Legal
Privacy Policy
This policy explains what Preshow.link collects, why, how long we keep it, and the choices you have. We collect what the product needs to work. No advertising trackers, no data sales, and no AI training on your content. Your content reaches an AI service only when you use Preo AI.
Last updated October 6, 2026
1. What we collect
Depending on how you use the service:
- Account data: name, email address, profile photo and job title (from Google sign-in or what you enter).
- Workspace data: team names, member emails and roles, branding you upload.
- Content: 3D scenes, video, images, audio, comments, annotations, camera views and exports you create or upload.
- Review activity: names entered by guest reviewers, their comments and approvals, and when review links were opened.
- Support: the messages and files you send us through support chat.
- Preo AI: how many requests you make each month, to apply your allowance. In the editor we do not store what you ask or Preo AI's answers on our servers; that conversation stays in your browser tab. In support chat, Preo AI's answers are saved in the conversation like any reply.
- Billing data: plan, invoices and the last four digits of a card, held by Stripe; we never store full card numbers.
- Sign-in history: for each device you sign in on, the device and browser type, the IP address and an approximate location (country, region, city) derived from it, so you and we can spot sign-ins you do not recognise.
- Technical data: IP address, the approximate location derived from it, browser type and diagnostic reports needed for security and to fix problems, and page-speed measurements (how long pages and 3D stages take to load and respond, with the kind of device, never who you are).
2. How we use it
To provide and secure the service (sign-in, storing and streaming your media, sharing review links), to bill paid plans, to send transactional emails (invitations, review notifications, billing), to provide support, and to understand overall usage so we can improve the product. We do not sell personal data and do not show advertising.
We do not use your content, support conversations or review activity to train AI or machine-learning models, ours or anyone else's.
In support chat, Preo AI answers first, from our help content and answers our team has reviewed, and it knows only your plan, not your projects or files. It hands the chat to a person when it is not sure, when the question needs one (billing, refunds, account or data requests, bugs) or whenever you ask; you can also tap Talk to a person. Your support messages are sent to Anthropic to produce Preo AI's answers, under the same terms as below, and our team can read the whole conversation.
When you use Preo AI in the editor, we send Anthropic only what that request needs: what you typed, the recent messages of that conversation, a text description of the open scene (object names, sizes, positions and materials, media and camera names, the look settings), a snapshot of the 3D view, and a smaller copy of any image you attach to your message. An attached image is also saved to the project's Media like any upload, which is where a texture lives. Nothing is sent to an AI service unless you ask Preo AI something.
3. Our legal grounds
Where the law asks us to name one (for example the EU and UK GDPR), this is the ground for each use:
- Your account, workspaces, content, review links, storage and streaming, transactional emails, support and Preo AI when you use it: needed to provide the service you signed up for (performance of a contract).
- Billing and invoices: performance of a contract, and keeping tax and billing records because the law requires it.
- Sign-in history, security logs, rate limiting, bot protection, error and diagnostic reports: our legitimate interest in keeping the service and your account secure and working, weighed against your rights.
- Page-speed measurements and product usage events: our legitimate interest in understanding overall usage so we can improve the product. You can object at any time.
- Integrations (Slack, Airtable) and push notifications: your consent, which you can withdraw at any time by disconnecting them or turning notifications off.
- Answering lawful requests from authorities and enforcing these policies: a legal obligation, or our legitimate interest in protecting our rights and other users.
- Giving us your email address and accepting the Terms are required to create an account; without them we cannot provide it. Everything else (your name, photo, job title, integrations, notifications) is optional. Guest reviewers only need to enter a name.
4. Who is responsible
Toy Robot Media is responsible (the controller) for account, billing, support and technical data. For the content a workspace uploads and for the guests it invites to review, the workspace owner decides what is collected and why, and we process it on their behalf. Business customers can ask info@preshow.link for a data processing agreement. We do not make decisions about you based solely on automated processing.
5. International transfers
Our providers may store and process data in the United States and other countries. Where data leaves the EU, UK or Switzerland, we rely on the safeguards the law provides, such as the European Commission's Standard Contractual Clauses or an adequacy decision, as offered by each provider.
6. Who processes it for us
A small number of providers, each bound by its own data-processing terms:
- Google Cloud and Firebase: sign-in, database, file storage, website hosting, server functions and bot protection. The service is protected by reCAPTCHA, and Google's Privacy Policy (policies.google.com/privacy) and Terms of Service (policies.google.com/terms) apply to it.
- Google Fonts: delivers the typeface the site uses; your browser requests it from Google.
- Mux: video encoding, storage and streaming.
- Toy Robot Media: on the Max plan, exports you send to the render farm are rendered on computers the studio operates; the finished file is kept like any cloud export.
- Anthropic: when you use Preo AI (in the editor on plans that include it, and in support chat), its Claude models produce the answer from the request described above. Under its commercial terms Anthropic does not train its models on that data and keeps it only for a limited time for safety and abuse monitoring. If we ever use a different AI provider for Preo AI, we will name it here first.
- Google Firebase Cloud Messaging and your browser's push service: deliver push notifications, only if you turn them on.
- Stripe: subscriptions and payments.
- Resend: transactional email delivery.
- Slack and Airtable: only if you connect them, for the notifications and syncs you choose.
6a. Who else can see it
Besides the providers above, personal data can reach:
- the members and guests of the workspaces and projects you take part in, who see your name, photo, comments, approvals and what you share there;
- apps and webhooks a workspace connects through our API, which receive the project data that workspace allows them;
- courts, police and other authorities, when the law requires it or to protect people's safety or our rights;
- a company that takes over the service, under this policy, if we sell or transfer the business; we will tell you first.
7. Cookies and local storage
The service uses only strictly necessary storage: your sign-in session, your preferences (theme, layout) and caches that make the app fast, kept in your browser's local storage. We also remember which wording of an upgrade message you were shown, on your device only, so it stays the same between visits. We do not set advertising or third-party analytics cookies, which is why you will not see a cookie banner. If we ever add analytics cookies, we will ask for your consent first. Stripe sets its own cookies on its hosted checkout pages.
8. Review links
Content is private to your workspace unless you share it. Each review link can be open to anyone who has it (they enter a name) or limited to signed-in accounts, can carry a passphrase, and can turn downloads off. You can revoke a link at any time; that also ends every guest session opened through it.
When someone opens a review link, we record:
- the name a guest enters, or the name and photo of a signed-in reviewer;
- their comments, approvals and change requests;
- when they last viewed each shared item, and for each link how many times it was opened and when it was last opened. This is what producers see in the app.
9. What we do not record about reviewers
We do not ask a guest for an email address, do not track reviewers across other sites, and do not fingerprint their devices. A reviewer's network address is used only to protect the service (rate limiting and security logs); it is never attached to their name or comments. Watermarks on shared media show your logo, not the viewer's identity. Passphrases are stored only in scrambled (hashed) form.
10. How long we keep things
Your content stays for as long as you keep it. After that:
- Recently deleted: deleted projects, comps, media, stages and versions stay in Recently deleted for 30 days so you can restore them, then are permanently deleted within about a day. You can delete them permanently sooner.
- Files and video: permanent deletion removes the files from our storage and the video from Mux, except where the same file is still used by another of your projects (for example, a duplicate).
- Review links expire after 30 days unless you choose a shorter or longer time (up to 90 days), and can be revoked at any moment. A guest's access through a link lasts at most 12 hours before they must open it again. Links you send to invited collaborators do not expire, but they only work for people who already have access.
- Cloud exports are kept for 7 days.
- Error reports and email delivery records: 90 days. Device diagnostic reports and page-speed measurements: 30 days. Product usage events: 13 months.
- A signed-in user's last known IP address is cleared after 90 days of inactivity. Per-device sign-in history (above) is kept until you remove the device or delete your account.
- Project activity history keeps the most recent 500 events per project. Records of who viewed each shared item stay with the project and are deleted with it.
- Notifications in the app and your monthly Preo AI request counts are kept until you delete your account.
- Records of actions our team takes on accounts (support, billing and security changes) are kept as long as needed for security and accountability, and server logs for 30 days.
- Support conversations are kept until you delete your account, or sooner if you ask.
- Billing records are kept as long as tax law requires.
- Our database keeps a rolling 7-day recovery window, so deleted records disappear from it within 7 days.
11. Deleting your account
Deleting your account (Settings → Personal settings) is immediate and permanent; there is no grace period. It cancels your subscription and removes your profile, the projects you own with their files and video, workspaces you own, your support conversations and attachments, your notifications and Preo AI request counts, and the error reports, email records and usage events that identify you.
Some things stay where they belong: comments you left in other people's projects stay in those projects, projects you created inside someone else's team workspace stay with that workspace, and Stripe keeps the invoice records tax law requires.
12. Your rights
You can access and update your profile in Settings, export your media at any time, and delete your account yourself. If you are in the EU or UK you also have the rights to data portability, restriction and objection, and to complain to your supervisory authority. For any request, email info@preshow.link.
13. Security
Data is encrypted in transit and at rest by our providers, access is limited to what each role needs, and two-factor authentication (an authenticator app) and passkeys are available for every account. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you as the law requires.
14. Children
The service is not intended for anyone under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
15. Changes and contact
We will announce material changes to this policy in the app or by email. For any privacy question, or to ask for a copy or deletion of your data, contact Toy Robot Media at info@preshow.link and we will respond within 30 days.
See also the Terms of Service.
