Privacy Policy
How Screenshot Capture Studio handles capture data, local storage, optional integrations, usage analytics, and browser permissions.
Last updated: September 8, 2026
Last updated: 2026-09-10
Screenshot Capture Studio is a Chrome extension for capturing visible areas, selected regions, or full pages from the active Chrome tab, then editing, copying, saving, or attaching edited screenshots to new Linear issues.
Summary
Screenshot Capture Studio is local-first. Screenshot capture, editing, clipboard, and local export processing happen in Chrome on the user's device. The extension does not send screenshot pixels, page content, selected text, full page URLs, filenames, clipboard contents, saved files, or stable personal identifiers to the developer of this extension or to analytics.
Premium users can set one custom filename pattern for local saves and cloud uploads, then explicitly upload an edited PNG to Google Drive or Dropbox after connecting a provider. These workflows are optional and never upload screenshots automatically.
Jira issue creation is disabled for the current public rollout.
The extension offers an optional Premium subscription through Paddle. Billing does not require a Screenshot Capture Studio account and is separate from screenshot capture, editing, and export data.
Optional Post-Uninstall Feedback
When a Chromium user uninstalls the extension, Chrome may open the first-party https://glechyan.com/extensions/screenshot/uninstall/ page. The extension does not include query parameters, identity, extension storage, screenshot data, page content, URLs, clipboard data, billing or install tokens, or analytics identifiers in that navigation. The page clearly states that the extension has already been removed and can be closed without responding.
If a person voluntarily submits the optional Tally form, Tally receives only the selected reason and any optional free text they enter under Tally's privacy notice. Please do not include personal, sensitive, screenshot, or page information. Access to those responses is limited to the developer and they are deleted within 90 days. The landing and submission do not create PostHog events and are not a complete uninstall count; aggregate uninstall reporting uses Chrome Web Store Developer Dashboard Installs & Uninstalls metrics.
Data the Extension Can Access
When the user starts a capture, the extension can access only the active tab through Chrome's temporary activeTab permission. Depending on the capture mode selected by the user, the extension can access:
- the visible pixels of the active tab for visible-area capture;
- a user-selected region of the active tab for selected-area capture;
- a user-selected same-document element or visible scrollable container after billing policy grants element-capture access;
- page screenshots captured during local scrolling and stitching for full-page capture;
- basic local export metadata, such as capture timestamp, app name, extension version, capture mode, image dimensions, and the captured page origin when Chrome exposes an
httporhttpspage URL.
Captured page origin is limited to scheme, host, and port, such as https://example.com. The extension does not embed or send full URLs, paths, query strings, fragments, page content, selected text, filenames, clipboard contents, cookies, account data, or stable identifiers.
How the Extension Uses Data
The extension uses captured screenshot data only to provide its user-facing screenshot features:
- opening the screenshot in the local preview editor;
- drawing annotations, shapes, text comments, crop edits, and blur redactions;
- saving the edited screenshot as PNG, JPEG, or PDF;
- copying the edited PNG to the clipboard after the user chooses copy;
- preparing the current edited screenshot before a provider action;
- uploading the edited screenshot image only after the user authorizes Linear and chooses Create issue, then opening Linear's issue composer;
- storing short-lived capture handoff data so the preview editor can load the current screenshot and bulk capture results can support local thumbnails, batch saving, and preview queues during the current Chrome session;
- storing successful captures in the offline History page when automatic History is enabled, including the immutable original, local thumbnail, origin-only page metadata, dimensions, local title, pin state, byte usage, and latest committed editor operations.
Local Processing and Storage
Screenshot processing is local to Chrome. The extension normally stores captured images in chrome.storage.session only long enough for the preview editor to load the current capture. If Chrome rejects a large session-storage write, the extension stores that handoff in local IndexedDB under a random marker kept in the same Chrome session. Preview removes either form after loading it, and a later browser session removes stale fallback entries. The handoff may also contain the capture's CSS-pixel width so text annotations can match the screenshot density; this short-lived local metadata is not sent over the network or used for analytics.
For finished bulk capture jobs, the extension keeps the local bulk job record in chrome.storage.session and referenced captured images in session storage or its same-session IndexedDB capacity fallback until the earliest of: the user choosing Clear results, the user starting another bulk capture job, or the next Chrome session starting. Clearing bulk results deletes only local extension capture data and does not delete files already saved to disk. There is no time-based bulk-results auto-delete in this version.
Automatic capture History is enabled by default and uses a separate versioned IndexedDB database with transactional stores for summaries, original image blobs, thumbnails, and latest committed editor operations. It keeps at most 100 items or 250 MB of extension-owned History data and removes the oldest unpinned items first. Pinned items are never removed automatically; if they prevent enough reclamation, the incoming History write is skipped without blocking its preview. Disabling History stops future saves and preserves existing items. Deleting an item or confirming Clear history removes its owned records from this device. Clearing transient bulk results does not delete durable History. History has no account, synchronization, cloud backup, search index, revisions, or library import/export.
The extension uses chrome.storage.local for local settings such as default capture mode, default export format, local export folder, appearance mode, and the selected issue creation service. It also stores a versioned first-launch onboarding outcome (in_progress, completed, or skipped) and manual and detected flags for the Pin, Capture, Edit, and Export checklist steps, with no account or page information.
For onboarding Step 4, the open page can temporarily receive the successful local export's Chrome download ID and actual file path, or custom folder name and filename. These details are held only in page memory and discarded on the next export attempt, reload, or close. They are not added to persisted onboarding progress, analytics, or diagnostics. The file manager is opened only when the user chooses Show in folder; custom folders instead have manual guidance. For billing, local storage may also hold a random pending checkout claim, an opaque install token, the latest entitlement status, and a cached feature-tier policy. The extension does not store the purchase email or one-time verification code locally. If you choose a custom local export folder, Chrome stores the browser-managed folder handle in local IndexedDB so future explicit PNG, JPEG, and PDF saves can write to that folder when permission is still available. The extension removes the saved handle if Chrome reports that its folder no longer exists. If permission is no longer available, the save fails and tells you to restore access, choose another folder, or switch the save location to Chrome Downloads. Premium filename patterns use only the safe {hostname}, {captureMode}, {date}, and {time} tokens. {hostname} contains only the normalized page hostname, never its path, query, or fragment. The pattern setting remains local to Chrome; the generated filename is sent to a cloud provider only with an explicit upload.
Selected-element capture uses a temporary random local marker on the selected element during capture, then removes it after the capture is restored. The marker, element text, selectors, page content, and full URLs are not sent to analytics or remote services.
The preview editor renders the current edited screenshot as an in-memory local browser blob only after the user chooses Create issue. If Linear is not connected, no screenshot pixels are transmitted before authorization succeeds. The extension stores only the short-lived access token returned by Linear. It then sends the edited screenshot image to Linear through the upload proxy and opens https://linear.new in a new active tab with the returned image asset as the only prefilled description content. Title, prose description, page origin, capture context, and destination fields are not sent by the extension. Jira and GitHub issue submission are not connected in the current public rollout and fail closed.
Premium Billing
Choosing a monthly or yearly Premium trial opens the first-party https://glechyan.com/extensions/screenshot/checkout/ page. That page loads Paddle Checkout and sends the selected Paddle price plus a random checkout claim to Paddle. Paddle acts as the merchant of record and collects the email, payment details, tax information, and other checkout information it requires under Paddle's own privacy terms. Payment-card details are not sent to or stored by the extension, checkout site, or Cloudflare billing Worker.
Paddle webhook notifications send the billing Worker Paddle customer, subscription, transaction, adjustment, product, price, status, and billing-date identifiers needed to determine Premium access. The Worker stores this limited billing state in Cloudflare D1. It validates that events belong to Screenshot Capture Studio's configured product and monthly or yearly price, rejects invalid signatures, and does not receive screenshot pixels, page content, selected text, full page URLs, filenames, clipboard contents, or analytics identifiers.
To restore a purchase, the user explicitly enters the checkout email. The Worker hashes the normalized email for matching and uses Resend to send a six-digit verification code. Resend receives the destination email and the verification message. Codes expire after 10 minutes; pending checkout claims expire after 24 hours. Opaque install tokens remain in local extension storage until the extension data is cleared or the token is revoked. A cached Premium entitlement may be honored for up to 24 hours when the billing service is temporarily unreachable, then access fails closed until status can be checked. Billing records are retained while needed to provide access, prevent duplicate webhook processing, handle refunds or disputes, and support billing requests.
The extension requests a public feature-tier policy from the billing Worker so the developer can designate an existing feature as free or Premium. The policy contains feature keys and tiers only. These billing actions do not add analytics events and do not send the purchase email to PostHog.
Data Sharing
The extension does not sell screenshot pixels, page content, selected text, full page URLs, filenames, clipboard contents, saved files, cookies, or account data to third parties. Screenshot pixels are transmitted to a third party only when the user explicitly chooses Create issue and sends the edited screenshot image through the Linear upload proxy, or when an explicitly chosen cloud-upload provider action is enabled and used.
The developer of this extension does not receive the user's screenshots, saved files, clipboard contents, page content, selected text, or full page URLs through the extension.
For optional Premium billing, Paddle receives checkout and payment information, Cloudflare processes and stores the limited billing and entitlement records described above, and Resend receives the purchase email only when the user requests a restore code. Each provider processes data under its own terms and privacy policy.
First-Party Extension Usage Analytics
The extension may send limited, cookieless product usage events through the first-party https://e.glechyan.com endpoint to the developer's PostHog EU Cloud project. The endpoint is a PostHog-managed reverse proxy that forwards requests through Cloudflare. The extension does not fall back to direct PostHog ingestion. PostHog documents that this managed proxy does not cache request content or retain request logs. These events are explicitly allowlisted and contain extension metadata such as capture mode, trigger, broad failure category, bounded popup action and page context, bounded capture failure stage and reason, export format, result, editor tool or shortcut action, cloud or issue provider, and, for full-page failures, standard initial/final browser zoom, bounded image-scale and page-height values, captured/drawn tile count buckets, scroll strategy, whether the page grew, and why capture stopped. Only storage failures additionally include encoded-image-size, final page-height, and local storage-fallback-result buckets. Events may also contain extension version, analytics schema version, build variant, the current capture and export settings values, the onboarding step (pin, capture, edit, or export), completion source (detected or manual), completed-or-skipped outcome, and a boolean that states whether the locally cached entitlement currently grants Premium access. This boolean never includes a plan, billing status, customer information, billing token, annotation text, image data, edit coordinates, issue text, or issue links.
When Chrome reports a fresh installation through runtime.onInstalled with the install reason, the extension sends one extension_installed event with only the common properties described above. It does not add an install token or identifier, and it does not run for extension updates, Chrome updates, or unpacked-extension reloads. Chrome does not provide an uninstall callback that can reliably send a corresponding event. The optional post-uninstall Tally form is therefore only partial feedback; Chrome Web Store Developer Dashboard Installs & Uninstalls is the aggregate source of truth for daily install and uninstall counts.
History events contain only success/failure result, capture mode where relevant, and a bounded failure category. They never contain History titles, origins, URLs, item IDs, timestamps, dimensions, byte sizes, screenshot pixels, or editor operations.
Usage analytics does not use PostHog autocapture, session replay, surveys, heatmaps, implicit page tracking, cookies, browser localStorage, or stable personal identifiers. The analytics session identifier is generated in Chrome session storage and is not persisted across browser sessions.
Every usage event and manually classified exception disables PostHog GeoIP enrichment. The PostHog project also discards client IP data before storage.
Analytics requests never include screenshot pixels, page content, selected text, page hostnames, full page URLs, URL paths, queries, fragments, exact image sizes, exact page dimensions, filenames, filename patterns, generated filenames, cloud provider share links, clipboard contents, saved files, account identifiers, full user agents, IP or GeoIP properties, or stable personal identifiers.
The extension may also send a manually classified PostHog Error Tracking exception when an unexpected extension operation fails. These reports contain only a synthetic failure category and limited technical context such as runtime surface, operation, trigger, bounded integration provider and stage, export action and format, bounded capture failure stage and reason, the full-page failure context described above, storage-only failure buckets, build variant, analytics schema version, and extension version. They never include raw error messages, stacks, breadcrumbs, console logs, screenshot data, page content, URLs, filenames, account details, or authentication credentials.
The extension may store the user's selected extension UI language locally when the user changes it in Settings. The selected language and Chrome locale are not sent in analytics events.
First-launch onboarding may record only that the onboarding page was viewed, that one of the original Pin, Capture, Edit, or Export milestones was completed, and whether all five steps completed or the user explicitly skipped. Shortcut step completion stays local and does not add a new analytics property value. Each existing step/source pair is sent at most once from the stored state. These events do not contain the UI language, Chrome locale, page information, screenshots, shortcut assignments, physical keys, or identifiers beyond the session-scoped analytics id described above.
Premium feature access is evaluated from the first-party billing Worker's feature_policy response and the locally cached entitlement. Billing requests do not include the PostHog session identifier, screenshot pixels, page content, selected text, full page URLs, filenames, filename patterns, clipboard contents, or saved files.
Premium Cloud Upload
The extension package includes the identity permission for explicit cloud provider authorization flows. Premium cloud upload runs only after the user selects a cloud service in Settings and explicitly chooses the preview editor Upload action. In that flow, the extension may authorize with Google Drive or Dropbox and send the edited PNG plus generated filename to the selected provider and folder to create the uploaded file and, where supported, a share link. The extension does not upload in the background, sync folders, read existing cloud file contents, persist refresh tokens, persist provider account details, or send cloud share links to analytics. When a user explicitly opens the Google Drive folder picker, the extension reads only folder names and parent relationships to show available locations and create a folder in the selected location; it does not read existing Drive file contents. When a user explicitly opens the Dropbox folder picker, the extension lists visible folder metadata and may create a folder in the selected Dropbox location; it does not read existing Dropbox file contents.
Linear screenshot attachment runs only after the user authorizes Linear and chooses Create issue. Authorization uses the product-owned Screenshot Capture Studio OAuth application, so users authorize access to their own Linear workspace without creating a Linear developer application. The extension sends the edited screenshot image through the configured Cloudflare Worker upload proxy at https://screenshot-linear-upload-proxy.gevorg-glechyan-company.workers.dev. The proxy uses the user's short-lived Linear access token to request Linear file upload metadata, performs the signed upload to Linear storage, and returns the Linear asset URL without storing the screenshot. The extension then opens https://linear.new in a new active tab with only a Markdown image referencing that asset in the description. The user enters all issue details and decides whether to submit in Linear. The extension does not call Linear's issue-create mutation in the default mode, submit issues in the background, persist Linear account details or refresh tokens, learn the resulting issue link, or send Linear issue links to analytics.
Jira Availability
Jira issue creation is disabled for the current public rollout. The public extension does not offer Jira authorization, site lookup, issue creation, or screenshot attachment.
Remote Code
The extension does not load or execute remotely hosted extension code. Its extension pages, background service worker, content helpers, and dependencies run from the packaged extension files.
Permissions and Site Access
The extension requests these Chrome permissions:
activeTab: allows a user-initiated screenshot of the active tab without requesting broad host access;scripting: injects user-initiated helpers into the active tab for selected-area capture, selected-element capture, and full-page scrolling;storage: stores short-lived capture handoff data, durable local capture History and latest committed edits, local extension settings, the local export folder preference, browser-managed native folder handle, and the selected Linear issue connection;clipboardWrite: copies the edited screenshot to the clipboard only after the user chooses copy;downloads: saves explicit local PNG, JPEG, and PDF exports when the user selects Chrome Downloads as the save location;identity: supports explicit cloud provider authorization flows when cloud upload is enabled and explicit Linear authorization for screenshot attachment.tabs: lists and activates tabs in the current Chrome window only after the user starts the premium bulk tab capture workflow from the guided popup dialog. Bulk tab capture runs locally, one tab at a time, with jobs capped at 30 tabs split into six-tab batches. The same premium bulk workflow can reuse one user-drawn selected-area rectangle and scroll offset across selected open tabs. These workflows store local job status, selected-area geometry, scroll offset, and preview handoff ids without sending tab URLs, page content, or screenshot data to a remote service.
The extension does not request host permissions or optional host permissions.
Limited Use Statement
The extension's use of data is limited to the user-facing screenshot capture, editing, copy, save, local settings, billing access, and limited extension usage analytics described in this policy and in the Chrome Web Store listing. The extension does not use screenshot data, browsing data, page content, or clipboard contents for advertising, profiling, resale, credit worthiness, or any unrelated purpose.
The use of information handled by this extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Contact
For privacy questions, support, or bug reports, use GitHub Issues:
https://github.com/Gevorg-Glechyan/screenshot-extension/issues