Screencrate
Screencrate Privacy Policy
Effective date: August 23, 2026
Applies to: Screencrate (free) and Screencrate Pro, on Android and iOS ("the app", "Screencrate")
Developer and publisher: Diego Cordova (d/b/a BlackBox Tools) ("we", "us", "our")
Contact: toolsblackbox@gmail.com
This policy covers the Screencrate mobile app only. For the BlackBox Tools website privacy policy, see blackboxtools.com/privacy.
1. The Short Version
Screencrate itself collects nothing. No accounts, no sign-in, no servers of ours, no analytics, no tracking pixels, no personal data sent to us. Everything you save in Screencrate lives in a local database on your own phone. Your content leaves your device only through actions you take yourself (backups to a folder you choose, sharing, and exports) and, in the free version only, through the limited collection performed by third-party advertising networks described in Section 6.
We wrote this policy to be readable. The sections below explain exactly what the app does with data, in plain language, in as much detail as we can give.
2. Who We Are and What This Policy Covers
Screencrate is developed and published by Diego Cordova (d/b/a BlackBox Tools). This policy covers both versions of the app:
- Screencrate (free): supported by banner advertising, with an optional one-time upgrade to Pro.
- Screencrate Pro: a paid version with no advertising and no advertising SDK included in the app at all.
This policy covers the mobile apps only. It does not cover third-party websites you open from links you saved, third-party services you choose to send data to (such as your own cloud storage), or the platforms that distribute the app (Google Play and the Apple App Store), each of which has its own privacy policy.
3. Data We Collect: None
We do not collect, receive, store, sell, rent, share, or otherwise process your personal data on any server of ours, because we do not operate any servers. The app has no user accounts and no login. We have no database of users. We cannot see your saves, your boards, your notes, your photos, your screenshots, your evidence captures, or anything else inside the app, and we could not produce that data even if asked, because it exists only on your device.
The app does not use any analytics or crash-reporting service. We do not know how many times you open the app, what you save, or what features you use.
4. What Stays on Your Device
Everything. Specifically, all of the following is stored only in the app's private local storage on your phone:
- Boards, saved items, links, notes, tags, prices, and reminders
- Images, screenshots, and documents you save or import
- Text extracted from your screenshots and images (OCR), image labels, detected faces, detected prices, and detected expiry dates. All of this analysis runs entirely on the device using on-device machine learning. No image or text is ever uploaded anywhere for analysis.
- Semantic search indexes (Pro). If you enable semantic search, a machine-learning model is downloaded to your device once, and all indexing and searching happens locally.
- Evidence Locker captures, including web page snapshots, screenshots, PDFs, hashes, manifests, and the append-only audit log. These are sealed and verified entirely on your device (see Section 9 for the network requests the feature can make).
- All app settings, PINs, and preferences.
Deleting the app deletes all of this data. There is no copy anywhere else unless you created one yourself with the backup, share, or export features.
5. When Data Leaves Your Device (Always by Your Action)
Content leaves your phone only when you make it happen:
- Backups. If you set up backups, the app writes backup files to the folder you choose. If that folder is synced by a cloud service you use (for example your own Google Drive), the data goes to your cloud account, under that service's terms, not to us.
- Sharing and exporting. When you share an item, a board file, an evidence bundle, a PDF report, or anything else, the data goes to the app or person you sent it to.
- Evidence exports. Evidence bundles and reports you export or email go where you send them.
In every case the destination is chosen by you, and we never receive a copy.
6. Network Requests the App Makes
Although we run no servers, the app does make network requests from your device in order to work. These requests go directly from your phone to the services involved:
- Link previews and prices. When you save a link, the app fetches that web page directly from your device to build a preview and detect a price. If you enable price drop alerts or the dead link check, the app periodically re-fetches your saved pages from your device on a schedule you control.
- YouTube playback. Playing saved YouTube videos uses the official YouTube embedded player. YouTube receives the requests needed for playback (including your IP address and player interactions) under Google's own terms and privacy policy. Screencrate uses YouTube API Services; by using the playlist feature you also agree to the YouTube Terms of Service, and Google's Privacy Policy applies. Screencrate does not receive or store any data from your YouTube activity beyond the link and title you saved.
- Semantic search model download (Pro). If you enable semantic search, the model file is downloaded once from a public model host. This is a plain file download; your content is not sent.
- Trusted timestamps (Pro, Evidence Locker, optional). If you request a trusted timestamp for an evidence capture, the app sends only a cryptographic hash (a SHA-256 fingerprint that cannot be reversed into your content) to a public RFC 3161 timestamp authority (freetsa.org, timestamp.digicert.com, or timestamp.sectigo.com) and to the OpenTimestamps calendar servers a.pool.opentimestamps.org and b.pool.opentimestamps.org. Your captured content itself is never sent, only the hash.
- Dead link rescue. When a saved link stops working, the app asks the Internet Archive (archive.org) whether it holds an older copy of that page, so it can offer you the archived version. That request sends the address of the saved link.
- Evidence Locker capture. A page you choose to capture is loaded in the app's own browser from your device, exactly as a browser would load it, which means that site receives a normal page request. When a capture is sealed, the app asks worldtimeapi.org for the current time, and google.com if that does not answer, so the record can note the time from a source other than your phone's clock. Neither request carries anything from your capture.
- Board pages you share. A board exported as a web page links to a Google Fonts stylesheet, so whoever opens that file loads a font from Google. Your board data is inside the file itself and is not sent anywhere.
None of these requests identify you to us, because none of them come to us.
7. Advertising (Free Version Only)
The free version of Screencrate shows banner ads served by Google AdMob. Additional mediation networks (such as AppLovin MAX) may be added in the future; if they are, this policy will be updated to name them.
Ad networks operate under their own privacy policies and may collect:
- Device identifiers (such as the advertising ID on Android and, only with your permission, the IDFA on iOS)
- IP address and coarse location derived from it
- Device and app information (model, OS version, app version)
- Ad interaction data (which ads were shown, viewed, or tapped)
They use this data to serve, personalize (where permitted), measure, and secure advertising. Relevant policies: Google and, if added, AppLovin.
Consent and choices:
- Where the law requires it (for example in the EEA and UK), you will be shown a consent prompt before personalized ads are served. If you decline, ads are non-personalized.
- On iOS, the App Tracking Transparency prompt controls access to the IDFA. If you decline, the identifier is not available to ad networks.
- On Android, you can reset or delete your advertising ID in system settings.
- Upgrading to Pro, or installing Screencrate Pro, removes all advertising and with it all ad-network collection. Screencrate Pro does not contain any advertising SDK, requests no advertising identifier permission, and shows no ads of any kind.
8. Purchases
The Screencrate Pro upgrade is processed by Apple (App Store) or Google (Google Play). We never see your name, card number, or billing details.
Purchase state is managed through RevenueCat, a subscription-management service, which receives a randomly generated pseudonymous identifier and your purchase state so the app can unlock Pro features and restore your purchase on a new device. RevenueCat does not receive your name, email, or content. RevenueCat's privacy policy.
9. Evidence Locker
The Evidence Locker makes tamper-evident captures of web pages for your own documentation purposes. Privacy-relevant facts:
- Captures are stored only on your device, sealed with cryptographic hashes computed on your device.
- The append-only audit log (chain of custody record) is stored only on your device.
- The contents of a capture are never transmitted to us or to any third party. Three network requests are involved in the feature, all described in Section 6: loading the page you chose to capture, which that site sees as an ordinary visit from your device; a request for the current time when the capture is sealed, which carries nothing from the capture; and, only if you ask for a trusted timestamp, sending the capture's hash and nothing else. Exporting a capture sends it wherever you choose to send it.
- The app captures what is rendered on your screen. You are responsible for only capturing content you are lawfully allowed to view. Nothing in this feature is legal advice, and the admissibility of any capture is always decided by a court.
10. Notifications
Price drop alerts, revisit reminders, item reminders, expiration reminders, and the weekly digest are all generated locally on your device by the app itself. No notification content is sent to us or to any push service of ours. The app uses the operating system's local notification facility only.
11. App Lock, PINs, and Biometrics
App Lock and the other lock features use your phone's own fingerprint or face unlock. Screencrate never sees, stores, or transmits biometric data; the operating system only tells the app whether the unlock succeeded. PINs you set in the app are stored only on your device.
12. Permissions the App Requests
The app asks for permissions only when a feature needs them, and every feature degrades gracefully if you decline:
- Photos and media: to save images you share into the app, import screenshots, pick board covers, and save images back to your gallery.
- Camera: only if you use a capture feature that needs it.
- Notifications: to show the local reminders and alerts described above.
- Biometric authentication: for the lock features.
- Calendar (optional): only if you add a reminder to your calendar.
- Network access: for the request types listed in Section 6.
The free version additionally declares the advertising identifier permission used by ad networks (Section 7). Screencrate Pro does not.
13. Children
Screencrate is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and because the app collects no personal data itself, we hold no information about any user of any age. In the free version, ad-network consent rules for minors are enforced through the consent mechanisms described in Section 7.
14. Your Rights (GDPR, UK GDPR, CCPA/CPRA, and Similar Laws)
Laws like the EU and UK GDPR and the California Consumer Privacy Act give you rights over personal data a company holds about you: access, correction, deletion, portability, restriction, objection, and the right not to be sold or shared.
Our honest answer to any such request is that we hold nothing to produce, correct, or delete. Your data is on your device, under your control:
- To access or export your data: use the app's backup and export features.
- To delete your data: use Settings > Clear All Data, or uninstall the app.
- To stop ad-network processing: upgrade to Pro, use Screencrate Pro, decline the consent or tracking prompts, or reset your advertising ID in system settings. For data the ad networks may have collected, exercise your rights directly with them under their policies (links in Section 7); we do not control or have access to that data.
We do not sell or share personal information as defined by the CCPA/CPRA, and we have no data with which to do so. We do not respond to Do Not Track signals because we do no tracking to turn off.
If you are in the EEA or UK and believe you need a data controller to address: for all data inside the app, you are the only controller, because processing happens on your device. For advertising data in the free version, the ad networks act as independent controllers of the data they collect.
15. Data Security
Your data is protected by your device's own security: the app's storage is private to the app, protected by your device lock, and covered by your phone's encryption when enabled. The app adds optional locks (PIN and biometric) for sensitive areas. Because nothing is stored on servers, there is no server to breach.
16. Data Retention
We retain nothing, so there is no retention period. Data on your device stays until you delete it. Backups and exports you created are retained wherever you put them, for as long as you keep them.
17. International Transfers
We transfer no data internationally, because we receive no data. Requests your device makes to third parties (web pages you saved, YouTube, ad networks, timestamp authorities, RevenueCat) may be served from wherever those services operate, under their own policies.
18. Changes to This Policy
If the app's behavior changes in a way that affects privacy (for example, adding a new ad network), we will update this policy, change the effective date at the top, and highlight material changes in the app or in the update notes. The current version of this policy is always available at this page and inside the app under Settings.
19. Contact
Questions, concerns, or requests: toolsblackbox@gmail.com
We aim to answer every privacy question directly and in plain language.