Legal

Privacy Policy

What SpecShot collects, what it never touches, where your data lives, and the rights you have over it.

Last updated: August 28, 2026

What we collect

We collect only what's necessary to provide the Service:
  • Account info: name, email, and authentication identifiers from Clerk.
  • Captures: screenshots, DOM data, and styles you explicitly capture from third-party sites.
  • Prompts: generated AI development briefs you create from captures.
  • Usage metrics: capture and prompt counts per month, to enforce plan limits.
  • Billing: handled entirely by Stripe. We never see card numbers.

What we do not collect

  • We do not capture form values or password fields from third-party sites.
  • We do not auto-upload anything. Every capture requires explicit user action.
  • We do not sell or rent your captures or prompts, and we do not share them with third parties for their own purposes.
  • One exception you control. If you add your own OpenAI key in Settings to turn on semantic search, the text of a capture is sent to OpenAI under your key so it can be indexed. Remove the key and that stops. With no key configured, no capture text ever leaves our infrastructure.

The Chrome extension

The SpecShot browser extension is the tool you capture with, and it is covered by this policy. What it does, precisely:
  • It reads a page only when you ask it to. The extension loads a small script on the sites you visit, but that script does nothing except wait for a message. It reads no content, draws nothing, and sends nothing until you open the side panel and start a capture. Nothing runs on its own when a page loads.
  • What a capture contains. The section you select, as structured data: its layout, computed styles, colors, fonts, text content, and a screenshot. We also store the address and title of the page you captured and the time you captured it, so you can find the capture again later.
  • What it leaves behind. Form values and password fields are never collected. Where a form is part of the design you captured, we record its structure, meaning the field types, visible labels and placeholder text, and never what anyone typed into it.
  • Where it sends things. Only to your own SpecShot account. The extension contacts no other server. It contains no analytics, no tracking, and no advertising code.
  • Drafts stay on your machine. A capture you have not saved yet, including its screenshot, is held in your browser's local extension storage so it survives closing the side panel. It is removed when you save or discard it, and it is never uploaded on its own.
  • Sending a prompt to an AI tool. If you choose to open an AI assistant from the panel, the extension fills that tool's message box with the prompt you generated. That happens in your browser, at your instruction, and what you then send is governed by that tool's own privacy policy.
  • Captured DOM is data, never code. It is stored as JSON and is never executed or re-rendered as a live page.

Where data lives

  • Database: Supabase (Postgres) hosted on our infrastructure.
  • Authentication: Clerk (clerk.com).
  • Payments: Stripe (stripe.com).
  • File storage: Supabase Storage with workspace-scoped access controls.

Your rights

You can:
  • Export all your captures and prompts as JSON or Markdown at any time.
  • Delete individual captures, prompts, or your entire account.
  • Request a complete data export by emailing hello@specshot.cc.
Account deletion removes all your data within 30 days.

Cookies

We use only essential cookies for authentication and session management. No tracking, ad-targeting, or third-party analytics cookies are set on visitor browsers without consent.

GDPR & data processing

For agency customers handling EU client data, we offer a Data Processing Agreement (DPA). See our DPA for details.

Contact

Privacy questions or requests? Email hello@specshot.cc.