Privacy Policy

Last updated: May 2026

What we collect

When you create an account, we store your name, email address, and a hashed password. If you use Google Sign-In, we receive your name, email, and profile image from Google. We also store Stripe customer and subscription identifiers to manage billing.

What we don't collect

DrawShot processes screenshots locally on your Mac. Your screenshots, annotations, and files never leave your device and are never sent to our servers.

How we use your data

Your email is used to send you a welcome message, your license key (if you purchase Pro), and critical account notifications. We do not send marketing emails unless you opt in. We never sell your data.

Third-party services

We use Stripe for payment processing (subject to Stripe's privacy policy), Resend for transactional email, and Railway for hosting. PostgreSQL data is stored on Railway-managed infrastructure in the US.

Data retention

Your account data is retained while your account is active. You can request deletion at any time by emailing [email protected] — we'll delete your data within 30 days.

Security

Passwords are hashed using bcrypt with a cost factor of 12. All communication uses TLS. We do not store plaintext passwords or payment card data.

Contact

Questions? Email [email protected].