Privacy Policy
Last updated August 13, 2026
This Privacy Policy explains how Duckring ("Showdit", "we", "us") collects, uses, and protects personal data when you use Showdit. We act as the data controller for the account data described below.
1. Data we collect
We collect only what we need to operate the Service:
- Account data — your name, email, and authentication identifiers (including data from Google or Apple sign-in if you use it).
- Brand & product data — the product information, brand assets, and settings you add to generate content.
- Connected-account data — tokens and basic metrics from publishing accounts (TikTok, Instagram, Facebook, YouTube) you choose to connect.
- Billing data — subscription status and limited payment metadata processed by our payment provider (we do not store full card numbers).
- Usage data — log, device, and analytics data used to operate, secure, and improve the Service.
2. Cookies & similar technologies
Showdit and our analytics/error-monitoring providers place, access, or recognize cookies and similar technologies (such as local storage) on your device or browser to run the Service and, where you consent, to monitor errors and analyze usage.
- Essential cookies — required to keep you signed in, remember your language/locale, and secure the Service. These are always on.
- Optional cookies — error monitoring and product analytics, used only if you accept them in the cookie banner shown on your first visit.
- You can change your choice at any time by clearing your cookies and revisiting the Service, which shows the banner again.
3. How we use it
We use personal data to:
- Provide the Service — generate and publish content you request.
- Operate billing, support, and account management.
- Secure the Service and prevent abuse.
- Improve output quality and develop new features.
- Send service and, where you consent, marketing communications.
4. Legal bases
Where the GDPR or similar laws apply, we rely on: performance of our contract with you (to provide the Service), our legitimate interests (to secure and improve the Service), your consent (for optional marketing), and legal obligations (such as tax and accounting).
5. AI processing & sub-processors
To generate content we send your relevant Inputs to AI and infrastructure providers acting as our processors — including model providers (e.g. for script, voice, and caption generation), our hosting and database provider, and our media-rendering provider. They process data only on our instructions and under contractual safeguards.
6. Sharing
We do not sell your personal data. We share it only with the processors above, with platforms you connect (to publish your content), and where required by law or to protect our rights.
7. YouTube API Services
Showdit's YouTube publishing feature uses YouTube API Services.
By connecting a YouTube channel to Showdit, you agree to be bound by the YouTube Terms of Service: https://www.youtube.com/t/terms
Google's Privacy Policy applies to any data YouTube API Services shares with us: https://policies.google.com/privacy
You can revoke Showdit’s access to your Google/YouTube account at any time from your Google Account security settings: https://security.google.com/settings/security/permissions — or by disconnecting the channel from Showdit’s dashboard, which deletes the stored access/refresh tokens immediately.
We store your YouTube authorization tokens only for as long as necessary, and use them only to upload/schedule videos to the channel you connected — the specific purpose you consented to when connecting it. We do not use these tokens for any other purpose. We retain YouTube channel tokens and basic metrics only for as long as the channel stays connected; disconnecting the channel or deleting your account deletes this data per our Retention policy below.
8. Facebook & Instagram
Showdit's Facebook and Instagram publishing feature connects via Facebook Login and Meta's Graph API, subject to the Meta Platform Terms: https://developers.facebook.com/terms/
You can revoke Showdit’s access to your Facebook/Instagram connection at any time from Facebook’s "Apps and Websites" settings, or by disconnecting the channel from Showdit’s dashboard, which deletes the stored access tokens immediately. If you revoke access or request data deletion from Facebook’s own settings instead, we receive that request automatically and delete the same connection data on our side — you can check the status of that specific request at the confirmation URL Facebook shows you.
We retain Facebook/Instagram connection tokens and basic page/account metadata (e.g. the connected Page name) only for as long as the channel stays connected; disconnecting the channel, revoking access from Facebook, or deleting your account deletes this data per our Retention policy below.
9. TikTok
Showdit's TikTok publishing feature connects via TikTok Login Kit and the TikTok Content Posting API, subject to the TikTok Developer Terms of Service: https://www.tiktok.com/legal/page/global/tik-tok-developer-terms-of-service/en
We access only basic profile information (to identify the connected account) and the permission to publish the video content you approve — we do not read, store, or otherwise use any other TikTok data. You can revoke Showdit’s access to your TikTok account at any time from TikTok’s app permissions settings, or by disconnecting the channel from Showdit’s dashboard, which deletes the stored access/refresh tokens immediately.
We store your TikTok authorization tokens only for as long as necessary, and use them only to publish the videos you approve to the account you connected — the specific purpose you consented to when connecting it. We retain TikTok connection tokens only for as long as the channel stays connected; disconnecting the channel or deleting your account deletes this data per our Retention policy below.
10. International transfers
Your data may be processed in countries other than your own. Where it is transferred out of your region, we use appropriate safeguards such as standard contractual clauses.
11. Retention
We keep personal data for as long as your account is active and as needed to provide the Service, then for the period required to meet legal, tax, and security obligations, after which it is deleted or anonymized.
Rendered video files (the .mp4 itself) are kept for a limited window after creation, then deleted from storage: on the Free plan, 3 days if you have both downloaded and published the short, 5 days if you have done one of the two, and 7 days if you have done neither; on paid plans those windows are 7, 10, and 14 days respectively. We send an email at least 1 day before a file is removed. These windows may be adjusted from time to time — the exact expiration date for each of your shorts is always shown on that short’s page in your dashboard. Deleting the rendered file never deletes the underlying script, captions, or generation history, and you can re-render a short at any time.
12. Your rights
Subject to your local law, you may access, correct, export, or delete your personal data, object to or restrict certain processing, and withdraw consent. You can delete your account and associated data at any time from settings or by contacting us.
13. Security
We use technical and organizational measures — including encryption in transit, access controls, and least-privilege practices — to protect personal data. No method of transmission or storage is perfectly secure.
14. Changes & contact
We may update this Policy; material changes will be posted here with a new "last updated" date.
For privacy requests or questions, contact privacy@showdit.com.
Duckring, 인천광역시 미추홀구 매소홀로488번길 6-32.