Hotshot
Privacy Policy
Hotshot is a local-first browser capture tool. It has no Hotshot-operated backend, account system, advertising, analytics, or crash-reporting service. Nothing leaves your device unless you explicitly send a capture to a third-party service you connected.
1. Scope
This policy explains how the Hotshot browser extension handles information when you capture, annotate, pin, record, save, or deliver content. It applies only to Hotshot and not to websites or third-party services you access through your browser.
2. Information Hotshot does not collect
Hotshot does not collect or use information for:
- Advertising or ad targeting
- Analytics, behavioral profiling, or usage tracking
- Selling or renting personal information
- Creditworthiness or lending decisions
- Unrelated transfers to data brokers or other third parties
- Background collection of browsing history
Hotshot does not operate a server that receives your captures, settings, credentials, or browsing activity.
3. Information stored on your device
Depending on the features you use, Hotshot may store:
- Screenshot images and associated capture metadata
- Capture mode, delay, retention, and filename preferences
- Page URL, page title, viewport size, and capture timestamp
- Integration configuration and recently used destinations
- Personal API tokens that you enter for connected services
Preferences, integration configuration, and tokens are stored with
chrome.storage.local. They are not stored with Chrome
Sync. Capture images are stored locally in IndexedDB for the capture
library and are subject to your configured retention settings.
4. Screenshots and recordings
Screenshots, annotations, pinned captures, WebM recordings, and GIFs are created and processed on your device. Copying an image to the clipboard or downloading a file does not send it to Hotshot or to a Hotshot-operated service.
Hotshot runs only after you explicitly invoke it. Temporary access to the active tab is used to capture the page and, for element capture, identify the webpage element that you select.
5. Connected third-party services
Hotshot can connect directly to Jira Cloud, Notion, and ClickUp using credentials that you provide. Connecting these services is optional. Their host permissions are requested only when you choose to connect the corresponding service.
When you explicitly send a capture, Hotshot may transmit the following information directly to the service you selected:
- The screenshot selected for delivery
- The selected issue, task, page, project, database, or list
- Page URL and title, if enabled
- Viewport size and device-pixel ratio, if enabled
- Capture timestamp, if enabled
- User-agent information, if enabled
The request travels directly from your browser to the connected provider. Hotshot does not proxy, receive, or retain it. Information received by Jira, Notion, or ClickUp is governed by that provider's own terms and privacy policy.
6. Integration credentials
Integration tokens are stored locally and are never intentionally logged or included in capture metadata. Personal API tokens may carry significant permissions in the connected account. You should use only tokens you trust, remove credentials you no longer use, and revoke them through the provider if you believe they have been exposed.
7. Incognito browsing
Captures taken in an Incognito window are not written to Hotshot's local capture history. You remain responsible for files you explicitly copy, download, or send from an Incognito window.
8. Browser permissions
Hotshot uses the following permissions for its core functionality:
-
activeTabfor temporary access after you initiate a capture -
scriptingto display capture, annotation, and pinning interfaces in the active page -
storagefor local settings, history metadata, and credentials downloadsto save files you request-
offscreento stitch and encode full-page captures -
notificationsto explain capture failures on pages where Chrome blocks extensions
Optional host permissions for Atlassian, Notion, and ClickUp are used only for the connected-service actions described above.
9. Your controls
You can:
- Delete individual captures from the local library
- Clear the entire local capture history
- Choose how long captures are retained
- Disable individual context fields before delivery
- Remove stored integration credentials
- Revoke optional host permissions
- Revoke API tokens through the corresponding provider
- Uninstall Hotshot to remove extension-managed local data
10. Security
Hotshot packages its executable code with the extension and does not load remote executable code. It uses temporary active-tab access and optional integration permissions to limit access to what is needed for the action you requested.
No software can guarantee absolute security. Keep your browser updated, protect access to your device, and revoke third-party tokens that are no longer required.
11. Children's privacy
Hotshot is a general productivity tool and is not directed to children under 13. Hotshot does not knowingly collect personal information from children.
12. Changes to this policy
This policy may be updated when Hotshot's functionality or data handling changes. The effective date at the top of this page will be updated when a revised policy is published. A change that introduces new collection or transmission will also require corresponding product and Chrome Web Store disclosure updates.
13. Contact
Questions, privacy requests, and security reports may be submitted through Hotshot's public project issue tracker. The Chrome Web Store listing identifies the current official support location.