Skip to main content

Privacy Policy

Last Updated: June 3, 2026

This Privacy Policy explains how Shine ("Shine," "we," "our," or "us") collects, uses, and protects your information when you visit our website, use our platform, upload content, or interact with our services.

We built Shine to help companies create, manage, and distribute customer proof: stories, claims, interviews, and review-ready assets. We maintain strict respect for user privacy and consent.

1. Information We Collect

1.1 Information You Provide

We collect information you voluntarily provide, including:

  • Account information: name, email, password, company, role.
  • Brand settings: logos, fonts, color palettes, legal text.
  • Interview content: uploaded recordings, transcripts, metadata.
  • Claims & approvals: edits, comments, structured data inputs.
  • Consent data: consent scopes, revocation events, timestamps.
  • CRM-related inputs — personas, industries, tagging metadata.

1.2 Automatically Collected Information

When using the site or app, we may automatically collect:

  • Device and browser data
  • IP address
  • Usage logs (pages viewed, actions taken)
  • Cookies or similar tracking technologies (see Section 8)

1.3 Third-Party Integrations

If you connect Shine to external tools (CRM, Zapier, storage platforms, etc.), we may access limited data necessary to operate features you enable.

We never access external systems without your explicit authorization.

1.4 YouTube Publishing (Google API Services)

If you connect your YouTube channel, Shine requests only the youtube.upload permission, used exclusively to publish video clips you choose to your channel. Shine does not read, list, modify, or delete any videos on your channel, and requests no other YouTube data.

To perform uploads you initiate, we store an encrypted authorization token and the ID and title of the channel returned when you first publish. You can disconnect at any time in Shine under Settings › Integrations, or revoke Shine’s access directly at Google Account permissions; on disconnect we delete the stored token.

Shine’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

2. How We Use Your Information

We use your information to:

  • Provide and maintain the Shine platform
  • Process transcripts, generate claims, and create assets (PDFs, videos, social tiles, review text)
  • Power the Proof Ledger (claims, metadata, evidence, permissions)
  • Support customer workflows (invitations, approvals, reminders)
  • Improve product performance, accuracy, and reliability
  • Provide customer support and troubleshooting
  • Communicate updates, new features, and relevant service information
  • Ensure security, detect misuse, and comply with legal requirements

We do not sell personal information.

Legal bases (GDPR Art. 6). We rely on: performance of our contract with you, to provide and maintain the platform; our legitimate interests, to secure the service, prevent misuse, and improve product performance; compliance with a legal obligation, where the law requires it; and your consent, for analytics and marketing cookies — which you can withdraw at any time.

3. How We Handle Customer Content

Customer content includes recordings, transcripts, claims, approvals, and generated assets ("Customer Content").

3.1 Ownership

You retain full ownership of Customer Content.

We only process it to provide the Shine service.

3.2 Consent

Our platform includes built-in:

  • Consent prompts
  • Consent scope selection
  • Timestamped logs
  • Support for revocation

If a participant revokes consent, we flag all dependent assets and prevent further use unless you obtain new permissions.

3.3 AI Processing

Customer Content may be processed using AI models for:

  • Transcription
  • Claim extraction
  • Summaries
  • Text generation
  • Metadata inference

We do not use Customer Content to train general-purpose AI models.

4. How We Share Information

We may share information with:

  • Infrastructure: Supabase (database, authentication, serverless functions)
  • Payments: Stripe (payment processing, subscription management)
  • Communications: Resend (transactional email delivery)
  • Analytics: Google Analytics 4 and Microsoft Clarity
  • AI providers used strictly as processors, not data owners
  • Legal authorities, if required by law

We never sell your data.

All vendors must meet our security and confidentiality standards.

5. Data Retention

We retain your data only as long as needed to deliver the Services, comply with legal obligations, resolve disputes, or enforce agreements. Specific defaults:

  • Account data — retained for the lifetime of your account. Upon account closure or written request, we remove your personal data within 30 days, except where retention is required by law (e.g., billing records for tax purposes, typically up to 7 years).
  • Interview recordings and transcripts — retained for the lifetime of the parent account. When you delete a recording, it enters a 30-day recycle bin and is permanently purged thereafter.
  • Email and system logs — retained for up to 90 days for deliverability troubleshooting and security forensics, then purged.
  • Marketing & sales contacts — waitlist, newsletter, and quote requests are retained for up to 24 months from your last interaction, then deleted, unless you become a customer or ask us to remove you sooner.
  • Job applications — applicant details and résumés are retained for up to 12 months after a decision, then deleted, unless you ask us to remove them sooner.
  • Aggregate analytics — retained indefinitely in anonymized, non-identifying form.

You may request deletion at any time (see Section 7).

6. Data Security

We implement administrative, technical, and physical safeguards including:

  • Encrypted storage (SSL/TLS in transit, encryption at rest)
  • Access controls and role-based permissioning
  • Audit logs and anomaly detection
  • Secure media handling and deletion

No system is 100% secure, but we actively mitigate risk and respond quickly to incidents.

Breach notification. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected customers and applicable regulators without undue delay, and in any event within 72 hours of awareness, as required by GDPR Article 33.

7. Your Rights

If you are in the EEA or UK, you have the following rights under the GDPR; similar rights apply under other laws such as the CCPA. You have the right to:

  • Access your data
  • Correct inaccurate information
  • Request deletion
  • Object or restrict processing
  • Export your data
  • Opt out of certain communications
  • Withdraw consent at any time, where processing is based on consent (this does not affect processing already carried out)
  • Lodge a complaint with your local data protection supervisory authority

Authenticated Shine users can self-serve a portable JSON export of their account data directly from the application. For all other requests — including erasure, correction, and respondent-side requests from people who were interviewed — contact us at hello@shine.studio. We respond within 30 days as required by GDPR Article 12(3).

8. Cookies & Tracking

We use cookies and similar technologies to:

  • Keep you logged in
  • Improve performance and analytics
  • Understand how users interact with the platform

You may disable cookies, but some features may not function properly.

9. International Data Transfers

If you use Shine from outside the United States, your data may be transferred to and processed in U.S.-based systems and the systems of our subprocessors. For transfers from the European Economic Area, United Kingdom, or Switzerland, we rely on the applicable European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, the Swiss Federal Data Protection and Information Commissioner's adequacy framework, and equivalent transfer mechanisms — as appropriate for the relationship with each subprocessor.

Where supplementary measures are warranted under Schrems II, we apply them — for example, encryption in transit and at rest, access controls, and contractual commitments to challenge access requests from public authorities where legally permitted.

For the full list of subprocessors and where each is located, see our Subprocessors page. Customers may request our Data Processing Agreement at any time by emailing hello@shine.studio.

10. Children's Privacy

Shine is not designed for or targeted at children under 16. We do not knowingly collect information from children.

11. Changes to This Policy

We may update this Privacy Policy occasionally. If changes are material, we will notify you via email or platform notice.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the following rights. The categories of personal information we collect, the sources, the purposes, and the parties we disclose to are described in Sections 1, 2, and 4.

  • Know & access — request the specific pieces and categories of personal information we have collected about you.
  • Delete — request deletion of personal information we collected from you.
  • Correct — request correction of inaccurate personal information.
  • Opt out of sale/sharing: we do not sell your personal information for money. Because our website uses third-party analytics and session-replay tools (Google Analytics, Microsoft Clarity), some activity may constitute "sharing" for cross-context behavioral advertising under the CPRA. You can opt out at any time via Do Not Sell or Share My Personal Information, and we honor the Global Privacy Control (GPC) browser signal as a valid opt-out.
  • Limit sensitive information — we do not use sensitive personal information for purposes that trigger the right to limit.
  • Non-discrimination — we will not discriminate against you for exercising any of these rights.

To exercise these rights, email hello@shine.studio. You may use an authorized agent to submit a request on your behalf; we will verify your identity before fulfilling it.

13. Contact Us

For questions, requests, or privacy concerns: