Privacy & data

Privacy, masking and where data lives

How Sendshot keeps passwords, payment fields and secrets out of reports, and where your data is stored.

All help articles

Nothing is sent until someone submits

The widget keeps its context in the page. Data only goes to Sendshot when a person clicks send.

Masking in screenshots

Password fields and card number, expiry and security code fields are masked automatically before a screenshot is taken.

To hide anything else, add data-sendshot-mask to the element:

<div data-sendshot-mask>Account balance: $12,480</div>

Redaction on our side

As a second line of defense, Sendshot scrubs common secrets from incoming logs and requests before storing them: bearer tokens, JWTs, password= style values and long hex keys are replaced with [REDACTED].

Locked to your domains

Each project only accepts reports from its allowed domains, so your key can't be used from someone else's site.

Hosted in the EU

Sendshot runs on servers in Germany and is built in the Netherlands. We don't sell data, and there are no ad trackers. The full details are in the privacy policy.

Export and delete

You can download all your data or delete your account at any time.

Try it on your own site

One script tag. Your first 10 reports are free, no credit card needed.

Start free