SHOTCOUNT

Privacy Policy

Last updated: 6 August 2026

This Privacy Policy explains how Shotcount (“Shotcount”, “we”, “us”, or “our”) collects, uses, stores, and protects information when you use shotcount.app and the Shotcount workspace.

Information we collect

Google API data

When you choose to connect Google, Shotcount requests only the permissions needed for the connected features you use:

The OAuth permissions used for these features are openid, email, profile, https://www.googleapis.com/auth/gmail.readonly, https://www.googleapis.com/auth/gmail.compose, https://www.googleapis.com/auth/calendar.events, https://www.googleapis.com/auth/calendar.events.freebusy, and https://www.googleapis.com/auth/contacts.readonly. Shotcount does not request a permission merely for a future feature.

Google User Data Limited Use statement

Shotcount’s use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.

How we use information

We use information to provide the features you request: organizing your work, creating plans, preparing drafts, reading relevant messages, resolving recipients, syncing calendars, and carrying out user-approved actions. We use Google data only to provide or improve a user-facing feature or a user-directed use case.

Some user-directed tasks may send the relevant task context or Google content to an AI processing provider to generate a response or carry out the requested feature. We do not use Google User Data to create, train, or improve generalized, foundational, or frontier AI models.

What we do not do with Google User Data

Sharing and service providers

We do not sell your information. We share information only as needed to provide the service, protect users, comply with law, or complete an action you request. Our current service providers include Supabase for authentication, database, and server functions; Vercel for public web hosting; and OpenAI for user-directed AI processing. They may process information only for the services they provide to Shotcount and under appropriate contractual or technical controls. Google data remains subject to Google’s policies and your Google account controls.

Storage, security, and retention

OAuth access and refresh tokens are stored server-side in encrypted form. Token-bearing records are not exposed to the browser or ordinary authenticated database access. We use access controls, encrypted transport, bounded provider requests, and approval gates for external Gmail and Calendar actions.

We retain account and workspace information while your account is active, together with the limited task and action records needed to resume work, provide support, and maintain security. We do not keep a permanent copy of all Google data; connected data is requested from Google when a feature needs it. You can revoke Shotcount’s Google access from your Google Account and request deletion of your Shotcount account and account-linked data by contacting us. Some limited records may be retained where required for security, fraud prevention, legal compliance, or resolving disputes.

Your choices

You can choose whether to connect Google, review or revoke Shotcount’s access in your Google Account, edit or delete workspace information, and request account deletion. If you revoke access, connected features that need Google data will stop working until you reconnect.

Children

Shotcount is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes to this policy

We may update this Policy when our service or data practices change. We will publish the updated Policy here and, where appropriate, notify users of material changes.