Privacy Policy
Last updated: May 2, 2026
Shortodella is a product and brand operated by WOOPICX SPÓŁKA Z O.O., NIP 7011263646, REGON 541936910, a company registered in Poland (the "Company", "Shortodella", "we", "our", "us"). The Company is the data controller for personal data processed in connection with your use of the Services provided through https://shortodella.com/ (the "Website"). This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over your data.
By using the Website, you agree to this Privacy Policy and to the practices described below. If you do not agree, please do not use the Services.
Our contact email address is info@shortodella.com. We do not currently have a separately appointed Data Protection Officer; data protection requests are handled by the Company directly via this address.
Why do we process your data?
- Performance of a contract (Article 6(1)(b) GDPR) — to register your Account, deliver the Services you request, generate AI content from your prompts, process payments, and provide customer support. Data is retained while your Account is active.
- Legal obligations (Article 6(1)(c) GDPR) — to keep accounting, tax, and anti-money-laundering records as required by Polish law, including:
- the Accounting Act of 29 September 1994;
- the Tax Ordinance of 29 August 1997;
- the Counteracting Money Laundering and Terrorist Financing Act of 1 March 2018.
- Legitimate interests (Article 6(1)(f) GDPR) — to secure the Services, prevent fraud and abuse, monitor and improve product performance, defend legal claims, and conduct limited direct marketing of our own similar services to existing Customers. You may object to processing on this basis at any time.
- Consent (Article 6(1)(a) GDPR) — for non-essential cookies, marketing and advertising analytics, newsletter sign-ups, and similar activities. You may withdraw consent at any time without affecting processing carried out before withdrawal.
What data is being processed?
Data that you voluntarily provide us with
You may provide us with personal data when you sign up for an Account, make a payment, subscribe to a newsletter, fill in a form, contact our support, or use any feature of the Services. This may include:
- your full name and email address;
- your Account password (stored as a salted hash, never in plain text), or your authentication identity provided by Google or Apple if you sign in with those providers;
- billing information processed via Stripe (card data is collected directly by Stripe and is never stored on our servers);
- any contact preferences you set;
- any content you upload to the Services — including images, videos, audio, brand assets, prompts, project files, and similar Customer Content (see "Customer Content and AI Generation" below).
We do not require you to provide a phone number or postal address to use the core Services. If you provide such data voluntarily (e.g. for support or invoicing), we use it only for the purpose for which it was provided.
Data that we collect automatically
When you visit or use the Services, we automatically collect technical and usage data, including: your IP address (which may reveal approximate location), browser type and language, device information, operating system, referring/exit pages, the URL of the page requested, the date and time of access, and information about how you interacted with the Services (e.g. clicks, generations performed, features used). We use this information to operate, secure, debug, and improve the Services.
Application logs and in-product debug data
For debugging, security, and reliability purposes, we maintain server-side application logs (the internal "wooLog" system) that record events such as your user ID, session ID, page paths, action names, error stack traces, and limited contextual payloads. These logs are stored on infrastructure under our control (hosted in the EU) and are retained for a rolling window of approximately 60–90 days, after which they are automatically deleted.
Session recordings
When you have given consent for analytics cookies, we use PostHog (EU cloud) to record limited session replays of your interaction with the Services so we can diagnose bugs and improve usability. Password fields and other sensitive inputs are masked at capture time and are never sent to PostHog. You can disable session recordings at any time by withdrawing analytics consent in our cookie banner.
First-party analytics (Shortid)
In addition to the third-party analytics tools listed below, we operate our own first-party analytics script ("Shortid"), loaded from https://shortid.me/cr.js. Shortid is hosted on infrastructure controlled by the Company (no separate third-party processor) and is used to capture aggregate page views, clicks, and similar interaction events for product and marketing analysis. Data collected by Shortid is stored on our EU-based servers and is subject to the same retention and deletion rules as our other application data.
Cookies and tracking
Cookies are small data files that are placed on your computer or mobile device when you visit a website. Website owners use cookies to make their websites operate, improve functionality and user experience, as well as to provide reporting information.
We may set our own cookies and use third parties cookies (e.g. for advertising, interactive content and analytics).
We use different types of cookies, including:
- Essential website cookies: these are important cookies as they are necessary to provide you with services available through our Website, such as access to secure areas.
- Performance and functionality cookies: these cookies are necessary to enhance the performance and functionality of our Website but are non-essential to their use. However, without these cookies, certain functionality may become unavailable.
- Analytics and customization cookies: these cookies collect information that is used either in aggregate form to help us understand how our Website is being used or how effective our marketing campaigns are, or to help us customize our Website for you in order to enhance your experience.
- Advertising cookies: these cookies are used to make advertising messages more relevant to you. They perform functions like preventing the same ad from continuously reappearing, ensuring that ads are properly displayed, and in some cases selecting advertisements that are based on your interests.
You may opt out from cookies at any time by customizing your cookie preferences. However, in some cases we will not be able to provide you with all services.
By browsing and using our Website and Services, you agree to the use of cookies and similar technologies as stated in this Privacy Policy.
Web beacons and similar technologies
Apart from cookies, we use other similar technologies, like web beacons, to monitor traffic, deliver and communicate with cookies, and improve site performance. Similar to cookies you may opt out from web beacons at any time.
Data from third party sources
We may receive some information about you, such as name, email address, demographic information, IP address, location from third parties.
We collect information about your activity on our Website to enable us to:
- measure and analyze traffic and browsing activity on our Website;
- show advertisements for our products and/or services to you on third-party sites;
- measure and analyze the performance of our advertising campaigns.
Opting-Out
You may decline to have your personal data collected via third party tracking technologies by navigating to the settings feature in your browser and declining all third party cookies or declining third party cookies from specific sites, or, for mobile, limiting ad tracking or resetting the advertising identifier via the privacy settings on your mobile device.
You can use the following third party tools to decline the collection and use of information for the purpose of serving you interest based advertising:
- The NAI's opt-out platform
- The EDAA's opt-out platform
- The DAA's opt-out platform
Who will the data be shared with?
We do not share personal data you have provided to us without your consent, unless:
- Doing so is appropriate to carry out your own request;
- We believe it is needed to enforce our Terms, or if it is legally required;
- We believe it is needed to detect, prevent or address fraud, security or technical issues;
- Otherwise protect our property, legal rights, or that of others.
As per above, we may need to share personal data with our service providers that perform certain tasks on our behalf and who are under our control (our "Service Providers") in order to provide products or services to you. Unless we tell you differently, our Service Providers do not have any right to use personal data or other information we share with them beyond what is necessary to assist us. You hereby consent to our sharing of personal data with our Service Providers, namely:
| Provider | Purpose | Region |
|---|---|---|
| Cloudflare, Inc. | CDN, edge compute (Workers), object storage (R2), key-value (KV), background queues, DNS | USA / global |
| DigitalOcean, LLC | Hosting of backend application, PostgreSQL database, and Redis cache | EU (Amsterdam region) |
| Hetzner Online GmbH | Auxiliary scraping and screenshot infrastructure | EU (Germany / Finland) |
| Stripe Payments Europe, Ltd. | Payment processing, billing, subscription management | EU / USA |
| Google LLC (Firebase Authentication) | Authentication backend (sign-in, session tokens) | USA / global |
| Google LLC (Sign in with Google) | OAuth login provider | USA / global |
| Apple Inc. (Sign in with Apple) | OAuth login provider | USA / global |
| Sendinblue SAS (Brevo) | Transactional email (welcome, billing, password reset, support) | EU (France) |
| Telegram FZ-LLC | Internal team notifications about Service events (e.g. signup alerts, error reports) | UAE / global |
| Google LLC (Google Analytics 4) | Aggregated product and traffic analytics (consent-based) | USA / EU |
| Google LLC (Google Tag Manager) | Tag and consent-mode management; loads other analytics and advertising tags after consent | USA / global |
| Pinterest, Inc. | Advertising conversion tracking and audience targeting (consent-based) | USA / global |
| Meta Platforms Ireland Ltd. (Facebook / Instagram Pixel and Conversions API) | Advertising conversion tracking, retargeting, and look-alike audiences across Facebook and Instagram (consent-based) | EU (Ireland) / USA |
| PostHog, Inc. (EU cloud — eu.i.posthog.com) | Product analytics, feature usage, funnel analysis, session recordings with passwords masked (consent-based) | EU (Germany) |
| OpenAI, L.L.C. | AI text and image generation (API) | USA |
| Anthropic, PBC | AI text generation and agent reasoning (Claude API) | USA |
| Google LLC (Gemini / Vertex / Veo / "Nano Banana") | AI image, video, and text generation | USA / EU |
| Kuaishou Technology (Kling AI) | AI text-to-video and image-to-video generation | Singapore / China |
| ByteDance / Volcano Engine (Seedance) | AI video generation | Singapore / China |
| xAI Corp. (Grok) | AI text and vision generation | USA |
| Moonshot AI (Kimi) | Alternative LLM routing for selected tasks | Singapore / China |
| ElevenLabs Inc. | AI voice and audio generation | USA / EU |
We may also share data with social-platform APIs (YouTube, Instagram, Pinterest) when you explicitly connect those accounts to publish content created in the Services. The list above represents the subprocessors active as of the "Last updated" date. We will update this Privacy Policy when we add or remove subprocessors. To request the current list at any time, email info@shortodella.com.
International transfers
Several of our subprocessors are located outside the European Economic Area (EEA), in particular in the United States, the United Kingdom, Switzerland, the United Arab Emirates, Singapore, and China. When we transfer personal data to such countries, we rely on the following safeguards under Chapter V GDPR:
- Adequacy decisions of the European Commission (e.g. UK, Switzerland, and the EU-U.S. Data Privacy Framework where the recipient is certified);
- Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented where necessary by additional technical and organizational measures (e.g. encryption in transit and at rest);
- Your explicit consent for the specific transfer, where applicable.
You can request copies of the safeguards in place for transfers to a specific subprocessor by emailing info@shortodella.com.
Do we Collect Data of Minors?
Minors and children under the age of 18 (or other legal age of your country of residence) should not use our Services. If you are 13 years of age up to 18, you need to obtain a written parental or guardian consent, unless the law of the country of your residence prescribes higher age requirements, in which case you need to meet such requirements. We do not knowingly provide any Services to minors. If you access our Services, you represent that you have the legal capacity to enter into a binding agreement.
Profiling and automated decision-making
We perform limited profiling for product analytics and advertising. Specifically:
- We use Google Analytics 4 and PostHog to understand aggregated usage patterns (which features are used, conversion funnels, retention).
- We use the Pinterest Conversions API and the Meta (Facebook / Instagram) Pixel and Conversions API, together with similar tools listed in the subprocessor table below, to measure the performance of our advertising campaigns and to show our ads to people similar to existing Customers ("look-alike" audiences). These activities are based on your consent (Article 6(1)(a) GDPR), which you can withdraw via our cookie banner or by using the opt-out tools listed in the "Opting-Out" section.
- We do not make decisions that produce legal or similarly significant effects about you solely by automated means within the meaning of Article 22 GDPR. Account suspensions, content removals, and similar enforcement actions are reviewed by humans before taking effect.
- Generative AI features process your prompts and Customer Content to produce Generated Output. This is performance of the contract you entered into by using the Services and is not "profiling" of your personal traits — see the next section for details.
Customer Content and AI Generation
The Services let you generate images, videos, voiceovers, and other media using third-party AI models. To do this, we transmit your prompts, uploaded reference materials, and other inputs ("Customer Content") to the AI providers listed in the subprocessor table. These providers process the data only to return the requested generation.
No training of foundation models on your data. We do not use your Customer Content, prompts, or Generated Output to train our own AI models. We require contractual or product-level commitments from third-party AI providers that data submitted via API is not used to train their public foundation models, and we use providers' "no-training" data settings where available. We cannot guarantee third-party behaviour beyond their published policies.
Storage. Customer Content and Generated Output are stored in our Cloudflare R2 buckets under our control. Generated Output is associated with your Account so you can re-access it. You may delete individual assets or your entire Account at any time; deletions propagate to backups within a reasonable period.
Sensitive data. Please do not upload special-category personal data (Article 9 GDPR — e.g. health, biometric, racial/ethnic, religious, sexual orientation data) or government-issued IDs to the Services. The Services are not designed to process such data.
How do we use your Data?
We only use your personal data for the following purposes:
- to provide you with the Services that you requested;
- to promote the use of our Services to you;
- to analyze and improve our Services;
- to send you informational and promotional content that you may subscribe to or unsubscribe;
- to bill and collect payment for Services ordered;
- to send you notifications, including notifications on change of our Services;
- to communicate with our Customers about our Website and Services and provide customer support in response to their inquiries;
- to enforce compliance with our Terms and applicable law;
- to protect our rights and safety as well as the rights and safety of our customers and third parties;
- to meet legal requirements;
- to provide information to representatives and Service Providers;
- to prosecute and defend a court, arbitration, or similar legal proceeding;
- to respond to lawful requests by public authorities, including to meet national security or law enforcement requirements;
- to provide suggestions about products or services that you may be interested in and which you may opt out;
- to transfer your information in the case of a sale, merger, consolidation, liquidation, reorganization, or acquisition.
What are your rights?
- Right of access to personal data processed by us (Article 15 of the GDPR).
- Right to rectify entrusted personal data, including their correction (Article 16 of the GDPR).
- Right to delete personal data from our systems, the so-called "right to be forgotten", if in your opinion there are no grounds for us to process your data, you can request that we delete it (Article 17 of the GDPR).
- Right to restrict the processing of personal data. You may request that we restrict the processing of personal data only to their storage or to the performance of activities agreed with you, if we have incorrect data about you or process them unjustifiably; or you do not want us to delete them because they are necessary for you to establish, pursue or defend claims; or for the duration of the objection to data processing (Article 18 of the GDPR).
- Right to data portability. You have the right to receive from us, in a structured, commonly used, and machine-readable format (e.g. ".csv" format), personal data relating to you held by us on the basis of a contract or consent. This right will be granted when we have data in electronic format. If data is only in paper form, you will not be able to use this right. You can commission us to transfer this data directly to another entity (Article 20 of the GDPR).
- The right to withdraw consent to the processing of personal data. At any time you have the right to withdraw consent to the processing of personal data that we process on the basis of consent in accordance with Article 7(3) GDPR. The withdrawal of consent shall not affect the lawfulness of any processing performed on the basis of your consent prior to its withdrawal. Withdrawal of consent occurs by sending an e-mail to info@shortodella.com.
- Right to object. You may object to the processing of your data if the basis for the use of data is our legitimate interest in accordance with Article 21 GDPR. In such a situation, after examining your request, we will no longer be able to process the personal data subject to the objection on this basis, unless we demonstrate the existence of legitimate grounds for the processing that are considered to override your interests, rights, and freedoms.
- Right to lodge a complaint with a supervisory authority. If you believe that our processing violates the GDPR, you may lodge a complaint with the supervisory authority of the EU member state of your habitual residence, place of work, or place of the alleged infringement. For Polish residents this is the President of the Personal Data Protection Office (Prezes UODO, https://uodo.gov.pl/).
Changes to the Privacy Policy
We may amend this Privacy Policy from time to time. Use of information we collect now is subject to the Privacy Policy in effect at the time such information is used. If we make major changes in the way we collect or use information, we will notify you by posting an announcement on the Website or sending you an email.
Business transfers
If the Company merges with, is acquired by, or sells all or a portion of its assets to another company or organization, your personal data may be disclosed to our advisers and to any prospective purchaser (and their advisers), and may be among the assets transferred. In any such transfer, the recipient will be bound by terms no less protective than this Privacy Policy, and we will notify you of the change in controllership.
Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Indicative retention periods:
- Account data and Customer Content — for the lifetime of your Account, plus a short grace period (typically up to 30 days) after deletion to allow recovery from accidental deletions; backups are purged within a reasonable additional period.
- Generated Output — stored under your Account until you delete it or your Account.
- Billing and tax records — retained for the period required by Polish accounting and tax law (currently 5 years from the end of the relevant fiscal year).
- Application logs (wooLog) — rolling window of approximately 60–90 days.
- Marketing-consent records — until you withdraw consent, plus a short audit trail proving the legal basis.
Our primary databases are located in the European Union. Some subprocessors process data in other regions as described above; in those cases the safeguards listed in the "International transfers" section apply.
Contact
If you need additional information about how we protect your personal data, or would like to exercise any of your rights under the GDPR, please contact us at: info@shortodella.com. We will respond within one (1) month, as required by Article 12(3) GDPR. If your request requires more time due to its complexity, we will inform you.