Privacy
Snapture Privacy Policy
Applies to Snapture browser extension version 0.18.0 and the Snapture web application.
Effective date: 13 August 2026 · Last updated: 13 August 2026
Snapture is user initiated
Snapture does not continuously monitor your browsing activity and does not automatically capture screenshots. When you explicitly use Snapture to capture a screenshot, record your screen, or create a bug report, the extension accesses the information required to perform that action and create your report. At any other time it is idle and reads nothing from the pages you visit.
1. Who we are
Snapture is a browser extension and web application for screenshots, screen recordings, annotation, and bug reporting. You capture a screenshot or a screen recording of a web page, annotate it, describe the problem, and Snapture files it as a task in Snapture or in an issue tracker you have connected.
Snapture is operated by Galaxy Weblinks and served from snapture.galaxyweblinks.com. We decide what data Snapture collects and why, which makes us the data controller.
Contact for anything in this policy, including privacy requests: snapture@galaxyweblinks.co.in.
2. Data we collect
This table lists every category of data Snapture collects. Everything the extension reads from a web page is read at the moment you start a Snapture action, and not before.
2.1 Full list of data
| Data type | Example | Source and trigger | Why we collect it | Legal basis |
|---|---|---|---|---|
| Email address | priya@example.com | You type it when you sign up | To identify your account, verify your email, reset your password, and send you account email | Performance of our contract with you |
| Name | Priya Sharma | You type it when you sign up | To label you on your tasks, comments, and project memberships | Performance of our contract with you |
| Password | Stored only as a bcrypt hash. Your plain-text password is never written to our database. | You type it when you sign up | To log you in | Performance of our contract with you |
| Issue tracker access tokens and refresh tokens | A Jira access token with your Jira site URL and cloud ID, an Asana access token with your Asana user ID, a Trello access token with your Trello user ID, a Shortcut API token, and an ActiveCollab issue token | The tracker's own login or authorisation screen, after you press Connect and approve | To read your projects, boards, and members so you can pick a destination, and to create the task in your tracker when you press send | Performance of our contract with you |
| Screenshots you capture | A PNG image of the visible area of the tab, of the full page, of a region you drag, or of an element you pick, with your drawings, arrows, text, and blur marks flattened into it | The extension, only after you press Capture or pick the Snapture right-click menu item | To show the bug visually and attach it to the task you create | Performance of our contract with you |
| Screen recordings you make | A WebM video of the tab, window, or screen you selected in Chrome's sharing dialog, with your microphone or tab audio if you turned it on | The extension, only after you press Record and then choose what to share in Chrome's own picker | To show a bug that needs motion to explain, and to attach it to the task | Performance of our contract with you |
| Task content you write | The title, the rich-text description with any images you paste or attach, the severity, the platform, the status, the assignee, and comments | You type it in the extension or the web app | To create and track the task, and to send it to your connected tracker | Performance of our contract with you |
| Page address and page details of a capture | https://shop.example.com/cart?step=2, the domain, the browser and operating system, the viewport size, and information about the element you selected | The extension, at the moment you capture | To record where the bug happened so it can be reproduced, and to group tasks by website | Performance of our contract with you |
| IP address | 203.0.113.44 | Received automatically by our server on requests, and recorded against your device and trial records | To rate limit sign-up and login, and to detect one person opening repeated free trials | Our legitimate interest in securing the service and preventing trial abuse |
| Device fingerprint, browser fingerprint, and user agent | Identifiers derived from your browser and device, the user agent string, and the time you were last seen | Generated by the extension and the web app and sent with your requests | To recognise your device across sessions and to detect one person opening repeated free trials | Our legitimate interest in preventing trial abuse |
| Billing and tax details | Your PayPal subscriber ID, your PayPal subscription ID, your plan, your subscription status, your billing period dates, your invoices, your country code, your GST number if you enter one, and whether you are a business customer | PayPal, after you approve a subscription, and details you type in the billing form | To run your subscription, unlock your plan, issue invoices, and meet tax obligations | Performance of our contract with you, and legal obligation for tax records |
| Referral and coupon records | Your referral code, who referred you, and coupons you redeemed | Generated when you use the referral or coupon features | To apply discounts and to credit the person who referred you | Performance of our contract with you |
We never receive your card number, card expiry date, or card security code. Those go directly to PayPal.
2.2 When the extension reads a web page
Snapture reads information from a web page only when you start a Snapture action. The actions that read a page are:
- pressing Capture in the Snapture sidebar,
- dragging a region or picking an element to capture,
- starting a screen recording,
- choosing the Snapture entry in your browser's right-click menu,
- opening the Snapture sidebar on a page so you can write a report there.
Outside those actions the extension does not read the pages you visit. It does not run a timer that records where you are, it does not send us the address of your active tab in the background, and it never takes a screenshot on its own. Nothing is captured while you are idle, while your screen is locked, or when you move between tabs.
Because a capture is an image of your screen, it can contain personal data, customer data, or internal company data that happened to be visible on the page you captured. Use the blur tool, or crop the capture, before you send a report that shows data you do not want stored.
3. How we use data
Each purpose below names the exact data it uses. We use your data for nothing else.
- Account and login uses your email address, your password hash, and your name.
- Building and storing your bug reports uses your screenshots, your screen recordings, your task title and description, your attachments, and the page address and page details of the capture.
- Sending a task to your tracker uses your issue tracker tokens together with the task content and attachments, and runs only when you press send.
- AI assistance uses your task title, your task description as plain text, and workspace task data. Section 4 sets out exactly what leaves our server.
- Billing uses your PayPal identifiers, plan, invoices, country code, and GST number.
- Account email uses your email address and your name to send verification, password reset, one-time codes, invitations, task notifications, billing notices, and service alerts.
- Security and trial-abuse prevention uses your IP address, your device and browser fingerprints, and your user agent.
What we do not do:
- We do not use your data for advertising, ad targeting, or ad measurement.
- We do not sell your personal data.
- We do not share your personal data for cross-context behavioural advertising as the CCPA defines it.
- We do not use your data to build profiles for purposes unrelated to running Snapture, and we do not buy data about you from data brokers.
- We run no advertising network code, no analytics product, and no third-party error tracking product inside the extension or the web app.
4. AI processing
4.1 The only AI provider we use
Snapture sends data to one AI provider: Groq, Inc. We call the Groq API with the model llama-3.3-70b-versatile. We use no other AI provider, and the production build cannot send your data to any other AI provider.
4.2 Exactly what we send to Groq
- Improve a bug report:the task title you typed and the task description you typed, converted to plain text. Images inside the description are stripped out and replaced with the marker "[image]" before the text leaves our server.
- Generate test cases: the same title and stripped plain-text description.
- AI search in your workspace: the question you type, plus the matching task titles, descriptions, statuses, and project names read from your own workspace to answer it.
- Project intelligence reports: aggregated task data from your projects, which includes task titles, severities, statuses, platforms, creation dates, and assignee names.
4.3 What we never send to any AI provider
Your screenshots, your screen recordings, your image attachments, your password hash, your issue tracker tokens, your IP address, your device fingerprint, and your billing details are never sent to Groq or to any other AI provider. The model we use processes text only.
4.4 Training and retention at Groq
We do not train any AI model on your data, and we do not allow anyone else to train a model on it under our agreement with our AI provider. What Groq does with an API request after it answers is governed by Groq's own terms and privacy policy, which you can read at groq.com/privacy-policy. We state no retention period on Groq's side here, because that is Groq's commitment to make and not ours.
The AI output we get back is stored with your task in our database, and it follows the retention rules in section 6.
5. Sharing and disclosure
5.1 Service providers that process data for us
These companies receive data because they run part of Snapture for us.
- Groq, Inc. receives the text described in section 4.2, to generate bug report improvements, test cases, search answers, and project reports. Privacy policy.
- Twilio SendGrid, Inc. receives your email address, your name, and the content of the email being sent, to deliver our account and notification email. Privacy policy.
- PayPal Holdings, Inc. receives your payment details directly from you and returns your subscriber ID, subscription ID, plan, and status to us, to run your subscription and take payment. Privacy policy.
5.2 Destinations you choose
When you connect a tracker and press send, we deliver your task title, description, screenshots, recordings, attachments, and page address into that workspace. That workspace belongs to you or to your employer, not to us. From the moment the task is created there, that provider's privacy policy governs the copy it holds, and you manage or delete it in that product.
- Atlassian Jira — Privacy policy.
- Atlassian Trello — Privacy policy.
- Asana, Inc. — Privacy policy.
- Shortcut Software Company — Privacy policy.
- ActiveCollab, on the ActiveCollab instance your organisation configured — Privacy policy.
5.3 Other people inside Snapture
Members of a project you belong to can see the tasks, comments, and attachments in that project, and your name against them. Administrators of your workspace can see your the tasks and reports in the projects they administer.
5.4 Legal and compliance disclosure
We will disclose your data when a valid and binding legal order from a court, regulator, or law enforcement authority requires it, when disclosure is needed to establish or defend a legal claim, when it is needed to enforce our terms, or when it is needed to protect someone's safety. We check each request against the law, we disclose only what the order covers, and we tell you before we disclose unless the law forbids telling you.
5.5 Business transfer
If Snapture is sold, merged, or transferred to another company, your data moves with the service as part of that transaction. We will email account holders before the transfer takes effect so you can delete your account first. The receiving company remains bound by this policy until it gives you notice of a different one.
6. Data retention
We keep the following data for as long as your account exists, and we delete it when you ask us to delete it under section 7. We do not currently run automatic time-based deletion of these categories, and we would rather tell you that plainly than publish a schedule we do not keep.
- Account record (email, name, password hash, verification state, referral and onboarding fields): kept until you ask us to delete your account.
- Tasks, comments, and their history: kept until you or a project member deletes them, or until you ask us to delete your account.
- Screenshots, screen recordings, and attachments: kept until deleted. When you delete an attachment in Snapture, the file is removed from our storage immediately and the database row is marked deleted.
- Issue tracker tokens: kept until you disconnect that integration or until your account is deleted. Disconnecting deletes the stored token.
- Device, trial, and IP records: kept while your account exists, because they exist to stop one person opening repeated free trials.
- Billing records and invoices: kept after account deletion for as long as tax and accounting law requires us to keep them.
7. Deletion and your rights
7.1 Rights you have
If the GDPR or the UK GDPR applies to you, you have the right to access your data, correct it, delete it, restrict our processing of it, object to processing we base on our legitimate interests, receive a portable copy, and complain to your data protection authority.
If the CCPA and CPRA apply to you, you have the right to know what we collect and why, to access it, to delete it, to correct it, to opt out of sale or sharing, and to be free from discrimination for using these rights. We do not sell or share personal data, so there is nothing for that opt-out to act on.
If India's Digital Personal Data Protection Act 2023 applies to you, you have the right to a summary of your data and our processing, to correction and completion, to erasure, to nominate someone to act for you, and to raise a grievance with us.
7.2 How to delete your data
Snapture does not yet have a self-service delete button, so deletion runs through us. Email snapture@galaxyweblinks.co.in from the address on your account with the subject line "Delete my account", and tell us whether you want your whole account deleted or only specific data, such as your captures. If you write from a different address, we will ask you to confirm from the account address, because we must not hand your data to someone impersonating you.
You can already delete some data yourself, without contacting us:
- Delete an attachment, a task, or a comment from the Snapture web app.
- Disconnect Jira, Trello, Asana, Shortcut, or ActiveCollab from the integrations screen, which deletes the stored token for that integration.
- Remove the extension from Chrome, which erases everything the extension stored on your device.
7.3 Response times
We acknowledge privacy requests within 5 working days and complete them within 30 days of verifying who you are. If a request is complex enough that we need longer, we will email you before the 30 days are up and tell you why. We charge nothing for these requests.
8. Security
These are the protections Snapture actually has today. We list no certification we do not hold.
- Traffic between the extension, the web app, and our servers runs over HTTPS to snapture.galaxyweblinks.com.
- Passwords are stored only as bcrypt hashes. We cannot read or recover your password.
- Sessions use signed JSON Web Tokens, sent either in a
tokencookie on our domain or in an Authorization header, and they expire. - Sign-up and login are rate limited by IP address to slow down guessing and automated abuse.
- Access to task data is checked per request against your account and your project membership.
Two limits you should know about. Your issue tracker access tokens are stored in our database without an additional application-level encryption layer, so they are protected by our database and server access controls rather than by per-field encryption. And uploaded screenshots, recordings, and attachments are served from a file URL that carries a hard-to-guess generated filename but does not require a login, so anyone who has that exact URL can open the file. Do not paste attachment URLs anywhere you would not paste the file itself.
If a security breach puts your personal data at risk, we will notify the relevant supervisory authority and affected users as the applicable law requires, and our email will tell you what happened, what data was involved, and what to do.
9. International transfers
Snapture stores your account data, your tasks, and your uploaded screenshots and recordings on servers operated by Galaxy Weblinks. Our AI provider Groq, our email provider Twilio SendGrid, and our payment provider PayPal are United States companies and process the data described in section 5.1 in the United States and in the other locations their own policies name. Your connected issue tracker processes your task data wherever that provider hosts your workspace, which you chose when you created it.
If you are in the European Economic Area or the United Kingdom, this means your data is transferred outside that area. Email snapture@galaxyweblinks.co.in if you need the current transfer documentation for a specific provider before you sign up.
10. Children
Snapture is a tool for professional software and testing teams. It is not directed to children, and we do not knowingly collect data from anyone under 16, or under 18 in India. Do not create an account if you are below that age. If you believe a child has given us data, email snapture@galaxyweblinks.co.in and we will delete the account and its data.
11. Cookies and local storage
11.1 Cookies on the Snapture website
We set one cookie, named token, on our own domain. It holds your session token and it exists to keep you logged in. It expires when your session expires or when you log out. We set no advertising cookies, no analytics cookies, and no third-party tracking cookies. Pages you reach from Snapture that belong to PayPal or to your issue tracker set their own cookies under their own policies.
11.2 What the extension stores on your device
The extension uses Chrome extension storage, which stays on your computer:
- Your login state, which holds your Snapture session token, your role, and your login type, so you are not asked to log in on every page.
- Your device fingerprint value, so the same value is reported across sessions for trial-abuse checks.
- Your selections and settings, which cover your active project, your Jira project selection, your last capture mode, your recording preferences, your sidebar and theme settings, and the list of sites where you turned the Snapture sidebar off.
- Your draft task, which holds the capture you are working on, your annotations, and the text you typed, so closing the sidebar does not lose your work.
- Your subscription and update state, which caches your plan status and the latest available extension version so the sidebar does not have to ask our server on every page.
- Short-lived session values, which cache the setup step you are on while the browser is open.
Removing the extension deletes all of this from your device. It does not delete your Snapture account or anything already stored on our server, which section 7 covers.
12. Chrome extension permissions
Chrome shows you these permissions when you install Snapture 0.18.0. Here is every permission and the reason we ask for it.
- activeTab— to act on the tab you are currently viewing when you start a capture from the toolbar icon or the right-click menu.
- scripting— to inject the Snapture sidebar and annotation tools into the page you are reporting on.
- storage— to keep your login state, settings, and draft capture on your device, as listed in section 11.2.
- tabs— to identify the tab you are capturing and record its address on the report, and to open the Snapture dashboard and login pages in a new tab. It is used when you start a capture, not to watch the tabs you open.
- cookies— to read and clear the Snapture session cookie on our own domain, so that logging in or out on the Snapture website also logs you in or out inside the extension.
- offscreen— to run screen recording and video encoding in a hidden document, so recording continues while you switch tabs.
- desktopCapture— declared for screen recording. Version 0.18.0 records through Chrome's standard screen-sharing picker in the offscreen document and does not call this permission's API, so it grants us nothing extra today.
- alarms— to schedule three maintenance jobs: revalidating your Snapture session, checking whether a newer extension version is available, and refreshing the list of websites linked to your projects. None of them read the pages you visit.
- contextMenus— to add the Snapture entry to your browser's right-click menu so you can start a report from any page.
- Access to all websites (
<all_urls>) — Snapture exists to report bugs on whatever website you are testing, and we cannot know those websites in advance, so the sidebar and capture tools must be able to load on any site. Snapture does not use this permission to continuously monitor the websites you visit. It reads webpage information when you explicitly start a Snapture capture or reporting action, as section 2.2 describes.
13. Chrome Web Store Limited Use disclosure
Snapture's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
14. Changes to this policy
When we change this policy we update the "Last updated" date at the top and post the new version on this page. If a change widens what we collect, adds a new company that receives your data, or adds a new purpose, we will email account holders before it takes effect. If you do not accept a change, stop using Snapture and ask us to delete your account under section 7.2.
15. Contact
Write to snapture@galaxyweblinks.co.in for privacy questions, data access requests, deletion requests, or complaints. If you are in the European Economic Area or the United Kingdom, you may also complain to your national data protection authority.
Effective date: 13 August 2026. Last updated: 13 August 2026. Applies to Snapture extension version 0.18.0.