Skip to content
Shotpop
Design Tools Privacy Pricing FAQ Support

Legal

Privacy Policy

Last updated 15 August 2026 · Applies to the Shotpop iPhone app and to shotpop.app

On this page

  1. The short version
  2. Who this is from
  3. What never leaves your iPhone
  4. Where your projects live
  5. Photos access
  6. What is collected, and by whom
  7. Advertising and the tracking prompt
  8. EEA and UK consent
  9. Notifications
  10. Stock photo search
  11. No account, no email
  12. Legal bases (GDPR / UK GDPR)
  13. Your rights
  14. California (CCPA / CPRA)
  15. Children
  16. Retention and deletion
  17. Security
  18. International transfers
  19. This website
  20. Changes to this policy
  21. Contact

The short version

  1. Your screenshots never leave your iPhone.

    Editing, text recognition, auto-redaction and export all run on the device. Shotpop has no upload path for your images, and we have no server that could receive one.

  2. There is no account.

    No sign-up, no login, no password, no email address. We never learn your name.

  3. What does leave the device is ad, purchase and crash data.

    It goes to Google, Meta, RevenueCat and Firebase. Every one of them is named below, with what it gets and why. Nothing is hidden in a footnote.

This policy explains what Shotpop does with data. It is written to be read, not to be survived. If anything here is unclear, email hello@shotpop.app and we will explain it in plain words.

1. Who this is from

Shotpop is an iPhone app published under the bundle identifier com.hmtech.shotpop. For the purposes of the UK and EU GDPR, the data controller is the app's publisher.

The data controller is Harimurti Technologies, Surat, Gujarat, India.

Contact for anything privacy-related: hello@shotpop.app.

2. What never leaves your iPhone

Your images. Screenshots and photos you bring into Shotpop stay on your device. Everything the app does to them happens locally:

  • Editing — backgrounds, device frames, templates, filters, annotations, stickers, spotlight, carousel slicing and scroll stitch are all rendered on the device.
  • Text recognition. One-tap auto-redaction reads the text in your screenshot to find things like email addresses, card numbers and API keys so it can cover them. That reading is done by Apple's Vision framework, on the device. The recognised text is used to place the redaction and is not transmitted anywhere.
  • Subject Lift — isolating a subject from a photo — also runs through Apple's on-device Vision framework.
  • Export — the finished image is composed on the device and saved or shared by you.

We do not receive your images. We could not produce one if we were asked to. There is no image upload anywhere in the app, and no Shotpop server exists for an image to be uploaded to.

3. Where your projects live

Your Shotpop projects are stored on your device, in the app's own storage. There is no Shotpop account and no Shotpop server holding them.

  • They do not sync between devices. A project made on your iPhone stays on that iPhone. Live iCloud sync is not part of this version.
  • They are included in your backups. If you back your iPhone up to iCloud or to a computer, your projects travel with that backup and restore onto a new phone with it. That backup is Apple's, governed by Apple's privacy policy, and we have no access to it.
  • Deleting the app deletes them. Export anything you want to keep before you do.

To be exact about the thing people usually assume: we do not run a server. Shotpop has no backend of its own that stores your content, and there is nothing for us to read even if we wanted to.

4. Photos access

  • Importing a screenshot uses Apple's system photo picker. The picker runs outside the app and hands over only the one image you chose. Shotpop is never granted permission to read your photo library, and iOS never asks you for that permission — because the app never requests it.
  • Saving a finished image asks for add-only Photos access: permission to write new images into your library, not to look through it. That is the only Photos permission Shotpop declares.

5. What is collected, and by whom

Shotpop uses a small number of third-party services. Each one gets a specific, limited slice of data, and each one is listed here with a link to its own policy. Data goes to these providers directly from your device — it does not pass through us first.

Third-party services used by Shotpop, what each receives and why
Provider What it receives Why
Google AdMob
Policy
Your advertising identifier (IDFA) only if you allow tracking; ad requests, impressions and taps; the technical information any internet request carries, such as IP address, device model and iOS version. Serving the ads shown to free users, and measuring them.
Meta
Policy
App events such as installs and app opens; your advertising identifier only if you allow tracking. With tracking declined, Meta runs in Apple's SKAdNetwork mode, which reports aggregated results without identifying you. Advertising and install attribution — knowing which campaign an install came from.
RevenueCat
Policy
An anonymous user ID generated on your device, plus your Shotpop purchase and subscription history from the App Store. No name, no email, no payment details — Apple handles payment and never shares your card with us. Knowing whether this device has Pro, and restoring it after a reinstall.
Firebase Analytics (Google)
Policy
Product-interaction events — which onboarding page you reached, which template category you browsed, that an export finished — plus an app-instance identifier, device model, iOS version and coarse region. Understanding which features are used, so the next version improves the right things.
Firebase Crashlytics (Google)
Policy
Crash reports and performance diagnostics: the stack trace, device model, iOS version, and app state at the moment of a crash — which screen you were on, which tool was active, whether an export was running, and device health readings such as memory use, memory warnings, uptime and thermal state. Reports carry no identifier of any kind: they are not tagged with your RevenueCat ID or anything else that could group them back to one person. Finding and fixing crashes.
Firebase Remote Config (Google)
Policy
A request from your device for the current configuration values. It carries no content and nothing about your images. Adjusting settings such as ad frequency and the free daily export allowance without shipping an app update.
Unsplash and Pexels
Unsplash · Pexels
The search words you type, and the IP address the request comes from — and only while the stock photo picker is open. Your own images are never sent. Stock photo search is not enabled in the current release, so nothing is sent to either service today; this row describes what would be shared if it is turned on. Returning stock photo results for a background.
Apple
Policy
Your purchases (App Store), your device backup (iCloud), and — if you turn notifications on — push delivery (APNs). Payments, backups and notifications, all through Apple's own systems.

That is the complete list. Shotpop does not collect your contacts, your location, your health data, your messages, your browsing history, or the contents of your photo library.

We do not sell your personal information.

6. Advertising and the tracking prompt

The free tier of Shotpop shows ads: a banner, native ads inside some lists, occasional full-screen interstitials, and an optional rewarded video you can choose to watch in exchange for extra exports. Pro turns every ad off.

The App Tracking Transparency prompt

Shortly after you finish onboarding — not at first launch — iOS shows Apple's tracking prompt, asking whether Shotpop may track you across other companies' apps and websites. It is asking about your advertising identifier (IDFA).

  • If you allow it, your IDFA is shared with Google AdMob and Meta, and the ads you see can be personalised.
  • If you decline it, nothing breaks. The app works exactly the same, you keep every feature, and you still see ads — they are just non-personalised.
  • You can change your mind at any time in iOS Settings → Privacy & Security → Tracking.

7. EEA and UK consent

If you are in the EEA, the UK or Switzerland, Shotpop shows Google's consent form (the User Messaging Platform) before requesting any ad. Your choice there controls whether personalised advertising is allowed.

If you decline, the app does not request ads at all for that choice — no banner, no native ad, no interstitial. The app remains fully usable.

The current version of Shotpop has no in-app button to reopen that form. To change a consent choice, email hello@shotpop.app and we will walk you through it, or delete and reinstall the app, which resets the choice. A control for this is planned.

8. Notifications

Shotpop may ask permission to send notifications after you have exported something. If you say yes:

  • Some reminders are scheduled locally on your device and never touch a network.
  • Your device also registers a push token with Apple's push service and with Firebase Cloud Messaging, so occasional product messages can be delivered. A push token identifies a device for delivery; it carries none of your content.

If you say no, nothing is registered and no feature is withheld. You can turn notifications off at any time in iOS Settings.

9. Stock photo search

Stock photo search is not enabled in the current release of Shotpop. The picker is hidden and no request is made to any stock photo service. This section describes what would happen if it is switched on in a later version, so you can see the terms before rather than after.

If you open the stock photo picker to find a background, the words you type are sent to Unsplash and Pexels so they can return results. That request happens only while that picker is open, only when you have typed something, and it contains nothing but your search text. Your screenshot is not part of it.

10. No account, no email

Shotpop has no sign-up and no login. We do not ask for, store, or receive your email address, name, phone number or date of birth. If you email support, we obviously have that email — we use it to answer you and for nothing else.

11. Legal bases (GDPR / UK GDPR)

Where the EU or UK GDPR applies, we rely on these bases:

Performance of a contract
Processing your purchase and subscription state through RevenueCat, so the Pro features you paid for actually unlock.
Consent
Personalised advertising and the advertising identifier (via the ATT prompt and the Google consent form), and notifications. You can withdraw consent at any time — see the sections above.
Legitimate interests
Crash and performance diagnostics, and basic product analytics, so the app can be kept working and improved. You can object to this — email us and we will act on it.

12. Your rights

Depending on where you live, you may have the right to access the data held about you, correct it, delete it, restrict or object to its processing, receive a portable copy, and withdraw consent. To exercise any of these, email hello@shotpop.app.

One honest caveat: because there is no account, we usually cannot connect a request to a specific person on our own. To find anything at all we may need the anonymous identifier or the App Store receipt associated with your purchase. If we cannot verify a request, we will say so rather than hand data to the wrong person.

You can also complain to your data protection authority — in the UK, the Information Commissioner's Office; in the EEA, your national supervisory authority.

13. California (CCPA / CPRA)

We do not sell personal information for money. If you allow tracking through the ATT prompt, the sharing of your advertising identifier with Google and Meta for advertising may count as "sharing for cross-context behavioural advertising" under California law.

To opt out, do either of these — both are immediate and free:

  • Decline the tracking prompt, or turn Shotpop off under iOS Settings → Privacy & Security → Tracking.
  • Email hello@shotpop.app with the subject "Do Not Sell or Share".

California residents also have rights to know, delete and correct, and the right not to be discriminated against for exercising them. We do not offer financial incentives for data, so there is nothing to be discriminated about.

14. Children

Shotpop is a design tool for a general audience. It is not directed at children and is not in the App Store Kids Category. We do not knowingly collect data from children under 13 (or under 16 where local law sets that age). If you believe a child has provided data, email us and we will delete what we can.

15. Retention and deletion

  • Your projects and images stay on your device for as long as you keep them.
  • Delete the app and its data goes with it. If you also want it gone from your backups, delete or replace the iPhone backup in iOS Settings → your name → iCloud → Manage Account Storage. We are not involved in either step, and cannot be — we never had a copy.
  • Data held by the providers above is kept for each provider's own retention period, described in their policies. Purchase records may be kept longer where tax or accounting law requires it.

16. Security

Your content is protected by iOS itself — app sandboxing and device encryption — and, where you use it, by Apple's iCloud security. Every network request the app makes goes over encrypted HTTPS. No system is perfect, but the strongest security property here is structural rather than promised: your images are not on a server we hold, so there is no server of ours to breach.

17. International transfers

Google, Meta and RevenueCat are United States companies and may process data outside your country. Transfers rely on those providers' own safeguards, such as the EU–US Data Privacy Framework and Standard Contractual Clauses, described in the policies linked in the table above.

18. This website

shotpop.app is a static site. It sets no cookies, runs no analytics, loads no fonts or scripts from anyone else, and has no tracking pixels. Our hosting provider keeps standard server logs, which include IP addresses, for security and reliability.

19. Changes to this policy

If the app's data practices change, this page changes with them and the "last updated" date at the top moves. Material changes will also be noted in the app's release notes. This policy, the app's privacy manifest and the App Store privacy label are updated together, so they always say the same thing.

20. Contact

Questions, requests, corrections, or a suspicion that something here is wrong — email hello@shotpop.app. A real person reads it.

Something here look wrong?

Privacy claims should be checkable. If you find a gap between what this page says and what the app does, tell us and we will fix the page or the app.

Email hello@shotpop.app Read the Terms
Shotpop

A screenshot beautifier for iPhone. Everything happens on your device.

Product

Design Tools Pricing FAQ

Legal

Privacy Policy Terms of Use

Help

Support hello@shotpop.app

© 2026 Shotpop. All rights reserved.

Made for iPhone · iOS 18+ · Graphics & Design