Toggle navigation

Legal

Imprint and Privacy Policy

Effective:


Imprint

Information pursuant to Section 5 of the German Digital Services Act (Digitale-Dienste-Gesetz, DDG):

Julian Vögel
Kurt-Schumacher-Straße 76
67663 Kaiserslautern
Germany

Email: [email protected]
Phone: +49 156 79687309

VAT identification number pursuant to Section 27a of the German VAT Act: DE457273026

Responsible for editorial content pursuant to Section 18(2) of the German State Media Treaty (Medienstaatsvertrag, MStV):

Julian Vögel, address as above.

We are neither willing nor obliged to participate in dispute-resolution proceedings before a consumer arbitration board.

Privacy Policy

1. Controller

The controller responsible for processing personal data through Shortly AI is:

Julian Vögel
Kurt-Schumacher-Straße 76
67663 Kaiserslautern
Germany

Email: [email protected]

No data protection officer has been appointed because the legal requirements for mandatory appointment do not currently apply.

This notice covers the consumer version of Shortly AI. It does not constitute a data processing agreement for a business customer that uses Shortly AI to process personal data on behalf of others.

2. Data we process

Depending on how you use Shortly AI, we process:

  • Account and authentication data: email address, name, profile image and profile-picture preferences, internal user ID, authentication method, session data, login events, IP address, and device or browser information. Profile information may be provided directly by you or obtained from a linked sign-in provider.
  • Chat and content data: prompts, conversations, model outputs, search queries, feedback attached to messages, uploaded files and images, file metadata, and generated titles. This content may include personal data if you choose to enter it.
  • Subscription and billing data: selected plan, subscription status, customer and subscription identifiers, billing periods, transaction status, and information needed to reconcile entitlements. Full payment-card details are handled by the checkout and payment provider, not stored by Shortly AI.
  • Usage and operational data: models and features used, timestamps, token and cost information, quota reservations, technical identifiers, error and security logs, and pseudonymous traces used to operate, secure, troubleshoot, and improve the service.
  • Communications: support requests, feedback emails, and the information you include in them. When you use the authenticated support form, we associate the request with relevant account information, such as your account email and plan, so that we can identify, respond to, and handle your request.
  • Marketing data: email address, subscription preferences, campaign delivery data, and opt-out status if you subscribe to marketing messages.
  • Website and delivery data: request metadata, IP address, security events, and aggregate performance and traffic measurements generated when Cloudflare delivers the website.

We generally receive this data from you, your device, the identity provider you choose, our service providers, or from use of Shortly AI itself.

3. Purposes and legal bases

PurposeLegal basis
Provide and administer Shortly AIArticle 6(1)(b) GDPR (contract and pre-contractual steps)
Manage billing, communications, and customer serviceArticle 6(1)(b) GDPR
Comply with legal obligationsArticle 6(1)(c) GDPR
Protect the service and enforce or defend rightsArticle 6(1)(f) GDPR (legitimate interests in a secure and reliable service)
Analyse, maintain, and improve the serviceArticle 6(1)(f) GDPR (legitimate interests in operating and improving the service)
Send marketing messagesArticle 6(1)(a) GDPR (consent), where consent is required; you may withdraw it at any time

Where processing is based on legitimate interests, you may object for reasons arising from your particular situation. We will then stop the processing unless we demonstrate compelling legitimate grounds or need it for legal claims.

4. Prompts, uploads, and AI processing

Shortly AI sends the content necessary to process your request to the relevant AI or search service. Depending on the feature or selected model, processing may involve one or more of the providers listed below and their authorised subprocessors. The selected model and its creator are shown in the product.

Shortly AI is not designed as a repository for bulk personal data, passwords, authentication secrets, government identifiers, payment-card data, medical records, or similarly highly sensitive information. Please do not submit unnecessary personal data, special-category data under Article 9 GDPR, criminal-offence data, or another person's confidential information. Only submit personal data when you have the right to do so and it is genuinely necessary for your request. If you include personal data in a prompt, it will be processed to provide the response and may appear in the model output.

AI output can be inaccurate and can reproduce information contained in your input. Review it before relying on it or sharing it.

5. Shared chats

You can create an unlisted public link for a chat. When you do so, we make the chat title and the publicly renderable content of messages created no later than the sharing time available to anyone who has the link. Messages created later are not included. The public link uses a separate random identifier that does not reveal the private chat identifier or your account identifier.

Shared views do not provide the underlying uploaded files, private file identifiers, protected file URLs, or stored filenames. They may show a generic file-type placeholder such as “PDF attachment” or “Image.” A filename or other information that appears in the text of a message or model response remains part of the shared text.

If publicly included message content is changed, or an included message is deleted, we may automatically disable the existing share to prevent a different conversation from appearing under the same link. You can stop sharing at any time and later create a new link for the then-current version of the chat. Stopping sharing or deleting the source chat prevents further access through Shortly AI, but it cannot retrieve screenshots, downloads, link previews, forwarded content, or other copies already made by recipients or third-party services.

Shared pages are configured not to be indexed by search engines, but an unlisted link is not confidential. Services through which you send or post the link may retrieve the chat title and a short prompt excerpt for a link preview. The recipients are anyone who obtains the link and any service to which you submit it. Processing requested through the sharing feature is based on Article 6(1)(b) GDPR. Security and abuse-prevention processing is based on Article 6(1)(f) GDPR.

6. Service providers and recipients

We use the following providers where needed to operate Shortly AI. The linked privacy notices mainly describe each provider's own processing. Where a provider processes personal data on our behalf, the applicable contractual data protection terms govern that processing.

ProviderService categoryPrivacy information
RailwayHosting and infrastructureRailway Privacy Policy
PolarBilling servicesPolar Privacy Policy
ResendEmail communicationsResend Privacy Policy
CloudflareWebsite delivery, security, and analyticsCloudflare Privacy Policy
Impossible CloudStorage servicesImpossible Cloud Privacy Policy
VercelAI service infrastructureVercel Privacy Notice
PerplexityAI servicesPerplexity Privacy Policy
DeepInfraAI servicesDeepInfra Privacy Policy
xAI (X.AI LLC)AI servicesxAI Privacy Policy
LangfuseService monitoring and analysisLangfuse Privacy Policy
Better AuthAuthentication servicesBetter Auth Privacy Policy

When you use paid services, we provide Polar with the account and billing information needed to create and manage your purchase, such as your email address, display name where available, account identifier, selected plan, and transaction information. We receive customer, subscription, and payment-status information from Polar. If your Shortly AI display name is empty, we may use the customer name associated with your Polar billing record to complete your account profile. Full payment-card details are handled by Polar and are not stored by Shortly AI.

If you use Google sign-in, we receive basic account information from Google, such as your Google account identifier, email address, display name, and profile picture. This information may be refreshed when you sign in again. You can choose whether to display your Google profile picture, a custom profile picture, or the default avatar. Google processes the information needed to complete the sign-in under the Google Privacy Policy. We may also disclose data to professional advisers, authorities, or courts where required by law or necessary to establish, exercise, or defend legal claims. Support communications are handled through an email-hosting provider in Germany.

7. International transfers

Our primary application servers and object-storage buckets are configured in Amsterdam in the European Economic Area. Some providers or their subprocessors are located in, or can access data from, countries outside the EEA, particularly the United States.

Where required, these transfers rely on an adequacy decision such as the EU–U.S. Data Privacy Framework, the European Commission's Standard Contractual Clauses, and supplementary safeguards. Provider DPAs and subprocessor information can be requested using the contact details above where disclosure does not compromise confidential security information.

8. Retention and deletion

We keep personal data only for as long as needed for the purposes above, subject to the following principles:

  • Account, profile, chat, and uploaded content remains available until you delete it, delete all chats and files, or delete your account, unless a shorter product-specific cleanup rule applies.
  • A custom profile picture is retained until you replace or delete it, or until your account is deleted. Copies in provider backups may remain until overwritten under the provider's ordinary backup cycle.
  • An active share record remains until you stop sharing, delete the source chat, or the share is automatically disabled because its included public content changed. Re-sharing creates a new random public link.
  • When you request account deletion, access is blocked and a 7-day recovery period starts. Signing in does not cancel the request. You can explicitly keep the account or use the separate “Delete now” confirmation link in the email. After the period ends, or after you confirm immediate deletion, the active account and app content are permanently deleted.
  • Storage objects are put into a deletion queue. A short technical delay may be necessary for pending uploads and retryable storage operations. Provider backups and security logs may remain until overwritten under their ordinary backup or log cycles; they are protected from routine use.
  • A completed deletion-request record is removed after a short operational period. A canceled request is removed after its anti-abuse cooldown. Old or already-used email links then have no effect.
  • To prevent repeated use of a one-time lifetime allowance, we retain an irreversible keyed hash (HMAC) derived from the normalized account email indefinitely. We do not retain the email in that ledger. The legal basis is Article 6(1)(f) GDPR (preventing abuse and applying the allowance fairly).
  • Detailed usage events are kept for the configured operational and billing periods, then deleted or aggregated. Pseudonymous cost and observability records may be retained for as long as needed for security, cost control, troubleshooting, analytics, and service improvement. After account deletion, an internal user identifier in such records is no longer linked through an active account.
  • Personal data in feedback and support emails is generally removed after 12 months. The substance of feedback may be retained longer after identifying information is removed.
  • Billing, transaction, and business records are retained for applicable statutory tax, accounting, and limitation periods.
  • Marketing data is retained until you withdraw consent or object. We may keep a minimal suppression record so that we continue to respect an opt-out.

9. Account and content controls

Account settings let you delete all chats and uploaded files without deleting the account, or schedule deletion of the full account. Deleting chats and files does not delete the account, subscription, or usage records required for billing and service operation.

You can choose between an available Google profile picture, a custom profile picture, and the default avatar. You can delete a custom profile picture independently of your account.

Account deletion does not automatically erase communications that you separately sent as ordinary emails, records that must be kept by law, or data that has been irreversibly anonymized. If deletion cannot be completed immediately because a provider operation fails, the account remains blocked and the deletion is retried.

10. Cookies and analytics

Shortly AI uses strictly necessary cookies and similar storage for authentication, session security, preferences, and abuse prevention. These are necessary to provide the service and do not require consent.

Cloudflare may process request data and set strictly necessary security cookies when protecting and delivering the site. Cloudflare Web Analytics is used for aggregate performance and traffic measurement. It is designed without cross-site user tracking or advertising profiles. Shortly AI does not use advertising cookies.

11. Your GDPR rights

Subject to the statutory conditions, you have the right to:

  • access your personal data and obtain a copy;
  • correct inaccurate or incomplete data;
  • erase personal data;
  • restrict processing;
  • receive data you provided in a structured, commonly used, machine-readable format and, where applicable, transmit it elsewhere;
  • object to processing based on legitimate interests or to direct marketing;
  • withdraw consent at any time without affecting earlier lawful processing; and
  • lodge a complaint with a data protection supervisory authority.

Shortly AI does not make decisions producing legal or similarly significant effects about you solely by automated means.

You may exercise your rights using the account controls or by emailing [email protected]. We may need to verify your identity and may retain information necessary to document the request. The competent local authority is the State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate.

12. Security

We use technical and organisational measures appropriate to the risk, including encrypted transport, access controls, separation of secrets, restricted database access, private object-storage keys, rate limiting, security logging, and deletion procedures. No online service can guarantee absolute security. Keep login codes and devices secure, and contact us if you suspect unauthorised access.

13. Children

Shortly AI is intended for people aged 18 or older. We do not knowingly offer the service to children.

14. Changes to this notice and provider list

We may update this notice and the provider list as the service changes. Routine changes that do not materially alter the purposes, legal bases, or risks of processing may be published here with a new “Last updated” date. If a change materially affects how we use personal data or your rights, we will provide an appropriate additional notice, such as an in-app message or email, before the change takes effect where required. A change to this privacy notice does not by itself require a change to the Terms of Service.