Skip to content
ShineAIO
FeaturesDashboard

Privacy Policy

Last updated: September 27, 2026

This policy explains what information Shine AIO LLC handles when you use Shine AIO, this website and the dashboard, and what stays on your own computer.

Contents

  1. The short version
  2. What stays on your computer
  3. What our servers receive
  4. Cookies
  5. How we use it
  6. Who we share it with
  7. How long we keep it
  8. Security
  9. Your choices and rights
  10. Where your data is processed
  11. Children
  12. Changes to this policy
  13. Contact

1. The short version

  • Your checkout data stays on your computer. Profiles (including card details), store accounts, proxies, tasks and order history live in the Shine AIO app on your own machine. We never receive them.
  • Our servers only handle your licence. That means your account email, a hashed password, your licence key, a fingerprint of the computer it is activated on, and a small check-in from the app every few minutes.
  • We do not sell your data, show you ads, or use tracking or advertising cookies.

2. What stays on your computer

The Shine AIO desktop app keeps its data in a folder on your computer. This includes your profiles (names, addresses, emails, phone numbers and payment card details), your store accounts and their saved sign-ins, your proxy lists, task groups, settings and order history. Saved store sign-ins and account passwords are encrypted at rest with a key kept on your computer. None of this is sent to us.

When you run tasks, the app talks directly to the stores you choose, through the proxies you choose, and sends them what a checkout needs (for example your shipping details and card). That is between you and the store; please read their privacy policies.

If you set a webhook (for example a Discord webhook) or a captcha-solving service key, the app sends checkout details or captcha tasks to that address or service, and nowhere else. You control those settings.

3. What our servers receive

When you create an account and sign in

  • your email address (it is your username);
  • your password, which we store only as a bcrypt hash, never in readable form;
  • your licence key and its status.

When the app activates your licence on a computer

  • a machine fingerprint: a one-way hash derived from your operating system’s machine ID, not the ID itself;
  • the computer’s name, operating system and number of CPU cores;
  • the IP address it connected from.

While the app is running

About every five minutes the app checks in to confirm your licence is valid. Each check-in tells us the app’s version, your operating system, how many task groups are running (a number only), which store modules are installed, and the IP address it came from. We keep the latest check-in per licence, and it expires 30 days after the last one. It never includes your profiles, cards, accounts, products or orders.

If you connect Discord

Connecting Discord is optional. If you do, Discord tells us your Discord user ID, username and avatar, which we link to your licence for customer-support access. We ask Discord only for the “identify” permission: no email, servers or messages.

Security and abuse prevention

We use IP addresses and account names to limit repeated sign-in and password-reset attempts, and our servers keep routine access logs for [LOG RETENTION, e.g. 30 days].

Payments

Purchases are processed by [PAYMENT PROCESSOR]. We receive confirmation of payment, not your full card number.

4. Cookies

This website sets no cookies. The dashboard sets one cookie when you sign in: an encrypted, httpOnly session cookie that keeps you signed in for up to 30 days and that scripts on the page cannot read. We use no analytics, tracking or advertising cookies.

5. How we use it

  • to provide your licence: sign you in, activate it on one computer at a time, and let you move it;
  • to send you account email, such as the welcome message and password-reset links (links expire after two hours);
  • to deliver updates and tell you when a store module is switched off or a version can no longer be used;
  • to prevent fraud, licence sharing and abuse, and to keep the Service secure;
  • to provide customer support;
  • to comply with the law.

6. Who we share it with

We share data only with the service providers that run parts of the Service for us, and only what each one needs:

  • Keygen (keygen.sh): licence keys and machine activations (fingerprint, computer name, platform, CPU cores, IP address).
  • Courier: your email address, to send account email.
  • DigitalOcean: hosts our licence servers and their database.
  • Vercel: hosts this website and the dashboard.
  • Cloudflare: provides DNS for our domain.
  • Amazon Web Services (S3): serves app downloads and updates.
  • GitHub: serves the browser component the app downloads on first use.
  • Discord: only if you choose to connect your Discord account.
  • [PAYMENT PROCESSOR]: processes purchases.

Downloading the app or updates, or visiting these sites, means those providers see your IP address as part of serving the request. We may also disclose information if the law requires it, to protect our rights or users, or as part of a sale or reorganisation of the business. We do not sell or rent personal information.

7. How long we keep it

We keep your account and licence information for as long as you have an account, and for a reasonable period afterwards where we need it for legal, accounting or fraud-prevention reasons. Check-in records expire 30 days after the last check-in. Password-reset links expire after two hours. When you ask us to delete your account we delete or anonymise your personal information unless we must keep it.

8. Security

Traffic to our servers is encrypted in transit, passwords are hashed, licence tokens are signed, and our database requires encrypted, authenticated connections. No system is perfectly secure; if we learn of a breach affecting your information we will tell you as the law requires. Keep your password secret and your computer secure, since your checkout data lives there.

9. Your choices and rights

You can:

  • see your account details and change your password in the dashboard;
  • release your licence from a computer at any time;
  • ask us for a copy of your personal information, or to correct or delete it, by writing to [CONTACT EMAIL, e.g. support@shineaio.com].

Depending on where you live (for example California, or the European Economic Area and the United Kingdom), you may have further rights, such as to object to or restrict processing, or to complain to a data-protection authority. We will not treat you differently for using them. Our legal bases for processing are performing our contract with you, our legitimate interests in securing the Service and preventing abuse, and complying with the law.

10. Where your data is processed

Our servers are located in [SERVER LOCATION, e.g. the United States], and our providers may process data in other countries. Where the law requires it, we rely on appropriate safeguards for those transfers.

11. Children

The Service is for adults. We do not knowingly collect information from anyone under 18.

12. Changes to this policy

We will update this policy when what we collect or how we use it changes, and change the date at the top. If a change is significant we will tell you by email or in the app or dashboard.

13. Contact

Shine AIO LLC, [MAILING ADDRESS]. Email: [CONTACT EMAIL, e.g. support@shineaio.com].

ShineAIO

© 2022–2026 Shine AIO LLC. All rights reserved.

Terms of ServicePrivacy PolicyDashboard