Privacy Policy
Last updated:
This Privacy Policy explains how BaseShot handles information when you use our desktop apps, website, BaseShot Cloud, and shared capture pages. It covers people who create an account, upload captures, join a team, view shared content, or leave comments. Contact us at contact@baseshot.io with privacy questions.
Local capture and editing
You can capture, edit, and save screenshots and recordings without a cloud account. These captures, local editing data, and capture history stay on your device unless you choose to upload or otherwise share them. Desktop caption generation runs locally. Local capture does not mean the app never connects to the internet: updates, caption-model downloads, sign-in, diagnostics, and usage analytics can make separate network requests.
Account and workspace information
Authentication is provided by Clerk. When you sign in, we receive account identifiers and available profile details such as your name, email address, verification status, and profile picture. Google sign-in does not give BaseShot access to your Gmail, Google Drive, contacts, calendar, or Google password.
For teams, we store workspace names, membership and roles, invitations and invited email addresses, and workspace preferences. We also store your notification and sharing preferences. An invitation can contain your email address before you create an account. Contact us if you received an unwanted invitation or need help with this information.
Payments and billing
BaseShot Cloud subscriptions are sold through Polar, which acts as the merchant of record. When you subscribe, Polar and its payment processors collect your name, email address, billing address, tax details, and payment method to process payments, calculate taxes, and issue invoices. BaseShot does not receive or store your full card number.
We store your Polar customer and subscription identifiers, subscription status, seat count, billing period, and cancellation status. We also track how much storage and cloud transcription each subscription uses so we can apply its allowances. Polar keeps its own customer, order, and invoice records under its privacy policy and legal obligations, including tax and accounting rules.
Captures, text, and transcripts
When you upload a capture, we store the image, GIF, or recording and details needed to organize and share it, including its name, size, dimensions, duration, owner, workspace, upload time, revision, and sharing settings. A recording can include microphone audio, system audio, and camera footage that you chose to record.
Uploaded screenshots can include text recognized on your device so you can search their contents. Uploaded recordings can include captions created in the desktop editor. If usable local captions are not available, a recording upload can also send an audio-only copy to Cloudflare Workers AI to generate a transcript. This cloud processing is separate from generating captions locally in the desktop app.
We store extracted text, transcripts, and caption timing information to support library search and caption playback. Transcripts and captions on shared pages follow the capture's access settings. Review your capture and its sharing settings before uploading sensitive information.
Sharing and collaboration
Shared pages can be accessible to anyone with the link, password-protected, limited to team members, or private. A capture may inherit workspace defaults. Without a more restrictive setting, the default is anyone with the link. Updating a capture can keep the same link, so people who still have access may see the replacement content.
When comments are permitted, we store the comment, replies, display name, posting time, and the commenter's account identifier when signed in. Guests provide a display name. Comments and names are visible to people with access to the conversation and can appear in notification emails. People who can view your content may copy or redistribute it; changing access settings cannot recall copies or emails already received.
Uploading to a team makes the capture available in that team's library. Owners and administrators can manage team content and membership. A shared-link setting does not remove team members' library access. Team files can remain after an uploader leaves the team or deletes their account.
Cookies and device storage
We use cookies and browser storage for sign-in, access to password-protected captures, workspace preferences, and comment drafts. Shared pages also use a first-party visitor cookie to help count views without repeatedly counting the same visitor and to protect access requests from abuse. This visitor cookie can remain for up to one year. Signed-in visits can use an account-derived identifier for view counting. Uploaders can see view totals and receive a first-view notification; this feature does not provide a list of individual viewers.
You can clear cookies and browser storage through your browser, although this can sign you out, remove drafts, or require you to unlock a capture again. The desktop app stores preferences and local history on your device. It saves sign-in credentials using operating-system protected storage when available; signing out removes the saved token. Signing out or revoking Google access does not delete cloud captures.
Diagnostics and service communications
BaseShot and its hosting providers may process IP addresses, request details, browser or device information, and service logs to operate and secure the service. When diagnostics are configured in the desktop app or website, Sentry receives error reports and technical context such as app version, browser or server information, and sampled performance data. This reporting can operate without a cloud capture upload. Desktop error reporting is configured not to attach screenshots automatically. Website diagnostics do not enable Sentry session replay and disable automatic collection of user details, cookies, HTTP bodies, and local variables. Website diagnostics can include logs, HTTP headers, and URL query parameters, with Sentry’s built-in filtering of sensitive values. Error messages, stack traces, URL paths, and other diagnostic context can also be included. Signed-in error reports are associated with your Clerk account identifier. Desktop and browser reports also include your available name and email address. Signing out clears this account identity for subsequent reports.
We process recipient addresses and notification details to send team invitations, comment and reply alerts, and first-view notifications by email or on your desktop. Alerts may contain a capture name, commenter name, comment text, and a link. You can manage optional alerts in Cloud notification settings. We also process information you send when contacting support or reporting a problem.
Usage analytics
PostHog receives usage data automatically to help us understand and improve BaseShot. Website data includes page URLs and query parameters, referring pages, campaign information, clicks and other interactions, browser and device information, and browser and session identifiers. PostHog can process IP addresses to derive approximate location. Website performance metrics, heatmaps, and session replay help us understand how the website works and where people encounter problems. Replay can include visible page content and interactions, with PostHog’s built-in masking of sensitive inputs.
Desktop events include app launches, completed captures, copies, saves, and cloud uploads, together with media type, app version, operating system, and a random installation identifier. The desktop analytics integration sends usage events; it does not upload your screenshot or video files to PostHog. When you sign in, we associate analytics with your Clerk account identifier and include your available name and email address in your PostHog profile. This connects your signed-in activity across the website and desktop app. Signing out returns subsequent activity to a separate anonymous identifier.
Desktop analytics also includes device specifications for debugging: operating system and build, CPU model and logical processor count, architecture, installed RAM, available GPU and driver details, display configuration, and app/runtime versions. These details appear on desktop events and the signed-in user profile. Events can also include available system memory at the time of the event. Detailed hardware collection applies to the desktop app; website analytics uses PostHog’s standard browser information.
Website analytics uses cookies and browser storage; desktop analytics stores its installation identifier locally. Usage analytics starts automatically on the website and in distributed desktop apps, without an in-app toggle. PostHog’s SDK and project settings determine the collection behavior.
How we use information
- Sign you in and operate personal and team workspaces
- Process subscriptions and apply storage and transcription allowances
- Store, organize, search, update, and share captures and related content
- Apply access settings and support comments, captions, and notifications
- Maintain reliability, investigate errors, and prevent abuse
- Understand feature usage and improve BaseShot
- Respond to support, privacy, and legal requests
Where applicable data protection law requires a legal basis, these activities may rely on performing our agreement with you, legitimate interests in operating and securing BaseShot, compliance with legal obligations, or consent where required. We do not sell your personal information or use it for targeted advertising.
Service providers
The services used to operate BaseShot include:
- Clerk for authentication and account management, including Google sign-in
- Convex for application data, search, and background processing
- Cloudflare R2 for media storage and Workers AI for cloud transcription
- Polar for subscriptions, payments, taxes, and invoices
- Resend for notification and invitation emails
- Sentry for desktop and website diagnostics when configured
- PostHog for usage analytics
- Vercel for website hosting and delivery
These providers process information needed for their role in delivering the features you use. We may also disclose information when legally required or necessary to investigate abuse, protect safety, or defend legal rights. This policy does not govern independent copies made by recipients or services you choose outside BaseShot.
Retention and deletion
We retain account and workspace information while needed to provide the service. Cloud captures and associated content remain until deleted, removed with a workspace or account, or expired under an automatic deletion setting. Local files and history are managed separately on your device. Retention of service records depends on their purpose, including troubleshooting, security, resolving requests, and legal obligations.
You can delete captures you are authorized to manage and configure automatic deletion. For account deletion, open your account profile in BaseShot Cloud and choose Delete account. Team owners must transfer ownership or delete their teams first, and subscribers must cancel their Cloud subscription. Account deletion removes personal cloud files and account data, but published files in active teams remain with those teams. Your signed-in comments are replaced with deleted-user placeholders so other people's replies can remain.
Deletion involves background cleanup and is not an instant erasure of every stored copy. Backup, cache, delivery-log, and security records may persist according to their purpose and applicable provider retention. Account deletion removes BaseShot's billing records, but Polar keeps customer and invoice records as required for tax and accounting purposes. We retain a one-way account identifier to prevent deleted account data from being recreated by delayed requests. Copies already downloaded by others and emails already delivered are outside this deletion process.
Contact contact@baseshot.io for help with deletion, guest comments, or data you cannot manage through your account. We may need to verify your identity or authority before acting on a request.
Your choices and privacy rights
You can use local capture without an account, choose what to upload, change sharing and notification settings, and use available download and deletion controls. For team content, you may also need to contact the workspace owner or administrator.
Depending on the law that applies to you, you may have rights to access, correct, delete, or obtain a copy of your personal information; restrict or object to processing; and withdraw consent where processing relies on consent. Withdrawal does not affect earlier lawful processing. Send requests to contact@baseshot.io. You may also have the right to complain to your local data protection authority. These rights can be subject to legal conditions and exceptions.
Security and international processing
We use access controls and other technical safeguards to protect information, but no online service can guarantee absolute security. BaseShot and its providers may process information in countries other than your own. Applicable data protection and transfer requirements depend on your location and the providers involved. Contact us for information about processing locations and safeguards relevant to your use of BaseShot.
Children
BaseShot is not directed to children under 13, or a higher minimum age where required by applicable law. We do not knowingly collect personal information from children under that age. Contact us if you believe a child has provided personal information so we can investigate and take appropriate action.
Changes and contact
We may update this policy as our features, providers, or legal obligations change. The date above identifies this revision. Where required, we will provide notice of material changes or seek consent before applying them. Questions and privacy requests can be sent to contact@baseshot.io.