Legal
AI Usage Notice
A plain-language summary of when and how we call AI on your behalf.
01
One-page summary
Our promise
We call AI only when you ask, send the minimum data, and never use your content to train AI models. Calls to upstream providers run under their commercial API terms, which prohibit training on your content.
02
When AI is called
External AI is called only when you take an explicit action:
- Typing a request into the AI dock and sending it.
- Asking for an image in the AI dock's Image mode — a new one, or an edit of the image you selected.
Routine editing — moving objects, changing colours, saving — never invokes AI.
03
What data is sent
We send the minimum data needed to fulfil your request. Every request travels through SSHOW's server to the provider — your browser never calls a provider directly. Per feature:
- “AI edit” — your prompt, plus the layout of the document you're editing (object names, positions, text, styles), your current selection, and the last few completed turns of your conversation in that document (kept only in your browser, never stored on our server).
- “Image generation / editing” — your prompt and, when editing, a downscaled copy of the selected image.
Direct identifiers like your username or email are not transmitted. Note, however, that text or images you author may themselves contain personal information.
04
Training and retention
- We do not train any model on your content.
- Calls to upstream providers run only over commercial API paths whose terms prohibit training on your content.
- We keep the prompts you write and usage records (feature, counts, token counts, cost, time, request id) for up to 400 days (about 13 months) to improve quality, bill accurately, and prevent abuse; they are deleted automatically after that. These records never include your document, your images, or the AI's output.
- Stored prompts are read only by authorised staff and only when necessary — for example to investigate abuse — and every access is written to an audit log.
- Some providers retain a short safety-monitoring log (typically 30 days). See the linked provider policies in §8.
05
Limits of AI output
AI output may be inaccurate or biased. We recommend:
- Treat AI output as a draft — you make the final decision.
- Do not rely on AI output for medical, legal, or financial decisions.
- Verify any AI-generated content for possible IP or trademark conflicts before reuse.
06
Your rights & opt-out
- You can stop using AI features at any time. Core SSHOW (editing, playback, sharing) keeps working.
- A single switch under Settings → Privacy & AI (post-beta) disables all AI calls for your account.
- We do not make decisions that significantly affect you based solely on automated processing.
07
Minors
SSHOW is not directed at children under 14 (or under 13 in the US under COPPA), and the same threshold applies to AI features. Users between 14 and 19 see additional safety guidance around AI output.
08
Model providers
| Provider | Use | Region | Retention | Policy |
|---|---|---|---|---|
| OpenAI, L.L.C. | AI edit assistance & image generation | USA | Typically up to 30 days (abuse monitoring) | openai.com/policies |
| Anthropic, PBC | AI edit assistance | USA | Typically up to 30 days (abuse monitoring) | anthropic.com/legal |
| Google LLC | AI edit assistance & image generation (Gemini) | USA (may process in other countries) | Typically up to 30 days (abuse monitoring) | policies.google.com/privacy |
This list may change. We update this page and announce changes at least 7 days before they take effect.
09
External AI apps you connect
You can connect an external AI app (for example claude.ai) to your SSHOW account yourself (the MCP connector). Such a connection is created only when you explicitly allow it while signed in, and the app you allowed can then read the contents of the projects you have open in an editor at that moment (scenes, objects, text, screenshots) and edit them as you. Your account username and the names of those open projects are sent along with it. The full list of what is disclosed is tabulated in §5 of our Privacy Policy.
- Data that flows to a connected app is governed by that app provider's own terms and privacy policy. It is a third party separate from our model providers (Section 8), and we do not control how it stores the data or whether it trains on it.
- We only relay tool calls to your editor and do not store project contents for this feature. What remains is the grant record shown in your profile — the app's name, the scopes you granted, when you granted it and when it was last used — and a security record (audit log) noting that you allowed or revoked it.
- You can disconnect an app at any time under Profile → Connected AI apps, and its access ends immediately. Deleting your account removes every connection with it.
10
Changes
- v1.4 — 2026-09-04 — Section 9 now spells out what is disclosed (including your username and the names of open projects) and which records remain, and links to the table in Privacy Policy §5.
- v1.3 — 2026-09-04 — New section on external AI apps you connect (MCP connector): the contents of open projects may be sent to a third-party app under your explicit permission.
- v1.2 — 2026-09-03 — AI dock: edit requests now include the document's recent conversation turns (kept in the browser, not stored server-side).
- v1.1 — 2026-08-31 — Switched to the server gateway: transmission path, per-feature data items, prompt and usage-record retention (up to 400 days), and the provider table updated.
- v1.0 — 2026-04-25 — Initial version.