Privacy Policy
Effective date: August 13, 2026
This policy describes how CloudShots ("CloudShots," "we," "us") handles information when you use the CloudShots app on iOS, macOS, and watchOS, and when you visit this website.
Your library syncs through your own private iCloud, not a CloudShots server.Automatically collected diagnostics never contain screenshot pixels, recognized text, tags, Vision feature prints, or annotations. If you deliberately share or export a screenshot, its recipients receive that content; an image you choose to attach to a problem report is sent to Sentry. All OCR, tagging, AI naming, summaries, and natural-language search run entirely on your device; there is no remote inference, ever. Automatic diagnostics — described in full below — consist of crash reports, performance measurements, and product-interaction events, keyed to a random identifier we generate and keep in your own iCloud, so your devices count as one person rather than one identifier per install, never your screenshot content.
Who we work with
CloudShots decides what is collected and why. The services below carry that out on our instructions, each bound by its own agreement with us and its own privacy policy — we link to every one so you can check it yourself. No provider decides on its own what to collect.
- Cloudflare hosts this website, runs its two backend functions, provides the cookieless Web Analytics described below, and forwards mail sent to [email protected] to a private inbox without storing it. See cloudflare.com/privacypolicy.
- Resend delivers the support-form and launch-notification emails described below, and stores the launch-notification address as a contact. See resend.com/legal/privacy-policy.
- PostHog provides anonymous product analytics, shared by the app and this website. See posthog.com/privacy.
- Sentry provides crash and error reporting for the app only, not this website. See sentry.io/privacy.
- Apple / iCloud stores your screenshot records, images, and annotations in your own private CloudKit database — this is your Apple account, not a CloudShots server. See apple.com/legal/privacy.
Your screenshots stay yours
CloudShots is a privacy-first screenshot manager. There is no screenshot-storage server for your content, and CloudShots does not automatically collect your screenshot pixels. An image you deliberately attach to a problem report is an exception, described below. Free and Pro sync screenshot records and image assets through your own private Apple iCloud account using CloudKit. On Free, the 30 most recent screenshots are the ones you can open; everything older stays stored on your device and in your iCloud and is shown locked, unavailable for opening, sharing, or exporting. Nothing is deleted to enforce that limit. Pro opens the full synchronized history. How large the library may grow is a separate setting, available on Free and Pro alike — 1,000 screenshots by default, adjustable from 200 up to its top position of Unlimited. Out of the box it deletes nothing. Lowering it below your current library size is the only thing that removes anything: after an explainer and a confirmation naming the exact count, CloudShots permanently deletes the oldest excess from its own library and from its iCloud on every device. Raising it, Unlimited included, deletes nothing and asks nothing. Your Photos library and source folder are never touched by it. OCR text, tags, Vision feature prints, generated names, summaries, and Private state stay local and do not sync. Annotations sync with screenshot records and assets. On-device processing such as Vision, OCR, feature recognition, and Apple Intelligence runs entirely on your device. Marking a screenshot Private, a Pro feature, hides it on that device and excludes it from future uploads from that device; it does not delete a copy already synced to iCloud or mark copies private on other devices. CloudShots has no separate account system.
The search index that powers OCR, tagging, AI naming, summaries, and natural-language search is local-only and never synced: each device builds its own, and search works with no network at all.
Pro's cleanup removes a source original from Photos or your Mac only once it is confirmed uploaded to your iCloud, and always into a recoverable bin — Recently Deleted on iOS, Trash on macOS.
Permissions
CloudShots asks for four permissions. Photos access on iOS and iPadOS, to import your Screenshots album, and Screen Recording access on macOS, to capture your screen, are required — the app depends on them. Notifications access, to show sync progress and outcome, and Accessibility access on macOS, to raise the exact window being captured so it is not captured as a dimmed background frame, are both optional: CloudShots works without either, falling back to activating the owning app when Accessibility is not granted.
Diagnostics and analytics
CloudShots collects anonymized diagnostics to help us find crashes and fix bugs. App Store builds collect them by default; onboarding shows that choice, and you can turn it off there or later in Settings.
- Crash and error reports are sent via Sentry, a third-party processor.
- Anonymous product-usage analytics may be sent via PostHog, a third-party processor.
- Automatically collected diagnostics never include screenshot pixels, OCR text, recognized content, tags, feature prints, generated names, summaries, or annotations — only de-identified technical and usage data such as crashes, errors, and feature usage. A user-authored feedback description can include whatever context you choose, including a description of screenshot content; it is redacted for file paths and email addresses before sending.
- Apple's own MetricKit framework measures how CloudShots behaved on your device and hands us the summary roughly once a day — launch time, hang time, disk writes, CPU time, and whether Low Power Mode was on, plus counts of crashes, hangs, CPU exceptions, and disk-write exceptions. We send it to Sentry. When the system recorded a crash or a hang, the report also carries the call stack for it — every thread, with the memory addresses and function names of the code that was running, in CloudShots and in the Apple frameworks it was calling. A call stack names code, never data: no screenshot content and nothing you typed can appear in either kind of report.
- Session recording is never enabled in the app. PostHog can replay what happens on a screen, and CloudShots pins that off in its own code on every build, together with automatic screen and interaction capture. The guarantee lives in the app, so no setting changed in the PostHog console can turn it on.
- Your identity in this data is a random identifier we generate and keep in your own iCloud key-value store, so your Mac, iPhone, iPad, and Watch count as one person instead of one identifier per device, and a reinstall rejoins the same one. It is never joined to your Apple account and never reveals who you are — with one exception, described under "Report a problem": a beta tester who types an email address into that screen has it attached to their install as well. CloudShots does not use an advertising identifier (IDFA), does not request App Tracking Transparency, and does not perform cross-app or cross-website tracking or share data with ad networks.
- PostHog's GeoIP location lookup and IP address retention are disabled for the app: no location is derived from your address, and it is not retained. See "This website" below for what this website does with your IP address, which is different.
Our declared App Privacy label lists Crash Data, Performance Data, Product Interaction, Other Diagnostic Data, Other Usage Data, and Other User Content. Every category is marked not linked to your identity and not used for tracking.
We operate no servers that store this diagnostic data — it is held by Sentry and PostHog under their own privacy policies: sentry.io/privacy and posthog.com/privacy.
Your choice: App Store builds collect anonymized diagnostics by default. Onboarding shows that choice, and you can use the Diagnostics/Privacy toggle in Settings to turn it off at any time. Turning it off takes effect immediately: the choice is written before anything else can run, so no further event can pass the gate, and the processors are then shut down. One last anonymous event records the opt-out itself — it carries no content beyond the fact that you turned collection off — and nothing is sent after it.
Beta builds have no opt-out. If you installed CloudShots through TestFlight or a debug build, diagnostics collection is always on and cannot be turned off — the setting exists but has no effect, because a beta build exists to find crashes before release, and diagnostics are what make that possible. CloudShots shows that fixed state instead of a control that cannot change it. The same content boundaries and random per-person identity still apply. If you would rather not send diagnostics, use the App Store build and turn the toggle off there.
Report a problem
Settings includes an in-app "Report a Problem" screen, where the description you type is sent to us via Sentry. You may also deliberately choose an image attachment, preview it, or remove it before sending. That image is sent as shown; CloudShots does not automatically attach library screenshots or your app's view hierarchy. Before it leaves your device, the report text passes through the same redaction step as all diagnostic data, which strips file paths and accidental email addresses from free-form text. This feature is available whenever diagnostics collection is active. TestFlight/debug builds may include an optional contact email with the report and future diagnostics for that install; App Store feedback has no contact-email field.
This website
This website loads PostHog product analytics only when an analytics key is configured for the deployment. When it does load, the site starts PostHog with session recording disabled, autocapture disabled, and no analytics cookies — the identifier PostHog assigns is kept in memory for the current tab and is gone when you close it. The site also honors your browser's Do Not Track setting. It records a page view, leaving a page, a page section scrolling into view, how far down the page you scrolled, a click on a download button, a click on any link leading off this site, opening a question in the FAQ, switching the language, and opening or submitting the launch-notification form, each with the page address and browser details PostHog attaches to any event — never the email address typed into the launch-notification form, which is not attached to any event. The website and the app report into the same PostHog project, so we can tell how many visits turn into installs. There is no cross-site tracking, no ad network, and nothing is sold to anyone.
This website asks PostHog to derive an approximate country, region, and city from the IP address of each request. That happens on PostHog's side, from the network request itself; nothing about it is written to or read from your device. The app does not do this.
This website also runs Cloudflare Web Analytics, a cookieless page-view counter built into our hosting. It sets no cookie and assigns no cross-site or cross-visit identifier, so a visit here cannot be linked to you elsewhere. It belongs to this website, not to the app, and is entirely separate from PostHog and from any diagnostics the app sends.
The support page has a contact form. It asks for your email address and your message, both required, and a name, which is optional. Sending it posts those fields to a small function running on this site's host, which composes one email — your name or "Anonymous", your email address, the address of the support page, and your message — and hands it to Resend, a third-party email delivery service, which delivers it to our support inbox with your address set as the reply-to. The form also sends two hidden values used to filter out automated submissions; the function checks them and never forwards them. The function keeps no database and writes nothing down: once the email is handed to Resend, the only copy of your message is the one in our inbox, which we keep for as long as we keep our support mail, and the one Resend holds under its own privacy policy: resend.com/legal/privacy-policy.
Before CloudShots is on the App Store, every page lets you leave an email address to be notified at launch. Submitting it posts that address to a function that sends one email — your address — to our inbox through Resend, the same way a support message does, and also adds that address as a mailing contact in a Resend audience, so we have a real list to send the single launch announcement to. That contact record holds only your email address — no name, no IP address, no page you signed up from — and exists solely to send that one announcement; it is not used for anything else. It is kept until CloudShots launches and the announcement has gone out, or until you ask us to remove it sooner, at [email protected].
Purchases
CloudShots Pro purchases are handled entirely by Apple through the App Store and StoreKit. We never receive your payment card details; Apple processes payment and manages billing under its own privacy policy.
Data retention
Your screenshots remain under your control in local storage and, on Free and Pro, your private iCloud account for as long as you keep them. OCR, tags, feature prints, generated names, summaries, and Private state remain local, while annotations sync with screenshot records and assets. Diagnostic data collected via Sentry and PostHog is retained by those processors according to their own retention policies.
Children's privacy
CloudShots is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
Your rights
Because your screenshot content is kept in your devices and private iCloud account, you retain direct access, deletion, and portability control over it at all times. For diagnostic data described above, App Store users can opt out in Settings, and you may contact us to request access to or deletion of data associated with your random identifier.
If you are a beta tester and entered an email address in "Report a Problem," that address is attached to the whole install and not only to the report you sent: it is stored on your device and re-applied at every launch, so later crash reports and usage events from that install carry it too, in both Sentry and PostHog. That makes the install identifiable by your address until you ask us to remove it, so you can request access or deletion by that email as well as by the random identifier. Clearing the field and sending another report erases the stored address, so it is no longer applied from the next launch onward; it stays attached for the rest of the current session. App Store builds never offer the field, so an App Store install has no address attached to it at all.
International data transfers
Your library sync uses your own Apple iCloud account and is subject to Apple's data location practices. Deliberate exports and problem-report attachments go to the recipients or service you choose. Sharing publishes nothing by default: a share link is a CloudKit share you create deliberately, and until you create one nothing about a screenshot is public. A public, read-only iCloud link you create yourself makes that one screenshot viewable by anyone holding it. You may instead invite specific people to view or edit a screenshot; that invite is managed entirely through Apple's own sharing interface, not by us, and an invited participant's edits are written back to your iCloud through the same CloudKit sharing Apple provides. Diagnostic data may be processed by Sentry and PostHog in countries other than your own, as described in their respective privacy policies.
Changes to this policy
We may update this policy from time to time. We will update the effective date above when we do. Continued use of CloudShots after a change constitutes acceptance of the revised policy.
Contact us
Questions about this policy or your data can be sent to [email protected].