ShadowboxStudio
Open studio
Terms of Service Privacy Policy Refunds and cancellation Legal notice

Privacy Policy

Last updated 6 October 2026

This policy explains what personal data Shadowbox Studio collects, why, who else sees it, how long we keep it, and what rights you have. We collect as little as we can. We don't run ads, we don't use analytics or tracking cookies, and we don't sell your data.

1. Who is responsible

The controller of your data under the EU General Data Protection Regulation (GDPR) is:

[set SHADOWBOX_LEGAL_NAME]
[set SHADOWBOX_LEGAL_ADDRESS]
[set SHADOWBOX_LEGAL_EMAIL]

Shadowbox Studio is run by one private individual. There is no data protection officer; write to the address above about anything in this policy.

2. What we collect and why

DataWhyLegal basis (GDPR)
Account: e-mail address, the name you give (optional), your password if you set one (stored only as a salted scrypt hash, never in readable form), plan, plan requests, the terms version you accepted, and when you signed up and last logged in. To create and run your account and let you log in. Contract, Art. 6(1)(b)
Sign-in with Google or Facebook (only if you choose it): from Google, your Google account ID, name, e-mail address and whether Google has confirmed that address; from Facebook, your app-scoped Facebook user ID, name and e-mail address (the public_profile and email permissions). We don't receive your password, and we don't ask for or receive your friends, posts, photos or anything else. We never post on your behalf. To create your account or log you in without a password, and to recognise you the next time you sign in that way. Contract, Art. 6(1)(b)
Sessions: a random login token (we store only its hash), the IP address and browser name it was created from, and when it expires. To keep you logged in, and so we can spot and stop misuse of an account. Contract, Art. 6(1)(b); our legitimate interest in security, Art. 6(1)(f)
Your artwork: the SVG file you upload and your settings. To generate your lamp. The file, and the result made from it, are kept only in the server's memory while your design waits its turn and is generated, and are discarded once the result has reached you (at most 10 minutes after the generation ends), unless you save it as a project: then the SVG, its file name and your settings are stored with your account so you can open the design again. We don't look at your artwork or use it for anything else. Contract, Art. 6(1)(b)
Usage log: for each generation, the time, how long it took, whether it worked (and the error if not), the file's name and size, and the number of sheets. To apply the daily limit of your plan, and to find and fix problems with the generator. Contract, Art. 6(1)(b); legitimate interest in running a reliable service, Art. 6(1)(f)
Server logs and abuse protection: IP address, time and address of each request; failed log-in attempts per IP address and e-mail. To keep the Service secure, block password-guessing and fix faults. Legitimate interest in security, Art. 6(1)(f)
Messages: what you write when you e-mail us. To answer you. Contract or legitimate interest, Art. 6(1)(b)/(f)
Payments (once online payment is live): name, billing country and address, what you bought and when. Card details go straight to the payment provider; we never see them. To take payment and keep the accounting records the law requires. Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c)

You don't have to give us any of this, but without an e-mail address (with a password, or a Google or Facebook sign-in) we can't create an account, and without your artwork we can't generate a lamp. We don't make decisions about you by automated means that have legal or similarly significant effects.

3. Cookies and local storage

We use one cookie, sbx_session, which keeps you logged in. It is strictly necessary, lasts up to 30 days, and is deleted when you log out. When you choose "Continue with Google" or "Continue with Facebook", a second cookie, sbx_oauth, holds a random check value for up to 10 minutes so the reply from Google or Facebook can be matched to your browser; it is deleted as soon as you are signed in. Your browser also keeps your studio settings and layout preferences in its local storage, on your device only; they are never sent to us. Because we only use what is strictly necessary for the Service you asked for, we don't need to ask for cookie consent, and there is no cookie banner.

4. Who else receives data

We don't sell or rent personal data, and we don't share it with advertisers. These providers handle data for us or are involved when your browser loads the website:

  • Server hosting: [set SHADOWBOX_LEGAL_HOSTING]. Your account data and logs are stored on this server.
  • Vercel Inc. (USA) runs shadowboxstudio.app: your browser connects to Vercel, which passes each request on to our server and the answer back. To do that it handles your IP address, browser details and what you send and receive, including uploaded artwork, and keeps short-lived request logs. It doesn't store your account data.
  • Tailscale Inc. (Canada / USA) carries the encrypted connection between Vercel and our server. It can see connection times, but not the content, which stays encrypted end to end.
  • Google Fonts (Google Ireland Ltd. / Google LLC, USA): your browser downloads the website's typeface from Google, which sends Google your IP address and browser details.
  • Google (Google Ireland Ltd. / Google LLC, USA) and Meta (Meta Platforms Ireland Ltd. / Meta Platforms Inc., USA), only if you choose "Continue with Google" or "Continue with Facebook": you log in on their page, so they know you are signing in to Shadowbox Studio, and they send us the details listed in section 2. Their own privacy policies cover what they do with your data.
  • jsDelivr and cdnjs (content delivery networks run with Cloudflare Inc. and Fastly Inc., USA): your browser downloads the 3D viewer (three.js) and the ZIP library from them, which sends them your IP address and browser details.
  • Payment provider (once online payment is live): named on the order page, with a link to its own privacy policy.
  • Authorities, where the law requires us to share data, for example with tax authorities or in response to a valid court order.

5. Data outside the EU

Some of the providers above are based in the USA or Canada, so data such as your IP address may be processed there. Canada has an adequacy decision from the European Commission. For US providers, the transfer is based on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses. You can ask us for more detail.

6. How long we keep it

  • Account data, Google/Facebook sign-in details and usage log: as long as your account exists. When your account is deleted, all of it is deleted within 30 days.
  • Sessions: until you log out or the session expires after 30 days.
  • Uploaded artwork: not stored, unless you save it as a project. It and its result are held in memory only, and discarded once the result has reached you, at most 10 minutes after the generation finishes.
  • Saved projects: until you delete them in My projects, or until your account is deleted.
  • Server logs: no more than 30 days. Failed log-in counters: no more than one hour, in memory only.
  • E-mails with us: as long as needed to deal with your request, and at most 3 years after it is closed.
  • Payment and invoice records: as long as tax and accounting law requires (usually 5 to 10 years, depending on the country).

7. Your rights

Under the GDPR you have the right to:

  • get a copy of the personal data we hold about you (access);
  • have wrong data corrected (rectification);
  • have your data deleted (erasure), including deleting your whole account;
  • have us limit how we use your data (restriction);
  • receive the data you gave us in a machine-readable format (portability);
  • object to processing based on our legitimate interests;
  • withdraw any consent you've given, without affecting what happened before.

To use any of these, e-mail [set SHADOWBOX_LEGAL_EMAIL] from the address on your account. We'll answer within one month. You also have the right to complain to a data protection authority, in particular the one where you live or work. Ours is [set SHADOWBOX_LEGAL_AUTHORITY].

Deleting your account and data

To have your account and everything we hold about you deleted, e-mail [set SHADOWBOX_LEGAL_EMAIL] from the address on your account and ask us to delete it. If you signed in with Facebook and no longer have access to that e-mail, tell us the name on your Facebook account instead. We delete the account, its sign-in details, sessions, saved projects and usage log within 30 days and confirm by e-mail.

If you signed in with Facebook, you can also remove Shadowbox Studio from your Facebook account: on Facebook go to Settings & privacy → Settings → Apps and websites, choose Shadowbox Studio and select Remove. After that, Facebook sends us nothing more about you. For Google, open your Google Account, go to Security → Your connections to third-party apps & services, choose Shadowbox Studio and remove its access.

8. Visitors from the USA and elsewhere

We handle everyone's data the same way, wherever they live, and give everyone the rights listed above. For residents of California and other US states with privacy laws: we collect the categories of data described in section 2 (identifiers such as e-mail and IP address, account and usage information, and commercial information once payments go live), only for the purposes described there. We do not sell personal information and do not share it for cross-context behavioural advertising. You have the right to know, correct and delete your data, and we won't treat you differently for using those rights. Because we don't track you across sites, we don't respond differently to "Do Not Track" or Global Privacy Control signals; there is nothing for them to switch off.

9. Children

The Service is not intended for children. You must be at least 16 to create an account. If we learn that we hold data about a child under 16, we will delete it.

10. Security

All traffic is encrypted (HTTPS). Passwords are stored only as salted scrypt hashes, and login tokens only as hashes, so a copy of our database couldn't be used to log in. Log-in attempts are rate-limited. No system is perfectly secure; if a breach puts your data at risk, we will tell you and the authorities as the law requires.

11. Changes to this policy

We'll update this policy when the Service changes, for example when online payment goes live. The date at the top shows the latest version. If a change matters for how we use your data, we'll tell you by e-mail first.

© 2026 Shadowbox Studio
TermsPrivacyRefundsLegal notice