Privacy Policy
This policy covers two separate things: the GoFullScreenshot Chrome extension, and this website at gofullscreenshot.com. They are described separately because they behave differently.
Last updated: 14 September 2026
1. The Chrome extension
What is processed
When you start a capture, the extension reads the content of the page you chose in order to measure, scroll, stitch, and render it into an image. All screenshot processing, stitching, editing, export, settings, and optional history stay local to your device. The extension has no backend and sends no screenshots, page content, URLs, settings, or local history anywhere.
What the extension never does
- No screenshots or page content are uploaded to any server.
- No accounts, sign-ups, or email addresses.
- No analytics, telemetry, or usage tracking in the extension.
- No advertising or third-party identifiers.
- No browsing history collection and no background browsing.
- No remote code and no third-party services in the capture path.
Permissions
The Stable extension requires only the permissions it needs to do its job:activeTab, scripting, storage and alarms.
- activeTab / scripting - measure, read and scroll the page you explicitly choose to capture, so the full page can be stitched together.
- storage - remember your own settings (format, quality, capture mode, export scale, filename pattern, history retention) on your device.
- alarms - local one-shot cleanup retries only, for example when a popup closes, the service worker stops, or Chrome restarts. Alarms never schedule captures, websites, uploads, or analytics.
- downloads (optional) - requested only after an explicit Settings action for native Save As. Ordinary manual downloads work without this permission.
The manifest declares https://*/* and http://*/* only as an optional host capability. There is no required <all_urls>, and the package declares no tabs, debugger or webNavigation permission. No required website host permissions are granted at installation. It can request optional access to one exact embedded site only after you choose Allow & capture. Capture, editing, export, settings, history and diagnostics make no remote requests; the only automatic external navigation is the official welcome page described below.
Embedded cross-origin pages, step by step
- You start Full page capture yourself.
- Only when the real long page sits inside a dominant cross-origin iframe does the popup show "Allow full-page access?".
- The popup names the exact site concerned.
- "Remember access for this site" is off by default.
- Only after "Allow & capture" does Chrome show its own permission dialog.
- Chrome receives only the exact HTTP(S) origin pattern: scheme, hostname and effective port.
- Without permission, nothing of the embedded page is captured.
- The permission is used locally only to measure, scroll, capture and restore that embedded page.
- One-time access is removed after success, cancellation, or failure.
- If you deliberately choose "Remember access for this site", only that exact origin stays allowed.
- You can remove remembered access in GoFullScreenshot Settings, in Chrome's extension controls, or by uninstalling the extension.
- This access is never used for background browsing, tracking, advertising, analytics, collection, or transmission.
Same-origin embedded pages are processed without any extra host permission. Extra permission is only needed when a non-scrolling website shell loads the real long page in a dominant cross-origin iframe.
Chrome Web Store Limited Use disclosure
GoFullScreenshot's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically: page content accessed during a capture is used only to provide the capture, editing and export features you requested; it is not transferred to any third party except as required by law; it is never used for advertising, ad personalization, credit assessment or lending; and no human reads it, because it never leaves your device.
Local history
New users get an explicit choice before their first popup-started capture. "Keep 10 locally" is the recommended choice, and "Not now" leaves history off. An update never silently enables history for existing users. The retention limit is 1 to 20 completed captures, stored locally in IndexedDB. The extension removes the oldest items first and tries to stay below roughly 250 MB; a single current capture can temporarily be larger.
A local record can contain the image Blob, local creation time, pixel dimensions, DPR, capture type, source URL, source title, an optional note, and the filename. This data does not leave your device. You can delete individual items, clear everything, or turn history off. With history off, only the current capture stays temporarily available for the viewer.
Diagnostics
"Copy diagnostic info" runs only after an explicit click in Settings, and it only copies text to your local clipboard. It is never uploaded or sent automatically. The text can contain UTC time, extension version, release profile, installation type, browser, platform and architecture, browser language, screen size, DPR, reduced-motion status, relevant local settings, the downloads permission status, the number of granted HTTP(S) origin patterns, and only the count and total size of retained captures. It never contains page URLs or titles, screenshot pixels, captured page content, filenames, notes, templates, project names, origin names, or record-level metadata. It reaches support only if you paste the text yourself.
Review request
The popup has a manual button to the public Chrome Web Store review page. After the third successful capture, a voluntary support dialog may appear that asks for an honest review and welcomes positive as well as critical feedback. There is no reward, feature unlock, sentiment filter, five-star steering, or obligation, and no feature depends on a review. It closes with X, Escape, or the background. Automatic prompts are capped at three per prompt version, and after dismissal at least seven days and five new successful captures must pass before the prompt is eligible again. After the review link is opened there is a local 90-day cooldown. Chrome offers no API to determine whether a review was written, so nothing is checked. Opening the Store review page attaches no screenshot, page URL, setting, or counter data.
Local files
file:///* is an optional capability, not an install-time permission. It is used only after you enable Chrome's separate Allow access to file URLs switch for GoFullScreenshot and then explicitly capture the active local file. GoFullScreenshot never enumerates folders, scans your device, opens unrelated files, runs on files in the background, or uploads file content.
Directly opened local HTML supports Full page, Visible area and Select area. Other browser-rendered local formats are not currently guaranteed. Chrome's protected local PDF viewer supports Visible area only. If you keep optional History on, a record can retain the local file:// path on your device only; it is never transmitted, and you can delete it or turn history off.
Protected pages
Chrome blocks capture on chrome:// pages, the Chrome Web Store, the Developer Dashboard, and pages belonging to other extensions. In those cases GoFullScreenshot shows a clear message and never attempts to bypass Chrome's security protections.
First-install welcome page
Starting with extension version 1.9.56, immediately after first installation, GoFullScreenshot opens its official Getting Started page at https://gofullscreenshot.com/welcome once in a new browser tab. It does not open this page after extension updates, Chrome updates, extension reloads, or browser startup. The extension does not attach or transmit screenshots, captured-page URLs or titles, settings, local history, or a unique installation identifier. The visit is handled as an ordinary website visit under the Website visitors section below.
To keep the distinction precise: capture, editing, export, settings, history and diagnostics make no remote requests at all. This one-time official welcome page is the only automatic external navigation the extension performs. All other website, support, privacy and review links stay user-initiated and open only after you click them.
2. This website
This website is a separate, static marketing and documentation site. It has no accounts, no payments, no cloud uploads of your screenshots, and no third-party advertising or social trackers. It does not read, receive, or store any screenshot you take with the extension.
To be accurate rather than flattering: the hosting platform that serves this website (Lovable) injects its own first-party analytics script (/~flock.js, which posts to /~api/analytics) on the published site. It measures aggregate page views and basic technical request data for the website itself. It is served from this same domain, it is not used for advertising or profiling, and it is unrelated to the extension, which contains no analytics at all. The script itself is injected by the hosting layer and cannot be removed by this website.
What this website can and does control is whether that measurement is allowed to report anything. A gate installed by this site blocks analytics event requests and writes of its random session-idcookie until you choose "Accept analytics". If you decline or withdraw consent, event requests remain blocked and that analytics cookie is removed. The banner is functional, not decorative: your choice is stored locally for 180 days and is enforced on every page. The hosting script file still loads, and Lovable/Cloudflare can set short-lived cookies needed to deliver and protect the site: the Lovable hosting cookie __dpl lasts about 24 hours, the Cloudflare security cookie __cf_bm about 30 minutes of inactivity, and the consent choice gfs-consent-v1 180 days. Website analytics never receives extension screenshots, captured pages, settings, or local counters. Google Tag Manager runs on every page with Google Consent Mode: all storage categories start denied, so no analytics or advertising cookies may be written before your choice. With analytics consent, this site also loads Google Analytics 4 (Google Ireland Ltd.) to measure page views and "Add to Chrome" clicks, with advertising features and Google signals off; withdrawing consent returns storage to denied and removes its _ga cookies. See the cookie statement for details and for how to change or withdraw your choice.
Fonts and images used by this website are served from this domain. No requests are made to third-party font or CDN hosts while you browse it.
This website has no account, contact, feedback, or screenshot-upload form. A support button can open an external GitHub issue template only after you click it. GitHub then applies its own privacy terms, and you decide what to enter; never include passwords, private URLs, personal messages, or unredacted screenshots.
3. Payments and subscriptions
There are no payments today. This website has no checkout, no payment provider, no billing account and no subscription. GoFullScreenshot Pro is in development, and nobody can be charged for it. If paid plans are introduced later, this section will be updated before any payment is possible, and it will name the payment processor and describe exactly what billing data it handles.
4. Retention, children, changes and contact
The extension transmits nothing, so there is no server-side screenshot data to retain, export, or delete. Removing the extension removes its locally stored settings and history. Neither the extension nor the website is directed at children, and no personal profile is built about you.
If this policy changes, the updated version is published on this page with a new "last updated" date. Privacy questions can be sent through the support request form.
