Legal
Privacy Policy
Last updated September 29, 2026 · Effective October 13, 2026
Skipshoot LLC ("Skipshoot LLC," "we," "us," or "our") provides AI-powered product visualization and room-scene tools for furniture and interior brands. This Privacy Policy explains how we collect, use, disclose, and protect information about you when you visit our website, create an account, or use our platform and related services (collectively, the "Service").
By accessing or using the Service you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service. This Privacy Policy is incorporated by reference into our Terms and Conditions.
1. Definitions
- Personal Information means any information that identifies or could reasonably be used to identify a natural person, directly or indirectly.
- Content means any text, images, photographs, product data, metadata, or other material you upload, submit, or otherwise make available through the Service.
- Generated Output means images, scene renders, visualizations, or other AI-generated material produced by the Service based on your Content and inputs.
- Sub-processor means a third-party service provider that processes Personal Information on our behalf to help us deliver the Service.
- Workspace means the shared environment within an account where team members collaborate on catalogs and scenes.
2. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information received from third parties.
2a. Information You Provide
- Account registration. When you create an account with a password we collect your name, email address, and a hashed password. When you sign up or sign in with Google or Microsoft, we receive your name and the email address that provider has verified, and nothing else: we never receive your password for that provider, and we keep no token from it. Whichever way you sign in, it is the same account.
- Profile and workspace data. Company name, role, workspace name, and any other details you add to your profile or workspace settings.
- Content you upload. Product images, room-scene photographs, catalog data, metadata, tags, and any other files or data you submit to the Service. This includes images processed through our AI visualization pipeline.
- Connected sources. If you connect Dropbox, Google Drive or Microsoft OneDrive to import product images, we store the account name that provider reports and a read-only access token, so that we can browse the drive at your direction and copy the files you choose. We copy only the files you pick. Disconnecting the source deletes the token.
- Payment information. We use a third-party payment processor (Stripe) to handle billing. We do not store your full card number on our servers; Stripe stores and processes payment data under its own privacy and security standards.
- Communications. Emails, support tickets, chat messages, and any other correspondence you send to us.
- Survey and feedback responses. Any information you voluntarily provide in response to surveys, user interviews, or product feedback requests.
- Sales enquiries and the catalog fit quiz. When you write to us through the form on our site, we keep your name, email address, company, what you are interested in, and your message, together with the IP address and browser the enquiry came from. If you take the catalog fit quiz, we save your answers as you go, under a random session identifier with no contact details, so an unfinished quiz tells us what was answered but not by whom; if you reach the last step and send your details, the answers and the plan the quiz recommended are kept with your enquiry. Our staff see enquiries on an internal page, may match them to an account by email address, and may export them to reply to you.
- Acceptance records. When you accept the Terms, the EULA and this Policy, or an in-product notice, we record which version you accepted, when, and the IP address and browser you used, as evidence of the agreement.
2b. Information Collected Automatically
- Log data. IP address, browser type and version, operating system, referring URL, pages visited, time and date of visit, and other standard server log information.
- Usage and event data. Feature interactions, clicks, button presses, scene renders initiated, catalog actions, and similar product-usage events.
- AI usage records. For every call the Service makes to an AI model we record which model ran, what the call was for, how long it took, the number of tokens the provider reported, and an estimated cost, against your Workspace, your user account and the render session. These records hold no images, prompts or outputs.
- Device information. Hardware model, screen resolution, operating system, and unique device identifiers where relevant.
- Cookies and similar technologies. Session cookies (required for authentication), preference cookies, analytics cookies, and your browser’s local storage for preferences. See Section 6 for full details.
2c. Information From Third Parties
- Authentication providers. If you sign in with Google or Microsoft, we receive your name and the email address that provider has verified. We do not receive a profile picture, a password, or any other part of that account.
- Payment processors. Stripe may share billing status, subscription tier, and fraud-signal information with us.
- Analytics partners. Aggregated or anonymized data from analytics tools that help us understand traffic sources and product usage.
3. How We Use Information
We use the information we collect for the following purposes:
- Providing the Service. Authenticating users, operating Workspaces, processing uploaded Content, generating room visualizations, and delivering all other features of the platform.
- Account management. Creating and managing accounts, processing subscription changes, and communicating transactional information such as invoices and password resets.
- AI processing pipeline. Your uploaded images and product data are passed through our AI models and third-party AI APIs solely to produce the Generated Outputs you request. We do not use your Content to train our models or third-party foundation models without your separate, explicit consent.
- Service improvement. Analyzing aggregate usage patterns, debugging errors, testing new features, and improving platform performance and reliability.
- Cost accounting. Using the AI usage records to measure what the Service costs to run, per render, per Workspace and per feature, and to check our providers’ bills.
- Customer support. Responding to inquiries, troubleshooting issues, and fulfilling requests.
- Security and fraud prevention. Detecting and preventing unauthorized access, abuse, and other potentially harmful activity.
- Legal compliance. Complying with applicable laws, regulations, legal processes, and enforceable governmental requests.
- Communications about the Service. Sending product updates, feature announcements, and important notices. You may opt out of non-essential communications at any time.
4. Legal Bases for Processing
Where applicable law requires a legal basis for processing Personal Information (e.g., under GDPR or similar frameworks), we rely on the following bases:
- Contract performance. Processing necessary to provide the Service you have subscribed to, including account management, Content processing, and billing.
- Legitimate interests. Processing necessary for our legitimate business interests, such as security, fraud prevention, product analytics, and service improvement, where those interests are not overridden by your rights.
- Legal obligation. Processing required to comply with applicable laws and regulations.
- Consent. Where we rely on your consent (e.g., optional marketing communications or use of non-essential cookies), you may withdraw consent at any time without affecting the lawfulness of prior processing.
5. How We Share Information
We do not sell, rent, or trade your Personal Information to third parties for their own marketing purposes. We may share information in the following circumstances:
- Sub-processors. We share data with trusted service providers who help us operate the Service (see Section 7 for a list). These providers are contractually bound to use data only as directed by us and to maintain appropriate security standards.
- Workspace members. When you operate within a shared Workspace, other members of that Workspace may see your name, profile information, uploaded Content, and Generated Outputs associated with the Workspace.
- Public share links. When a member of your Workspace shares a render by link, anyone with the link can view that image on a page carrying a “Made with Skip Shoot” line. The page shows no name, Workspace, or product data. Messaging and social platforms fetch the image to build link previews and may cache it. We do not record who views a shared link beyond our standard server logs. A share can be withdrawn at any time from the gallery, after which the link stops working; copies already fetched may persist briefly in caches.
- Our staff. Skipshoot LLC staff can access Workspaces to operate and support the Service, see sales enquiries and usage records, and, at a Workspace administrator’s request, issue a password reset link (Section 10).
- Business transfers. If Skipshoot LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Service prior to your information becoming subject to a different privacy policy.
- Legal requirements. We may disclose information when required by law, subpoena, court order, or other governmental authority, or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Skipshoot LLC, our users, or the public.
- With your consent. We may share information with third parties when you have given us explicit consent to do so.
- Aggregated or de-identified data. We may share aggregated or de-identified information that cannot reasonably be used to identify you for industry research, analytics, or marketing purposes.
6. Cookies and Analytics
We use cookies and similar tracking technologies to operate and improve the Service. A "cookie" is a small text file stored in your browser. We use the following categories:
- Strictly necessary cookies. Required for authentication, session management, and core Service functionality. These cannot be disabled without breaking the Service.
- Preference cookies. Store your settings and preferences (e.g., UI state) to personalize your experience.
- Analytics. We use Vercel Web Analytics and Speed Insights, which record page views and page performance without cookies and without identifying you across sites, and PostHog to collect usage events, page views, feature interactions, and session data. Analytics data is used exclusively to understand and improve the Service. When you are signed in, PostHog events may be associated with your account identifier to give us a complete view of your product journey.
- Local storage. We keep a few preferences in your browser’s local storage, such as which notices you have dismissed and which tab you last used. That data never leaves your browser.
You can control cookies through your browser settings. Disabling analytics cookies will not prevent you from using the Service, but it may limit our ability to improve the product based on usage patterns. For more information on PostHog’s data practices, see posthog.com/privacy.
7. Sub-processors
We work with the following categories of sub-processors to deliver the Service. Each is subject to data processing agreements and appropriate safeguards:
- Cloud infrastructure. Vercel hosts the Service, runs its render jobs, stores uploaded and generated images, and serves them; a managed PostgreSQL provider hosts the database.
- AI model providers. Google’s Gemini API analyses room and product images and generates renders; Replicate upscales finished renders. Your Content is transmitted to them solely to fulfil the request you initiate. What each may do with it under its own terms is set out in Section 8.
- Payment processing. Stripe, Inc. handles all payment card data. Stripe is PCI-DSS compliant. See stripe.com/privacy.
- Email delivery. Transactional and notification emails are sent through Resend.
- Analytics. Vercel Web Analytics and Speed Insights, and PostHog (see Section 6).
- Authentication. Google and Microsoft, only when you choose to sign in with them.
- Connected sources. Dropbox, Google Drive and Microsoft OneDrive, only when you connect one to import images, and only to read what you choose.
8. AI Processing and Your Content
- Purpose limitation. Images and product data you upload are processed by our AI pipeline exclusively to produce the room visualizations and Generated Outputs you request. We do not use your Content for any other purpose without your consent.
- No training on your data. We do not use your Content to train or fine-tune any AI model, and we do not hand it to a provider for that purpose. What a provider may do with it under its own terms is described below.
- Which Google tier your images go through. Generating a render — in Studio, Editorial and Dream Scenes — runs on the paid tier of Google’s Gemini API. Under Google’s terms for paid services, Google does not use prompts, images or outputs to improve its products, though it may log them to detect abuse and for legal reasons. The analysis steps before a render — finding the surfaces in a room photograph, locating a surface in a scene, and estimating a product’s size from its photograph — currently run on the unpaid tier. Under Google’s terms for unpaid services, Google may use what is submitted to improve its products and machine-learning technologies, and human reviewers may read it after it has been disconnected from our account. Those steps send the room or product photograph and no other data about you.
- Retention by providers. Content sent to a provider is sent to fulfil that request. Providers keep logs for the periods their own terms state, and removing something from the Service does not delete the copies they hold.
- Generated Output storage. Generated Outputs are stored in your account so you can access, download, and manage them. You may delete Generated Outputs at any time from within the Service.
9. Data Retention
- Account data. We retain your account information for as long as your account is active. If you close your account, we will delete or anonymize your Personal Information within 90 days unless we are required to retain it by law.
- Content and Generated Outputs. Uploaded Content and Generated Outputs are retained for as long as your account is active and for a reasonable period thereafter to allow for account recovery. Following account deletion, Content is purged from active storage within 90 days and from backups within 180 days.
- Billing records. Transaction and invoice records are retained for up to 7 years to comply with financial and tax record-keeping requirements.
- Log and analytics data. Server logs are retained for up to 90 days. Anonymized or aggregated analytics data may be retained indefinitely.
- AI usage records. Kept with our billing records, for up to 7 years, including after a Workspace or account is deleted, because they are the record of what the Service cost to run. They identify a Workspace and user by number only and hold no Content.
- Sales enquiries and quiz answers. Kept while we are in, or reasonably expect, a business relationship with you, and deleted on request.
- Acceptance records. Kept for as long as we may need to show that the agreement was made, which can be after the account is deleted.
- Share links. Kept until you withdraw them or delete the render they show, whichever is first.
- Legal holds. We may retain information beyond the standard periods described above where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
10. Security
We implement and maintain administrative, technical, and physical safeguards designed to protect your Personal Information against unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of data in transit using TLS.
- Encryption of sensitive data at rest.
- Access controls limiting data access to authorized personnel only.
- Regular security reviews and dependency monitoring.
- Use of managed cloud infrastructure with built-in security controls.
Passwords and sessions. We store only a hash of your password. Changing or resetting it signs you out of every other session. If you cannot reset your password by email, a Workspace administrator may ask us to issue a single-use reset link for you; we issue it only after verifying the request, it expires after one hour, and nobody at Skipshoot LLC sees or sets your password.
No method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of your information. If you become aware of a security vulnerability or incident, please notify us immediately at hello@skipshoot.com.
11. International Data Transfers
Skipshoot LLC is headquartered in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States and other countries where our sub-processors operate. These countries may have data protection laws that differ from those in your jurisdiction.
Where required, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses approved by the European Commission, or other lawful transfer mechanisms, to ensure your Personal Information receives adequate protection when transferred internationally.
12. Children’s Privacy
The Service is intended for business and professional use by individuals who are at least 18 years of age. We do not knowingly collect Personal Information from children under 13 (or the applicable age of digital consent in your jurisdiction). If we learn that we have inadvertently collected such information, we will promptly delete it. If you believe a child has provided us with Personal Information, please contact us at hello@skipshoot.com.
13. Your Rights and Choices
Depending on your location, you may have the following rights regarding your Personal Information:
- Access. Request a copy of the Personal Information we hold about you.
- Correction. Request that we correct inaccurate or incomplete Personal Information.
- Deletion. Request that we delete your Personal Information, subject to certain legal exceptions.
- Portability. Request that we provide your Personal Information in a structured, machine-readable format.
- Restriction. Request that we restrict processing of your Personal Information in certain circumstances.
- Objection. Object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw consent. Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.
- Account settings. You may update your profile information and notification preferences directly in your account settings at any time, and you can delete your own account from your settings; what that removes is set out in Section 8 of the EULA.
To exercise any of these rights, email us at hello@skipshoot.com with a description of your request. We will respond within 30 days (or within the timeframe required by applicable law). We may ask you to verify your identity before processing your request.
14. US State Privacy Rights
Certain US state privacy laws grant additional rights to residents of those states.
- California (CCPA / CPRA). California residents have the right to know what Personal Information we collect and how it is used, the right to delete Personal Information, the right to correct inaccurate Personal Information, the right to opt out of the sale or sharing of Personal Information (we do not sell or share Personal Information for cross-context behavioral advertising), and the right to non-discrimination for exercising these rights. To submit a verifiable consumer request, email hello@skipshoot.com.
- Other states. Residents of Virginia, Colorado, Connecticut, Texas, and other states with comprehensive privacy laws may have similar rights. We will honor verified requests made in accordance with applicable state law.
15. Do Not Track
Some browsers offer a "Do Not Track" (DNT) setting that signals to websites that you do not want to be tracked. Because there is no accepted industry standard for responding to DNT signals, our Service does not currently alter its data collection practices in response to DNT signals. We will revisit this position if a standard practice emerges.
16. Links to Third-Party Sites
The Service may contain links to third-party websites, integrations, or services that are not operated by Skipshoot LLC. Clicking those links will take you away from the Service. We have no control over and assume no responsibility for the content, privacy practices, or conduct of any third-party sites. We encourage you to review the privacy policy of every site you visit.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page and provide at least 14 days’ advance notice by email or in-app notification before the changes take effect. For non-material changes, updating the date is sufficient notice.
Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.
18. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: hello@skipshoot.com
- Company: Skipshoot LLC
- Jurisdiction: State of Georgia, United States
We will make every reasonable effort to address your concern promptly and in accordance with applicable law.
