Privacy Policy

Last updated: July 20, 2026

This policy explains what ScreenPolish collects, why, and the choices you have. It is written to be plain and honest. The single most important fact comes first, because it is the whole point of the product.

Your images never leave your device

ScreenPolish is a client-side editor. When you open, edit, and export a screenshot, every step happens locally in your browser using your device's own processing. Your images are never uploaded to our servers, never stored by us, and never transmitted to any third party. We could not look at your screenshots even if we wanted to — they simply never reach us. Closing the tab discards them.

Data we do collect

You can use the editor and make a demo export without an account. If you sign in to unlock free monthly exports or to subscribe to Pro, we keep a deliberately small amount of data:

  • Your email address — to identify your account and to send magic-link sign-in emails.
  • Sign-in and session records — to keep you securely logged in and to protect the account.
  • Your monthly export count — a simple number so we can enforce the free plan's five-export monthly allowance.
  • Subscription status — whether you are on the free or Pro plan, so we can grant the right entitlements. Billing details themselves are held by our payment processor, not by us.

We do not collect your name, address, or profile beyond what is listed above, and we never store image content of any kind.

Aggregate usage analytics

To understand roughly how much the product is used, ScreenPolish keeps a small, first-party counter of a fixed set of events — currently “editor opened” and “export completed.” This is cookieless and deliberately coarse. For each event we increment a per-day total, split only by whether the person was signed in. We store no IP address, no device or browser identifier, no location, no filename, and no image data — only a running count of the form (day, event, signed-in or not) → number. These are aggregate event counts, not a profile and not a measure of unique people, and they cannot be traced back to you.

Page-view analytics (self-hosted Umami)

Where enabled, ScreenPolish uses Umami — an open-source, privacy-focused analytics tool that we run on our own infrastructure. It is not a third-party analytics vendor, and this measurement is not shared with one. This is a separate system from the first-party aggregate counter described above. It is off unless we have explicitly configured it.

What it measures. Umami records views of our public pages (the page path only — never the query string or the part after a #, and never private pages such as your account, the admin area, or sign-in) and the same small, fixed set of product events — currently “editor opened” and “export completed.” Concretely, each analytics record we store, linked to a temporary visit (see below), contains: our own site's hostname, the sanitized public page path, the event name (for product events), your screen size, language, browser, operating system, and device type, and an approximate location — country, and where our geolocation resolves them, region and city — all derived from your request. It also records the sequence and timing of the public pages you view within a single visit.

How visits are counted (cookieless). Umami sets no cookies and stores no persistent identifier in your browser. To tell one visit apart from another it computes a temporary, non-reversible hash of your IP address, your browser's user-agent string, and the site identifier (with a rotating salt). Your IP address is used to compute that hash and to estimate your country; in this configuration Umami does not retain your raw IP address as part of the analytics record.

What it never receives. Umami never receives your screenshots, any image data, filenames, image metadata, or other editor content — those never leave your browser. We also deliberately suppress several fields the tracker could otherwise collect: it is never sent the referrer (the page you came from), the page title, any query string or URL fragment (the part after a #), or the path of any private or authenticated page. Our analytics wrapper overwrites the referrer and title with empty values on every page view and event before anything is sent, so a referrer or title that happened to contain an email address or a filename can never reach the tracker.

Purpose and legal basis. We use this data only to understand, in aggregate, how much the product is used and to improve it. Where the GDPR or a similar law applies, our legal basis is our legitimate interest in operating and improving ScreenPolish, which we pursue with a deliberately privacy-preserving, cookieless configuration. Depending on your jurisdiction, local rules on analytics may also apply; we do not claim that being cookieless removes every such requirement.

Your choices. The tracker honors your browser's “Do Not Track” setting — turn it on and Umami will not collect analytics for your visit. You can also block the analytics script in your browser; the editor works either way.

Retention. Because we host Umami ourselves, we control how long these analytics records are kept. We retain them for at most 90 days: a scheduled cleanup job runs daily and deletes any self-hosted Umami analytics records older than 90 days. We run Umami with the privacy options described here and will update this policy if that materially changes.

Abuse prevention

To protect sign-in and checkout from abuse, we apply short-lived rate limits. Where a request needs to be counted per sender, the identifier (such as an email or IP) is first passed through a one-way keyed hash so the stored value cannot be reversed, and these counters expire automatically. The aggregate usage counter described above does not read or store your IP at all.

Third-party processors

We rely on a few trusted providers to operate. Each receives only the narrow data it needs to do its job, and none of them ever receive your images:

  • Google — if you choose Google sign-in, Google handles the OAuth authentication and shares your email address with us.
  • Resend — delivers the passwordless magic-link emails you request when signing in by email.
  • Stripe — securely processes Pro payments and stores your billing information. We never see or store your full card details.

Because images are processed only in your browser, image data is never shared with Google, Resend, Stripe, or anyone else.

Cookies

We use only strictly-necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies. If we ever enable analytics, it is a privacy-friendly, cookieless measurement that does not profile you. See our Cookie Notice for details.

Legal basis and your rights

If you are in the European Union or another region with similar laws, you have the right to access, correct, export, and delete your personal data, and to object to or restrict certain processing. We process your data to provide the service you asked for (a contract) and to meet our legal and security obligations.

You can delete your account and its associated data yourself at any time from your account page — this is self-service and takes effect immediately. If you would prefer we handle a request for you, email support@getscreenpolish.com.

Data retention

We keep account data only for as long as your account exists. When you delete your account, we remove your email, session records, and export counts. Some records held by our payment processor, and limited transaction records we must retain for accounting or legal reasons, may persist for the period required by law. Image data is never retained because it is never stored in the first place.

Changes to this policy

We may update this policy as the product evolves. When we make material changes, we will update the date above. Continued use of ScreenPolish after an update means you accept the revised policy.

Contact

Questions about privacy? Reach us at support@getscreenpolish.com. The company and legal entity behind ScreenPolish will be confirmed here before general availability (placeholder to finalize).