Privacy

Local-first, by design.

Capto is a desktop app. It does not require an account and there is no Capto cloud holding your screenshots.

No account

Nothing to sign up for, nothing to sign in to.

No telemetry

No analytics, crash pings or usage beacons.

No Capto server

The only endpoints are the ones you configure.

What stays on the device

Captures, recordings, History and settings live under %APPDATA%\Capto. OCR runs on-device with Tesseract. Diagnostic logging is optional, off by default, and written locally when enabled.

Secrets

Translation API keys and cloud credentials are encrypted with Windows DPAPI and scoped to your user account. They are never written in plain text, and they are never sent anywhere except the provider they belong to.

Cloud share

Cloud share is opt-in. When you turn it on, Capto uploads to storage you configure — Cloudflare R2, Amazon S3, Tencent COS or Aliyun OSS — signing the request locally with your keys. Files live in your account. Uninstall Capto and every object remains yours.

Translation providers

The built-in keyless provider and any provider you add (OpenAI, DeepSeek, OpenRouter, DeepL, Google Cloud, or a custom endpoint) receive only the text you explicitly ask to translate. You bring those keys, and you can remove them at any time.

Automation URLs

The capto:// scheme is disabled until you enable it. While it is off, no external app can trigger a capture.

This website

The marketing site is static. It sets no cookies and runs no analytics. The only third-party request is the Google Fonts stylesheet used for Inter and JetBrains Mono.