Multi-Toolkit

Privacy Policy

Last updated: September 2, 2026 · Applies to: ShotFlow — Full Page Screenshot, Recorder & Mockups (Chrome Extension)

Overview

ShotFlow ("the Extension") is a Chrome browser extension that captures full-page screenshots, records your screen, a tab, a region of a tab, or your camera, and lets you annotate, edit and present those captures — including in device mockups and a responsive device simulator.

Summary: everything ShotFlow captures — images, video, microphone audio, camera video — is produced and processed on your device and stored in your own browser. Nothing is transmitted anywhere by default. The one exception is the optional Share / Upload to Cloud feature, which — only when you press it — uploads the single file you are looking at so you can get a link. That feature is described in full below. There is no analytics, no telemetry, and no background upload of any kind.

Data We Do NOT Collect

Outside of the optional Share feature described below, ShotFlow does not collect, store, or transmit any of the following:

  • Personal information (name, email, account details)
  • Browsing history, or a log of which sites you visit
  • Page text, form data, passwords, or anything you type into a website
  • Cookies or authentication tokens belonging to sites you visit
  • Device information, IP address, or geolocation data
  • Analytics, telemetry, or usage statistics of any kind
  • Any recording, camera image, or microphone audio — unless you explicitly upload that one file

The Extension's content script runs on pages you choose to capture so it can measure page size and prepare the page for screenshotting — it does not read, log, or transmit the page's text, DOM, cookies, or form values.

Data Stored Locally (On Your Device)

ShotFlow uses Chrome Storage (local) and an in-browser IndexedDB database to persist your captures and settings between sessions. This storage exists entirely within your browser, on your device, and is never synced to your Google or Chrome account.

  • Screenshot library — thumbnails of every capture, and, if you leave the "keep full-size copies" setting on (the default), the full-resolution image too, up to a storage budget you control
  • Recording library — every video you record is written to the same in-browser database when you stop recording, together with a poster frame and its duration. Recordings stay there until you delete them or clear the Extension's data
  • Editor and capture settings — your preferences such as image format, export quality, filename template, annotation colours, theme, recording quality and format, and the local storage budget
  • Share history — if you have ever used Share, a short local list of your own links (used to show "recent shares" and to let you revoke a link) and a randomly generated installation identifier (see below)

This data is accessible only to the Extension itself. Uninstalling ShotFlow, or clearing the Extension's browsing data from Chrome, permanently deletes all of it.

Screen, Tab, Camera and Microphone Recording

ShotFlow can record your whole desktop or a chosen window, the current tab, a region of the current tab, or your camera on its own — with your microphone and the tab's own audio optionally mixed in.

  • Recording is always started by you, from the Extension's own popup. ShotFlow cannot and does not start a recording on its own, on a schedule, or in response to anything a website does
  • Screen and window capture uses Chrome's own picker. Chrome — not ShotFlow — asks you which screen or window to share, and Chrome shows its native sharing indicator for the whole time
  • Camera and microphone access is requested through Chrome's standard permission prompt, on first use, and only for the modes that need it. You can review or revoke it at any time in Chrome's site settings for the Extension. A recording without the microphone enabled never opens the microphone at all
  • The video never leaves your device unless you choose to upload it. When you stop recording, the file is written straight into your browser's local database and opened in the review page. The recorded bytes are never sent to us, and never pass through any server, unless you press Upload to Cloud
  • Nothing is recorded before you press start or after you press stop. The capture stream is opened when the recording begins and closed when it ends — including when it ends because you used Chrome's own Stop sharing control, closed the tab, or unplugged the camera

On-Screen Overlays and Password Protection

If you turn them on, ShotFlow can draw overlays into a recording — highlighting the cursor, rippling your clicks, counting clicks, and showing keyboard shortcuts as you press them. These read input events while a recording is running, so they deserve to be spelled out:

  • Overlay data is drawn into the video frame and nothing else. It is never stored separately, never written to disk as text, and never transmitted
  • Only keyboard shortcuts (such as Ctrl+C or Cmd+Shift+4) are shown. ShotFlow does not display or record ordinary typed text
  • Password fields are excluded before anything is read. Keystrokes in a field that is a password field — or that looks like one by its type, name, id, autocomplete or placeholder — are dropped at the source, in the page, and never reach the overlay or the Extension
  • Because a recording captures whatever the page itself draws, ShotFlow additionally covers password fields visually while you type into them, so a recording does not reveal even the length of a password

The Responsive Simulator and the debugger Permission

ShotFlow includes a responsive device simulator that shows a page as it would appear on a real phone, tablet, laptop or TV. Doing this accurately — correct viewport behaviour, device pixel ratio, touch input, and matching browser identification — requires Chrome's DevTools Protocol, which is why the Extension requests the debugger permission. Chrome does not allow this permission to be optional, so it is requested at install even though it is used by one feature only.

Because this is the most powerful permission ShotFlow asks for, here is exactly what it is used for:

  • A debugger session is attached only to the Extension's own preview tab, only while you have the simulator open, and is detached as soon as you close it
  • It is used to set emulation overrides (screen size, pixel ratio, touch, user agent, locale, timezone, media features, network conditions) and to photograph that preview tab so the mockup export contains a real image
  • ShotFlow never reads page content through it. It sends commands and does not subscribe to any DevTools Protocol events at all, so no network traffic, console output, or DOM data is received
  • The simulator can optionally set the request headers for the framed preview so a site serves its mobile version and can render inside the device frame. These rules are scoped to that one preview tab and are removed when it closes — they never apply to your ordinary browsing

Clipboard

ShotFlow writes to the clipboard when you use Copy image to clipboard, and reads from it when you use Paste Image to bring an image in for annotation. Those two actions are the only clipboard use in the Extension. Nothing is read from the clipboard in the background, and nothing read from it is stored or transmitted.

Optional Feature: Sharing a Screenshot or Recording

ShotFlow can upload one screenshot, or one recording, to our server to generate a link you can send to someone else. This is off by default and never automatic — it only happens when you press Share or Upload to Cloud for that specific file.

When you do, the following is sent over HTTPS to a server we operate:

  • The flattened screenshot image, or the recorded video file, that you chose to share — including any annotations or edits you added
  • A randomly generated installation identifier stored in your browser — not your name, email, or Google account, and not linked to your identity. Its only purpose is to enforce a daily limit (currently 10 image uploads and 5 recording uploads per day per installation)
  • An authentication token that is built into the Extension, used so our server can tell the request came from ShotFlow

What happens to it:

  • The file is stored at a unique, hard-to-guess link (a random 128-bit id) and is not listed, indexed, or discoverable by us or anyone else — but it is not password-protected either. Anyone who has the exact link can view it, so avoid sharing captures containing sensitive information
  • It is automatically deleted after 30 days, whether it is an image or a recording
  • You can delete it immediately at any time by clicking Revoke, in the share dialog or from your Library
  • Recordings are uploaded in parts, so a large file can resume rather than restart. An upload you abandon part-way is never published and is discarded automatically
  • The installation identifier is used only to count that day's uploads and is never used to build a profile or to link separate shares to one another

The server behind this feature runs on Cloudflare (Cloudflare Workers and R2 storage), which acts as our infrastructure processor for this optional feature. Cloudflare processes standard web request metadata (such as your IP address) transiently to deliver the request and to apply short-lived abuse-prevention limits on our behalf; we do not use it for tracking, and it is not shared with anyone else. See Cloudflare's privacy policy for how they handle it.

Permissions and Why They Are Required

ShotFlow requests the following Chrome permissions:

PermissionWhy It Is Needed
activeTabTo capture the tab you are currently viewing when you click the extension. Grants access only to that one tab, only after you interact with the extension — not persistent access to every tab.
scriptingTo inject the capture engine into the page you choose to screenshot, so it can measure the page, scroll it into position, and stitch the tiles together into one image.
downloadsTo save the exported image, video, GIF or PDF to your chosen download location when you click Download. Does not read your existing downloads.
storageTo save your capture, recording and editor settings locally in the browser, so they persist between sessions.
unlimitedStorageSo the local library (IndexedDB) is not capped at the browser's default storage quota — full-page screenshots are large, and a few minutes of video is larger still.
offscreenScreen capture and video encoding cannot run in an extension's background service worker. The offscreen document is the only place a recording can be produced, and it is where the recorded bytes stay.
debuggerPowers the Responsive Simulator, as described in detail above. Attached only to the Extension's own preview tab, only while the simulator is open, used only to set emulation overrides and photograph that tab, and detached immediately afterwards. Chrome does not permit this permission to be optional.
tabsTo read the address and title of the tab you ask to capture or simulate, so the right tab is targeted and the capture can be named. Not used to observe your browsing.
clipboardWriteFor "Copy image to clipboard" in the editor and the Mockup Studio.
clipboardReadFor "Paste Image", so you can annotate an image already on your clipboard. Nothing else reads the clipboard, and nothing read is stored or transmitted.
content_scripts: <all_urls>The capture overlay, region selector and annotation layer must already be present when you click, so the capture starts without a visible injection delay. It does nothing until you start a capture, and it does not read, log, or transmit page content.
tabCapture (optional)Requested at runtime, only when you choose to record "This Tab" or a region of it. Never requested for desktop or camera recording.
declarativeNetRequestWithHostAccess (optional)Requested at runtime on first use of the simulator's framed Device Preview. Sets that preview's browser identification and allows the page to render inside the device frame. Scoped to the preview tab alone and removed when it closes.
optional_host_permissionsRequested at runtime — never at install — for uploads and for the framed Device Preview. None are granted at install time.

Third-Party Services

Aside from Cloudflare, which powers the optional Share feature described above, ShotFlow does not integrate with, communicate with, or send data to any third-party service, analytics platform, or advertising network. There is no tracking and no telemetry.

Data Retention & Deletion

Local data — your screenshot and recording library, your settings, and your share history — is kept until you delete it yourself, from the Library page, from Settings, or by uninstalling the Extension, which erases everything ShotFlow stored in your browser. Files you chose to share are kept on our server for 30 days and can be deleted sooner at any time using Revoke.

Children's Privacy

ShotFlow does not target or knowingly collect any information from users under the age of 13.

Changes to This Policy

If this policy changes, the updated version will be posted at https://multi-toolkit.com/shotflow/privacy-policy and the "Last updated" date at the top will be revised.

Contact

If you have questions about this privacy policy or the Extension, please contact:

Muhammad Sohail Nazar
Email: sohail.nazar@outlook.com
Website: https://multi-toolkit.com

← Back to Multi-Toolkit