/DPA:

  • Stripe - payment processing, subscription and invoice management. Receives your email and payment details directly; we never see or store your card number.
  • kie.ai (running the Kling, Seedance, and other video models) - receives the prompt text and any reference image, video, or audio you submit for a generation, in order to produce the video.
  • Anthropic (Claude API) - receives your prompt text when you use the "improve my prompt" feature, to return a rewritten prompt.
  • Amazon Web Services (S3) - hosts your generated videos, thumbnails, and reference-image library. Generated files are re-uploaded here rather than left on the provider's servers, and the bucket is private - playback/download links are short-lived and signed.
  • Cloudflare - sends transactional email (verification, password reset, contact notifications) via Cloudflare Email Service, and verifies you're not a bot on public forms via Turnstile (processes your IP address and browser signals). See Cloudflare's privacy policy.
  • Google / Apple - only if you choose "Continue with Google/Apple", in which case that provider authenticates you and shares your verified email and account identifier with us.
  • PostHog (EU Cloud) - product analytics, only if you accept the analytics banner. See Analytics below for what it collects.
  • Our hosting provider - runs the application and database.

Where a processor is located outside the EU/EEA (e.g. in the US), transfers are covered by that provider's Standard Contractual Clauses or equivalent safeguard.

Analytics

We use PostHog (hosted in the EU) for product analytics - page views, feature usage, where in the product people get stuck or drop off, session recordings of how the app is used, and conversion rates for things like subscribing or buying credits. If you're signed in, these events are linked to your account so we can see the full journey (e.g. viewed pricing → subscribed), not just anonymous aggregate counts.

This only runs if you accept the analytics banner shown on your first visit - nothing is collected before that, and you can decline. We don't use it for advertising, and we don't share it with ad networks or data brokers.

The banner covers activity in your browser. Some product usage is also recorded server-side - for example, activity through our API - since there's no browser for a banner to appear in there. This is tied to your account the same way, still PostHog, still never shared for advertising, and never includes the content of your prompts or generations.

Cookies

We use one essential cookie - your session token - needed to keep you signed in. It's httpOnly, secure, and can't be read by page scripts. If you accept the analytics banner, PostHog sets its own cookie to recognize you across visits; declining or ignoring the banner means it's never set. We don't use advertising or cross-site tracking cookies. Turnstile (above) may set its own cookie when active on the contact or forgot-password forms.

Data retention

We retain your account data for as long as your account is active. Contact-form messages submitted without an account are kept only as long as needed to respond, then deleted on request. Deleting your account permanently removes your account record, credits and transaction history, generation history, and asset library. Some records (e.g. payment records Stripe or tax law require us to keep) may be retained for a limited period afterward as required by law.

Your rights

If you're in the EU/EEA or UK, GDPR gives you the right to access, correct, delete, restrict, or export (portability) your personal data, to object to processing based on our legitimate interest, and to withdraw consent at any time where we rely on it. You can exercise most of these yourself - view your account email and generation/credit history from your account menu, and delete your account and all associated data from Account settings. For anything else, or if you contacted us without an account, email support@shadowteck.com. You also have the right to lodge a complaint with your local data protection supervisory authority.

Children

ShadowTeck isn't directed at children and isn't intended for anyone under 16. We don't knowingly collect data from children; if you believe a child has created an account, contact us and we'll remove it.

Security

Passwords are hashed with argon2id and never stored in plaintext. Session tokens are hashed at rest - only their hash lives in our database, so a database leak alone can't be used to hijack a session. No method of transmission or storage is 100% secure, but we take reasonable technical and organizational measures to protect your data.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by an updated "Last updated" date above, and, where required, we'll notify you directly.

Contact

Questions about this policy, or want to exercise a data-protection right? Email support@shadowteck.com.

We'd like to use privacy-respecting product analytics to see how the app is used and improve it. See our Privacy Policy.