Legal
Privacy Policy
Last updated: 2026-06-08. Effective immediately.
The short version
- Your screenshots and recordings stay on your computer by default.
- Privacy Shield (sensitive-data & face detection) runs entirely on-device, on a model on your machine. It never connects to the internet.
- Cloud features only ever run when you trigger them, and send only what that feature needs: AI Explain and AI guide generation (Google Gemini), optional video transcription and premium voice-over, end-to-end encrypted Ozulon Cloud share links, and — if you connect them — OneDrive and Google Drive.
- Cloud AI never runs on its own: it works only when you're signed in, have AI Credits, and explicitly click to use it. We never use your content to train AI models, and we never sell your data.
- We don't store readable screenshots on our servers. If you create an Ozulon Cloud share link, the shared image is encrypted on your device before upload.
What runs entirely on your device
These happen on your computer, with no network connection required:
- Screen capture (region, window, full screen, delayed, scrolling)
- Screen recording and video editing
- Every annotation tool
- OCR (text extraction) and Find Text
- Privacy Shield detection of emails, phone numbers, SSNs, credit cards, IP addresses, API keys, passwords, and faces — using a model that runs locally
- Blur and pixelate redaction
- Your local Library, thumbnails, and metadata
- Sign-in tokens for any cloud accounts you connect (encrypted on your device with Windows DPAPI)
Cloud AI features (always opt-in)
Ozulon's cloud AI features include AI Explain, which writes a description of a screenshot in the style and tone you choose, AI guide generation, which writes the title, step descriptions, and summary for a How-To Guide built from several screenshots, and optional video transcription for captions and premium voice-over. Free Windows voice options run locally; premium Gemini voices use cloud AI credits.
These features never run automatically or in the background. They work only when you are signed in to an Ozulon account, have AI Credits, and explicitly choose to run them on a specific capture or guide. You receive some free credits when you sign up or start a trial; when your credits run out, the features simply stop running until you choose to buy more. Nothing is sent to the cloud unless you click to run one of these features.
When you do run one of them, the screenshots you're working on, plus any text Ozulon extracted from them (OCR) and the annotations you added, are sent over HTTPS to Ozulon's backend, which checks your AI Credit balance and forwards the request to the Google Gemini API. The generated text is returned to your computer and shown in the editor. We don't retain your screenshots after generating your result, and we don't use your content to train AI models. Only the captures you're explicitly working on are sent — never other screenshots, filesystem content, or metadata.
Google's handling of Gemini API requests is governed by the Gemini API Additional Terms of Service. Per Google's published policy, paid-tier Gemini API data is not used to train Google's models, and Ozulon routes these features through the paid tier. Because these features send your images to the cloud, we recommend running Privacy Shield first to redact anything sensitive.
Ozulon Cloud share links (opt-in)
If you upload a capture to create a share link, Ozulon encrypts the image and thumbnail on your device before upload. Cloudflare R2 and Ozulon's backend store the encrypted bytes plus the metadata needed to run the link, such as timestamps, the expiry you choose, view count, and a hashed password if you set one.
Ozulon Cloud share links are end-to-end encrypted: the decryption key lives in the URL fragment and is never sent to Ozulon's servers. Anyone with the full link, including that fragment, and the password if you set one, can view the image. Run Privacy Shield first, and don't share anything you wouldn't want a link-holder to see. You can delete a share at any time, which removes the stored encrypted image.
Connecting OneDrive or Google Drive (opt-in)
If you connect a personal or work cloud account, files you choose are uploaded directly from your device to your own account. Ozulon's servers are not part of that transfer, and we do not receive or store those files. Connection tokens are kept only on your device, encrypted with Windows DPAPI, and you can disconnect at any time.
- OneDrive: we use Microsoft's OAuth and request only the access needed to add files to the folder you choose and create a share link. We don't read your other files.
- Google Drive: Ozulon requests only the
drive.filescope, which limits access to files you create or open with Ozulon — we cannot see the rest of your Drive.
Ozulon's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your consent, for security or legal reasons, or as required by law.
Your account, credits, and payments
When you create an account or sign in (with email and password, or "Continue with Google"), we receive your email address, display name, profile photo, and a user identifier, through Google Firebase Authentication. We keep your AI Credit balance and a usage history to run the service and show you your activity.
Purchases are processed by our reseller, Lemon Squeezy, who handles your payment details. We don't receive or store your full card numbers.
What we don't collect
We don't collect screenshot content other than content you explicitly send to cloud AI features or encrypted payloads you choose to upload as Ozulon Cloud shares. We don't collect filenames, the applications you capture, your screen resolution, advertising identifiers, or in-app analytics and telemetry. Diagnostic logs are sent to us only if you choose to export them from Settings → Support.
GDPR & CCPA
You have the right to request access to, correction of, or deletion of the personal data we hold about you. Email privacy@ozulon.com and we will respond within 30 days. We do not sell personal information, and we do not share it with advertisers.
Security
Data is encrypted in transit using TLS. Ozulon Cloud share images and thumbnails are encrypted on your device before upload and stored as ciphertext on Cloudflare R2; the decryption key lives in the URL fragment and never reaches Ozulon's servers. Connection tokens for OneDrive and Google Drive are encrypted on your device with Windows DPAPI. To report a security vulnerability, email security@ozulon.com; we acknowledge reports within 48 hours.
Children
Ozulon is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their personal data.
Changes to this policy
If this policy changes in a material way, we'll notify active account holders by email at least 30 days before the change takes effect.
Contact
Ozulon · privacy@ozulon.com
Ozulon