Privacy policy
Last updated September 14, 2026. How Shortsmark processes source material, AI questions, and personalized feed activity.
Android billing and AI answer reports
Google Play processes purchases. Shortsmark processes an opaque account identifier, purchase tokens, and subscription status to verify and synchronize access; it does not receive card numbers. An AI answer report stores a reason and identifiers pointing to the existing conversation. Authorized staff may review the reported conversation for safety. Deleting the conversation or account also deletes its reports.
Personalized feed and AI sharing choices
Shortsmark stores recent feed impressions, thread opens, and source opens linked to your account to personalize feed ranking. This activity is deleted with your account and is not used for advertising tracking across other companies’ apps or websites.
AI questions may send your question, conversation history, and relevant excerpts from saved material to the AI providers. In iOS and Android Settings, AI Data Sharing lets you withdraw permission for new source submissions and AI questions from this device and clears its offline queue. Already-submitted requests may finish, and saved notes remain readable. Enabling sharing again requires reviewing and accepting the disclosure.
Controller and contact
Shortsmark is operated by 자동화연구소 (Jadonglab), represented by 김동구 (Dongku Kim), in Seoul, Republic of Korea. Its address and registration number appear in the legal notice. Privacy requests may be sent to dkim@jadonglab.com or 010-8314-8770.
Accounts are not intended for children under 14. Shortsmark does not request a birth date and asks users to confirm locally that they are at least 14 before sign-in.
Information processed
- Account. Shortsmark handles the Firebase user ID and profile fields you choose to share through Apple or Google, plus language, categories, plan, and allowance state. It does not receive your password.
- Public links. Shortsmark handles URLs, public metadata, page text, captions, attachment URLs, transcripts, generated notes, tags, and citations. An artifact for the same public source may be reused across accounts, but Shortsmark does not provide public note links.
- Private documents and text. Shortsmark handles the display name, MIME type, owner-scoped content hash, normalized extracted or pasted text, PDF page map, processing state, generated note, and short exact citation quotes. These materials are not reused across accounts.
- Billing, technical, and support. Shortsmark handles Polar, Google Play and Apple App Store subscription identifiers and status; request IP, device, browser, error, or security logs; and information you provide in support, privacy, or rights reports. It does not receive your full card number.
This policy explains how Shortsmark handles the material you submit; it does not decide what you are allowed to submit. For that, and for the rightsholder report process, see the copyright policy.
Original files and temporary text
Uploaded file bytes are parsed only in server memory, are never written to disk or object storage, and are discarded immediately after parsing. Full extracted text and a PDF page map are kept in an expiring owner-and-note processing row while queue retries remain possible, then deleted on successful generation, terminal failure, or the current retry-expiry boundary of no more than 48 hours.
After generation, neither the original file nor full text can be reopened or downloaded. Only short exact citation quotes and, when available, PDF page numbers remain in the generated note.
Purposes and AI providers
Information is used for sign-in, source processing and note generation, synchronization, search and organization, allowance metering, security, billing, support, and legal compliance. It is not sold or used for behavioral advertising, and submitted material is not used to train or fine-tune models.
For note generation, Shortsmark sends source content and output language—without your Firebase user ID or email—to OpenRouter and uses a pinned DeepInfra or Google Vertex AI inference path. Requests are configured to deny provider data collection and require an endpoint OpenRouter marks as zero data retention. For public links, Shortsmark may send the URL and requested language to Supadata.
Google Cloud and the database operate in the Seoul region, but Firebase Authentication, AI, public-link extraction, and the Polar, Google Play, and Apple App Store billing providers may process information outside Korea under their applicable terms and technical and contractual safeguards.
Provider and international-processing details
- Google Cloud/Firebase. The app and database operate in the Seoul region; Firebase Authentication may process account identity and authentication logs in the United States. See the Firebase privacy documentation and Cloud Data Processing Addendum.
- Supadata. Dumpling Software UG in Germany receives a public-source URL and requested language and returns public page text, metadata, or transcripts. See the Supadata privacy policy.
- OpenRouter, DeepInfra, Google Vertex AI. They use source material and output language to generate the note. Requests are configured to deny provider data collection and require a zero-data-retention-eligible endpoint. See OpenRouter data collection and DeepInfra data privacy.
- Polar Software, Inc. It processes checkout, payment, and tax information in the United States. See the Polar privacy policy.
Retention and deletion
- Private notes. When removed, the note, entries, tags, source metadata, hash, and processing payload are permanently deleted from the active database. The spent credit remains counted for that period in a content-free usage event.
- Public-link artifacts. These may remain when one account hides a note or is deleted because another account may independently use the same public-source artifact. Account-specific saved relationships and categories remain separate.
- Account deletion. This deletes all private notes, temporary inputs, content-free usage events, account relationships, categories, preferences, and local plan records. A legacy shared URL artifact may remain where another account continues to use it on an independent basis.
- Backups and legal records. Deleted live data may remain in encrypted disaster-recovery backups during the seven-day backup rotation. Billing, security, support, and rights-report records may be kept as required by provider policies or legal obligations.
Choices, rights, and security
You can delete a private note or your account in the app and manage subscriptions in Settings. Where applicable, request access, correction, portability, deletion, or restriction by contacting the privacy address; identity verification may be required.
Shortsmark uses owner-scoped access controls, HTTPS, managed secrets, and encryption-required database connections. No system is perfectly secure. Visit Support for help.