Privacy Policy
Last updated August 25, 2026
The short version
Shader Lab is a browser-based tool for creating, stacking and animating shaders, built and operated by basement.studio. This policy covers the editor and the community gallery.
You can use the editor without an account. While you do, your work stays on your machine: the editor autosaves into your browser's own IndexedDB storage and sends us nothing. Everything below applies once you sign in and save or publish something.
Signing in
You sign in with Google or GitHub. We never see or store a password.
From Google we request three scopes and nothing else: openid, email and profile. That gives us your email address, name and avatar. We do not ask for Drive, contacts, calendar or any other Google data.
Authentication is brokered by Neon Auth, which means the sign-in screen and the OAuth callback are hosted on Neon's infrastructure rather than ours. Neon stores your email address, name, avatar URL and provider account ID on our behalf.
Your profile
Signing in creates a public profile: a handle, an optional display name, and your avatar. These appear next to every scene you publish.
If you rename your handle we keep a record of the handles you previously claimed, so old links keep resolving and a handle can't be recycled to impersonate you.
Scenes you save or publish
Saving a draft to your account and publishing a scene both send that scene to us. A draft is private — it stays out of the gallery until you publish it — but it lives on our servers either way, not only in your browser.
Either one stores:
- The scene itself: title, description, layer setup, composition size and duration.
- Any file you added to it: audio, 3D models, images and video. These are stored on Cloudflare and served publicly.
- Remix lineage, so a scene built from someone else's credits the original.
- Which scenes you liked.
- Daily counters for how much you have uploaded, so we can enforce publishing limits.
Moderation
Published scenes are public by design. Deleting a scene removes it from the gallery.
If you report a scene we store your account ID, the reason you picked and any note you wrote. A short allowlist of basement.studio staff can read the report queue and take scenes down.
Analytics and error monitoring
- Vercel Analytics and Speed Insights, for page views and performance. Aggregate, and not used to track you across other sites.
- Sentry, in production only, for crashes and errors. A report can include the page you were on, your browser, and — server side — local variable values from the stack trace.
- We do not run Sentry Session Replay. We never record your screen, your pointer or your keystrokes.
- Vercel BotID on every endpoint that writes something — saving a draft, publishing, deleting a scene, liking, remixing, reporting and changing your handle — to keep automated abuse out.
IP addresses
We use your IP address for exactly one thing: not double-counting remixes from people who aren't signed in.
We don't store it. It is combined with the current date and a server-side secret, hashed with HMAC-SHA256, and only that hash is written to the database. Because the date is part of the input, today's hash cannot be matched against yesterday's.
Our infrastructure providers see raw IP addresses in their own request logs, under their own policies.
What we don't do
- We don't sell or rent your data.
- We don't run advertising or ad trackers.
- We don't record your session.
- We don't send you marketing email.
Who else touches it
Data is processed on our behalf by:
- Vercel — hosting, analytics, bot protection.
- Neon — Postgres database and managed authentication.
- Cloudflare — storage and delivery for uploaded assets.
- Sentry — error monitoring.
- Google or GitHub — only the one you chose to sign in with.
Deleting your data
You can delete any of your scenes from your profile at any time.
There is no self-serve account deletion yet. Email dev@basement.studio and we will remove your account, which also removes your profile, your scenes, your likes and your upload counters.
Scenes that other people remixed from yours are their own work and stay published.
Depending on where you live you may have the right to access, correct, export or delete the personal data we hold about you. Email us and we will take care of it.
Contact
Questions about any of this: dev@basement.studio.
If we change this policy materially, we'll update the date at the top.