Privacy Policy
Last updated: October 2026
ScreenshotAgent captures web pages that you choose. This policy covers what we collect to do that, including site credentials and browser sessions for pages behind a login, who we share it with, and how to delete it.
1. Who we are and what this covers
This policy explains how Cuyahoga Valley Code Shop LLC, which operates ScreenshotAgent (“we,” “us”), collects, uses, and shares information when you visit screenshotagent.com or use the ScreenshotAgent app, embed URLs, and API. For your account information we act as a controller. For content you capture with the Service, we process it on your behalf and under your instructions.
2. Information we collect
- Account information: your name, email address, password (stored as a one-way hash), two-factor settings, and team memberships and roles.
- Billing information: plan, billing status, and invoices. Payment card details are collected and stored by Stripe, not by us.
- Captured content: URLs you add, screenshots and their versions, page titles and structure gathered during discovery, annotations, comments, and tags.
- Site credentials and browser sessions: if you choose to capture pages behind a login, the username and password you provide and saved browser session data (such as cookies and local storage) for that site. Credentials are encrypted at rest.
- API tokens: we store a hash of each token, not the token itself.
- Usage and device data: IP address, browser type, pages viewed, actions taken, and logs from our servers, used to run, secure, and improve the Service.
- How you found us: when you first visit our website we note the campaign tags in the link you followed (such as
utm_sourceandutm_campaign), the website that referred you, and the first page you landed on. If you sign up, we save this with your account so we can tell which channels bring people to ScreenshotAgent. - Communications: messages you send to support and your email preferences.
3. How we use information
- To provide the Service: capture and store screenshots, run discovery and schedules, serve embed URLs, and send notifications.
- To sign in to sites on your behalf, only when you have configured credentials or a saved session, and only for the pages you set up.
- To process payments and manage subscriptions and trials.
- To keep the Service secure, prevent abuse (including automated sign-ups, which we screen with Cloudflare Turnstile), and enforce our Terms of Service.
- To send service emails such as verification, security, billing, and important product notices.
- To understand aggregate usage, measure which marketing channels lead to sign-ups and subscriptions, and improve the product.
4. AI processing
Features such as automatic page discovery send page content, page structure, and screenshots of the sites you direct us to capture to AI providers (currently Anthropic and Google’s Gemini API) so they can analyze the page and return results to us.
We use these providers’ commercial APIs, and we do not permit them to use your content to train their models. When discovery needs to sign in to your site, the AI agent receives the login credentials you configured for that project so it can complete the sign-in. Because AI providers may see what is on a captured page, and may handle those credentials, we recommend capturing with demo or test accounts rather than accounts that display real customer data.
6. Subprocessors
| Provider | Purpose | Data involved |
|---|---|---|
| Stripe | Payment processing, subscriptions, and invoicing | Billing contact details and payment information (we never see full card numbers) |
| Cloudflare | Infrastructure: browser rendering for captures, storage, and content delivery; bot protection on sign-up (Turnstile); cookieless website analytics (Web Analytics) | Pages you capture, screenshots, and request metadata such as IP address, browser, and pages viewed |
| Anthropic | AI analysis for page discovery | Page content, structure, and screenshots of pages you direct us to capture; site credentials when discovery signs in |
| Google (Gemini API) | AI image and page analysis | Screenshots and page content of pages you direct us to capture |
| Resend | Transactional email (verification, invitations, notifications) | Name, email address, and message content |
| Laravel Forge and our hosting provider | Server provisioning and application hosting | All data stored by the Service |
8. Security
We encrypt data in transit with TLS, encrypt stored site credentials, hash passwords and API tokens, support two-factor authentication, and limit internal access to production data. No system is perfectly secure, so please use dedicated test accounts for captures and tell us at support@screenshotagent.com if you find a vulnerability.
9. Retention and deletion
We keep your information for as long as your account is active. Screenshots and versions are kept until you or your team deletes them.
You can delete your account from your profile settings at any time. This deletes your user account and the teams you own, including their screenshots, stored credentials, and saved sessions. Residual copies in backups and stored image files are purged within 30 days. We may keep limited records, such as invoices, where the law requires it.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. You can update most information in your account settings. For anything else, email support@screenshotagent.com and we will respond within 30 days. We will not discriminate against you for exercising these rights.
If you are in the EEA or UK, we rely on these legal bases: performing our contract with you, our legitimate interests in running and securing the Service, compliance with legal obligations, and your consent where we ask for it. You can also complain to your local data protection authority.
If your information is in content a ScreenshotAgent customer captured, please contact that customer first. We will help them respond to your request.
11. International transfers
ScreenshotAgent is based in the United States, and we and our subprocessors may process information in the US and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
12. Children
The Service is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
13. Changes to this policy
We will post any changes here and update the date above. If a change is material, we will notify account owners by email or in the app before it takes effect.
14. Contact
Questions or requests about privacy? Email support@screenshotagent.com.