Privacy policy
Screenshot Files is designed to collect as little personal data as possible. This policy explains what we process, why we are allowed to process it, how long we keep it, and what you can require us to do about it.
Who is responsible for your data
The controller for the processing described here is:
Jueminel VOF, trading as Screenshot Files
Netherlands
Chamber of Commerce (KvK): 42010375
VAT identification number: NL869272810B01
Email: [email protected]
Our registered address is recorded in the Dutch Commercial Register under the KvK number above, and we will give it to you on request by email. We are not required to appoint a data protection officer and have not appointed one.
Data we process
- Browser session. We place a random, HttpOnly session token so you can start without an account. Only a SHA-256 hash of that token is stored server-side, and sessions can be revoked.
- Account email address. If you create or access an account, we store your email and verification time. Sign-in links expire after 15 minutes and only a hash of each temporary token is stored. Brevo processes the recipient address and message contents to deliver essential account and billing emails.
- Optional profile photo. If you add a profile photo, it is resized and stored with your private account data. It is shown only inside your ScreenshotFiles account and is not added to public share pages.
- Pro billing references. Stripe collects and processes your payment details as an independent controller, not on our behalf, which is explained under Service providers below. We store only the Stripe customer and subscription references and the subscription status. To enforce one free trial per payment method, a Stripe-provided payment-method fingerprint is transformed with a keyed one-way hash before storage. We never receive full card or bank details.
- Your cloud screenshots. Images synchronized to the cloud are converted to WebP and stored in Cloudflare R2. Guest uploads are limited to 5 screenshots and 10 MB for 7 days. Free accounts are limited to 25 screenshots and 100 MB for 30 days. Pro accounts are limited to 2,000 screenshots and 2 GB.
- Encrypted local vault. New screenshots and imported images are encrypted on your device with the browser Web Crypto API and stored in IndexedDB before cloud synchronization is attempted. The device key is non-exportable and stays in that browser. Local-only file contents and metadata are not sent to our servers. Clearing site or browser data removes the local files and their encryption key, which makes those copies unrecoverable.
- Device exports. Saving to a chosen desktop folder or downloading to Photos, Gallery, Files, or Downloads is handled by your browser and device. These exported files are outside ScreenshotFiles and are controlled by your operating system.
- Browser capture source. When you send a capture from the ScreenshotFiles browser extension, the page title, web address, and domain are stored with the cloud screenshot so you can find its source later.
- OCR text. Text recognition runs in your browser. For Pro accounts, recognized text is stored in the cloud library search index so screenshots can be found by their contents. The screenshot image is not sent to an external OCR or AI provider.
- Passkeys. If you add a passkey, we store its public key, a signature counter, the label you gave the device, and when it was created and last used. The private key never leaves your device and we never receive it, so this data cannot be used to sign in as you. A passkey is removed when you delete it or when you delete your account.
- Support messages. If you use the contact form, we process your name, email address, subject, message, and a request reference so we can answer you. Brevo delivers the message to ScreenshotFiles support.
Retention and deletion
- A browser session expires after 7 days of inactivity and no later than 30 days after it was created. Signing out revokes it immediately.
- Guest screenshots are automatically deleted after 7 days. Free account screenshots are automatically deleted after 30 days. Quick Share images are deleted after 24 hours.
- Cloud expiry does not automatically remove an encrypted local copy. A local copy is only deleted after you confirm that action in ScreenshotFiles or clear browser data yourself.
- Expired sign-in tokens and share links are removed automatically.
- Passkeys are removed immediately when you delete them or delete your account.
- Deleting a screenshot removes its stored object and database record.
- Invoices and the accounting records behind them are kept for 7 years, because Dutch tax law requires it. Together with the payment records Stripe keeps under its own responsibility, this is what we cannot delete on request.
- Daily abuse-prevention IP hashes are removed after two days. One-trial payment-method hashes are retained for up to two years for fraud prevention, including after account deletion.
- Successful transactional email delivery jobs are removed after 30 days. Permanently failed jobs are removed after 90 days so delivery problems can be investigated.
- Support correspondence is kept only as long as needed to answer the request and handle reasonable follow-up.
Why we are allowed to process this
Under the General Data Protection Regulation every purpose needs a legal basis. These are ours.
| What we process | Why | Legal basis |
|---|---|---|
| Browser session, your library, sharing, and the local vault | To deliver the service you asked for | Performance of a contract, article 6(1)(b) |
| Email address, sign-in links, passkeys | To give you an account and sign you in | Performance of a contract, article 6(1)(b) |
| Optional profile photo | Only because you chose to add one | Consent, article 6(1)(a). You can withdraw it by removing the photo |
| Pro subscription and payment references | To run your subscription | Performance of a contract, article 6(1)(b) |
| Invoices and accounting records | Dutch tax law requires us to keep them | Legal obligation, article 6(1)(c) |
| OCR text for Pro accounts | To make your screenshots searchable | Performance of a contract, article 6(1)(b) |
| Daily abuse-prevention IP hashes and rate limiting | To keep the service available and stop abuse | Legitimate interest, article 6(1)(f) |
| One-trial payment-method hashes | To stop the same payment method taking the free trial repeatedly | Legitimate interest, article 6(1)(f) |
| Support messages | To answer your question | Performance of a contract, or legitimate interest if you have no account |
Where we rely on a legitimate interest, that interest is keeping the service secure and financially viable, and we have weighed it against your privacy. You can object to those two processes at any time, see your rights below.
An email address is required to hold an account, because there is no other way to sign you in or reach you about your subscription. Everything else is optional. You can use Screenshot Files as a guest without giving us any identifying data at all.
Service providers and where your data goes
Two different relationships are involved here, and the difference decides who answers to you for what.
Processors, acting only on our instructions.
Cloudflare R2 stores screenshot objects. Railway hosts the application and database. Brevo delivers essential passwordless sign-in, account and subscription emails.
Each of these processes your data only as we instruct, under a data processing agreement, and may not use it for its own purposes. We remain responsible for what they do with it, so bring us any question about them.
Stripe, an independent controller for payment processing.
Stripe handles Pro billing and official receipts. For the payment data it collects, Stripe is not our processor: it is a separate controller in its own right and decides for itself how that data is used. It has to, because it carries its own legal duties as a regulated payment institution, including fraud prevention and anti-money-laundering and know-your-customer obligations that no instruction from us could override. That is also how Stripe's own data processing agreement describes the relationship.
In practice this means we cannot instruct Stripe to delete or alter payment records, and we never receive your full card or bank details. Stripe's own privacy policy governs that processing and sets out the rights you have against Stripe directly, at stripe.com/privacy. We remain the controller for what we store on our side, which is the customer and subscription references and the subscription status described above.
Some of these companies are established outside the European Economic Area, or use infrastructure and support staff outside it, so your data may be transferred there. For our processors those transfers take place under the European Commission's standard contractual clauses, or under an adequacy decision where one applies, together with the additional technical measures described under Security. Stripe, as an independent controller, is responsible for the lawfulness of its own transfers and documents them in its privacy policy. You can ask us for details of the safeguards that apply to a specific provider.
Your rights
You have the following rights over your personal data. Most of them you can exercise yourself, immediately, from the Account screen.
- Access. Ask what we hold about you. The Account screen exports your account metadata and OCR text, and downloads all your images.
- Rectification. Have inaccurate data corrected.
- Erasure. Delete individual screenshots, or delete your account permanently. Account deletion removes cloud screenshots, share links, OCR text and profile data, and cancels an active Pro subscription. Two things survive it: records we must keep by law, such as invoices, and the payment records Stripe holds as its own controller, which we cannot delete for you. For those, address Stripe directly.
- Restriction. Ask us to stop processing while a dispute about accuracy or legitimate interest is resolved.
- Portability. Receive the data you gave us in a structured, commonly used, machine-readable format. The account export is JSON and the image download is a standard archive.
- Objection. Object to processing based on a legitimate interest, which here means abuse prevention and trial-fraud prevention.
- Withdraw consent. Where we rely on consent, which is only the optional profile photo, you can withdraw it at any time by removing the photo. This does not affect processing that already happened.
For anything that cannot be done in the app, email [email protected]. We answer within one month, and will tell you if we need longer because a request is complex. Exercising these rights is free unless a request is manifestly unfounded or excessive.
Complaints
If you think we handle your data incorrectly, please tell us first so we can put it right. You also have the right to lodge a complaint with a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl. If you live in another EU or EEA country you can complain to the authority there instead.
Cookies and local storage
We set one cookie, the session token described above, and it is strictly necessary to operate the service. Without it the site cannot tell one visitor from another and nothing works. Dutch and European law does not require consent for a strictly necessary cookie, which is why you are not asked to accept anything.
We use no advertising cookies, no analytics cookies, no tracking pixels, and no third-party trackers. Your browser also stores your screenshots, your encryption key and your interface settings locally on your device. That storage is yours: it is not transmitted to us and clearing site data removes it.
Automated decisions
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you. Two checks are automated but limited in effect: whether your account is eligible for the one free trial, and whether traffic looks abusive and should be rate limited. If either decision affects you and looks wrong, email us and a person will look at it.
Children
Screenshot Files is not intended for children under 16. We do not knowingly process the data of a child under 16. If you believe a child has created an account, email us and we will delete it.
Security
We use revocable hashed sessions, short-lived hashed sign-in tokens, private object storage, exact-size signed uploads, server-side authorization, and database-backed rate limiting. Temporary browser-extension captures are encrypted with a browser-session key and removed after transfer, download, or expiry. No online service can guarantee absolute security, so keep a local copy of important screenshots.
Changes to this policy
We update this policy when the service changes. The date at the top always shows the current version. If a change materially affects how we use your data, we will tell account holders by email before it takes effect, so you can object or close your account.
Contact
Questions about privacy can be sent to [email protected]. Ask there for our postal address if you would rather write.