Privacy Policy
Effective date: September 21, 2026
This policy describes how CloudShots ("CloudShots," "we," "us") handles information when you use the CloudShots app on iOS, macOS, and watchOS, and when you visit this website.
Your library syncs through your own private iCloud, not a CloudShots server.Automatically collected diagnostics never contain screenshot pixels, recognized text, tags, Vision feature prints, or annotations. If you deliberately share or export a screenshot, its recipients receive that content; an image you choose to attach to a problem report is sent to Sentry. All OCR, tagging, AI naming, summaries, and natural-language search run entirely on your device; there is no remote inference, ever. Their results sync only through your private iCloud database to your own devices. Automatic diagnostics — described in full below — consist of crash reports, performance measurements, and product-interaction events, keyed to a random identifier we generate and keep in your own iCloud, so your devices count as one person rather than one identifier per install, never your screenshot content.
Who we work with
CloudShots decides what is collected and why. The services below carry that out on our instructions, each bound by its own agreement with us and its own privacy policy — we link to every one so you can check it yourself. No provider decides on its own what to collect.
- Cloudflare hosts this website, runs its backend functions, stores the Mac Direct download (the DMG and its update feed) in Cloudflare R2, provides the cookieless Web Analytics described below, and forwards mail sent to contact@cloudshots.app to a private inbox without storing it. See cloudflare.com/privacypolicy.
- Resend delivers the support-form emails described below. See resend.com/legal/privacy-policy.
- Paddle is the merchant of record for CloudShots Pro purchased directly on cloudshots.app: it receives your payment details and email to process that purchase. See paddle.com/legal/privacy. Our own licence server, described below, issues and validates the licence key.
- Lemon Squeezy is a draft alternate checkout for CloudShots Pro, not shown while Paddle is the live direct-purchase provider. See lemonsqueezy.com/privacy.
- PostHog provides anonymous product analytics, shared by the app and this website. See posthog.com/privacy.
- Sentry provides crash and error reporting for the app only, not this website. See sentry.io/privacy.
- Apple / iCloud stores your screenshot records, images, and annotations in your own private CloudKit database — this is your Apple account, not a CloudShots server. See apple.com/legal/privacy.
Your screenshots stay yours
CloudShots is a privacy-first screenshot manager. There is no screenshot-storage server for your content, and CloudShots does not automatically collect your screenshot pixels. An image you deliberately attach to a problem report is an exception, described below. Free and Pro sync screenshot records and image assets through your own private Apple iCloud account using CloudKit. On Free, the 30 most recent screenshots are the ones you can open; everything older stays stored on your device and in your iCloud and is shown locked, unavailable for opening, sharing, or exporting. Nothing is deleted to enforce that limit. Pro opens the full synchronized history. How large the library may grow is a separate setting, available on Free and Pro alike — 1,000 screenshots by default, adjustable from 200 up to its top position of Unlimited. Out of the box it deletes nothing. Lowering it below your current library size is the only thing that removes anything: after an explainer and a confirmation naming the exact count, CloudShots permanently deletes the oldest excess from its own library and from its iCloud on every device. Raising it, Unlimited included, deletes nothing and asks nothing. CloudShots changes your Photos library only with your own edits, and Restore Original brings the original back. Your source folder is never touched. OCR text, tags, Vision feature prints, embeddings, generated names, and summaries are computed on device and sync through your private iCloud database to your own devices only; they are never written into a shared screenshot. Private state stays local. Annotations sync with screenshot records and assets. On-device processing such as Vision, OCR, feature recognition, and Apple Intelligence runs entirely on your device. Marking a screenshot Private, a Pro feature, hides it on that device and excludes it from future uploads from that device; it does not delete a copy already synced to iCloud or mark copies private on other devices. CloudShots has no separate account system.
The search index is built on each device from recognition results that sync through your private iCloud, so a screenshot is recognized once; search itself works with no network at all.
Pro's cleanup removes a source original from Photos or your Mac only once it is confirmed uploaded to your iCloud, and always into a recoverable bin — Recently Deleted on iOS, Trash on macOS.
Permissions
CloudShots asks for four permissions. Photos access on iOS and iPadOS, to import your Screenshots album, and Screen Recording access on macOS, to capture your screen, are required — the app depends on them. Notifications access, to show sync progress and outcome, and Accessibility access on macOS, to raise the exact window being captured so it is not captured as a dimmed background frame, are both optional: CloudShots works without either, falling back to activating the owning app when Accessibility is not granted.
Diagnostics and analytics
CloudShots collects anonymized diagnostics to help us find crashes and fix bugs. App Store builds collect them by default; onboarding shows that choice, and you can turn it off there or later in Settings.
- Crash and error reports are sent via Sentry, a third-party processor.
- Anonymous product-usage analytics may be sent via PostHog, a third-party processor.
- Automatically collected diagnostics never include screenshot pixels, OCR text, recognized content, tags, feature prints, generated names, summaries, or annotations — only de-identified technical and usage data such as crashes, errors, and feature usage. A user-authored feedback description can include whatever context you choose, including a description of screenshot content; it is redacted for file paths and email addresses before sending.
- Apple's own MetricKit framework measures how CloudShots behaved on your device and hands us the summary roughly once a day — launch time, hang time, disk writes, CPU time, and whether Low Power Mode was on, plus counts of crashes, hangs, CPU exceptions, and disk-write exceptions. We send it to Sentry. When the system recorded a crash or a hang, the report also carries the call stack for it — every thread, with the memory addresses and function names of the code that was running, in CloudShots and in the Apple frameworks it was calling. A call stack names code, never data: no screenshot content and nothing you typed can appear in either kind of report.
- Session recording is never enabled in the app. PostHog can replay what happens on a screen, and CloudShots pins that off in its own code on every build, together with automatic screen and interaction capture. The guarantee lives in the app, so no setting changed in the PostHog console can turn it on.
- Your identity in this data is a random identifier we generate and keep in your own iCloud key-value store, so your Mac, iPhone, iPad, and Watch count as one person instead of one identifier per device, and a reinstall rejoins the same one. It is never joined to your Apple account and never reveals who you are — with one exception, described under "Report a problem": a beta tester who types an email address into that screen has it attached to their install as well. CloudShots does not use an advertising identifier (IDFA), does not request App Tracking Transparency, and does not perform cross-app or cross-website tracking or share data with ad networks.
- PostHog's GeoIP location lookup and IP address retention are disabled for the app: no location is derived from your address, and it is not retained. See "This website" below for what this website does with your IP address, which is different.
Our declared App Privacy label lists Crash Data, Performance Data, Product Interaction, Other Diagnostic Data, Other Usage Data, Other User Content, and User ID. Every category is marked not linked to your identity and not used for tracking.
We operate no servers that store this diagnostic data — it is held by Sentry and PostHog under their own privacy policies: sentry.io/privacy and posthog.com/privacy.
Your choice: App Store builds collect anonymized diagnostics by default. Onboarding shows that choice, and you can use the Diagnostics/Privacy toggle in Settings to turn it off at any time. Turning it off takes effect immediately: the choice is written before anything else can run, so no further event can pass the gate, and the processors are then shut down. One last anonymous event records the opt-out itself — it carries no content beyond the fact that you turned collection off — and nothing is sent after it.
Beta builds have no opt-out. If you installed CloudShots through TestFlight or a debug build, diagnostics collection is always on and cannot be turned off — the setting exists but has no effect, because a beta build exists to find crashes before release, and diagnostics are what make that possible. CloudShots shows that fixed state instead of a control that cannot change it. The same content boundaries and random per-person identity still apply. If you would rather not send diagnostics, use the App Store build and turn the toggle off there.
Report a problem
Settings includes an in-app "Report a Problem" screen, where the description you type is sent to us via Sentry. You may also deliberately choose an image attachment, preview it, or remove it before sending. That image is sent as shown; CloudShots does not automatically attach library screenshots or your app's view hierarchy. Before it leaves your device, the report text passes through the same redaction step as all diagnostic data, which strips file paths and accidental email addresses from free-form text. This feature is available whenever diagnostics collection is active. TestFlight/debug builds may include an optional contact email with the report and future diagnostics for that install; App Store feedback has no contact-email field.
This website
This website loads PostHog product analytics only when an analytics key is configured for the deployment. When it does load, the site starts PostHog with session recording disabled, autocapture disabled, and no cookie or storage of any kind on your device. Instead, PostHog groups the page views from one visitor within the same day using a one-way hash it computes on its own servers, salted with a value that changes every day and is then deleted; the hash cannot be used to link your visits across different days. The site also honors your browser's Do Not Track setting. It records a page view, leaving a page, a page section scrolling into view, how far down the page you scrolled, a click on a download button, a click on any link leading off this site, opening a question in the FAQ, switching the language, and, on the direct-purchase page, steps of the checkout itself — the price loading, the Buy button, the checkout provider's own progress (loaded, a payment method chosen, completed, failed, or abandoned), and submitting the licence-key recovery or manage-billing forms — each with the page address and browser details PostHog attaches to any event, but never your email, payment details, or licence key. The website and the app report into the same PostHog project, so we can tell how many visits turn into installs. There is no cross-site tracking, no ad network, and nothing is sold to anyone.
This website's host, Cloudflare, reads the two-letter country your connection is coming from and adds only that code to each analytics event; no region or city is added, and PostHog discards the IP address of the request instead of storing it. The app does not do this.
This website also runs Cloudflare Web Analytics, a cookieless page-view counter built into our hosting. It sets no cookie and assigns no cross-site or cross-visit identifier, so a visit here cannot be linked to you elsewhere. It belongs to this website, not to the app, and is entirely separate from PostHog and from any diagnostics the app sends.
The support page has a contact form. It asks for your email address and your message, both required, and a name, which is optional. Sending it posts those fields to a small function running on this site's host, which composes one email — your name or "Anonymous", your email address, the address of the support page, and your message — and hands it to Resend, a third-party email delivery service, which delivers it to our support inbox with your address set as the reply-to. The form also sends two hidden values used to filter out automated submissions; the function checks them and never forwards them. The function keeps no database and writes nothing down: once the email is handed to Resend, the only copy of your message is the one in our inbox, which we keep for as long as we keep our support mail, and the one Resend holds under its own privacy policy: resend.com/legal/privacy-policy.
Purchases
CloudShots Pro purchases made through the App Store are handled entirely by Apple through StoreKit. We never receive your payment card details; Apple processes payment and manages billing under its own privacy policy.
CloudShots Pro bought directly on cloudshots.app is instead handled by Paddle, acting as merchant of record: it receives your payment details and email to process that purchase. The app itself never sends your payment details anywhere — to activate, check, or remove a licence, it sends only the licence key, an instance name (your Mac's name), and an instance id to our own licence server. That server, running on Cloudflare and storing its data in Cloudflare D1, keeps: the licence key itself; its tier and status; when it expires; the email address you checked out with; the payment provider's transaction and subscription ids for that purchase; and, for each Mac you activate it on, that Mac's name and an instance id. Your payment card details are never part of that record — Paddle holds those. We also email your licence key to that checkout email when your purchase completes, and again if you use the "Didn't get your key?" recovery form on the direct-purchase page, through the same Resend service described above. Lemon Squeezy is kept wired as a draft alternate checkout, not shown while Paddle is live.
Where you can buy
- App Store: Apple processes payment under the Apple Media Services Terms.
- Paddle, on cloudshots.app: Paddle is merchant of record under its Buyer Terms and Privacy Policy.
- Lemon Squeezy, on cloudshots.app: when it is the checkout shown, Lemon Squeezy is merchant of record under its Terms and Privacy Policy.
Data retention
Your screenshots remain under your control in local storage and, on Free and Pro, your private iCloud account for as long as you keep them. OCR, tags, feature prints, generated names, and summaries sync with screenshot records in your private iCloud; Private state remains local; annotations sync with screenshot records and assets. Diagnostic data collected via Sentry and PostHog is retained by those processors according to their own retention policies.
Children's privacy
CloudShots is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
Your rights
Because your screenshot content is kept in your devices and private iCloud account, you retain direct access, deletion, and portability control over it at all times. For diagnostic data described above, App Store users can opt out in Settings, and you may contact us to request access to or deletion of data associated with your random identifier.
If you are a beta tester and entered an email address in "Report a Problem," that address is attached to the whole install and not only to the report you sent: it is stored on your device and re-applied at every launch, so later crash reports and usage events from that install carry it too, in both Sentry and PostHog. That makes the install identifiable by your address until you ask us to remove it, so you can request access or deletion by that email as well as by the random identifier. Clearing the field and sending another report erases the stored address, so it is no longer applied from the next launch onward; it stays attached for the rest of the current session. App Store builds never offer the field, so an App Store install has no address attached to it at all.
International data transfers
Your library sync uses your own Apple iCloud account and is subject to Apple's data location practices. Deliberate exports and problem-report attachments go to the recipients or service you choose. Sharing publishes nothing by default: a share link is a CloudKit share you create deliberately, and until you create one nothing about a screenshot is public. A public, read-only iCloud link you create yourself makes that one screenshot viewable by anyone holding it. You may instead invite specific people to view or edit a screenshot; that invite is managed entirely through Apple's own sharing interface, not by us, and an invited participant's edits are written back to your iCloud through the same CloudKit sharing Apple provides. Diagnostic data may be processed by Sentry and PostHog in countries other than your own, as described in their respective privacy policies.
Changes to this policy
We may update this policy from time to time. We will update the effective date above when we do. Continued use of CloudShots after a change constitutes acceptance of the revised policy.
Contact us
Questions about this policy or your data can be sent to contact@cloudshots.app.