Policy
Privacy
Account data Request data Retention Third parties Your rights
Scrinly is a developer API for screenshot capture, visual comparison, and monitoring. The less request content we retain, the better. This page describes what the current product stores and sends to its service providers.
What we store about you
- Your email address — the only personal data required to hold an account. There is no password: sign-in is a link sent to that address.
- API keys, stored as a SHA-256 hash and a short display prefix. The secret is shown once at creation and is not recoverable, by us or by anyone.
- Usage counts — requests and credits per day per endpoint. Counts only; no URLs and no content.
- Billing records from our payment provider: plan, interval, and subscription status. Card details never reach us.
- Monitoring recipients, when configured, with addresses encrypted and a non-reversible fingerprint used for account-scoped lookup.
What we store about your requests
What is retained depends on the operation you request:
- Unstored synchronous screenshots — image bytes are returned directly and are not retained as a Scrinly job result.
- Stored screenshots, region crops, and diff images — files are written to the selected provider: Scrinly's default B2 storage or your B2, S3, or R2 storage. The response contains that provider's direct URL.
- Queued jobs — safe job metadata and the completed result
are retained so the owning account can use
/status. Secrets and provider credentials are excluded from public job metadata. - Monitors — target and credential-bearing configuration is encrypted. Monitor and run records are retained for the applicable plan's history window.
- Caches — screenshot caching is opt-in with
cache=true. Visual Style Guides use a separate automatic account-scoped cache.
One-shot storage credentials are used for that request and are not retained. Credentials needed by a recurring monitor are encrypted for as long as the monitor needs them. Direct storage URLs may remain accessible according to the selected provider's access settings and lifecycle.
How long
- Completed asynchronous jobs — 24 hours
- Failed asynchronous jobs — 7 days
- Screenshot cache entries — normally 1 hour, or 5 minutes for high-priority requests
- Successful Visual Style Guide cache entries — 7 days
- Monitor run history — 30 to 365 days, depending on plan; the active baseline is retained until it is replaced or released
- Stored image objects — according to Scrinly's or your selected storage provider lifecycle; expired Scrinly-owned monitor assets are scheduled for deletion
- Daily usage counters — 90 days
- Account and billing records — for as long as the account exists, then as required for tax and accounting
Where a retention window is stated, automated sweeps remove expired records. Deletion is not reversible.
Who else sees anything
- Cloudflare — runs the API, the browsers and the databases.
-
OpenAI, only when you request a Visual Style Guide. OpenAI
receives bounded screenshot derivatives—an overview and ordered region
images—plus a sanitised design projection. Target URLs, hostnames, HTML,
headers, cookies, selectors, and supplied page text are not sent as textual
input, although visible copy and branding may naturally appear in screenshot
pixels. Requests use
store:false. OpenAI's default abuse-monitoring retention may be up to 30 days unless the project has stricter controls. An optional provider key is used only for that synchronous request and is not stored. - Backblaze B2 — stores screenshots, region crops, and diff visualisations when you use Scrinly's default storage.
- Resend — sends sign-in, recipient-verification, and monitor alert emails.
- Our payment provider — handles checkout, tax and invoices as merchant of record.
We do not sell data, and we do not use your requests or their results to train anything.
Your rights
Email hello@scrinly.com to access, correct, export or delete your account data. Deleting an account removes the account row, its keys and its sessions; usage counters and billing records are retained where we are required to keep them. We respond within 30 days.