FrontCap Privacy Policy
Last updated: June 10, 2026
The English version of this document is authoritative; translations are provided for convenience only.
FrontCap is a local-first Chrome™ extension for capturing front-end UI elements and exporting them as Markdown. This policy explains exactly what stays on your device and the narrow cases where data touches the network. We keep it honest: FrontCap is not "completely offline", because sign-in and subscription checks require a network connection.
What stays on your device
Everything you capture is processed and stored locally. The extension does not upload any of it:
- DOM snapshots and excerpts
- Computed CSS, pseudo-elements, and visual features
- Source-location hints
- Element screenshots (opt-in per capture, off by default)
- Your annotations and notes
Captures live in the browser's local extension storage and, for screenshots, in your Downloads folder. You can delete them at any time from the side panel or your file system.
Important boundary: "We don't upload your captures" means the extension uploads nothing. The end of the workflow is you pasting the exported Markdown into a cloud coding assistant — at that moment the captured content travels to that assistant's provider as part of your paste. That transfer is your action, governed by that provider's terms, not ours.
Google user data and network flows
FrontCap is a paid extension, so Google sign-in, entitlement, and billing flows require limited network use. FrontCap requests the openid, email, and profile scopes.
Data accessed from Google
When you sign in, FrontCap may access your Google account identifier (sub), email address, email verification status, first name, last name or display name, profile picture URL, and the OAuth access token or ID token needed to verify sign-in.
How we use Google user data
We use Google user data to identify your FrontCap account, verify that your Google email is verified, start and check your trial or subscription entitlement, issue and validate your signed FrontCap license, display your account UI, provide account and technical support, handle billing or payment disputes, perform Paddle reconciliation, contact you about account, subscription, security, or service-interruption issues, and keep the website checkout account aligned with the installed extension account. Your email address is not used as the primary identity key; your Google account identifier is used for account identity.
Storage and retention
The extension may store your Google account identifier, email, display name, profile picture URL, cached license, and account display state locally in Chrome extension storage. FrontCap's server stores the Google account identifier, email address, and first/last name when available, along with trial, entitlement, checkout, billing, subscription, and event records needed to provide the paid service, support, reconciliation, account contact, and legal compliance. The website session cookie contains only a signed Google account identifier and timestamps; it does not contain your email, name, profile picture, license, payment details, or captured page content.
Sharing and transfer
We do not sell Google user data, use it for advertising or retargeting, provide it to data brokers or information resellers, use it for credit-worthiness or lending, or use it to train AI or ML models. We may provide your email address to Paddle, our Merchant of Record, for checkout, receipts, billing, subscription management, and payment support. We do not send Paddle your Google account identifier, Google name, profile picture, OAuth token, license, or captured page content. FrontCap never sees or stores your card number or other payment details.
Sensitive data & sanitization
Because you may capture real, logged-in pages, FrontCap sanitizes captures before they are stored: it strips likely secrets — tokens, emails, phone numbers, and passwords — from element attributes, and redacts matching PII patterns found in visible text. We do not deliberately collect this data.
Permissions we request
- activeTab / scripting — to inject the capture overlay into the current tab only after you turn it on.
- identity / oauth2 — for Google sign-in and account display. OAuth consent is shown by Google when you sign in.
- downloads — to save element screenshots to your Downloads folder. We read only the download item we just created to get its path; we never read your download history.
- storage — to keep your captures, settings, cached license, and account display state locally.
- sidePanel / contextMenus — for the main UI and entry points.
- Optional access to
localhost— requested only when you capture a local dev server.
The manifest also allows only https://frontcap.net to send the extension an entitlement-refresh message. We do not request broad host permissions, read your clipboard, or browse your tabs in the background. The overlay is injected only after you explicitly start capture on the active tab.
What we don't do
- No advertising, no third-party trackers, no analytics on your captured content.
- We do not sell your data or share captured content.
- We do not automatically harvest pages or traverse your browsing history.
Data retention & deletion
Captures stay on your device until you delete them. On the server we retain the account record tied to your Google identifier, including email, first name, and last name when available, plus one-time sign-in/checkout ticket records and billing, subscription, and event records needed for entitlement, technical support, billing or payment disputes, Paddle reconciliation, account contact, service-interruption notices, security, and applicable legal obligations. To request deletion of your account data, contact us at support.
Contact
Questions about this policy? Email support@frontcap.net.