Last updated: March 17, 2026
CaptureAPI ("we", "us", "our") is committed to protecting the privacy of our users ("you", "your"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at captureapi.dev and our API services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this policy, please do not access the Service.
We do not serve advertising. No advertising script runs on this site and no advertising cookie is set, with or without consent.
This section previously described Google AdSense. That description was inaccurate: the integration was never completed, and stating that we served ads overstated what actually happens to your data. Corrected on 2 August 2026. If advertising is ever introduced, this section and the sub-processor table in section 6 will be updated in the same change.
We use the following types of cookies:
You can control cookies through your browser settings and through our cookie consent banner. Declining non-essential cookies will not affect the core functionality of the Service.
We do not sell your personal information. We may share your information in the following circumstances:
These are every vendor that processes data on our behalf, what each one is for, and where it happens. The list is generated from the code, so it cannot fall out of step with what the product actually does — the previous hand-written version named three of them and omitted six.
| Vendor | What for | What it sees | Where |
|---|---|---|---|
| Vercel | Application hosting and page delivery | IP address and request metadata, in server logs | EU (deploy region) and United States |
| Upstash | Database holding accounts, keys and product data | Email, hashed API key, screenshot cache and usage counters | EU |
| Stripe | Payments and subscription management | Email, billing and payment details. Card numbers never touch our servers | EU and United States |
| Brevo | Transactional email (welcome, API key, alerts) | Email address and message content | EU (France) |
| Sentry | Application error reporting | Technical error details and browsing context. Configured with sendDefaultPii disabled, so we do not send identifying data | EU (.de ingestion host) |
| Vercel BotID | Bot protection on public forms | Technical browser signals, no personal identifier | EU and United States |
| PostHog | Product analytics on how features are used | Pseudonymous usage events. Loaded only with your consent | EU (eu.i.posthog.com) |
| Google Analytics 4 | Aggregate visit statistics | Cookie identifier and browsing data — only after you consent. Without consent it writes nothing to your device | United States |
| Vercel Analytics and Speed Insights | Page performance metrics | No cookies, no persistent identifier | EU and United States |
Our Data Processing Agreement covers the contractual side of these relationships.
We retain your account information for as long as your account is active. API usage logs are retained for 90 days for operational purposes. Screenshots and PDFs generated through our API are cached temporarily (up to 24 hours) and then automatically deleted. You may request deletion of your account and associated data at any time by contacting us.
If you are a resident of the European Economic Area (EEA), you have the following data protection rights:
To exercise any of these rights, please contact us at privacy@captureapi.dev. We will respond to your request within 30 days.
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (TLS), secure storage practices, access controls, and regular security audits. However, no method of transmission over the Internet or electronic storage is 100% secure.
Your information may be transferred to and processed in countries other than your country of residence. We ensure that appropriate safeguards are in place to protect your data in accordance with applicable data protection laws, including Standard Contractual Clauses approved by the European Commission.
Our Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete that information promptly.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
For any data protection inquiries or to exercise your GDPR rights, you may contact our Data Protection contact:
Email: privacy@captureapi.dev
CaptureAPI is operated by an independent developer based in Spain, EU. We are committed to ensuring that your data is processed in accordance with applicable EU data protection regulations.
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@captureapi.dev