Hotshot

Privacy Policy

Effective date: September 2, 2026

Hotshot is a local-first browser capture tool. It has no Hotshot-operated backend, account system, advertising, analytics, or crash-reporting service. Nothing leaves your device unless you explicitly send a capture to a third-party service you connected.

1. Scope

This policy explains how the Hotshot browser extension handles information when you capture, annotate, pin, record, save, or deliver content. It applies only to Hotshot and not to websites or third-party services you access through your browser.

2. Information Hotshot does not collect

Hotshot does not collect or use information for:

Hotshot does not operate a server that receives your captures, settings, credentials, or browsing activity.

3. Information stored on your device

Depending on the features you use, Hotshot may store:

Preferences, integration configuration, and tokens are stored with chrome.storage.local. They are not stored with Chrome Sync. Capture images are stored locally in IndexedDB for the capture library and are subject to your configured retention settings.

4. Screenshots and recordings

Screenshots, annotations, pinned captures, WebM recordings, and GIFs are created and processed on your device. Copying an image to the clipboard or downloading a file does not send it to Hotshot or to a Hotshot-operated service.

Hotshot runs only after you explicitly invoke it. Temporary access to the active tab is used to capture the page and, for element capture, identify the webpage element that you select.

5. Connected third-party services

Hotshot can connect directly to Jira Cloud, Notion, and ClickUp using credentials that you provide. Connecting these services is optional. Their host permissions are requested only when you choose to connect the corresponding service.

When you explicitly send a capture, Hotshot may transmit the following information directly to the service you selected:

The request travels directly from your browser to the connected provider. Hotshot does not proxy, receive, or retain it. Information received by Jira, Notion, or ClickUp is governed by that provider's own terms and privacy policy.

6. Integration credentials

Integration tokens are stored locally and are never intentionally logged or included in capture metadata. Personal API tokens may carry significant permissions in the connected account. You should use only tokens you trust, remove credentials you no longer use, and revoke them through the provider if you believe they have been exposed.

7. Incognito browsing

Captures taken in an Incognito window are not written to Hotshot's local capture history. You remain responsible for files you explicitly copy, download, or send from an Incognito window.

8. Browser permissions

Hotshot uses the following permissions for its core functionality:

Optional host permissions for Atlassian, Notion, and ClickUp are used only for the connected-service actions described above.

9. Your controls

You can:

10. Security

Hotshot packages its executable code with the extension and does not load remote executable code. It uses temporary active-tab access and optional integration permissions to limit access to what is needed for the action you requested.

No software can guarantee absolute security. Keep your browser updated, protect access to your device, and revoke third-party tokens that are no longer required.

11. Children's privacy

Hotshot is a general productivity tool and is not directed to children under 13. Hotshot does not knowingly collect personal information from children.

12. Changes to this policy

This policy may be updated when Hotshot's functionality or data handling changes. The effective date at the top of this page will be updated when a revised policy is published. A change that introduces new collection or transmission will also require corresponding product and Chrome Web Store disclosure updates.

13. Contact

Questions, privacy requests, and security reports may be submitted through Hotshot's public project issue tracker. The Chrome Web Store listing identifies the current official support location.