Privacy Policy
Last updated: August 2, 2026
This policy describes what Screenmint collects, why, and how it is handled. The short version: we collect the minimum needed to run an API with accounts and billing, we don’t sell data, and payment details never touch our servers.
What we collect
- Account data — your email address and a securely hashed password (bcrypt). We never store passwords in plaintext.
- Usage data — per-request logs (endpoint, API key, cache status, render time) used for quota enforcement, your usage dashboard, and abuse prevention.
- Rendered content — the screenshots, videos, and OG cards you ask the API to render, plus the target URLs and parameters you supply, are stored so results can be served at stable URLs.
- Billing data — handled entirely by Stripe. We store your Stripe customer reference and plan, never card numbers.
What we don’t do
- No selling or renting of personal data.
- No advertising trackers, and no third-party analytics services.
- No browsing of your rendered images beyond what’s needed for operations, debugging, or abuse investigation.
Analytics & session recording
Both tools below run on our own servers. Your data is not sent to Google Analytics, Hotjar, or any other third-party service.
- Page analytics (Umami). Counts page views and referrers. It sets no cookies, does not track you across sites, and does not build a profile of you. Because it collects no personal data, it runs without asking.
- Session recording (OpenReplay) — off unless you allow it. If you agree, we record how pages are used (clicks, scrolling, navigation) to find confusing or broken parts of the product. Everything you type, along with email addresses and API keys, is masked in your browser before anything is sent, so we never receive it. We ask once; if you decline, or simply ignore the prompt, nothing is recorded. To change your mind later, clear this site’s data in your browser and answer the prompt again.
Cookies & local storage
Your sign-in session is held in a secure, httpOnly cookie that JavaScript can’t read; we also use a small cookie for your light/dark theme and local storage to remember which team you’re viewing and whether you allowed session recording. We set no advertising or cross-site tracking cookies anywhere on the site.
Subprocessors
We share data only with the providers required to operate the Service, each receiving only what it needs:
- Stripe — payment processing; card details are handled entirely by Stripe and never reach our servers.
- Cloudflare (R2) — storage and CDN delivery of your rendered images and videos.
- Resend — transactional email (team invitations and quota notifications).
- Plexsicity Identity (auth.plexsicity.com) — authentication and sign-in.
- Our cloud hosting provider — application servers and the database.
Our analytics and session-recording tools are self-hosted on our own infrastructure and are therefore not subprocessors — that data is never handed to another company.
Retention & deletion
Account and usage records are kept while your account is active. Rendered output is retained for a plan-based period and then deleted automatically: screenshots and OG cards for 90 days (Free), 1 year (Starter), or 2 years (Pro); videos for 7, 45, or 90 days respectively. Cached copies expire within 24 hours. To delete your account and associated data, or to request earlier deletion of specific renders, email [email protected] and we’ll process it promptly.
Your rights
You can request a copy of your data, correction, or deletion at any time via the email above. If you are in a jurisdiction with specific data-protection rights (e.g. GDPR or CCPA), we honor requests accordingly.
Changes
If this policy changes materially, we’ll post the update here with a new date.
Contact
Privacy questions: [email protected].