Your authenticated browser session stays with the browser doing the capture or refresh; the screenshot you deliberately save becomes Kaptr.me content and can be stored in your dashboard.
The security boundary
A useful way to think about Kaptr.me is to separate source access from saved visual content. Source access is whatever your browser already knows: cookies, authentication state, an open company portal, a bank session, a Power BI workspace or another protected page. Kaptr.me does not need your password in order to reuse that local session.
The visual content is different. When you select a region and save it to a dashboard, that selected image is intentionally sent to Kaptr.me so it can appear in the board, be refreshed, placed in history and shared according to the board settings.
Local capture and refresh
For normal extension capture and local refresh, Kaptr.me asks the browser on the device performing the action to revisit the source and capture the selected area. The extension does not transfer your website credentials to another computer or create a portable login session for Kaptr.me.
That distinction matters for sensitive sources. If you capture a section of an authenticated account on Computer A, opening Kaptr.me on Computer B does not give Computer B the authentication state of Computer A. The second browser must independently have access to the source.
What is stored in the cloud
Once you save a snapshot, the selected image and the dashboard information needed to operate Kaptr.me are cloud data. Kaptr.me's primary Firebase data layer is configured in Europe. Stored snapshots use the encryption provided by the cloud platform, and traffic to the service is protected in transit.
This is why we avoid saying that a saved screenshot “never leaves your browser.” The session credentials stay local during the local workflow; the snapshot you choose to save is sent to Kaptr.me.
Private, shared and public dashboards
Private
New dashboards are private. Only the owner can access them until a sharing action is taken.
Shared
Access can be limited to specific Kaptr.me accounts. A visitor who is not signed in with an invited account cannot view the board.
Public
A public dashboard can be shared by URL. Search indexing is a separate choice, so a public link can remain non-indexed.
Use Security for the current product-level explanation of these modes and Privacy for the data-processing details.
AI is a separate boundary
Kaptr AI is not the same as the local extension workflow. Content submitted to AI features is processed remotely. Depending on the AI workflow, submitted content and AI-generated captures can be reviewed by authorized human reviewers and may be used to evaluate, train or improve AI systems.
If a source is highly sensitive and you do not want that content to enter an AI processing flow, keep the workflow local and do not submit that material to AI features. Local capture and local refresh do not require sending the source session itself to the AI system.
A practical security checklist
- Capture the smallest useful region. Do not save unrelated personal or confidential information just because it is visible on the page.
- Keep sensitive boards private by default. Change visibility only when there is a clear reason.
- Use Shared for named collaborators. It is the right choice when a link should not be enough to access the content.
- Treat Public as publication. Even when indexing is disabled, anyone who receives a public link may be able to open it.
- Separate local and AI workflows. Decide deliberately before sending sensitive material to an AI feature.
The safest Kaptr.me workflow is also the simplest: the browser keeps the session, you choose exactly what becomes a snapshot, and dashboard visibility stays explicit.
