Privacy

Privacy notice

LAST UPDATED Sep 10, 2026 ยท VERSION 1.0

This notice explains what Shadow Capture collects, why, how long it is kept and how to have it removed. It is written to be read rather than skimmed, so it is short.

Who we are

Shadow Capture is operated by Noventix LLC, a Missouri limited liability company, in Columbia, Missouri 65203, United States. Shadow Capture is offered to customers in the United States. Where US state privacy law gives you rights, we are the party responsible for the information described below.

You can reach us about anything on this page at privacy@shadowcapture.ai.

Requesting access to the beta

If you request access, we collect the email address and password you enter on the registration page. Passwords are handled by our authentication provider, Supabase; we never see or store them ourselves. We use your email address to run your account, to tell you when your access has been approved, and to send you product updates and marketing email about Shadow Capture: things like pricing, offers, case studies and events.

Three limits on that, which we hold ourselves to:

  • We do not sell or rent your address, and we do not share it with anyone else to market their own products.
  • We only email you about Shadow Capture. Requesting access does not sign you up for anything else Noventix does.
  • We do not enrich it with data bought from data brokers or scraped from elsewhere. What we know about you is what you typed into the form.
What we collect.
Your email address, the date you registered, and whether your access has been approved.
Why we may hold it.
To provide the account you asked for, and your consent to product and marketing email, which you give by registering, having been told on the form itself that we will send it.
How long we keep it.
Until you ask us to remove it, or until 24 months after the beta closes, whichever comes first.
How to be removed.
Use the unsubscribe link in any email we send, or write to privacy@shadowcapture.ai. We will remove you and confirm it. Unsubscribing from email does not close your account.

Account records are stored in our own database at Supabase, which hosts it for us under a data processing agreement. They are not passed to an email marketing company unless we start using one, and if we do we will name it here first.

This website

This site sets no cookies and loads no third-party scripts. Fonts are served from our own servers rather than a font network, so no request about you leaves this site while you read it. The playable walkthroughs on this site are self-contained files served from the same place, and nothing you do inside one is recorded or sent anywhere.

We do not use analytics on this site. We do not count page views, and we do not know who visits.

Our hosting provider, Railway, keeps standard server logs including IP addresses for security and troubleshooting, and retains them according to their own policy.

The product, when you use it

This part applies to beta participants using Shadow Capture itself, not to visitors to this site.

Your account.
Your email address and a password you set. Passwords are handled by our authentication provider, Supabase; we never see or store them ourselves.
What you record.
When you record a workflow, Shadow Capture saves copies of the screens you visited and a record of the actions you took. You choose what to record. Those copies contain whatever was on your screen at the time, which may include personal data belonging to your own customers or staff.
Who that belongs to.
It is yours. We hold it so you can use it, and we do not look at it except where you ask us to help with a support request. Under US state privacy law you decide what is collected and we are your service provider, acting on your instructions.
How we improve the product.
We look at how walkthrough generation performs: where a pass produced a poor result, where a check failed, which steps needed repair. We use what we learn to improve our prompts and the logic that turns a recording into a walkthrough. That is the only way what you record feeds back into Shadow Capture. Your content is not used to train AI models, ours or anyone else's. Nothing you record is absorbed into a model, and nothing from your recordings can surface in anyone else's walkthrough.
What we ask of you.
Record against a test or staging system wherever you can. Where you cannot, use Shadow Capture's editing tools to change names, figures and other details before you publish. Passwords, one-time codes and card fields are removed everywhere — from the step list, from the saved screen and from the picture taken alongside it. Nothing else is: whatever was on screen is part of the recording, including anything already typed into an ordinary form field. See the browser extension for exactly what is left out and what is kept.

The browser extension

The Shadow Capture Recorder is a Chrome extension you install yourself and connect to your own Shadow Capture account. It gets a section of its own because it runs inside your browser, on pages we otherwise never see, and because we would rather describe it in detail than have you infer it from a permission warning.

What it reads, and when.
Only while you are recording, and only in the tab you are recording in. When you press Start recording it saves a copy of each screen you pass through: the page's own HTML, and the images, stylesheets and fonts needed to show it again. It saves a picture of the visible window alongside each one, and a list of what you clicked and typed. Between recordings it reads nothing.
What is deliberately left out.
Passwords, one-time codes and card fields (number, security code, expiry and cardholder name) are blanked in the page before each screen is saved, and put back immediately afterwards, so they reach neither the saved screen, nor the picture, nor the step list. Everything else is saved as it was, including anything already typed into an ordinary form field and values a page holds in hidden fields. That is what makes a walkthrough faithful, and it is why we ask you to record against test data.
Where what you record goes.
To your Shadow Capture account, over an encrypted connection, and nowhere else. The extension contains no analytics, no telemetry, and no address of ours other than the Shadow Capture server you connect it to. No third party receives anything you record, and there is no route by which it reaches us other than the one you connected.
What it keeps on your computer.
The address of the Shadow Capture server it is paired with, the key that server issued it, and your panel preferences — appearance, whether automatic capture is on, whether the diagnostic log is open. Recorded screens are never written to disk: they are held in memory until you send them, and lost if you close the panel first.
Requests it makes to other websites.
To save a screen faithfully the extension has to fetch the images, stylesheets and fonts that page uses, from wherever the page loads them. Those requests go only to the addresses the page itself names, carry no cookies or credentials, and tell those sites nothing about you beyond that the file was asked for. Nothing you record is sent to them.
Why it asks for access to every site.
Chrome shows a broad permission warning when you install it. It is broad because the software you record is your own and we cannot know its address in advance — a recorder that only worked on a list of sites we had chosen would not work on yours. The permission is what lets the extension act on the tab you are recording. It does not mean it reads pages you are not recording, and this notice is the commitment that it does not.
Turning it off.
Every connected browser is listed on your account page and can be revoked there, which stops that browser sending anything from that moment. Removing the extension from Chrome erases everything it kept on your computer.

Limited use. What the extension sends us is used only to provide and improve Shadow Capture's recording and walkthrough features. We do not transfer it except as needed for that, to comply with the law, or to protect the service; we do not use it for advertising of any kind, and we do not sell it. No person at Noventix reads it except where you ask us to help with a support request, where the law requires it, or where we have to act on a security problem.

Sub-processors

We use a small number of providers to run the service. Each is bound by contract to process data only on our instructions.

  • Supabase. Account sign-in, and the database holding accounts. Canada (Montreal).
  • Railway. Website and application hosting. California, US.
  • Anthropic. Writing and checking walkthroughs. Content you record is sent to Anthropic to produce the walkthrough. Under Anthropic's commercial API terms that content is not used to train their models. United States.

That is the whole list. We do not use an advertising network, a session-recording tool or a third-party analytics service.

We will tell beta participants before we add or change a sub-processor.

Where your data is held

Shadow Capture is operated from the United States and is offered to customers in the United States. Your data is held in two countries, and we would rather be specific than vague about it:

  • Canada. Accounts and sign-in credentials are stored in our Supabase database in Montreal.
  • United States. The website and application run on Railway in California, US. Content sent for walkthrough generation is processed by Anthropic in the US.

So if you are in the United States, some of your data is stored outside the country. We are telling you because you may need to know it, not because it changes your rights. Everything in this notice applies to that data wherever it sits, and Supabase is bound by contract to process it only on our instructions.

Your rights

Wherever you live, you can ask us for a copy of your data, ask us to correct it, or ask us to delete it. You can withdraw consent at any time, which does not undo anything done before you did. Write to privacy@shadowcapture.ai and we will respond within 30 days. We will not treat you differently for exercising a right.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. There is nothing to opt out of, because we do not do it. Sending you our own marketing email is not a sale or a share under these laws, and you can stop it at any time with the unsubscribe link.

If you are in a US state with a privacy law, you may also have the right to appeal a decision we make about your request; write to the same address and we will handle it as an appeal. If we deny the appeal, we will tell you how to raise it with your state attorney general.

Security

Access to production systems is limited to people who need it, and traffic to and from Shadow Capture is encrypted in transit. Specifically:

  • Passwords never reach us. Supabase verifies them at sign-in. We never see, store or log a password.
  • Sessions are signed, not guessable. Your session is a cryptographically signed cookie, marked HttpOnly so page scripts cannot read it, and it expires after 30 days.
  • Extension tokens are stored hashed, one per paired browser, so a single device can be revoked without disturbing your others.
  • Accounts live in our Supabase database, which is encrypted at rest.
  • Recorded walkthroughs, the saved screens and step lists, are stored as files on our own server, protected by the server's access controls and disk encryption rather than by a separate layer of application encryption. If you are evaluating Shadow Capture for sensitive material, this is the detail to weigh, and it is why we ask you to record against test data wherever you can.

Shadow Capture is in beta. Being straight with you about where that leaves us: it has not been through an independent security audit, we hold no security certification such as SOC 2 or ISO 27001, and we do not yet operate a formal backup and disaster-recovery program for recorded walkthroughs. Keep your own copy of anything you cannot afford to lose. We would rather say all of this plainly than let you assume otherwise, and we will update this section as it changes rather than quietly leave it stale.

If a breach affects your data, we will tell you, and any regulator the law requires, as quickly as we can.

Children

Shadow Capture is a business product and is not intended for anyone under 16. We do not knowingly collect data about children.

Changes

If we change this notice we will update the date at the top. If a change materially affects you, we will email you rather than rely on you noticing.