Wingshot Privacy Policy
The short version: Wingshot has no servers and no accounts. We (the developer) never receive, store, or see your screenshots, your prompts, your API keys, or anything about you. The only place your data goes is to the AI provider you chose, using your own API key, when you press Send.
What Wingshot does
Wingshot is a browser extension that lets you capture a screenshot of a web page, your screen, or an app window; blur out anything sensitive; and then ask an AI model (Google Gemini or Anthropic Claude) questions about it. It is a "bring your own key" (BYOK) tool: you supply your own API key from the provider, and requests go directly from your browser to that provider.
Data we collect
None. Wingshot does not collect, transmit, or store any personal data, usage data, analytics, or telemetry. There is no Wingshot server. We cannot see what you capture or ask.
Data that stays on your device
- API keys you enter are saved in Chrome's extension storage (
chrome.storage.local) on your device only. They are never synced through your Google account and never sent anywhere except to the provider that issued them, as part of your own requests. You can remove them at any time from Wingshot's Advanced settings ("Clear all keys") or by uninstalling the extension. - Your provider choice and model preference are stored the same way.
- Screenshots are captured and blurred entirely inside your browser. While you are working on them, they are held in memory and in Chrome's session storage (memory-only; cleared when the browser closes). Wingshot never writes screenshots to disk on its own; the only exception is the Save Image button, which saves a copy of the blurred image to your Downloads folder because you asked it to. Nothing is ever sent to us.
- The current conversation is kept in the same session storage only while you are using it, so you can add another screenshot without losing your place. It is cleared when you press New, Discard or Close Wingshot, and whenever the browser closes. Nothing is kept between browser sessions.
Data sent to third parties
When you press Send, Wingshot transmits your question, the conversation so far, and the (blurred) screenshot you attached directly to the AI provider you selected, using your API key:
- Google Gemini —
generativelanguage.googleapis.com. Requests are sent withstore: false, asking Google not to retain the interaction. Google's handling of API data is governed by the Gemini API Terms and Google's privacy policy. - Anthropic Claude —
api.anthropic.com. Governed by Anthropic's privacy policy and API terms.
Nothing is sent until you press Send, and only to the one provider you chose. Wingshot contacts no other servers.
Anything you blur with the blur tool is pixelated before the image leaves your device; the original pixels are not recoverable from the sent image.
Permissions Wingshot asks for, and why
- Read the page you are on (activeTab / scripting) — to take the screenshot of the current tab when you ask for one, and to show the blur editor on top of it. This access is granted only when you trigger a snip, and only for that tab.
- Capture your screen (desktopCapture) — to snip your desktop or another app window. Chrome always shows its own "Choose what to share" dialog first; Wingshot reads a single frame and stops.
- Storage — to keep your API key and preferences on your device.
- Side panel and context menus — purely for the user interface: showing Wingshot in Chrome's side panel, and adding a right-click option on images. Neither reads or sends any data.
- Access to generativelanguage.googleapis.com and api.anthropic.com — to send your requests to the provider you chose. These are the only sites Wingshot communicates with.
Children
Wingshot is not directed at children under 13 and does not knowingly collect data from anyone (it collects no data at all).
Changes to this policy
If this policy changes, the new version will be published at this address with an updated effective date.
Contact
Questions about privacy: ekma.saberi@gmail.com