Privacy Policy

Last updated July 24, 2026

This Privacy Policy explains how Shape ("Shape," "we," "us," or "our") collects, uses, discloses, and protects personal data when you use the Shape desktop application, website at useshape.org, dashboard, APIs, documentation, and related services (collectively, the "Service"). By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.

1. Controller and contact

Shape is the controller of personal data processed in connection with the Service, except where we process data solely on behalf of an organization under a separate agreement. Privacy questions and data-subject requests may be sent through our contact page.

2. Data we collect

2.1 Account data

When you create an account we collect identifiers such as name, email address, password hash or passkey credentials, and authentication events. If you sign in with GitHub, we receive profile identifiers those providers share with us subject to your settings with them.

2.2 Billing data

For paid plans we process subscription tier, credit balances, invoices, and limited payment metadata through Stripe. We do not store full payment card numbers on Shape servers. Stripe acts as an independent payment processor under its own privacy policy.

2.3 AI and usage data

When you use Shape Cloud AI, we process prompts, selected context you choose to include, model selections, conversation history stored for your account, token counts, and related metering needed for delivery, billing, abuse prevention, and support. Aggregate usage metrics power your dashboard.

2.4 Device and security signals

To protect accounts we may process a stable device identifier from the desktop app, IP address, user agent, approximate location derived from IP, and recent login or step-up verification events. These signals are used for fraud prevention and security, not advertising.

2.5 Website analytics cookies

On the website we use a session cookie to keep you signed in. If you accept analytics in our cookie banner, we also use PostHog with localStorage and cookies to measure page views and product usage. Analytics are off until you accept. You may reject analytics cookies; essential session cookies may still be required for signed-in features.

2.6 Desktop telemetry (opt-in)

Shape Desktop does not transmit your source code unless you start an AI feature that sends prompts or selected context. Product telemetry in the IDE is off by default. If you enable it in Settings, we collect anonymous product events such as app launches and feature usage. Chat content and source code are not included in that telemetry stream.

3. How we use data

We use personal data to:

  • Provide, operate, secure, and improve the Service
  • Authenticate users, prevent abuse, and enforce our Terms and EULA
  • Process payments, credits, and invoices
  • Deliver AI features through our proxy and model providers
  • Communicate service, security, and (where permitted) product messages
  • Comply with law and respond to lawful requests

Legal bases may include contract performance, legitimate interests (security, product improvement with safeguards), consent (where required for cookies or optional telemetry), and legal obligation.

4. AI providers and training

Shape Cloud AI routes requests through Shape's servers to model providers via OpenRouter and similar infrastructure. Prompts and context you submit are processed by those providers to generate outputs. Provider policies apply to data they process. We do not sell your content. Unless you explicitly opt in to a training or improvement program described in the Service, we do not use your Content to train foundation models for general third-party use.

5. Sharing and sub-processors

We share personal data with vendors that help us run the Service, under contractual obligations appropriate to the processing. Current categories include:

  • Hosting and database (for example Neon)
  • Payments (Stripe)
  • Transactional email (Resend)
  • AI inference routing and model providers (OpenRouter and underlying providers)
  • Product analytics when consented (PostHog)
  • Optional CMS hosting for marketing content (Sanity)

We may disclose data if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale, subject to appropriate safeguards.

6. Retention

We retain account and billing records for as long as your account is active and as needed for legal, tax, and fraud-prevention purposes. Conversation history and usage records are retained to provide the Service and metering. When you delete your account we delete or anonymize personal data within a reasonable period, typically within 30 days, except where retention is required by law or for legitimate residual purposes such as dispute resolution.

7. Security

We implement administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, access controls, and build attestation for official Shape Cloud AI clients. No method of transmission or storage is fully secure, and we cannot guarantee absolute security.

8. International transfers

We may process data in the United States and other countries where we or our processors operate. Where required, we use appropriate transfer mechanisms such as standard contractual clauses.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or export personal data, to object to certain processing, and to withdraw consent where processing is consent-based. You may also lodge a complaint with a supervisory authority. To exercise rights, use dashboard account controls where available or contact us through the contact page. We may need to verify your identity before fulfilling a request.

California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, and correct personal information, and to opt out of "sale" or "sharing" as defined by those laws. We do not sell personal information for money. If our analytics practices are considered "sharing" for cross-context behavioral advertising in your jurisdiction, you can reject analytics cookies and contact us to exercise opt-out rights.

10. Children

The Service is not directed to children under 13 (or the higher age required in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps to delete it.

11. Changes

We may update this Policy from time to time. We will revise the date above and, for material changes, provide additional notice through the Service or by email where appropriate. Continued use after changes become effective constitutes acceptance of the updated Policy.

12. Related documents

Please also review our Terms of Service and End User License Agreement.