Privacy policy
This baseline policy describes the current no-account ScreenshotBolt capture flow. Confirm the operator identity, contact address, hosting providers, and any analytics or advertising tools before production launch.
Last updated: September 28, 2026ScreenshotBolt is designed for public, non-sensitive webpages. Do not submit passwords, access tokens, private customer data, or confidential documents to the public capture form.
What this policy covers
This policy covers the public ScreenshotBolt website screenshot tool, its result pages, the screenshot API foundation, and the supporting infrastructure used to queue and render captures.
Information processed when you capture a page
- Request details: the URL you submit, the selected device or custom viewport, and whether you request a full-page capture.
- Task information: a temporary task ID, creation and completion times, queue status, output dimensions, and failure status.
- Network information: an IP address or network identifier may be processed to enforce rate limits and protect the rendering service. Rate-limit keys are hashed in the Redis-backed limiter.
- Operational logs: the service may record a task ID, target hostname, status, duration, and error category. The current logger is designed not to record full query strings.
- Temporary output: the generated PNG is stored so the result page can display and download it.
How we use this information
- To validate and render the requested public URL.
- To show queue progress and return the generated image.
- To prevent abuse, private-network access, and excessive traffic.
- To diagnose failures, capacity problems, and storage errors.
- To maintain and improve the reliability of the service.
Storage and retention
Screenshot files are temporary and are expected to expire after about seven days. Depending on the deployment, files may be stored on the local server or in an object-storage/CDN service. The operator should configure the storage lifecycle rule and verify deletion in production.
The current public flow does not provide a permanent account history. Download an image if you need to keep it longer than the temporary retention period.
Cookies, local storage, and analytics
The current interface stores your language choice in browser local storage. The project currently contains advertising placeholders rather than a live advertising script. If analytics, advertising, affiliate pixels, or other non-essential tracking is added, this policy and the Cookie Policy must be updated and consent controls may be required for some users.
Service providers
Depending on where ScreenshotBolt is deployed, hosting, Redis, browser worker, object storage, CDN, DNS, monitoring, analytics, advertising, and payment providers may process limited service data. The production operator should publish the actual provider list and relevant policy links before enabling those services.
Accounts, API keys, and payments
When account features are enabled, ScreenshotBolt's account service processes your email, account identifier, authentication session, and Google identity data when you choose Google sign-in. ScreenshotBolt stores API key metadata and a one-way hash of each key so the plaintext key is shown only once. Waffo Pancake handles checkout, payment details, tax, and merchant-of- record obligations; ScreenshotBolt receives payment status and product identifiers through its signed webhook.
Data requests and deletion
Because the public flow does not require an account and temporary task data expires automatically, most captures disappear through the normal retention process. If you need to report a privacy issue or request deletion of a still-available result, use the privacy contact channel published on the production site and include the task ID or result URL.
Children
ScreenshotBolt is not directed to children and should not be used to submit a child's personal information.
Changes to this policy
This policy may change when the product adds accounts, payments, analytics, advertising, uploads, new storage providers, or new capture features. The production operator should update the date and publish a meaningful change summary when those changes occur.
Contact
Before launch, the operator must publish a dedicated privacy contact address and legal entity information here. This draft intentionally does not invent an operator name, address, email, or jurisdiction.