ViperCapture

Last updated August 12, 2026

Privacy policy

ViperCapture collects only the account, security, rendering, referral, and billing data needed to run the service.

Data we store

When you sign in through Clerk, we store your Clerk user identifier, verified primary email address, username, display name, avatar reference, and short-lived session cache entries. We do not store social-provider access tokens or raw Clerk session tokens. We store API key names, one-way hashes, render request IDs, outcome, weighted cost, artifact size, timestamps, and rate-limit counters. Raw API keys are shown once and are not recoverable. Signed-in website images above the plan’s direct-delivery limit and successful async-job images may be sent to UploadThing and made available as unguessable public objects for up to four hours. API callers may separately opt into a 15-minute UploadThing image cache. These objects are deleted after their stated lifetime.

Captures

URL, HTML, and Markdown input is processed in a temporary browser context to produce the requested image, video, PDF, HTML, Markdown, metadata JSON, viewport pack, slice archive, diagnostic bundle, or certified artifact response. Caller-supplied target headers are applied only to same-origin target requests. Synchronous artifacts and source content are returned directly and are not intentionally persisted after the request, except for signed-in website images using four-hour temporary delivery and API images explicitly submitted with cache=true for 15-minute reuse. Async-job source and target-header values are protected with authenticated encryption before storage in Neon, decrypted only by a worker, and erased when the job succeeds, finally fails, is cancelled, or expires in the queue. A keyed request fingerprint supports exact idempotent submission without storing raw source or header values. Retryable jobs may execute at most three times, with attempt-fenced state changes preventing stale workers from replacing newer state. Successful async images remain in UploadThing for up to four hours; job metadata is retained for up to 24 hours. API cache metadata contains an HMAC request fingerprint, account identifier, UploadThing file key, media metadata, size, and expiry; it does not contain the source or target-header values. Render accounting metadata may remain for credit accounting, reliability, and abuse prevention. Cleanup options run inside the temporary browser context, which is discarded after the request.

Browser presets

Capture presets and safe share-link settings are handled in your browser. Presets use local storage and are not synced to ViperCapture accounts. Sources, base URLs, custom headers, custom CSS, selectors, and wait text are excluded from presets and generated share links.

Referrals

A signed, Secure, HttpOnly, SameSite=Lax referral attribution cookie may be set for 30 days after you follow a referral link. We store aggregate visits, verified signups, paid conversions, attribution, reward grants, expiry, and refund or reversal clawback state. The dashboard does not reveal referred customer identities. Reward grants expire after 12 months.

Billing and providers

Clerk coordinates account authentication through the sign-in methods you choose. Neon hosts account data and encrypted async-job payloads, Upstash holds short-lived namespaced session entries, and UploadThing provides temporary website delivery, async-job results, and opt-in API image caching. Paddle is the merchant of record and processes subscriptions, taxes, and payment details; ViperCapture stores Paddle customer, subscription, transaction, price, payment outcome, cancellation boundary, plan-change, and grace-period data but does not receive full card or bank details. Providers may retain their own records under their policies and legal obligations.

Account deletion

You can delete your account from the dashboard. ViperCapture first confirms cancellation of active billing, then deletes your Clerk identity and your profile, API key, credit grants, render metadata, async jobs, referral data, and subscription records from its database. Provider records may remain under Clerk, Paddle, Neon, or Upstash policies and legal obligations.

Questions

For privacy questions, contact [email protected].