Privacy Policy
Last updated August 17, 2026
This policy explains what ScreenPolish collects, why, and the choices you have. It is written to be plain and honest. The single most important fact comes first, because it is the whole point of the product.
Your images never reach our servers
ScreenPolish is a client-side editor. When you open, edit, and export a screenshot, every step happens locally in your browser using your device's own processing. Your images are never uploaded to our servers and never stored by us. We could not look at your screenshots even if we wanted to — they simply never reach us. Closing the tab discards them.
That includes the Pro social pack: every selected platform size is rendered on your device and assembled into a local ZIP archive (or sequential single-file downloads if the archive packager cannot load). Pack-specific entitlement requests (a non-consuming capability preflight before rendering, and one metering grant only after outputs are ready for delivery) carry only capability metadata (that this is a pack export, the chosen format, and a fixed scale) — never the screenshot, never the ZIP, and never a target list that would reveal your layout. After a pack is delivered, the same ordinary analytics and entitlement-refresh requests that can follow any successful export may still run; those also contain no image or archive bytes.
The one way an image leaves your device is when you decide to send it somewhere yourself: downloading the exported file or pack ZIP, copying the image to your clipboard, or using the Share image action, which hands the finished image directly from your device to the app you pick in your device's share sheet (for example X, a messenger, or your photo library). That transfer goes straight from your browser to the app you chose — it does not pass through ScreenPolish, and what the receiving app does with the image is governed by that app's own privacy policy.
Chrome extension capture
If you install the optional ScreenPolish Chrome extension, capture starts only when you click its toolbar icon. It captures the visible viewport of the current tab, then hands the PNG to the ScreenPolish editor locally in your browser through a short-lived, one-time handoff. The extension is a capture entry point only. Editing and exporting still use the existing browser-side path described above.
The extension does not upload or persist screenshot pixels. The extension and website do not collect or retain the source URL, page title, favicon, browsing history, or other source-page metadata. It adds no telemetry. The website may still receive its ordinary technical, account, billing, and configured analytics data as described elsewhere in this policy, but the extension handoff does not add the image or browsing metadata to those requests.
During a handoff, in-memory Chrome session state contains only a random one-time nonce, the source and destination tab identifiers, the source window identifier, an expiry and a consumed state needed to reject replays. It expires after 20 seconds and is removed on completion or failure. You can remove the extension through Chrome at any time.
The extension is limited to its single stated purpose: capturing the visible tab area and opening it in the ScreenPolish editor. We do not sell this data, use it for advertising or credit decisions, or use it for any unrelated purpose. This use follows the Chrome Web Store Limited Use requirements.
Data we do collect
You can use the editor and make a demo export without an account. If you sign in to unlock free monthly exports or to subscribe to Pro, we keep a deliberately small amount of data:
- Your email address — to identify your account and to send magic-link sign-in emails.
- An account record — created the first time you sign in. Besides your email address it can hold a display name and a link to a profile picture, because that is what a sign-in provider returns about you. We never ask you for either of them — they arrive with the sign-in — and if your provider does not send them, the fields simply stay empty.
- A provider account record — if you sign in with Google, we store which provider you used, the account identifier that provider uses for you, and the sign-in tokens it issues (such as an access, refresh or ID token) together with their scope and expiry. This is what lets you sign in again as the same person. We use it for authentication only; we do not read anything else from your Google account with it.
- Session records — to keep you securely logged in and to protect the account. Magic-link sign-in also creates a short-lived, single-use verification record that expires on its own.
- Your export counts — a simple number per calendar month and, since July 2026, per UTC day. They let us enforce the free plan's five-export monthly allowance and show you your own statistics page. They are pure counters: never a filename, image content, dimensions or export settings.
- Recent export-meter retry records — when a share or copy has already reached its destination, we attach a random identifier to the small request that updates your export count. We temporarily keep that identifier, a one-way fingerprint used to detect incorrect reuse, and the quota result so a lost response can be retried without counting the same delivery twice. These records contain no filename, image content, canvas dimensions, preset or other image-derived information. We keep no more than 256 recent records per account and calendar month, replacing the oldest as new ones arrive. The next metered share or copy deletes records older than the previous calendar month. If no later metering request occurs, an older record may remain until another one does or until you delete your account.
- Subscription status — whether you are on the free or Pro plan, together with the identifiers our payment processor uses for your customer, subscription and checkout, the plan you chose and when the current period ends, so we can grant the right entitlements. Card and billing details themselves are held by that processor, not by us.
Apart from those records, and the short-lived abuse-prevention counters described below, an account holds nothing else about you. We never ask you for a postal address, a phone number, a date of birth or any other profile field, we do not build a profile of you from how you use the product, and we never store image content of any kind. All of it is deleted with your account — see Data retention below.
Aggregate usage analytics
To understand roughly how much the product is used, ScreenPolish keeps a small, first-party counter of a fixed set of events — currently “editor opened” and “export completed.” This is cookieless and deliberately coarse. For each event we increment a per-day total, split only by whether the person was signed in. We store no IP address, no device or browser identifier, no location, no filename, and no image data — only a running count of the form (day, event, signed-in or not) → number. These are aggregate event counts, not a profile and not a measure of unique people, and they cannot be traced back to you.
Page-view analytics (self-hosted Umami)
Where enabled, ScreenPolish uses Umami — an open-source, privacy-focused analytics tool that we run on our own infrastructure. It is not a third-party analytics vendor, and this measurement is not shared with one. This is a separate system from the first-party aggregate counter described above. It is off unless we have explicitly configured it.
What it measures. Umami records views of our public pages (the sanitized page path, never private pages such as your account, the admin area, or sign-in) and the same small, fixed set of product events — currently “editor opened” and “export completed.” Concretely, each analytics record we store, linked to a temporary visit (see below), contains: our own site's hostname, the sanitized public page path, any valid, short standard campaign labels present in the link (utm_source, utm_medium, utm_campaign, utm_content, and utm_term), the origin of an external referring site (for example, https://example.com, without the rest of that page's URL), the event name (for product events), your screen size, language, browser, operating system, and device type, and an approximate location — country, and where our geolocation resolves them, region and city — all derived from your request. It also records the sequence and timing of the public pages you view within a single visit.
How visits are counted (cookieless). Umami sets no cookies and stores no persistent identifier in your browser. To tell one visit apart from another it computes a temporary, non-reversible hash of your IP address, your browser's user-agent string, and the site identifier (with a rotating salt). Your IP address is used to compute that hash and to estimate your country; in this configuration Umami does not retain your raw IP address as part of the analytics record.
What it never receives. Umami never receives your screenshots, any image data, filenames, image metadata, or other editor content — those never leave your browser. We deliberately limit the fields the tracker could otherwise collect. An external referrer is reduced to its origin only, so its path, query string, and URL fragment never reach us; same-origin and invalid referrers are discarded. Apart from the five standard UTM campaign parameters listed above, no other query parameter is sent. We also suppress the page title, every URL fragment (the part after a #), and the path of every private or authenticated page. This prevents a referrer path, arbitrary query parameter, or title that happened to contain an email address or filename from reaching the tracker.
Purpose and legal basis. We use this data only to understand, in aggregate, how much the product is used and to improve it. Where the GDPR or a similar law applies, our legal basis is our legitimate interest in operating and improving ScreenPolish, which we pursue with a deliberately privacy-preserving, cookieless configuration. Depending on your jurisdiction, local rules on analytics may also apply; we do not claim that being cookieless removes every such requirement.
Your choices. The tracker honors your browser's “Do Not Track” setting — turn it on and Umami will not collect analytics for your visit. You can also block the analytics script in your browser; the editor works either way.
Retention. Because we host Umami ourselves, we control how long these analytics records are kept. We retain them for at most 90 days: a scheduled cleanup job runs daily and deletes any self-hosted Umami analytics records older than 90 days. We run Umami with the privacy options described here and will update this policy if that materially changes.
Abuse prevention
To protect sign-in and checkout from abuse, we apply short-lived rate limits. Where a request needs to be counted per sender, the identifier (such as an email or IP) is first passed through a one-way keyed hash so the stored value cannot be reversed, and these counters expire automatically. The aggregate usage counter described above does not read or store your IP at all.
Third-party processors
We rely on a few trusted providers to operate. Each receives only the narrow data it needs to do its job, and none of them ever receive your images:
- Google — if you choose Google sign-in, Google handles the OAuth authentication and returns your email address and, typically, the display name and profile picture link on your Google account, which we store as described above.
- Resend — delivers the passwordless magic-link emails you request when signing in by email.
- Stripe — securely processes Pro payments and stores your billing information. We never see or store your full card details.
Because images are processed only in your browser, image data is never shared with Google, Resend, Stripe, or anyone else.
Cookies
We use only strictly-necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies. If we ever enable analytics, it is a privacy-friendly, cookieless measurement that does not profile you. See our Cookie Notice for details.
Pricing and your location
Pro is priced in US dollars, and that single price is shown to everyone. We do not estimate where you are in order to price the product: there is no third-party location service, no lookup of your IP address for pricing, no currency selection, and no pricing preference stored on your device.
Legal basis and your rights
If you are in the European Union or another region with similar laws, you have the right to access, correct, export, and delete your personal data, and to object to or restrict certain processing. We process your data to provide the service you asked for (a contract) and to meet our legal and security obligations.
You can delete your account and its associated data yourself at any time from your account page — this is self-service and takes effect immediately. If you would prefer we handle a request for you, email support@getscreenpolish.com.
Data retention
We keep account data only for as long as your account exists. Deleting your account deletes the account record itself and everything attached to it, in one step: your email address, the display name and profile picture link your sign-in provider returned, the provider account record and the sign-in tokens stored with it, your sessions, your export counts, recent export-meter retry records, and your subscription record. Any pending magic-link verification record expires by itself. Some records held by our payment processor, and limited transaction records we must retain for accounting or legal reasons, may persist for the period required by law. Image data is never retained because it is never stored in the first place.
Changes to this policy
We may update this policy as the product evolves. When we make material changes, we will update the date above. Continued use of ScreenPolish after an update means you accept the revised policy.
Contact
Questions about privacy? Reach us at support@getscreenpolish.com. The company and legal entity behind ScreenPolish will be confirmed here before general availability (placeholder to finalize).