1. Information we collect
Account & Profile Information: When you create an account or sign in via Google OAuth or email authentication, we collect your email address, name (if provided via Google profile), profile image URL, account creation date, and authentication timestamps.
Uploaded Assets & Creative Inputs: We collect the product photographs, reference images, studio scene choices, custom prompt text, model attribute preferences (gender, ethnicity, skin tone), aspect ratio selections, and lighting configurations you submit.
Generated Content & Generation History: We store the AI-generated image outputs, format preferences, generation timestamps, and associated metadata created during your studio sessions.
Billing & Transaction Data: When you subscribe to a plan or purchase credit packs, our payment partner Dodo Payments processes your payment and provides us with transaction metadata, including subscription tier, status, payment event IDs, billing dates, currency, amount paid, and invoice identifiers. Monoshoot does not receive or store your credit/debit card numbers.
Usage, Device & Diagnostic Data: We collect technical diagnostic information including browser type, operating system, IP address, request timestamps, credit consumption records, error reports (via Sentry), and anonymized product interaction events (via PostHog) to improve platform reliability.
2. How we use your information
We use the collected information to: (a) authenticate your identity and maintain your account; (b) operate the AI photoshoot studio and execute generation pipelines; (c) optimize, convert, and serve images in requested formats (JPG, PNG, WEBP, AVIF); (d) track and manage your generation credit balances and monthly roll-overs; (e) process subscription billing and credit pack purchases via Dodo Payments; (f) provide customer support and troubleshoot errors; (g) prevent fraud, unauthorized access, and abusive usage; and (h) comply with legal and regulatory obligations.
We do not sell, rent, or trade your personal information or uploaded product photographs to third parties for advertising or data broker purposes.
3. AI processing and image storage
When you trigger a photoshoot generation, your uploaded product images and styling prompts are transmitted securely via encrypted API connections to OpenAI image generation infrastructure to synthesize the requested studio scene.
Generated images are converted, compressed for optimal web delivery, and securely stored on encrypted cloud object storage (Backblaze B2 S3 storage and Supabase Storage) within user-isolated directories.
Image Deletion Controls: You have full control over your creative history. You can delete individual generated images from your studio history at any time. When deleted, the database record and associated cloud storage files are permanently removed.
4. Payment processing & merchant of record
All payment transactions, plan checkouts, recurring billing cycles, and invoice generation are managed by Dodo Payments, acting as our Merchant of Record.
Dodo Payments maintains PCI-DSS Level 1 compliance and processes financial data in accordance with its independent privacy policy and security standards. Monoshoot retains only non-sensitive billing metadata necessary to maintain your account plan status.
5. Third-party service providers & sub-processors
We share data with trusted third-party service providers only as strictly necessary to operate the platform. These providers include:
- Supabase: Managed PostgreSQL database, authentication, and core platform data storage.
- Backblaze B2: Encrypted S3-compatible cloud object storage for uploaded and generated images.
- OpenAI: Cloud-based generative AI model infrastructure for image synthesis.
- Dodo Payments: Payment gateway, tax compliance, and Merchant of Record.
- PostHog: Product analytics and usage insights to improve user experience.
- Sentry: Real-time application error logging and performance monitoring.
- Hosting & CDN Infrastructure: Cloud hosting and content delivery networks for secure web delivery.
6. Data retention and account deletion
We retain your account information, generation records, and uploaded assets for as long as your account remains active or as needed to provide you with the service.
Self-Service Account Deletion: You can initiate complete account and data deletion from your Account settings by entering 'DELETE' in the confirmation prompt. Following submission, your account enters a 30-day grace period during which deletion can be cancelled.
After 30 days, your user profile, authentication credentials, generation history, and stored cloud images are permanently purged from active systems, retaining only non-personal billing audit records required by law.
7. Data security
We implement industry-standard technical and organizational security measures to protect your data, including HTTPS/TLS encryption for all data in transit, encrypted cloud storage at rest, database row-level security (RLS) policies, and restricted service-role access.
While we employ rigorous security practices, no method of transmission over the internet or electronic storage is 100% secure. You are responsible for safeguarding your login credentials.
8. Your privacy rights and choices
Depending on your location, you may have rights under applicable privacy laws (such as GDPR, CCPA, or Indian DPDP Act), including the right to: access the personal data we hold about you; request correction of inaccurate information; request deletion of your account and personal data; export your generated images; and withdraw consent where processing is based on consent.
To exercise any of these rights, you may use the self-service controls in your account dashboard or contact our privacy team at support@monoshoot.com.
9. International data transfers
Monoshoot serves users globally. Your personal data and visual assets may be processed and stored on servers located in various jurisdictions where our infrastructure partners operate, with appropriate technical and contractual protections in place.
10. Updates to this policy
We may update this Privacy Policy periodically to reflect changes in platform features, third-party providers, legal requirements, or operational practices. When material updates occur, we will revise the 'Last updated' date at the top of this page.
11. Contact us
If you have questions, comments, or data requests regarding this Privacy Policy, please contact our data team at support@monoshoot.com.
Legal entity: Monoshoot. Contact: support@monoshoot.com. Governing law and jurisdiction: Republic of India.