Privacy
Local-first, by design.
Capto is a desktop app. It does not require an account and there is no Capto cloud holding your screenshots.
No account
Nothing to sign up for, nothing to sign in to.
No telemetry
No analytics, crash pings or usage beacons.
No Capto server
The only endpoints are the ones you configure.
What stays on the device
Captures, recordings, History and settings live under %APPDATA%\Capto. OCR runs on-device with Tesseract. Diagnostic logging is optional, off by default, and written locally when enabled.
Secrets
Translation API keys and cloud credentials are encrypted with Windows DPAPI and scoped to your user account. They are never written in plain text, and they are never sent anywhere except the provider they belong to.
Cloud share
Cloud share is opt-in. When you turn it on, Capto uploads to storage you configure — Cloudflare R2, Amazon S3, Tencent COS or Aliyun OSS — signing the request locally with your keys. Files live in your account. Uninstall Capto and every object remains yours.
Translation providers
The built-in keyless provider and any provider you add (OpenAI, DeepSeek, OpenRouter, DeepL, Google Cloud, or a custom endpoint) receive only the text you explicitly ask to translate. You bring those keys, and you can remove them at any time.
Automation URLs
The capto:// scheme is disabled until you enable it. While it is off, no external app can trigger a capture.
This website
The marketing site is static. It sets no cookies and runs no analytics. The only third-party request is the Google Fonts stylesheet used for Inter and JetBrains Mono.