Privacy Policy
The technical sections below describe what the software actually
does, taken from the source. The legal commitments have not been
written — they need input from the operator of this service, not
from a code assistant. Do not treat this page as a policy in
force, and remove the noindex tag only once the
remaining sections are filled in.
What the service processes
URLs you submit
When you request a preview, the URL is sent to the Control Center, which forwards it to one or more regional worker nodes. Those nodes load the page in a headless browser and return an image.
Rendered screenshots
Screenshots are cached in S3-compatible object storage so that a
repeat request for the same URL, region and viewport does not have
to be rendered again. The storage bucket carries a lifecycle rule
that expires objects under the screenshots/ prefix
after 24 hours.
Shared captures
A capture is kept beyond that 24-hour cache only when you explicitly
press Share. Nothing is retained automatically. Pressing it
copies the images that were just rendered to a separate
shares/ prefix in the same bucket, which carries its own
lifecycle rule expiring objects after seven days.
Alongside the images, one row is written to the database recording the URL that was submitted, the viewport and image format, which regions were captured, the storage keys of those images, the load timings reported for that run, the account id if you were signed in (empty for a guest), and the creation and expiry times. Both the row and the images are deleted at the end of the seven days.
The resulting link contains a random 128-bit identifier that cannot
be guessed, and the page is marked noindex so it is not
offered to search engines. It is nevertheless unlisted rather
than private: anyone who holds the link can open it, without
signing in, for as long as it has not expired. Opening it reads the
stored images and never renders the target site again.
IP address
The requesting IP address is used to enforce rate limits (screenshot requests and login attempts), which is held in memory only and dropped once its window passes. It is additionally written to storage in two places: as the subject of the usage counters that enforce the free per-day capture quota for visitors who are not signed in, and in the sign-in and administrator-activity logs described below.
Server-side storage
The service keeps a SQLite database for its own operation. It holds developer API keys with their usage counts, worker-node configuration, registered accounts (email address, any name given at sign-up, and a linked Google account identifier where one is used), login sessions, capture-quota counters, shared captures as described above, and an audit log.
The audit log records every sign-in attempt to either the dashboard or the administrator portal — successful or failed — with the email address that was tried, the IP address, the browser's user-agent string, and the time; and separately, changes made from the administrator portal, with the IP address of the administrator who made them. Rendered screenshots are not stored in the database; they live in the object storage described above.
Browser storage
A single localStorage entry, pf-theme,
records whether you chose the light or dark theme. Signed-in visitors
receive a session cookie, pf_user, and administrators a
separate one, pf_session; both are HttpOnly,
SameSite=Strict and Secure.
Third parties
Object storage is provided by IDCloudHost. Fonts and icons are served from this domain, not from a third-party CDN.
Data controller and contact
PageFleets operates this service and is responsible for the personal data described in this policy. For any privacy question or request — including access to, correction of, or deletion of your data — contact us at hi@pagefleets.com.
Content required The operating legal entity's registered name and address, if one exists.