Privacy Policy
This Privacy Policy describes how Codemarket OÜ (“we”, “us”) processes personal data when you use SeenShot for Mac, seenshot.app, and related APIs. SeenShot is a screenshot capture and annotation app. You can save shots on your Mac. If you sign in and use Share Link, we store PNG files and account records on our cloud.
This notice is written for the EU/EEA/UK (GDPR and UK GDPR) and for the United States (including the California Consumer Privacy Act as amended, “CCPA”). It is not legal advice.
1. Controller
The data controller is:
- Company: Codemarket OÜ
- Address: Harju county, Tallinn, Lasnamäe district, Sepapaja tn 6, 15551, Estonia
- Registry code: 16234616
- VAT: EE102376140
- Email: support@code.market
- Website: https://code.market
Abuse reports for public screenshots: abuse@seenshot.com.
We have not appointed a separate data protection officer. Send GDPR and CCPA requests to support@code.market.
2. What SeenShot does
On your Mac, SeenShot captures a screen region (Path Screen Shot) or the full screen, lets you annotate (Square, Steps, Arrow, Line, Text, Blur, Photo, Color, Background, Save, Share Link), and can save a PNG locally. Sign-in uses email through Firebase. Share Link uploads the PNG to Cloudflare R2 and can publish a public URL on seenshot.app.
3. Personal data we process
We process only the categories below. We do not scrape your desktop except when you capture a screenshot. A screenshot can contain whatever was on screen (including third-party content). You decide what to capture, save, and share.
- Account: email address, Firebase user id (uid), password hash held by Google Identity Platform (we do not store your password), sign-in tokens.
- Cloud screenshots: PNG bytes, shot id, created time, size in bytes, public or private flag, public id. Stored in Cloudflare R2 under
private/{uid}/{shotId}.pngorpublic/{publicId}.png. - Quota and plan: used bytes, plan (
free,pro, orgrace), optional Polar customer id, account created time. - Mac sign-in (OAuth): short-lived authorization codes in D1 with uid, email, redirect URI, and expiry; consumed or expired codes are not kept as a login session.
- Website session: cookie
seenshot_id(Firebase ID token) and localStorage keys for id token, refresh token, uid, email, expiry, and pending email-link address. See the Cookie Policy. - Mac app session: Firebase tokens in the app’s QSettings store (not the macOS Keychain).
- Device permissions: Screen Recording and Camera are requested by macOS. Capture and Photo run on your device. We receive camera pixels only if you place a Photo on a shot and then upload that PNG with Share Link.
- Local files: Save writes a PNG on your disk. We do not receive that file unless you later Share Link.
- Analytics (Mac app only): PostHog events
app_started,sign_in,capture,save,share,update, plus crash reports. The SDK uses a machine identifier. We do not send email, uid, file paths, or share URLs in those events. Default host:https://eu.i.posthog.com. Opt-out file:~/.posthog_optout. - Landing page: the browser may call GitHub’s Releases API to list downloads. That request is between your browser and GitHub, not a SeenShot cookie.
- Payments: if you buy Member, Polar processes the card. We may store a Polar customer id on your user row. We do not store full card numbers.
- Reports: public-shot reports may create a GitHub issue and/or a takedown row (public id, reason, time) and remove the public PNG.
4. Legal bases (GDPR)
- Contract (Art. 6(1)(b)): account, Share Link, cloud storage, quota, export, deletion.
- Legitimate interests (Art. 6(1)(f)): security, abuse takedown, product analytics and crash reports without email/uid, keeping the site running.
- Consent (Art. 6(1)(a)): Camera for Photo; you can refuse in System Settings. Optional PostHog can be stopped with
~/.posthog_optout. - Legal obligation (Art. 6(1)(c)): tax and accounting if a paid Member invoice exists; responding to lawful requests.
5. Who we share data with
We use processors to run SeenShot. They process data on our instructions:
- Cloudflare (Workers, D1, R2) — hosting, database, PNG storage.
- Google (Firebase / Identity Platform) — authentication.
- PostHog — Mac app analytics and crash reports (EU host by default).
- Polar — Member payments, if you check out.
- GitHub — public source and issue reports you choose to file.
A public Share Link is visible to anyone with the URL. Do not publish shots you are not allowed to share.
We do not sell personal information as defined by the CCPA. We do not share personal information for cross-context behavioral advertising.
6. International transfers
Codemarket OÜ is in Estonia. Cloudflare, Google, Polar, and GitHub may process data in the United States and other countries. Those providers publish their own transfer tools (including Standard Contractual Clauses). PostHog’s default host for SeenShot is in the EU.
7. Retention
- Account and cloud PNGs: until you delete the account, delete or overwrite shots, or Free quota eviction removes oldest cloud shots when usage would exceed 10 MB.
- Public PNG: until you unpublish/delete, we take it down, or eviction applies.
- Inbox/upload leftovers: unused upload objects older than about one hour are deleted.
- OAuth codes: until expiry or use.
- Cookie / localStorage: until Sign Out or you clear site data.
- Mac QSettings session: until Sign Out.
- PostHog: per PostHog’s retention for the project.
- Polar: per Polar and tax rules if you paid.
8. How to access, export, and delete
- Access / export: in SeenShot Settings, signed in, use Export my data. That calls
GET /v1/account/exportand downloads a JSON file of your user row and shot metadata. - Delete account and cloud data: in SeenShot Settings, signed in, use Delete account. That calls
DELETE /v1/account, deletes your R2 PNGs and D1 rows, and attempts to delete the Polar customer if one exists. - Sign out (website): Sign Out clears
seenshot_idand localStorage tokens. - Email: support@code.market for GDPR access, rectification, restriction, objection, portability, or complaint follow-up. We will need enough information to verify the account (the email you signed in with).
You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local EU/UK supervisory authority. California residents may contact the California Privacy Protection Agency.
9. United States (including California)
Categories collected: identifiers (email, uid), commercial information (plan, Polar customer id if any), internet activity (app events without email/uid), visual information (screenshots you upload). Sources: you, your device, processors listed above. Business purposes: provide SeenShot, security, debug crashes, process payment. We do not sell or share as those terms are used in the CCPA. To request know, delete, or correct, email support@code.market or use Export / Delete in Settings. We will not discriminate for exercising these rights. You may use an authorized agent as allowed by California law; we will verify the agent and your identity.
10. Children
SeenShot is not directed to children under 13 (COPPA) or under 16 where GDPR requires a higher age. Do not create an account if you are under the applicable age.
11. Security
Traffic uses HTTPS. Cloud objects are in private or public R2 prefixes as described. No method is perfectly secure. A public link is public.
12. Changes
We will update this page and the “Last updated” date when the data we process changes.