Security & privacy
Your screenshots stay on your device. By design.
Screshot was built so there is nothing on our side to breach: no servers holding images, no user accounts, no tracking inside the extension. This page explains exactly how it works and how to check it yourself.
None
Screenshots or personal data stored by Screshot
None
Network requests made by the extension
3
Chrome permissions, all without install warnings
None
Accounts, passwords or tokens to protect
Data flow
What happens when you take a screenshot
- 1
You start a capture
By clicking the icon, using a shortcut or the right-click menu. Only then does Chrome give Screshot temporary access to that one tab (activeTab).
- 2
Chrome renders the image locally
The visible area is captured by Chrome itself. For a full page, Screshot scrolls the tab, pauses sticky headers and input, stitches the parts in memory, then restores the page exactly as it was.
- 3
The image opens in a local extension page
The editor and the full-page viewer are pages packaged inside the extension (chrome-extension://). They load no remote code, fonts or analytics.
- 4
You choose where it goes
Copy to the clipboard or download a file. Closing the tab discards the image: the extension has no storage permission, so nothing is kept.
Permissions
Every permission, and why it is needed
| Permission | Used for | What it cannot do |
|---|---|---|
activeTab | Capture the tab in front of you, only at the moment you click the icon or use a shortcut. | Read other tabs, run in the background, or see your browsing history. |
scripting | Scroll the tab you are capturing during a full-page capture, then put it back exactly as it was. | Run on any page you did not ask Screshot to capture. |
contextMenus | Add "Capture visible area" and "Capture full page" to the right-click menu on the Screshot icon. | Change menus on web pages or read what you click. |
Screshot requests no host permissions (such as "Read and change all your data on all websites") and no access to history, cookies, downloads or storage.
Pages the extension opens
Screshot itself sends no data. It opens two pages on screshot.com as normal browser tabs:
- A welcome guide after a manual install. It is skipped when IT installs Screshot by policy.
- An optional one-question survey after uninstall, which includes only the extension version.
The screshot.com website uses Google Analytics to measure visits. See the privacy policy.
Verify it yourself
- Open
chrome://extensions, turn on Developer mode and click Details on Screshot to see its permissions. - Click Inspect views: service worker and open the Network tab.
- Take a visible and a full-page screenshot. No requests leave the browser.
Compliance
Screshot does not currently hold SOC 2 or ISO 27001 certification. Because the extension never transmits or stores screenshots or personal data, it does not act as a data processor for the content your teams capture. If your review needs more detail, we are happy to answer your questionnaire.
Responsible disclosure
Found a security issue? Email contact@screshot.com with the steps to reproduce. Please give us a reasonable time to fix it before sharing it publicly.