Legal
Privacy Policy
This policy explains what personal data SSHOW collects, why we collect it, and the rights you have.
Revisions
v1.5 (takes effect 26 September 2026) — Live service status will be kept as a usage record. Before this revision (v1.4) it was deleted automatically 60 seconds after the last signal. After it, the live service status of a signed-in user is kept together with the time of use and deleted automatically 90 days after it was collected, or immediately when you delete your account. We use it to see what you were using when you contacted us or reported an error, to investigate incidents and to look into abuse, and only authorised staff can see it. The time of use is added to what we collect (§2), and how we use it (§3) and how long we keep it (§4) are updated; nothing else changes. Viewers of a play link and signed-out visitors are still not tied to an account, and the record is never disclosed to third parties or used for advertising or profiling. If you do not want this processing, you can object under §8 by writing to [email protected].
v1.4 (in effect 19 September 2026) — A new live service status signal, used to run the service, is now set out under what we collect (§2), how we use it (§3) and how long we keep it (§4). It covers the kind of screen you have open, the ID and mode of a project open in the editor, and your platform and app version. Its retention changes in v1.5 (above).
v1.3 (in effect 4 September 2026) — New clauses for the external AI apps you connect to your own account (the MCP connector): what is disclosed and to whom (§5), international transfers (§7), what we collect (§2), how long we keep it (§4), how to revoke (§8), and how this differs from our own AI features (§11). Because a connection exists only if you allow it yourself on a consent screen, and consent is taken at that moment, nothing changes for anyone who does not connect an app — so this revision takes effect on announcement.
v1.2 (takes effect 1 October 2026) — alongside a new audit trail for administrative actions and authentication events, section 4 states the retention periods required by Korea’s personal-data safeguards notice: operator access records (1 year) and access-rights change history (3 years). These records rest on a statutory duty (PIPA Art. 15(1)2) rather than your consent, and the retention period for user sign-in logs (3 months) is unchanged.
Questions: [email protected].
01
Scope & definitions
SSHOW (the “Service”) respects your privacy. This policy applies to s.show, our desktop and mobile apps, and any related services we operate. “Personal information” means information that identifies, relates to, or can reasonably be linked with an individual.
02
Information we collect
| Source | Required | What we collect |
|---|---|---|
| Email signup | Yes | Email, username, password (one-way hashed), signup time |
| Social signup | Yes | Provider ID, email, display name from Google or Apple |
| Profile | Optional | Nickname, bio, avatar |
| Two-factor auth | Optional | TOTP secret (encrypted), passkey public keys, hashed backup codes |
| Your content | Yes | Project files, uploaded media, fonts, audio, text, motion data |
| Feedback | Optional | The comment you send, an optional screenshot of your current screen, diagnostic context (browser user-agent, OS, app and engine version, viewport, theme, language, page path), and your account ID and email |
| Connected AI apps | Optional | The client ID and the name the app registered, the scopes you granted (read / edit projects), hashes of the access and refresh tokens (we never store the tokens themselves), and when the grant was created and last used |
| Access metadata | Auto | IP, user-agent, session ID, cookies, device IDs in apps |
| Live service status | Auto | The kind of screen you have open (site, studio, editor, play and so on), the ID and mode (edit / play) of a project open in the editor, your platform (web, macOS, Windows, Linux, iOS, Android) and app version, and when you used it. Sent only while the screen is visible, and recorded without your IP address or user-agent. When you are signed in it is tied to your account and kept as a usage record (see §4 for how long) — except that viewers of a play link are never tied to an account, and the site page a signed-in user is reading is not recorded. Signed-out visitors are counted only by a random identifier that is created afresh on every page load and never stored on the device; a signed-out app sends nothing. |
| Payments (post-beta) | Yes | Handled by our payment processor; we receive only transaction ID, amount, and timestamp |
Things we never collect
National identifiers (e.g. Korean RRN, US SSN), precise geolocation, race, political views, religion, biometric templates, or any other special-category data.
03
How we use information
- Account & authentication — sign in, 2FA, password reset, abuse prevention.
- Service delivery — saving and syncing projects, team and space collaboration, share links, playback.
- Customer support — responding to enquiries, feedback, and bug reports (including replying by email where needed); sending notices.
- Security — anomaly detection, blocking unauthorised access, audit logs.
- Improvement — usage analytics, preferring pseudonymous or aggregate data.
- Operations — seeing who is live on each platform right now, choosing when to deploy or run maintenance, investigating incidents, answering support requests (checking what you were using when you contacted us or reported an error) and looking into abuse. The screens a signed-in user has open, and the record of them (“live service status”), are visible only to authorised staff and are never used for advertising, marketing contact or profiling; usage statistics are built only from aggregates that are not tied to an account. Our legal basis under the GDPR is our legitimate interest in operating and supporting the service (Art. 6(1)(f)), and you can object to it at any time (§8).
- Incident response & quality — reproducing an error you reported, diagnosing a service failure, and reviewing a reported terms violation. Only within the limits set out in “Access to your content” below.
- Legal compliance — to meet retention obligations under applicable law.
Access to your content
We may open a project you created, to the minimum extent needed, only in these cases:
- to reproduce and diagnose an error or failure you reported;
- to find the cause of a service incident such as a failed save, sync, or render;
- to review a report of a terms violation, or to answer a lawful request under applicable law.
Access is limited to staff who need it for their work. Who opened which project, and when, is recorded automatically in our audit log and kept for one year under Korea’s personal-data safeguards notice (see §4).
Content we open is never used for advertising, profiling, or AI training (see §11 and our AI Usage Notice) and is not disclosed to third parties (see §5). You can ask us about the access history for your own projects using the contact in §14.
Legal bases (GDPR Art. 6): performance of contract (1, 2, and 7 where you reported the issue), legitimate interests (3, 4, 5, 6, 7), consent (marketing emails), legal obligation (8).
04
Retention
We delete personal data without undue delay once its purpose is fulfilled, except where law requires longer retention.
| Data | Period | Reason |
|---|---|---|
| Account info (active) | Until account deletion | Consent / contract |
| Account info (deleted) | Removed immediately | Consent / contract |
| Abuse records | 1 year after deletion | Dispute & legal duty |
| User sign-in logs | 3 months | Communications law |
| Live service status | 90 days from collection (then deleted automatically); deleted immediately when you delete your account | Operating the service (PIPA Art. 15(1)(4)) |
| Connected AI app grants | Access token 1 hour; refresh token 30 days, reissued with a fresh 30-day period each time the app refreshes — a connection lasts until you revoke it or it goes 30 days without a refresh. Deleted immediately when you disconnect or delete your account | Consent |
| Connection authorization codes | 10 minutes, deleted the moment they are used once | Consent |
| Operator access records | 1 year | PIPA Art. 29 & safeguards notice |
| Access-rights change history | 3 years | PIPA safeguards notice |
| E-commerce records | 5 years | Consumer protection law |
05
Sharing with third parties
We do not sell or rent your personal data, and we do not share it with third parties except: with your prior consent, when required by law or by a valid legal process, or in pseudonymised/anonymised form for statistics or research.
External AI apps you connect (the MCP connector)
One case works this way in practice: if you connect an external AI app to your own account, we disclose the following to that app, within the scope you allowed on the consent screen. This is not processing carried out on our behalf (§6) but a disclosure to a third party made on your consent.
| Item | Detail |
|---|---|
| Recipient | The operator of the AI app you allowed (for example claude.ai or ChatGPT). The consent screen shows the name that app registered for itself and the address it returns to; we do not verify that the name is genuine. |
| Purpose | Reading and editing your projects, as you instruct the app |
| Data disclosed | Your account username; the ID, name and window type (web or app) of the projects you have open at that moment; the project overview the app requests (canvas size, scene list, current selection, variables, fonts) and the contents of scenes and objects, including text; and screenshots rendered in your own browser or app (PNG) |
| Retention by the recipient | Governed by that app's own privacy policy, which we do not control. Disclosure stops from the moment you disconnect it. |
A connection exists only if you allowed it yourself while signed in, and you can end it at any time under Profile → Connected AI apps (§8). Disclosure happens when the app calls a tool, and only for the projects you have open in an editor at that moment. We do not store the tool calls or their results; only the edits the app makes are saved to your project, exactly as your own edits are. Full detail is in Section 9 of our AI Usage Notice.
06
Sub-processors
| Processor | Purpose | Region |
|---|---|---|
| Oracle Cloud Infrastructure | Cloud hosting (servers, storage, DB) | Chuncheon (ap-chuncheon-1) |
| Cloudflare, Inc. | DNS, CDN, DDoS protection | Global edge |
| Google LLC | OAuth (Google), transactional email infra | USA |
| Apple Inc. | OAuth (Sign in with Apple) | USA |
| OpenAI, L.L.C. / Anthropic, PBC / Google LLC | Optional AI assistance (see §11) | USA |
An external AI app you connected yourself (§5) is not one of these sub-processors. Even when the same company runs it, a disclosure through the connector is your choice, not processing we commissioned.
07
International transfers
Some sub-processors operate outside your country. Transfers rely on Standard Contractual Clauses (EU/UK) and equivalent safeguards. Data in transit is protected by TLS 1.2+. You may decline international transfers, in which case some features (social sign-in, AI assistance, connecting an external AI app) may be unavailable.
If you connect an external AI app (§5), the items and the recipient are the ones listed there. The transfer happens each time the app calls a tool, over TLS 1.2+, to whichever country that app's provider runs its servers in — the United States for claude.ai and ChatGPT — and we do not choose it. How long the recipient keeps the data is governed by its own policy. The sub-processor safeguards above do not cover it. You can refuse by not connecting an app, or end it later under Profile → Connected AI apps; only the connector becomes unavailable, and editing, playback and sharing keep working.
08
Your rights
- Access, rectify, erase, restrict, or object to processing.
- Withdraw consent at any time, without affecting prior lawful processing.
- Export your projects in portable formats (.sshow, .json) — data portability.
- Disconnect an AI app you connected — under Profile → Connected AI apps. Revocation takes effect on that app's very next request, and deleting your account removes every connection.
- Lodge a complaint with your supervisory authority (e.g. KOPICO in Korea, your DPA in the EU).
Most rights can be exercised on the profile page. For anything else, write to [email protected]. We respond within 30 days.
09
Deletion
Electronic data is destroyed using techniques that prevent recovery (e.g. cryptographic erasure, secure overwrite). Paper records, if any, are shredded or incinerated.
10
Cookies & similar technologies
We use only the cookies needed to keep you signed in, remember your language, and validate security tokens. We do not use third-party advertising cookies. You can block cookies in your browser, though some features may stop working.
11
AI features & your data
Some features (text generation, image cleanup, motion suggestions) call external AI APIs (e.g. OpenAI, Anthropic, Google Gemini) only when you explicitly request them. We follow these rules:
- Only the data needed for the request is sent.
- We never use your content to train AI models, and we set the “no training” option on the providers we call ourselves. That setting does not apply to an external AI app you connected to your own account (§5), because those calls are not ours.
- When you connect an external AI app (§5), we only relay its tool calls to the editor you have open; we do not store the calls or their results, though the edits the app makes are saved to your project exactly as your own edits are. How that app stores your data, and whether it trains on it, is governed by its own policy and is outside our control.
- See the dedicated AI usage notice for full details.
12
Children’s privacy
SSHOW is not directed at children under 14 (or under 13 in the United States, per COPPA). If we learn that we have collected data from a child without proper consent, we will delete it promptly. If you are a parent or guardian, contact [email protected].
13
Security
- Passwords are stored only as one-way hashes (bcrypt, cost ≥ 12).
- All traffic is TLS 1.2+ in transit; sensitive fields (2FA secrets, etc.) are encrypted at rest.
- Access follows the principle of least privilege; admin actions are recorded in audit logs — including the content access described in §3.
- We run regular vulnerability reviews and notify you of any breach without undue delay, as required by law.
14
Contact
- Data protection officer — the proprietor, via the SSHOW privacy team
- Privacy enquiries — [email protected]
- General support — [email protected]
- Company — SSHOW (쑈), business registration no. 147-38-01484
- Registered address — 3101 CS77, 31F Tower A, 323 Incheon tower-daero, Yeonsu-gu, Incheon, Republic of Korea
15
Changes
- v1.0 — 2026-04-25 — Initial version (beta).
- v1.1 — 2026-06-25 — Added disclosure of in-app feedback data (comment, screenshot, diagnostics).
- v1.2 — announced 2026-08-31 / effective 2026-10-01 — Introduced the administrative audit log. Added retention periods for operator access records (1 year) and access-rights change history (3 years).
- v1.3 — announced 2026-09-04 / effective 2026-09-04 — New clauses for external AI apps you connect (the MCP connector): what we collect (§2), retention (§4), disclosure to the app (§5), how it differs from a sub-processor (§6), international transfers (§7), revocation (§8), and the relationship to our own AI features (§11). Section 14 now carries the registered company details.
- v1.4 — announced 2026-09-19 / effective 2026-09-19 — New “live service status” item for seeing who is live right now: what we collect (§2), how we use it (§3), and retention (§4).
- v1.5 — announced 2026-09-19 / effective 2026-09-26 — Live service status is kept as a usage record (90 days from collection; deleted immediately on account deletion): time of use added to what we collect (§2), how we use it (§3), retention (§4).
We will give at least 7 days’ notice of any change in advance on this page. Material or adverse changes will be announced 30 days in advance, and we will obtain new consent where required by law.