Shape

Privacy Policy

Last Updated: August 28, 2026

Google API Services Limited Use Compliance

Shape's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements. Data received from Google Workspace APIs is never used to train, fine-tune, or improve any artificial intelligence or machine learning model, including our own, and is never transferred to any third party that would use it for such purposes.

1. INTRODUCTION

Shape Platforms, Inc. ("Shape," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your information when you use our experimental AI-powered visual platform.

1.1 Our Commitment. All changes you make in Shape are designed to be private until you decide to share or deploy them. However, as with any AI platform, certain data may be processed for service delivery, safety monitoring, and system improvement.

1.2 AI Capability Notice. Shape uses AI to provide product features. Our practices with respect to Google Calendar data are described in Section 22 and are limited to the purposes stated there.

2. INFORMATION WE COLLECT

2.1 Account Information. (a) We collect your name and email address, (b) company information if applicable, (c) payment information processed by third-party providers, (d) your account preferences and settings.

2.2 Product Usage Data. (a) Code, designs, and content you create or upload, (b) platform interactions and feature usage, (c) performance metrics and error logs, (d) AI feature usage and patterns.

2.3 Technical Information. (a) IP address and device information, (b) browser type and operating system, (c) platform performance data, (d) security and access logs, (e) automated monitoring data for abuse detection, (f) usage patterns and behavioral analytics, (g) error logs and debugging information, (h) system performance and capacity metrics.

2.4 Communication Data. (a) Support tickets and correspondence, (b) feedback and feature requests, (c) in-platform messages and tags, (d) media inquiries and public communications, (e) legal and compliance communications.

3. HOW WE USE YOUR INFORMATION

3.1 To Provide Our Service. (a) Process and store your designs, code, and content, (b) enable visual editing and AI-powered features, (c) generate code based on your inputs.

3.2 To Improve Our Platform. (a) Analyze usage patterns to enhance features, (b) identify and fix technical issues, (c) develop new features and capabilities. We do not use customer content to train, fine-tune, or improve any AI/ML model. See Section 22 for the specific rules that apply to Google Calendar user data.

3.3 For Communication. (a) Send service-related notifications, (b) respond to support requests and feedback, (c) provide important updates about the platform, (d) send billing and account information.

3.4 For Safety and Compliance. (a) Monitor usage for policy violations and abuse, (b) detect and prevent harmful or inappropriate content, (c) ensure compliance with applicable laws and regulations, (d) cooperate with law enforcement when legally required, (e) protect our rights and prevent fraud, (f) maintain service security and integrity.

3.5 For Business Operations. (a) Process payments and manage subscriptions, (b) prevent fraud and ensure platform security, (c) comply with legal obligations, (d) enforce our Terms of Service, (e) protect our intellectual property and brand, (f) defend against legal claims and litigation, (g) respond to regulatory inquiries and investigations.

4. AI FEATURES AND DATA PROCESSING

4.1 How AI Uses Your Data. (a) AI features analyze your content to provide editing suggestions, (b) Shape processes your product design to generate contextual improvements, (c) natural language commands are processed to understand your intent, (d) all AI processing respects the privacy of your changes until you share them.

4.2 No Training on User Content. We do not use customer content — including any content you create, upload, or that we receive from third-party APIs such as Google Workspace — to train, fine-tune, evaluate, or otherwise improve any AI/ML model. This applies to raw, aggregated, anonymized, and derived forms of the data. Anonymization is not a basis for training use.

4.3 AI-Generated Content. (a) Code and designs generated by AI belong to you, (b) we don't claim ownership of AI output, (c) you are responsible for reviewing AI-generated content before use.

5. DATA SHARING AND DISCLOSURE

5.1 We Do NOT Sell Your Data. Shape never sells your personal information to third parties.

5.2 When We May Share Information.
5.2.1 With Your Consent. (a) When you choose to share or collaborate on projects, (b) when you deploy changes using our platform.
5.2.2 Service Providers. (a) Payment processors for billing, (b) cloud infrastructure providers for hosting, (c) analytics services with anonymized data only, (d) customer support tools, (e) security and monitoring services, (f) legal and compliance consultants, (g) AI service providers, configured as described in Section 23.
5.2.3 Legal Requirements. (a) Comply with law enforcement requests, (b) protect our rights and prevent fraud, (c) in connection with legal proceedings, (d) protect user safety and platform security, (e) respond to regulatory investigations, (f) defend against legal claims or litigation, (g) comply with court orders or subpoenas.
5.2.4 Business Transfers. In the event of a merger, acquisition, or sale of assets, user data would be transferred under the same privacy protections.
5.2.5 Safety and Security. (a) Investigate policy violations or abuse, (b) protect against threats to user or public safety, (c) prevent illegal activities or harmful content, (d) maintain platform integrity and security.

6. DATA SECURITY

6.1 Security Measures. (a) Encryption of data in transit and at rest, (b) regular security audits and monitoring, (c) access controls and authentication requirements, (d) secure development practices, (e) 24/7 automated threat detection and response, (f) regular penetration testing and vulnerability assessments, (g) employee security training and background checks, (h) incident response and breach notification procedures.

6.2 Data Processing Transparency. (a) Service Delivery: Data may be processed to provide AI features and platform functionality, (b) Safety Monitoring: Content may be analyzed for policy violations and harmful content, (c) Human Review: Inputs and outputs are accessed by humans only (i) with the user's explicit consent for a specific message, (ii) to investigate security, abuse, or violations of law or our Terms, or (iii) as required by applicable law, (d) Legal Compliance: Data may be accessed for regulatory compliance and law enforcement.

6.3 Access Controls. (a) Zero-Trust Architecture: Every request is authenticated and authorized, (b) Role-Based Permissions: Team members only access what they need for their role, (c) Multi-Factor Authentication: Available for all accounts with enforcement options, (d) Session Management: Automatic timeouts and secure session handling, (e) Admin Access Logging: All administrative access is logged and monitored.

6.4 Data Isolation. (a) User Workspaces: Your projects are logically separated from other users, (b) Sandboxed Execution: All code execution happens in secure, isolated environments, (c) Network Segmentation: Critical systems are separated and monitored, (d) Geographic Isolation: Data processing occurs in controlled geographic regions.

6.5 Your Role in Security. (a) Keep your account credentials secure, (b) use strong, unique passwords, (c) report suspicious activity immediately, (d) review and configure your privacy settings, (e) do not share sensitive information in prompts or uploads, (f) regularly review your account activity and settings.

6.6 Incident Response. (a) We monitor for security breaches continuously, (b) affected users will be notified promptly of any incidents, (c) we work with security experts to investigate and resolve issues, (d) law enforcement may be contacted for serious security incidents, (e) regulatory authorities will be notified as required by law, (f) California residents will be notified of data breaches affecting personal information in accordance with California Civil Code Section 1798.82 and other applicable California privacy laws.

7. DATA RETENTION

7.1 How Long We Keep Your Data. (a) Account data: Until you delete your account, (b) Project data: According to your subscription plan, (c) Usage analytics: Up to 2 years, (d) Support communications: Up to 3 years.

7.2 Data Deletion. (a) You can delete projects and data at any time, (b) account deletion removes all associated personal data, (c) some data may be retained for legal compliance.

8. YOUR RIGHTS AND CHOICES

8.1 Access and Control. (a) View and download your data at any time, (b) delete projects, content, and account data, (c) modify your account information and preferences, (d) control sharing and collaboration settings.

8.2 Privacy Settings. (a) Choose what data to share with team members, (b) manage communication preferences, (c) configure security settings.

8.3 Opting Out. (a) Unsubscribe from marketing communications, (b) disable certain analytics features, (c) delete your account entirely.

8.4 Data Subject Access Request Limitations.(a) For GDPR and similar privacy requests, we will respond within legally required timeframes, (b) provide data in standard formats, (c) limit requests to reasonable scope and frequency, (d) charge administrative fees for excessive or repetitive requests, (e) verify identity before processing requests, (f) decline requests that would compromise trade secrets or other users' privacy.

8.5 California Residents' Privacy Rights.
8.5.1 California Consumer Privacy Act (CCPA) Rights. California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA): (a) Right to Know: You have the right to request information about the categories and specific pieces of personal information we've collected about you, the sources of that information, our business purposes for collecting it, and the categories of third parties with whom we've shared it, (b) Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions, (c) Right to Correct: You have the right to request correction of inaccurate personal information, (d) Right to Opt-Out: You have the right to opt-out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising. We do not sell personal information as defined by the CCPA, (e) Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA rights.
8.5.2 How to Exercise Your Rights.California residents can exercise these rights by contacting us atprivacy@shape.new or through your account settings. We will verify your identity before processing requests and respond within 45 days.
8.5.3 Authorized Agents. You may designate an authorized agent to make CCPA requests on your behalf by providing written authorization or power of attorney.

9. INTERNATIONAL USERS

9.1 Data Transfers. (a) Your data may be processed in the United States and other countries where our service providers operate, (b) we implement appropriate safeguards for international transfers including standard contractual clauses, (c) data protection standards are maintained regardless of processing location, (d) we comply with applicable data transfer regulations including GDPR Article 46.

9.2 Regional Compliance. (a) We respect regional privacy laws and regulations including GDPR, CCPA, and other applicable frameworks, (b) users in the EU have additional rights under GDPR including data portability and the right to be forgotten, (c) we're committed to expanding compliance as we grow and enter new markets.

10. CHILDREN'S PRIVACY

Shape is not intended for users under 13 years of age. We do not knowingly collect personal information from children. If we discover we have collected information from a child, we will delete it promptly.

11. CHANGES TO THIS POLICY

11.1 Updates and Notifications. (a) We may update this Privacy Policy periodically, (b) significant changes will be communicated via email, (c) continued use after changes indicates acceptance, (d) previous versions are available upon request.

11.2 Your Options. (a) You can review changes before they take effect, (b) contact us with questions or concerns, (c) discontinue use if you disagree with changes.

12. THIRD-PARTY SERVICES

12.1 Integrations. (a) Shape works with your existing tech stack, (b) third-party integrations have their own privacy policies, (c) we don't control how third parties handle your data, (d) review third-party policies before connecting services.

12.2 Links and References. (a) Our platform may contain links to external websites, (b) external sites have their own privacy practices, (c) we're not responsible for third-party privacy policies.

13. PLATFORM-SPECIFIC INFORMATION

13.1 macOS Launch. (a) Shape launches on macOS first, (b) data handling practices are consistent across platforms, (c) additional platforms will follow the same privacy standards.

13.2 Local Processing. The following operations happen locally on your device and do not leave your machine: rendering the editor, applying edits to local files, saving drafts to disk, and compiling or executing code you author. These operations never contact Shape servers or any third party.

13.3 Server-Side Processing.Operations that require Shape's servers or third-party AI providers — including AI-assisted edits, calendar lookups, content sharing, deployment, and any inference on user content — are sent to Shape's infrastructure and, where AI is involved, to the AI providers described in Section 23. Shape does not self-host AI models. Google Calendar data sent to AI providers is never transmitted back to a model provider for training, fine-tuning, or any secondary purpose, and is processed only under the Zero-Data-Retention configuration described in Section 23.

14. AI SECURITY

14.1 Technical Safeguards. (a) Model Isolation: AI processing is logically separated from other user data, (b) Training Data Protection: User data is not used for AI training under any circumstances, including with consent, (c) Secure Inference: AI features run in monitored environments with safety guardrails, (d) Data Minimization: AI features only access data necessary for the requested operation, (e) Bias Detection: Ongoing monitoring for AI bias and inappropriate outputs, (f) Content Filtering: Multi-layer safety systems to detect harmful content.

14.2 Model Limitations. (a) AI models may behave unpredictably and produce unexpected outputs, (b) AI models may reflect biases present in their original training data, (c) users should review AI output for accuracy and appropriateness before relying on it.

15. DELAWARE AI COMMISSION ALIGNMENT

Shape monitors guidance from the Delaware Artificial Intelligence Commission established under House Bill 333. We align our AI practices with evolving state recommendations for safe and responsible AI utilization while maintaining our commitment to user privacy.

16. BIOMETRIC DATA

Shape does not currently collect biometric identifiers or biometric information as defined by applicable privacy laws. If this changes, we will update this policy and obtain necessary consents.

17. AI MODEL TRANSPARENCY

17.1 Model Providers. (a) Shape uses third-party AI providers accessed through aggregators configured for Zero Data Retention, (b) we do not train our own AI models on user content, (c) we do not fine-tune, distill, or otherwise adapt AI models using user content, (d) we do not use customer data for any model training purpose.

17.2 Model Limitations and Bias. (a) AI models may reflect biases present in the data they were originally trained on by their provider, (b) users should review AI output for accuracy and appropriateness, (c) we continuously work to identify and mitigate harmful outputs in our AI systems, (d) report concerns about AI bias or inappropriate outputs toaifeedback@shape.new.

18. PROHIBITED DATA TYPES

18.1 What NOT to Submit to Shape. For your protection and legal compliance, do NOT upload: (a) biometric identifiers such as fingerprints, facial recognition data, or voice prints, (b) government-issued identification numbers like SSN, passport numbers, or driver's license, (c) financial account information including credit card numbers or bank accounts, (d) medical records or protected health information unless HIPAA-compliant, (e) children's personal information if you know the person is under 13, (f) classified or confidential business information belonging to others, (g) copyrighted content without proper licensing, (h) personal information of third parties without their consent.

18.2 Why These Restrictions Exist. (a) AI systems may not properly handle sensitive data, (b) regulatory compliance varies by data type, (c) security measures may not meet specialized requirements.

19. AUTOMATED DECISION MAKING

19.1 AI-Driven Processes. Shape uses automated systems for: (a) content moderation and safety filtering, (b) usage monitoring and abuse detection, (c) performance optimization and resource allocation, (d) security threat identification and response.

19.2 Your Rights Regarding Automated Decisions.(a) You can request human review of automated moderation decisions, (b) opt out of certain automated processing where legally required, (c) request explanation of how automated systems affect your account.

20. DATA BREACH RESPONSE

20.1 Our Commitment. In the event of a data breach affecting your personal information: (a) we will investigate immediately upon discovery, (b) affected users will be notified within 72 hours when legally required, (c) regulatory authorities will be notified as required by applicable law, (d) we will provide clear information about what happened and what we're doing.

20.2 What We Won't Do. (a) We will not ask for passwords or sensitive information via email, (b) request payment to restore access to your account, (c) blame users for security incidents beyond their control.

21. LAW ENFORCEMENT AND GOVERNMENT REQUESTS

21.1 Legal Process Requirements. (a) We require valid legal process such as subpoenas, court orders, or warrants for data disclosure, (b) we review all requests for legal sufficiency and scope, (c) we notify users when legally permitted, (d) we publish transparency reports on government data requests, (e) we challenge overbroad or legally deficient requests, (f) all legal proceedings involving user data are subject to confidentiality requirements.

21.2 National Security Requests. (a) We may receive national security letters or other classified requests, (b) we are legally prohibited from disclosing some government requests, (c) we challenge overbroad or legally deficient requests when possible.

21.3 Data Retention for Legal Purposes.(a) Data may be retained longer than standard periods for pending legal matters, (b) legal hold procedures may prevent deletion of relevant data, (c) we balance legal requirements with user privacy rights.

22. GOOGLE CALENDAR AND GOOGLE API COMPLIANCE

22.1 What We Access and Why. When you connect your Google account, Shape accesses Google Calendar on your behalf to power calendar-aware features inside Shape — for example, surfacing upcoming events when you draft or schedule content, and creating or updating calendar events that you explicitly request through the app. Shape does not access Gmail, Google Drive, Google Contacts, or any other Google service through this connection.

22.2 OAuth Scopes Requested. Shape requests only the scopes registered in the Google Cloud Console for this application. The current set is:
- https://www.googleapis.com/auth/calendar.events— read, create, update, and delete events on all calendars the connected account can access. Shape uses this scope to create, modify, or cancel events only when you explicitly take that action in the app.
- https://www.googleapis.com/auth/calendar.readonly— read event metadata, attendees, and free/busy information from the connected account's calendars. Shape uses this scope to surface upcoming events and availability in calendar-aware features.
Scope descriptions above describe what each scope grants; the user-facing use is the second sentence in each item. Additional scopes may be requested in the future and will be added to the Cloud Console registration and disclosed in this section before use.

22.3 Categorical Application of General Rules. The rules in Sections 4.2 (no training on user content), 6.2 (permitted human access only), and 23 (AI provider configuration) apply to Google Calendar data without exception. Nothing in those sections is relaxed, narrowed, or replaced by this section.

22.4 Retention of Calendar Data.Calendar data is retained only for the time necessary to provide the feature that requested it, after which it is deleted from active systems. When you disconnect your Google account from Shape, we delete the associated Calendar tokens and cached data within thirty (30) days, except where retention is required by law.

22.5 Account Disconnection and Deletion.You may disconnect your Google account from Shape at any time using either of the following methods:
- In Shape: open account settings and revoke the Google connection.
- In your Google account: visithttps://myaccount.google.com/permissions and remove Shape from the list of connected apps.
Upon disconnection, we revoke stored OAuth tokens and delete cached Calendar content associated with that connection, subject to legal retention obligations.

23. AI PROVIDERS AND ZERO DATA RETENTION

When you use AI features, Shape transmits the minimum data necessary to perform the requested operation to third-party AI providers, configured as described below.

23.1 AI Service Configuration. Shape uses third-party AI providers to deliver AI features. Access to these providers is routed exclusively through third-party aggregators and gateways that support Zero Data Retention (ZDR). Our configuration is set to permit only providers that have ZDR enabled; any provider that does not have ZDR available and active for our organization is excluded at the routing layer. We do not enable or use any consumer or free tier of any underlying AI provider, and we do not use any product surface where inputs may be used for training. The complete list of underlying AI providers and the contractual basis for no-training on each is maintained separately and provided directly to Google as part of the OAuth app review and on request.

23.2 No-Training on AI Inputs. Shape does not train, fine-tune, distill, evaluate, or otherwise improve any AI/ML model — whether developed by us, our subprocessors, or any other party — using raw, aggregated, anonymized, or derived user data, including any data received from Google Calendar APIs. The ZDR routing configuration referenced in Section 23.1 is the operational mechanism that enforces this rule at the inference layer. Inputs sent to AI providers are processed under each provider's API terms, which prohibit using API inputs or outputs for model training.

23.3 Self-Hosted / Offline Models.Shape does not currently self-host any AI model within its own infrastructure for inference on user content. Should this change, this policy will be updated to disclose the model, confirm that Google user data is processed within Shape's own infrastructure, and that the data is never transmitted back to the underlying model provider for training or any secondary purpose.

24. CONTACT US

24.1 Privacy Questions. For questions about this Privacy Policy, our handling of Google Calendar data, or your data generally:
Email:support@shape.new
Mail: 2261 Market Street STE 85658, San Francisco, CA 94114

24.2 Data Subject Requests. To exercise your privacy rights or request data deletion: (a) use the privacy controls in your account settings, (b) contact our support team for assistance. We respond to requests within 30 days.

This Privacy Policy is part of our commitment to transparency and user privacy. We believe you should have control over your data while using AI tools to build products.