Privacy Policy
Effective date: June 12, 2026. This policy explains what RenderShot collects on this website (rendershot.dev) and through the RenderShot API, and how it is used.
Who we are
RenderShot ("we", "us") is a screenshot, PDF, visual-diff and signed-evidence API operated by Eduardo Alcântara, Brazil. Contact: eduardoalcantara.sp@gmail.com.
What we collect on this website
- Analytics. We use Vercel Web Analytics (aggregate page views, referrers, country, device type, UTM parameters) and Microsoft Clarity (heatmaps and session replays showing clicks, scrolls and page interactions) to understand how visitors use the site and improve it. Clarity may use cookies or similar identifiers; data is processed by Microsoft under their privacy statement. We capture site usage and interactions; we do not intentionally collect the content of anything you type on third-party sites.
- Local storage. We store your language preference (
rs_lang) in your browser's localStorage and campaign parameters (utm_sourceetc.) in sessionStorage. These stay in your browser. - No accounts. This website has no sign-up forms and does not collect names, passwords or payment details. Subscriptions and payment are handled entirely by RapidAPI (see below).
What we collect through the API
- Request metadata. For operations and abuse prevention we log basic request data: requested endpoint, target URL, HTTP status and timing.
- Usage metering. We count requests per API key (request counts, errors, bytes served) to provide usage stats and enforce quotas. We receive your key as an opaque identifier via RapidAPI; we do not receive your payment details.
- Rendered content is transient. Pages you ask us to capture are rendered in an isolated browser context and returned to you. Responses may be held in an in-memory cache for a short period (typically up to 5 minutes) to speed up repeat requests. We do not maintain a database of your captures; Evidence archives and diff images are returned to you and are not stored server-side.
- Your responsibility. If the URLs you submit contain personal data, you are the controller of that data; only submit content you have the right to process.
Third parties we rely on
| Provider | Purpose |
|---|---|
| RapidAPI (Nokia) | API marketplace: subscriptions, authentication, billing, quota |
| Railway | API hosting (rendering infrastructure) |
| Vercel | Website hosting and web analytics |
| Microsoft Clarity | Site behavior analytics (heatmaps, session replays) |
What we do not do
- We do not sell personal data.
- We do not run third-party advertising trackers on this site.
- We do not use the content you capture through the API to train models or for any purpose other than returning it to you.
Data retention
Website analytics are retained by Vercel and Microsoft per their respective policies. API response caches expire automatically (minutes). Operational logs rotate on our hosting provider. Usage counters are kept in memory for service operation.
Security
All traffic is served over HTTPS. The API enforces SSRF protection (it will not fetch internal or cloud-metadata addresses), request limits and a bounded render queue. Evidence manifests are signed with Ed25519 so they can be verified offline.
Your rights
Depending on where you live (including under the GDPR and Brazil's LGPD), you may have rights to access, correct or delete personal data, and to object to processing. Contact eduardoalcantara.sp@gmail.com and we will respond within a reasonable period. To opt out of Clarity analytics, use your browser's tracking controls or see Microsoft's privacy options.
Children
The service is intended for developers and businesses and is not directed at children under 16.
Changes
We may update this policy; the effective date above will change and material updates will be reflected on this page.