Privacy Policy

Last updated 8 October 2026

Pashoot holds images of a personal kind, so this policy is specific about what is stored, who can reach it, how long it stays, and how to remove it.

1. What we collect

Account details. Your email address and a hashed password. We never store your password in a readable form.

What you create. The characters you define, the prompts and choices you make, and the images and short clips generated from them.

Usage records. Which jobs you ran, what they cost, and whether they succeeded. These are identifiers and amounts. Our analytics records are restricted by the database itself to a fixed list of fields holding short scalar values, so the content of your prompts and images cannot enter them.

Technical records. Ordinary server logs, including IP address and timestamps, kept for security and debugging.

We do not collect payment card details. A payment processor handles those directly.

2. What we use it for

  • Operating the service: generating images and showing them back to you.
  • Screening prompts and output for prohibited content.
  • Reviewing content our screening holds back, and acting on reports, so that rules are applied by a person and not only by an automated system.
  • Helping you when you ask for support.
  • Metering credits and preventing abuse.
  • Security, debugging, and meeting legal obligations.

We do not train models on your content, we do not sell it, and we do not use it for advertising.

3. Who can see your images and clips

Your images and clips are private to your account. They are stored in a private bucket and served only to your signed-in session: every request is checked against your account before a file is sent. There is no public URL for your content, and no sharing feature.

Access is enforced by the database rather than by the application alone: each row carries an owner, and the database refuses reads from anyone else. This means a bug in the application cannot by itself expose another user's images.

Staff access. Pashoot's administrator can view an account's characters, images and clips, through an internal dashboard on its own address that only that one account can sign in to. We do this only where it is needed to:

  • review content our screening has held back before it is shown or blocked;
  • investigate a report or suspected abuse of the rules;
  • help you, when you contact us for support;
  • comply with a legal obligation.

Every look is recorded. Opening an account, its library or any single image or clip writes an entry to an internal audit log — who looked, at whose account, and when — and the log cannot be edited afterwards. Changes made from the dashboard, such as adjusting credits or suspending an account, are recorded the same way. Staff cannot sign in as you, and cannot see your password.

4. Who we share it with

We use third parties to run Pashoot. Each receives only what its job needs:

  • Hosting and database. Stores your account, characters and images.
  • GPU compute. Receives the prompt and, for scenes and clips, your character's portrait or the picture being animated. It returns the result and does not retain it.
  • Content screening. Receives generated images, and still frames from clips, to classify them.
  • Payments. Handles card details directly; we receive only the result.

We may disclose information where legally required. Where a request appears invalid or overbroad we will challenge it.

5. How long we keep it

Characters and images are kept until you delete them or close your account. Deleting a character removes it and refuses new images against it.

Deletion is a two-step process. Content is first marked deleted and immediately disappears from the product. A daily job then removes the underlying files, within 7 days of the deletion. Deleting a character also removes the images made under it and any trained likeness, on the same schedule.

Closing your account skips the wait: the files go at the same time as the records. Backups are overwritten on their own cycle, so a short window exists where deleted content still sits in a backup.

Records of payments and credits are kept for as long as tax and accounting law requires, even after an account is closed. These are amounts and dates, not content.

6. Your rights

Depending on where you live, you may have the right to:

  • Get a copy of what we hold about you. Settings has it, as a single zip.
  • Correct anything inaccurate.
  • Delete your account and its content. Settings has this too, and it removes the files themselves rather than hiding them.
  • Object to or restrict certain processing.
  • Complain to your data protection authority.

Export and deletion are available in the product rather than by request, because a right you have to ask for is weaker than one you can exercise yourself.

7. Security

Content travels over encrypted connections and is stored in a private bucket. Access rules are enforced in the database, and our background workers must still name the owner of every row they touch.

No system is perfectly secure. If a breach affects your personal data we will tell you and the relevant authority where the law requires it.

8. Children

Pashoot is only for people aged 18 or over and is not offered to anyone under 18. We do not knowingly collect information from children. If we learn that an account belongs to a minor we close it and delete its content.

9. International transfers

Our providers operate in several countries, so your data may be processed outside where you live, including compute located in the European Union. Where required we rely on recognised transfer mechanisms such as standard contractual clauses.

10. Changes

We will post changes here with a new date at the top, and tell you directly if a change materially affects how your content is handled.

11. Who to contact

For anything about your data — a copy of it, a correction, deletion, or a complaint about how it has been handled — write to privacy@pashoot.co. For everything else, support@pashoot.co.

Most of what people write in about is faster from inside the product: Settings has a one-click export of everything we hold and a way to close the account, and both act immediately rather than waiting on a reply.

This document was drafted for Pashoot and has not been reviewed by a lawyer. Before taking payments or admitting users beyond the invited pilot, have it reviewed against the jurisdictions you operate in and the requirements of your payment processor.