Privacy policy
What we collect, why we collect it, how long we keep it, and who else touches it.
Last updated 14 September 2026 · Privacy · Terms · Refunds · Cookies · DPA · Security
Who we are
MB Tech256, Šv. Antano g. 22-1, Didžiasalio k., LT-13264 Vilniaus r., company number 305600824, is the controller for the personal data described here. Reach us at hello@urlshot.io.
What we collect
Your account
Your email address, a hash of your password if you set one, and a name if you give one — used only to greet you in the dashboard and in emails we send you, and changeable or removable in Settings. Passwords are stored as an Argon2id hash and never in a form we can read.
Signing in with Google
If you choose to sign in with Google, Google tells us your Google account's identifier, its email address, whether Google has verified that address, and your name. We keep the identifier and the address so that Google account can sign you in again, and use the name to greet you if signing in with Google is how your account was created. We receive no password and nothing else from your Google account, and you can disconnect it in Settings. Google handles the sign-in itself under its own privacy policy.
Sessions and security
When you sign in we record the IP address and a shortened description of your browser against that session, so you can see where your account is being used and end a session you do not recognise. The same details are recorded against security-relevant events such as sign-ins, password changes and API key creation.
How you use the API
For each screenshot request we record the workspace and key that made it, the outcome, how long it took, what it cost in credits, and the hostname of the page you asked us to capture.
We do not store the full target URL. A URL frequently carries a token or an identifier in its query string, so only the hostname is kept — enough to show you your own usage and to investigate a failure, and not enough to reconstruct what you were fetching.
The website demo
You can try the service on our home page without an account. A page you capture there is handled like any API request: we record its hostname, the outcome and how long it took, not the full address, against a workspace we run for the demo rather than against you.
Before a demo request is processed, Cloudflare Turnstile checks that it comes from a person. It loads only when you start using the demo, and it processes your IP address and details of your browser to make that decision.
To stop the demo being abused, we count how many screenshots each visitor takes. The count is kept against a keyed hash of your IP address — of its /64 network, for an IPv6 address — never the address itself, and it is deleted within 24 hours. Demo screenshots are cached for up to 24 hours so that a page someone already asked for is not rendered again; that cache is shared by everyone using the demo and is not linked to you.
The screenshots themselves
An image is returned to you and, if you asked for caching with cache_ttl, held at the edge for the period you specified — at most 24 hours. Cached images are scoped to your workspace and never served to anyone else. We do not keep a copy beyond that, and we do not look at them.
Payment
We never see or store card details. Payments are taken by Paddle.com, our reseller and the merchant of record, which handles payment details, tax and invoices under its own privacy policy. From Paddle we receive the plan you bought, the subscription's status and billing dates, and Paddle's identifiers for you and the subscription — enough to give your workspace the plan you paid for.
Why we are allowed to
| What | Why | Basis |
|---|---|---|
| Account and sessions | To give you an account and keep you signed in | Performance of a contract |
| Usage and request records | To meter credits, show you your usage, and investigate failures | Performance of a contract |
| IP address and browser on security events | To detect and block abuse, and to show you your own sessions | Legitimate interest in keeping accounts secure |
| Account email — verification, password reset | To prove you own the address and let you recover access | Performance of a contract |
| Billing records | To issue and retain invoices | Legal obligation |
How long we keep it
- Individual request records, including the target hostname: 30 days.
- Aggregated usage — counts and totals per hour, with no hostname: 730 days, so you can see a year-on-year picture.
- Cached screenshots: for the
cache_ttlyou set, up to 24 hours. - Account and session records: while your account is open. Revoked sessions are kept briefly so you can see that a sign-in was ended.
- Billing records: for the period tax law requires, which is longer than your account lives.
Closing your account
You can close your account from Settings in the dashboard. It takes effect immediately and cannot be undone.
Your API keys stop working, your usage history and request records are deleted, and every session ends. Your account record is not deleted outright — it is stripped of the personal data in it. The email address is replaced with a placeholder, the password hash is destroyed, a connected Google account is unlinked and its details deleted, and your name and the workspace name are removed. Addresses and browser descriptions are cleared from your security history, though the history that an event happened is kept.
We keep that stripped record, and the billing records attached to it, because we are required to retain financial records for a period set by law. Once stripped, it no longer identifies you. The email address is released, so you can sign up again with it.
Who else processes it
These are the services we use to run urlshot.io. We do not sell data to anyone.
| Provider | What they do | Where |
|---|---|---|
| Cloudflare, Inc. | API edge, authentication cache, per-workspace usage counters, screenshot cache, inbound email routing, bot check for the website demo (Turnstile) | Global edge network |
| Amazon Web Services EMEA SARL | Browser rendering | eu-central-1, Frankfurt |
| Railway Corp. | Application hosting and the PostgreSQL database | European Union |
| Mailgun Technologies, Inc. | Account email — verification, password reset | European Union (api.eu.mailgun.net) |
Rendering happens in Frankfurt and the database is in the European Union. Our API edge runs on Cloudflare's global network, so authentication caches and usage counters may be held outside the EU; those hold a workspace identifier, a key digest and counts, not your account details. Where a provider is outside the EEA, transfers rely on the European Commission's standard contractual clauses.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable form. Most of it you can see and act on yourself in the dashboard: your sessions, your usage, and closing your account.
Write to hello@urlshot.io and we will answer within one month. If you are unhappy with the answer you can complain to the Lithuanian State Data Protection Inspectorate, or to the supervisory authority where you live.
Cookies
We set four cookies, all strictly necessary, and no advertising or analytics cookies. The cookie page lists each one and what it does.
Children
urlshot.io is a developer tool sold to businesses. It is not intended for children, and we do not knowingly collect their data.
Changes
If this policy changes we update the date at the top. If a change materially affects how we use your data, we will tell account holders by email rather than relying on you to notice.