Skip to content
LumenGrab
  • Home
  • Features
  • Screenshots
  • How it works
  • See it in action
  • Privacy
  • Download
  • Changelog
  • Roadmap
  • Mac & Windows
  • Coming soon
LumenGrab editor with annotation tools
PRIVACY POLICY

Privacy, in plain sight.

What happens when you visit this website. What stays on your device.

Updated October 11, 2026

No visitor analytics

No analytics or advertising. Cloudflare Web Analytics stays disabled.

Local app, local files

Your captures stay on your device unless you share them.

Essential hosting

Cloudflare Pages receives connection data to deliver and protect the website.

ON THIS PAGE

01 Who is responsible02 Hosting & server logs03 Public GitHub updates04 Cookies & device storage05 If you email us06 Your rights07 The LumenGrab app08 Changes to this noticeLegal notice / Imprint

01 / Who is responsible

This privacy notice covers lumengrab.app. Tom Jacob is responsible for the processing of personal data on this website.

Ricarda-Huch-Straße 24 36251 Bad Hersfeld, Germany Email: [email protected]

02 / Hosting & server logs

This website is hosted on Cloudflare Pages, provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When you visit lumengrab.app, Cloudflare processes connection and request data, such as your IP address, requested URL, timestamps and browser information, to deliver and protect the website.

Cloudflare uses a global network; processing may take place outside the European Economic Area, including in the United States. Its Data Processing Addendum forms part of the applicable service agreement and describes the Data Privacy Framework and standard contractual clauses for relevant transfers. This is not a commitment to EU-only processing.

We use this data to provide a reliable website and maintain its security, based on our legitimate interests under Article 6(1)(f) GDPR.

Cloudflare's Security Events and Security Analytics datasets have a documented historical retention window of up to 31 days on our Free plan. We have not configured Logpush exports, visitor Web Analytics or application logging for the project-update Function. The normal Pages Functions debug-log stream is not stored or persistent.

The 31-day window is specific to those security datasets; it is not a deletion deadline for every item of Cloudflare request or network data. For other personal data Cloudflare processes, its published retention criteria consider the processing purpose, the nature and sensitivity of the data, security risks, whether the purpose can be achieved with less data, and legal or contractual requirements. Cloudflare describes these criteria in section 11 of its privacy policy.

Cloudflare privacy policy ↗Cloudflare Data Processing Addendum ↗Cloudflare security-data retention ↗Pages Functions logging ↗

03 / Public GitHub updates

Our changelog and roadmap use public information from the LumenGrab repository on GitHub. Public updates are delivered through lumengrab.app. A Cloudflare Pages Function retrieves a fixed public GitHub feed without forwarding visitor request headers or query strings. The browser does not automatically request GitHub for these updates. If live retrieval fails, the website keeps its last available snapshot.

If you follow a GitHub link, you leave this website and GitHub processes your request under its own privacy statement. Public repository content may contain contributor names; we use only the information needed to present project updates.

GitHub privacy statement ↗

04 / Cookies & device storage

We do not use visitor analytics, advertising cookies or persistent browser storage for project updates. Cloudflare Web Analytics is disabled. Fonts, scripts and visual assets are served from this website; there are no embedded videos or third-party tracking integrations.

Cloudflare's Browser Integrity Check and DDoS protection help secure the website. Bot Fight Mode and bot JavaScript detections are disabled. Ordinary visits checked on October 11, 2026 received no Set-Cookie header; security checks can still be triggered for other requests.

If Cloudflare presents a security challenge, it may set a cf_clearance cookie after the check is passed. This records proof of successful verification and avoids repeated challenges. Our Challenge Passage setting is 30 minutes; Cloudflare allows additional validation time for clock differences and XMLHttpRequests. Cookie issuance depends on the security flow and does not occur on every visit.

Processing needed to deliver and protect the website relies on Article 6(1)(f) GDPR. Device storage that is strictly necessary to provide the requested service is covered by Section 25(2)(2) TDDDG. We do not currently enable optional analytics or advertising storage. If a future feature requires consent, we will request it before that feature accesses or stores information on your device.

Cloudflare security-cookie information ↗Challenge Passage and validation time ↗Section 25 TDDDG ↗

05 / If you email us

If you contact [email protected], your email address, message and any information you include are used to respond to your request. Please avoid sending sensitive information that is not needed.

We process ordinary enquiries under Article 6(1)(f) GDPR, based on our legitimate interest in responding to correspondence. Article 6(1)(b) GDPR applies where an enquiry concerns a contract with you or steps taken at your request before entering into one. Article 6(1)(c) GDPR applies where processing is necessary to meet a legal duty, such as responding to a data-protection rights request.

Contact email is hosted by lima-city, a service of TrafficPlex GmbH, Konsul-Smidt-Str. 90, 28217 Bremen, Germany, under our data-processing agreement dated October 11, 2026. We access the mailbox in Apple Mail. Messages are not forwarded to Gmail or an iCloud mailbox.

We review closed enquiries monthly and delete personal correspondence once it is no longer needed to deal with the enquiry or for another documented retention purpose. Records required by law or for concrete legal claims are kept separately with their own applicable deadlines. This review also covers relevant local copies.

For email delivery, storage and spam or malware checks, lima-city processes sender and recipient addresses, message headers, contents and attachments. Mail data is stored in Frankfurt am Main, Germany; backup copies are stored in Helsinki, Finland. DKIM logs are retained for up to 72 hours and other email and security logs for up to 14 days.

Mailbox backups are normally kept for up to 180 days, with a possible overrun of a few days during automated cleanup. Deleted messages may remain in existing backups until cleanup. These provider periods apply to logs and backups; they do not determine how long we retain correspondence in the active mailbox.

lima-city email processing, locations and retention ↗

06 / Your rights

Subject to the applicable conditions, you may request access, correction, deletion, restriction of processing or data portability. You may object to processing based on legitimate interests for reasons relating to your particular situation.

Where processing relies on consent, you can withdraw that consent at any time without affecting earlier lawful processing. Contact [email protected] to exercise your rights.

You may complain to a data protection supervisory authority, including the authority in the country where you live or work. For the operator in Hessen: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit — datenschutz.hessen.de.

Technical connection data are needed to deliver the website. You are not required to send an email or open external links. We do not use automated decisions or profiling that produce legal or similarly significant effects.

Hessen data protection authority ↗

07 / The LumenGrab app

This policy covers the website. LumenGrab is a separate desktop application: screenshots, recordings and project files are processed locally. The operator does not receive them unless you choose to send or share them.

Review a capture before sharing it. Editable .lumengrab files can retain the original image; visually covering content is not the same as permanently removing it from a project file. See the app terms and file format documentation.

08 / Changes to this notice

We update this notice when the website or its data processing changes. The current version and its review date are shown at the top of this page.

LumenGrab

A free screenshot tool for people who want to be understood. Local-first, for macOS and Windows.

Product

FeaturesScreenshotsPrivacyDownloadFAQ

Project

Source on GitHubFile format specRoadmapReleasesChangelog

Legal

Legal notice / ImprintPrivacy policyApp termsLicensesPrivacy promise

© 2026 LumenGrab. The name and logo are not licensed for reuse.

Made for macOS and Windows