Skip to content

Legal

Privacy Policy

What ScreenshotLens collects, why, who it is shared with, how long it is kept, and the rights you have over it.

Last updated

1. Who is responsible

Screenshotlens is the data controller for the personal data described in this policy.

For any privacy question, or to exercise the rights in section 9, write to [email protected]. We answer within one month.

This policy covers https://screenshotlens.com, the dashboard at https://app.screenshotlens.com, and the capture API. It does not cover the third-party pages you ask us to capture.

2. What we collect

We collect only what the Service needs to work. There is no advertising, no profiling, and no data broking.

CategoryFieldsWhere it comes from
AccountEmail address, name, password hash, and, if you sign in with Google, your Google account identifier and profile picture URLYou, at sign-up, or Google when you use Google sign-in
API keysThe key value and the name you give itGenerated when you create a key
Usage logsEndpoint and operation, request identifier, the request parameters including the URL you asked us to capture, the target host, our response status, the target page’s status, start and completion time, duration, credits charged, and any error code and messageRecorded automatically for each API request
Captured assetsThe screenshot or video produced, its storage URL, size, and content typeProduced by your capture request
PurchasesPackage bought, credits and bonus credits, amount, currency, status, and the Stripe payment identifierRecorded when you buy credits
Technical dataIP address and request metadata in server and security logsCollected automatically when you connect
Contact formYour name, email address, and messageYou, when you submit the form

We never receive your card number. Card details go straight to Stripe, and we only ever see a payment identifier and the outcome.

3. Why we use it, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Creating and running your account, authenticating you, and providing capturesPerformance of a contract, Art. 6(1)(b)
Charging credits, taking payment, and keeping billing recordsPerformance of a contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c), for tax and accounting records
Showing you your own usage logs and credit historyPerformance of a contract, Art. 6(1)(b)
Keeping the Service secure, preventing abuse, and enforcing the acceptable use rulesLegitimate interests, Art. 6(1)(f), in protecting the Service and third parties
Sending transactional email such as password resetsPerformance of a contract, Art. 6(1)(b)
Replying to a message you send us through the contact formLegitimate interests, Art. 6(1)(f), in answering an enquiry you started
Complying with a lawful request from an authorityLegal obligation, Art. 6(1)(c)

We do not send marketing email. If that ever changes we will ask for your consent first, and you will be able to withdraw it in one click.

4. The pages you capture

This is the part of the Service most likely to touch someone else’s personal data, so it is worth being precise.

You choose the URL. We load it and store the resulting image or video, along with the URL itself in your usage log. A capture can therefore contain personal data belonging to people who are not our users: anyone whose name, photograph, or details happen to appear on the page.

For that captured material you are the controller and we are your processor: we process it only to carry out your capture instruction, we do not analyse it, index it, or use it to train anything, and we do not look at it except where we must investigate a credible abuse report or a legal request.

It follows that you need a lawful basis for the captures you make. The acceptable use clause in the Terms sets out the limits, and it is not decoration: capturing pages behind a login, or pages whose purpose is to expose private information, is a breach of contract as well as, quite possibly, of data protection law.

5. Cookies

This website sets no cookies. There is no analytics, no advertising pixel, and no third-party tracker anywhere on it, which is why you have not been asked to accept anything.

The dashboard sets one strictly necessary cookie, named “token”, which holds your session. It is HTTP-only, restricted to the dashboard domain, sent only over HTTPS in production, and expires after seven days. Signing out deletes it. Because it is strictly necessary for a service you asked for, it does not require consent.

Your browser may store a theme preference locally. That never leaves your device and never reaches us.

6. Who we share it with

We do not sell personal data and we do not share it for anyone else’s marketing. We use a small number of processors to run the Service:

ProcessorWhat it handlesWhere
StripePayment processing and billing portal. Receives your payment and billing details directly.EU and United States
CloudflareObject storage for captured assets, and delivery of them.EU and global edge network
ResendTransactional email, including password resets and contact form delivery.EU and United States
GoogleGoogle sign-in, if you choose it. Receives only the sign-in request.EU and United States

Each is bound by a data processing agreement and may use your data only on our instructions. We may also disclose data where the law compels us to, or to establish or defend a legal claim. If we are ever involved in a merger or acquisition, we will tell you before your data moves.

7. International transfers

Some processors above operate outside the European Economic Area. Where data is transferred there, we rely on the European Commission’s adequacy decisions where one applies, and otherwise on the Standard Contractual Clauses together with supplementary measures. Write to [email protected] for a copy of the safeguards for a specific transfer.

8. How long we keep it

DataRetention
Account dataWhile your account is open, then deleted within 30 days of closure
API keysUntil you revoke them, or account closure
Usage logsWhile your account is open, so you can audit your own spending; deleted with the account
Captured assetsUntil you delete them or the account closes, whichever comes first
Billing and purchase recordsTen years from the transaction, as Italian tax and accounting law requires. This survives account closure and cannot be erased on request.
Password reset tokensUntil used, or 30 minutes from issue
Contact form messagesUp to 24 months from your last message in the thread
Security and server logsUp to 12 months

9. Your rights

If you are in the EEA or the UK, data protection law gives you the right to:

  • Ask what we hold about you, and get a copy of it.
  • Have inaccurate data corrected.
  • Have your data erased, except where we must keep it, billing records being the main exception.
  • Restrict or object to processing we base on legitimate interests.
  • Receive your data in a portable, machine-readable form.
  • Withdraw consent, where we relied on consent, without affecting what we did beforehand.

Write to [email protected] to exercise any of these. We may need to verify your identity first. You will not be charged, and we will not treat you worse for asking.

You can also complain to a supervisory authority. In Italy that is the Garante per la protezione dei dati personali (garanteprivacy.it); otherwise it is the authority where you live or work.

10. Security

Passwords are stored only as hashes, never in a recoverable form. Traffic runs over HTTPS. Session cookies are HTTP-only. Access to production systems is limited to people who need it.

No system is perfectly secure. If you find a vulnerability, tell us at [email protected] and give us a reasonable chance to fix it before disclosing it publicly. If a breach ever puts your rights at risk, we will notify you and the supervisory authority within the deadlines the law sets.

11. Children

ScreenshotLens is a developer tool for adults and is not directed at children. We do not knowingly collect data from anyone under 18. Tell us at [email protected] if you believe we have, and we will delete it.

12. Changes to this policy

We may update this policy. The revision date at the top always reflects the current version, and where a change materially affects how we use your data we will tell you by email or in the dashboard before it takes effect.