Privacy Policy
Last updated: October 8, 2026
Oneshotted (oneshotted.io) is run by Codesaz Company for General Trading LTD. This policy explains what we collect when you use the website, the Oneshotted MCP server and the Oneshotted skill, what we do with it, and what you can ask us to do with it.
By using Oneshotted you agree to this policy. If you don't, please don't use the service.
1. What we collect
When you make an account. Your name, your email address and a password, stored only as a one-way hash. If you sign in with Google, we receive your name, your email address and Google's account ID for you. We don't receive your Google password or anything else from your Google account.
When you use the MCP server or the skill. Your API keys are stored as one-way hashes, plus a short prefix so you can tell them apart. We also keep the name you give each key, how many calls it has made, when it was last used, and the network address it was created from. For apps you connect with "Sign in" (such as claude.ai), we store the access tokens that let the app call the server for you.
When you pay. Payments are handled by Stripe. We store your Stripe customer ID, your plan, its status and renewal dates. We may also store the card brand and last four digits that Stripe sends us. We never see or store your full card number.
When you submit a video or a prompt, vote, or save a piece. What you submit, the X handle you give us, your votes and your saved pieces. When you submit, our moderators receive the post link, the handle you gave and the prompt, so they can review it.
When you subscribe to the newsletter. Your email address and whether you confirmed it.
When you claim a creator profile. Your X handle and the X account that verified it.
Automatically. Your network address and browser type. We keep the network address you signed in from and the one each key was made on, to apply limits and stop abuse; most rate-limit counters only keep a hashed version. We also measure the pages you visit and how you got here, through our analytics (section 5).
When you sign up with a password. We check whether your password has appeared in a known data breach. Only the first 5 characters of a scrambled (SHA-1) version of it go to Have I Been Pwned; your password itself never leaves our server.
2. How we use it
- To run the service: your account, your keys, your plan and its limits.
- To take payments and manage your subscription through Stripe.
- To stop abuse: rate limits, bot checks, and protecting creators' prompts from being copied wholesale.
- To answer you when you write to us.
- To send the newsletter, but only if you subscribed and confirmed.
- To understand how the site is used, so we can make it better.
We don't sell your personal data, and we don't use it for advertising.
3. Who we share it with
We share only what each service needs to do its job:
| Service | What for | What it gets |
|---|---|---|
| Stripe | Payments, invoices, the billing portal | Your email, name and payment details you enter on Stripe's pages |
| "Continue with Google", and the site's fonts | The sign-in itself; your network address when your browser loads the fonts | |
| Cloudflare | Hosting protection and bot checks (Turnstile) | Your network address and browser details |
| DataFast | Site analytics | Pages visited and a visitor ID |
| X (Twitter) | Showing posts in the library; reading posts you submit | X's embed loads its own script, which can set X's cookies; we look up public posts and profiles |
| Telegram | Our moderation chat | Submissions (post link, handles, prompt, notes, render link) and newsletter sign-ups (email address) |
| Anthropic | Reading public posts to find the prompt and details | Public post text, handles and prompts |
| Have I Been Pwned | Breached-password check at sign-up | 5 characters of a scrambled version of your password |
| Our hosting provider | Running the servers | Everything above, stored on our servers |
We also share information when the law requires it, or to protect the service and its users from fraud or abuse. If Oneshotted is sold or merged, your data would move with it, and we would tell you first.
4. Public content
Library pieces, creator profiles (name, bio, avatar, website and links) and approved prompts with their notes and render links are public. If you submit a prompt or claim a creator profile, the X handle attached to it is shown publicly. The handle you give when you submit a video goes to our moderators and isn't shown. Your email address and account details are never shown publicly.
5. Cookies and analytics
We use a session cookie to keep you signed in and to protect forms. If you tick "Keep me signed in", a longer-lived cookie does the same. Cloudflare Turnstile may set cookies to tell people from bots. DataFast sets a cookie (datafast_visitor_id, kept for a year) with a visitor ID to count visits; it isn't used for advertising, and your dashboard isn't counted. Pages that show an X post load X's script, which can set X's own cookies. We also keep a couple of preferences in your browser, such as light or dark mode. You can block cookies in your browser, but signing in won't work without them.
6. How long we keep it
- Account data: for as long as you have an account.
- Payment records: for as long as the law requires us to keep them.
- Rate-limit counters: a few minutes to a week.
- Sessions: expire on their own.
- Revoked keys: kept so your usage history stays accurate. When you ask us to delete your account, we delete them too.
- Newsletter: your email address until you ask us to delete it, even after you unsubscribe, so we don't email you again.
- Waitlist sign-ups: until the plan opens and we've sent the one email we promised, then deleted on request.
- Handles on submissions and prompts: for as long as the piece is in the library. For rejected submissions, until you ask us to delete them.
- Moderation messages: our Telegram chat keeps them until we delete them.
7. Security
Everything travels over HTTPS. Passwords and API keys are stored only as hashes. Only the people who run Oneshotted can reach the servers. No system is perfectly secure, but we work to keep yours safe and will tell you if something goes wrong.
8. Your rights
You can ask us to:
- see the personal data we hold about you;
- correct it;
- delete it;
- stop or limit how we use it;
- withdraw consent you gave.
To delete your account and its data, email us from the address on the account. Cancel any subscription first in Manage billing on your dashboard. We'll do it within 30 days, except for records the law requires us to keep.
9. Children
Oneshotted is for people 18 and over. We don't knowingly collect data from anyone younger. If you believe someone under 18 has given us data, email us and we'll delete it.
10. Changes
When we change this policy we update the date at the top. Significant changes will be announced on the site. If you keep using Oneshotted after a change, you accept the updated policy.
11. Contact
- Company: Codesaz Company for General Trading LTD.
- Registration: Incorporated in the Kurdistan Region, Iraq, Reg. No. 40550 (2021)
- Email: [email protected]
- Phone: +964 770 647 2323
- Website: oneshotted.io