Privacy policy

Last updated: July 26, 2026

Screenshot Files is designed to collect as little personal data as possible. This policy explains what we process, why we are allowed to process it, how long we keep it, and what you can require us to do about it.

Who is responsible for your data

The controller for the processing described here is:

Jueminel VOF, trading as Screenshot Files
Netherlands
Chamber of Commerce (KvK): 42010375
VAT identification number: NL869272810B01
Email: [email protected]

Our registered address is recorded in the Dutch Commercial Register under the KvK number above, and we will give it to you on request by email. We are not required to appoint a data protection officer and have not appointed one.

Data we process

Retention and deletion

Why we are allowed to process this

Under the General Data Protection Regulation every purpose needs a legal basis. These are ours.

Where we rely on a legitimate interest, that interest is keeping the service secure and financially viable, and we have weighed it against your privacy. You can object to those two processes at any time, see your rights below.

An email address is required to hold an account, because there is no other way to sign you in or reach you about your subscription. Everything else is optional. You can use Screenshot Files as a guest without giving us any identifying data at all.

Service providers and where your data goes

Two different relationships are involved here, and the difference decides who answers to you for what.

Processors, acting only on our instructions.

Cloudflare R2 stores screenshot objects. Railway hosts the application and database. Brevo delivers essential passwordless sign-in, account and subscription emails.

Each of these processes your data only as we instruct, under a data processing agreement, and may not use it for its own purposes. We remain responsible for what they do with it, so bring us any question about them.

Stripe, an independent controller for payment processing.

Stripe handles Pro billing and official receipts. For the payment data it collects, Stripe is not our processor: it is a separate controller in its own right and decides for itself how that data is used. It has to, because it carries its own legal duties as a regulated payment institution, including fraud prevention and anti-money-laundering and know-your-customer obligations that no instruction from us could override. That is also how Stripe's own data processing agreement describes the relationship.

In practice this means we cannot instruct Stripe to delete or alter payment records, and we never receive your full card or bank details. Stripe's own privacy policy governs that processing and sets out the rights you have against Stripe directly, at stripe.com/privacy. We remain the controller for what we store on our side, which is the customer and subscription references and the subscription status described above.

Some of these companies are established outside the European Economic Area, or use infrastructure and support staff outside it, so your data may be transferred there. For our processors those transfers take place under the European Commission's standard contractual clauses, or under an adequacy decision where one applies, together with the additional technical measures described under Security. Stripe, as an independent controller, is responsible for the lawfulness of its own transfers and documents them in its privacy policy. You can ask us for details of the safeguards that apply to a specific provider.

Your rights

You have the following rights over your personal data. Most of them you can exercise yourself, immediately, from the Account screen.

For anything that cannot be done in the app, email [email protected]. We answer within one month, and will tell you if we need longer because a request is complex. Exercising these rights is free unless a request is manifestly unfounded or excessive.

Complaints

If you think we handle your data incorrectly, please tell us first so we can put it right. You also have the right to lodge a complaint with a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl. If you live in another EU or EEA country you can complain to the authority there instead.

Cookies and local storage

We set one cookie, the session token described above, and it is strictly necessary to operate the service. Without it the site cannot tell one visitor from another and nothing works. Dutch and European law does not require consent for a strictly necessary cookie, which is why you are not asked to accept anything.

We use no advertising cookies, no analytics cookies, no tracking pixels, and no third-party trackers. Your browser also stores your screenshots, your encryption key and your interface settings locally on your device. That storage is yours: it is not transmitted to us and clearing site data removes it.

Automated decisions

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you. Two checks are automated but limited in effect: whether your account is eligible for the one free trial, and whether traffic looks abusive and should be rate limited. If either decision affects you and looks wrong, email us and a person will look at it.

Children

Screenshot Files is not intended for children under 16. We do not knowingly process the data of a child under 16. If you believe a child has created an account, email us and we will delete it.

Security

We use revocable hashed sessions, short-lived hashed sign-in tokens, private object storage, exact-size signed uploads, server-side authorization, and database-backed rate limiting. Temporary browser-extension captures are encrypted with a browser-session key and removed after transfer, download, or expiry. No online service can guarantee absolute security, so keep a local copy of important screenshots.

Changes to this policy

We update this policy when the service changes. The date at the top always shows the current version. If a change materially affects how we use your data, we will tell account holders by email before it takes effect, so you can object or close your account.

Contact

Questions about privacy can be sent to [email protected]. Ask there for our postal address if you would rather write.