This policy explains what Shocase collects, why, which other companies see it, how long we keep it, and how to have it deleted. It covers this website, the Shocase app at app.shocase.ai, the Shocase Chrome extension, the Shocase Recorder desktop app, and the videos, guides, demos and help sites our customers publish with Shocase.
Shocase is run by Full Send Technologies Private Limited ("Shocase", "we", "us"), Innov8, 4th Floor, Unit No. 1–2, Kalpataru Prime, Plot No. D3, Wagle Industrial Estate, Thane, Maharashtra 400604, India. Write to us at support@shocase.ai about anything in this policy.
The short version
- You record your product; we turn that recording into videos, guides and demos. Doing that means sending parts of it to the AI companies named below.
- We do not sell your data, we do not use it for advertising, and we do not train our own models on it.
- Everything we store is held in Google Cloud in Mumbai, India. The AI companies we use process data outside India.
- Ask us at support@shocase.ai and we will delete your account and its content.
Who is responsible for what
For your account, our website and the emails we send you, we decide what is collected and why.
For everything you record, upload and create in Shocase, we act on your instructions and on behalf of the organization whose workspace holds it. If you record a colleague or a customer, that organization is responsible for having a reason to do so, and for telling those people. We describe what we do with that material below.
What we collect
Your account
Your email address, your name if you give one, your role, the workspace you belong to, and the dates the account was created and changed. If you sign in with Google, we ask Google only for your basic profile and email address and store your Google account identifier. If you set a password, we store a scrambled (hashed) copy, never the password itself.
Everyone in your workspace can see the name, email address, join date and role of every other member, and every pending invitation.
What you record and upload
- Recordings. Your screen, and — when you switch them on — your computer's audio, your microphone and your camera. In the desktop recorder, computer audio is on by default; the microphone and camera are off until you turn them on.
- A file of what you did while recording. Pointer movements, clicks, scrolling and the keys you pressed, saved as key codes with timings, plus the position and type of the on-screen control under your pointer. Anything you type while a recording is running can appear in that file, so do not type passwords or other secrets during a recording. On a Mac this needs the Accessibility permission; without it, nothing of this kind is captured.
- The name of the screen or window you chose to record, which is usually its title.
- Files you upload: video, audio, images, presentations and documents, and whatever they contain.
- What we make from them: transcripts with word timings, detected language and speaker labels, narration audio, edited videos, written guides, demos, help sites, and comments your team leaves.
The desktop recorder also saves its own copy of each recording into a folder on your computer. That copy is yours; we never touch or remove it.
When Shocase records your own product for you
- The sign-in details you give us for your product, so the recorder can sign in later. They are encrypted with AES-256-GCM using keys held in Google Cloud's key management service.
- The signed-in browser session for your product, if you connect it that way, also encrypted, and kept until you remove the connection.
- Your product's pages and responses, if you use the connector to record an application inside your own network. During a recording they pass through our servers to the recording browser.
- Pictures of your product's screens. While the recorder is working out what to do, screenshots and the visible controls go to Anthropic. Those planning screenshots are sent as they appear. When the recorder films, sensitive text is masked in the page before any frame is captured: email addresses, payment card numbers, bank and government identification numbers, telephone numbers, passwords inside web addresses, and things that look like keys or tokens. Names are not masked, and you can add your own words to mask.
Whatever your product shows during a recording is what gets filmed, so point it at test data rather than real customer records where you can.
People who watch what you publish
When someone opens a video, demo or help site that you published, we record for you: the time and length of the visit, their browser and device string, the page they came from, the site the player was embedded in, campaign tags in the link, and, for demos, the country and language their browser or our content network reports. We do not store the viewer's IP address in your analytics.
If your share link carries a viewer's name, email address or company, or the viewer types them into a gated page or asks the AI host a question, we store those with the visit and show them to you. Questions typed to the AI host are stored word for word. A viewer's browser keeps a token in its local storage so it can carry on after a reload.
Technical records
Our servers write a line for each request: the method, address, response code, time taken and size. Our web server also writes standard access logs, which include the caller's IP address. When someone asks for a sign-in link, that email address is written into our application log. IP addresses are also counted in memory to limit how often sensitive requests can be made.
For each connected browser extension or desktop app we store an installation identifier, the browser or app's user-agent string, and when it was last used, so you can see and revoke your devices.
On this website
This site uses Cloudflare Web Analytics, which counts visits without cookies and without following people between sites. Cloudflare also serves the site, so it processes the requests your browser makes. Pages load typefaces from Google Fonts and Fontshare, which means your browser connects to those companies. If you book a call, that happens on Cal.com, and their code loads only when you reach for the booking button.
The Chrome extension and the desktop app
The Chrome extension asks for access to every site and for Chrome's debugger, because a capture can be made on any page. It records nothing until you start a capture. During one, it records what you do on the page — pointer movement, clicks, scrolling, typing into a field, dragging, menus opening — along with the full address of each page and the visible text of what you clicked. It records that a field changed, not what you typed into it.
The desktop recorder sends us no usage or crash reports. Its settings stay on your computer, and crash diagnostics are written to a file there.
Cookies and browser storage
- authToken — keeps you signed in. Set when you sign in, lasts 7 days, and cannot be read by page scripts.
- csrf-token — proves a request came from the Shocase page. Same 7 days, readable by our own scripts.
- connect.sid — a short-lived value used only while you connect a third-party integration.
- Browser storage in the app — your account id, email, name and workspace id, plus display preferences such as the theme, and a resume token on published pages when a visitor gives their email address.
That is all. We set no advertising or measurement cookies, which is why you see no cookie banner.
Why we use all this
To run your account and workspace; to make the videos, guides, demos and sites you ask for; to show you who watched what you published; to send sign-in links, invitations and notifications; to keep the service working and safe, including rate limits and troubleshooting; and to answer you when you write to us.
The companies that process data for us
- Google Cloud — hosting, database, job queue and file storage, all in the Mumbai (asia-south1) region.
- Google (Gemini) — receives the video itself to work out what is on screen, and transcripts and captions to translate them. Files uploaded for analysis are deleted from Google's file service after use.
- OpenAI — receives still frames from recordings, transcript text to draft narration and to power search in your library, and frames to find areas to blur.
- Anthropic (Claude) — receives what visitors ask the AI host and the recent conversation, screenshots while planning an automated recording, and some editing decisions.
- ElevenLabs — receives the audio of your recording to transcribe it, narration scripts to speak them, a sample of a voice when you ask for a cloned voice, and a visitor's microphone audio when they talk to the AI host. A cloned voice stays on their systems until it is deleted.
- BytePlus (Seedance) — receives the text prompt when you ask for a generated video clip. Your recording is not sent.
- SendGrid — sends our email: sign-in links, invitations, comment notifications, and questions from your published pages.
- Cloudflare — serves this website and counts its visits.
- Google Fonts and Fontshare — deliver typefaces to your browser.
We do not sell personal data, and we do not share it for advertising.
Training
We do not use your recordings, transcripts or documents to train our own models. Where a provider's interface lets us ask for a request not to be stored, we use it on the calls that support it; otherwise providers hold requests under their own terms, usually for a short period to detect abuse.
Where it is stored, and how it is protected
Our servers, database, job queue and the storage bucket holding recordings and finished videos are all in Google Cloud's Mumbai region (asia-south1). The AI companies above process data on their own infrastructure, outside India.
Traffic between your browser and Shocase uses HTTPS. Media files are fetched through links that expire, and the storage bucket is not open to the public. Credentials you give us for your own product are encrypted with keys held in Google Cloud's key management service, and our own secrets are held in Google Cloud Secret Manager. Nobody at Shocase has a console that signs in as you.
How long we keep it
- What you record and make stays until you delete it. Deleting a recording or a project is permanent and cannot be undone from the product. Some files written by the desktop recorder can remain in storage after a project is deleted; ask us and we will remove them.
- Deleted files in storage can be restored for 7 days, after which they are gone.
- Database backups are taken automatically and kept by Google Cloud SQL, with 7 days of transaction logs.
- Unpublishing a video stops the public page from serving it, but the file and the analytics already collected stay.
- A deleted comment is hidden from the workspace, and its text stays in the database.
- Viewer analytics stay for as long as the published item exists, and go when it is deleted.
- Working files made while dubbing are deleted after 14 days, and background job records after 7 to 30 days.
- Your account stays until you ask us to delete it.
Deleting your data
You can delete individual recordings, projects and connections in the app. There is no button yet for deleting a whole account or workspace, so email support@shocase.ai from the address on the account and we will delete the account and its content within 30 days, apart from copies in backups, which age out as described above.
Your rights
You can ask us to give you a copy of your personal data, correct it, delete it, or send it to you in a portable form, and you can withdraw consent where we relied on it. Write to support@shocase.ai and we will answer within 30 days.
If you are in India, you may also write to our grievance officer, Tejas Shetty, at tejas@shocase.ai, and you may complain to the Data Protection Board of India. If you are in the European Economic Area or the United Kingdom, you have the rights the GDPR gives you, including complaining to your local supervisory authority. Using Shocase means your data is processed in India and by the providers listed above in their own countries.
Children
Shocase is for work and is not intended for anyone under 18. We do not knowingly collect data about children. If you believe a child has used Shocase, write to us and we will delete the account.
Changes to this policy
When this policy changes, we update the date at the top of the page. If a change matters to how we use your data, we will tell account holders by email before it takes effect.
Contact
Full Send Technologies Private Limited, Innov8, 4th Floor, Unit No. 1–2, Kalpataru Prime, Plot No. D3, Wagle Industrial Estate, Thane, Maharashtra 400604, India. Email support@shocase.ai, or our grievance officer Tejas Shetty at tejas@shocase.ai.