Privacy Policy
How ScreenMocks collects, stores, and protects your information.
Last updated: August 14, 2026
Overview
ScreenMocks ("ScreenMocks," "we," "us") is a browser-based tool for designing App Store and Play Store screenshots. This policy explains what information we collect when you use ScreenMocks, why we collect it, and the choices you have. ScreenMocks is built and run by a single independent developer, not a large company, and this policy is written the same way: plainly, and only about what actually happens with your data.
Information We Collect
We collect as little as we can get away with. Specifically:
- Account information: if you create a ScreenMocks account, using an email and password or "Continue with Google," we collect the email address (and, with Google, the basic profile info Google shares: name, email, avatar) needed to identify your account. This is handled by Firebase Authentication, our account provider.
- Payment information: if you buy a paid plan or the one-time Launch Pass, our payment processor and merchant of record, Lemon Squeezy, collects your billing details (card number, billing address) directly and is the seller on your receipt and card statement. ScreenMocks never sees or stores your full card number. We store only what keeps your plan in sync: your tier, whether a subscription is active, and its renewal state.
- Project content: the projects you create, and the images you upload into them, are saved to your account so you can pick them up on any device. Project documents (layouts, text, colours, settings) are stored in Firestore and uploaded images in Firebase Storage, both under a path scoped to your account ID. An account is required to design, because there is nowhere else for the work to live.
- Support messages: if you email us, use the contact form, or file a bug report, we keep the message and your reply address so we can respond. Images attached to a bug report are rebuilt as plain PNG or JPEG before anything is stored, which strips any camera or location metadata they carried.
- Technical data: the ScreenMocks website is served by Vercel and its backend runs on Firebase (Google Cloud). Both automatically log standard web request data (IP address, browser type, timestamps) for security and abuse prevention, the same way most websites do. A few features are rate limited per IP address for the same reason.
We do not collect your name, phone number, or physical address unless you choose to give it to us, for example in a support email.
Your Projects and Screenshots
The screenshots, templates, and copy you design in ScreenMocks are saved to your account, so the same work is there when you sign in on another machine. Project documents live in Firestore and the images you upload live in Firebase Storage, each written to a path tied to your account ID. Security rules restrict both to you: no other ScreenMocks user can read or write your projects or your images.
Your project content is yours. We do not look through it, use it to train anything, or show it to anyone else, and there is no public or shared-link surface for projects today. We access it only when you explicitly ask us to, for example if you send a support request that we cannot diagnose any other way.
Rendering and export happen entirely in your browser. When you export a set, or push one to App Store Connect, the images are drawn on your own machine; nothing is uploaded to a rendering server, and the free plan is unlimited for exactly that reason. The one exception is the App Store push, where the finished PNGs are parked briefly in your own private storage area so our server can hand them to Apple, and are deleted straight after, whether the upload succeeded or failed.
AI Features
Two optional features use a third-party AI provider (OpenAI): Suggest, which proposes three alternative headlines for a caption, and Translate, which fills in missing translations. Both are on paid plans and neither runs unless you press the button.
When you do, we send only the text involved: the caption you are working on, the other captions in the project so the suggestion fits the set, and your project's name and description if you have written one. We do not send your screenshots, your uploaded images, your email address, or your account ID. The request goes from our server, not from your browser, so the provider never sees your IP address either. We do not use your content to train anything, and we use the provider's API, which under their published policy is not used to train their models by default.
What comes back is ordinary editable text in your project. Nothing is applied without you, and translation never overwrites a line that was already written.
Services You Connect Yourself
Three optional integrations involve credentials or requests of your own. Each is handled differently, on purpose:
- Figma. The importer runs entirely in your browser. Your Figma personal access token is kept in your browser's local storage and is sent only to Figma's own servers, never to ScreenMocks. We could not read it if we wanted to, because no ScreenMocks server is in that path.
- App Store Connect. This one is the opposite, because the key can act on your whole developer account: it is encrypted and stored on our server, and there is no way to read it back out, including for you. The app can only tell you which key is connected and when it was saved. Your project stores only the public half of the link (bundle ID, numeric app ID, app name). Deleting your account deletes the key.
- Stock photos. Photo searches are proxied through our server so our Pexels key stays private, which means Pexels sees our request, not your IP address. The photo itself is downloaded from Pexels' image CDN directly by your browser, and the photographer's credit travels with it.
Cookies and Local Storage
We use local storage and cookies for things the app needs to function: keeping you signed in, remembering your editor preferences (which panels you collapsed, notices you dismissed), a recovery backup of unsaved work, and, if you use the Figma import, your Figma token. Those live in your browser, not on our servers.
We also use Google Analytics to understand which templates and pages people use, which sets its own cookies and receives your IP address, browser and device type, and the pages you visit. Project IDs are stripped out of the page paths before they are sent. We do not use advertising cookies, we do not run remarketing, and we do not sell or share this data with advertisers.
Analytics only runs after you agree to it. Analytics cookies are not strictly necessary, so Google Analytics starts in a denied state on every visit and is switched on only if you accept in the cookie banner. Until then it writes no cookies and holds no identifier for you. You can change your mind at any time from here or in the footer of any page, and turning it off takes effect immediately. Your answer itself is stored in your browser's local storage, never in a cookie and never on our servers, so it is specific to this browser: clearing your browsing data means we will ask again.
If you arrived through an affiliate link (a link carrying ?aff=, shared by someone in our affiliate program), one more thing runs, and only for you. Lemon Squeezy's affiliate script records the visit so the person who referred you can be paid their commission. To recognise you when you come back and buy, it stores an ls_aff_ref cookie on this site for the length of our 60 day tracking window, and it computes a browser fingerprint (a number derived from your browser and device settings) which it sends to Lemon Squeezy along with the page URL and the page you came from. Lemon Squeezy describes this as cookie-free tracking; it is not, and we would rather tell you exactly what it does. It runs on no other visit, it is never used for advertising or profiling, and it is not behind the banner above, because switching it off would quietly take money from the person who recommended us to you rather than protect you from an advertiser.
How We Use Your Information
We use the information above to:
- Create and secure your account
- Store and render the projects you create
- Process payments and manage your subscription
- Respond to support requests and bug reports
- Keep the service reliable and prevent abuse
- Send you service-related email (account confirmation, password resets, billing receipts, security notices)
We do not sell your information, and we do not share it with data brokers or advertisers.
Payment Information
Paid plans are billed through Lemon Squeezy, our payment processor and merchant of record. That means Lemon Squeezy, not ScreenMocks, is the legal seller of your subscription, and they handle your card details, sales tax and VAT, and refunds under their own security standards (PCI DSS). ScreenMocks only receives confirmation that a payment succeeded, the plan you're on, and enough billing metadata (subscription status, renewal date) to keep your account entitlement in sync.
Third-Party Services
ScreenMocks relies on a small number of providers to run the product. Each receives only the minimum needed to do its job, and none are permitted to use your data for their own purposes.
- Vercel — serves the website itself.
- Firebase / Google Cloud — accounts, the database that stores your projects and subscription status, image storage, and the server functions.
- Lemon Squeezy — payments, as described above, and the affiliate program: if you arrived through an affiliate's link, their tracking script receives a browser fingerprint, the page URL and the referring page so the commission can be attributed. Nobody else's visit touches it.
- Zoho Mail — the mailbox that sends and receives our email: account confirmations, password resets, and your support messages.
- OpenAI — the two AI assists, and only the text described in that section.
- Pexels — stock photo search and delivery.
- Google Analytics — aggregate site usage (pages visited, general location, device type), and only once you have agreed to it in the cookie banner.
- Google Fonts, jsDelivr and Iconify — fonts and icon artwork loaded into the editor. Loading a font or an icon reveals your IP address to that provider, as any web request does.
Support replies come directly from a person at support@screenmocks.com, not an automated system.
Data Retention and Deletion
We keep account, billing, and project records for as long as your account is active, plus a reasonable period after for legal, tax, and fraud-prevention purposes. Deleting a project in the app removes it from your account straight away. You can delete the whole account yourself, under Settings, Security, Delete account: that erases every project, every uploaded image, your access tokens, your saved App Store Connect key, and your sign-in record, immediately and permanently. Export anything you want to keep first, because we cannot recover it for you afterwards.
Deletion asks you to have signed in recently, since it cannot be undone, and it is refused while a subscription is still live: cancel that first, so you are not left paying for an account that no longer exists. If you would rather we did it, email support@screenmocks.com.
One exception, stated plainly: bug reports and contact-form messages are not deleted with the account. They are a support conversation, often about a problem we are still fixing, and they can contain someone else's reply. Instead we de-identify them, removing the account ID and email address that tie them to you, and keep the report text.
Your Rights (GDPR / CCPA)
Wherever you're located, including in the EU, UK, and California, you can ask us to access, correct, delete, restrict, or export the data described above, or object to how we use it. On request we will:
- Tell you what account, billing, and project data we hold about you, and provide a copy in a portable format
- Correct inaccurate account data
- Delete your account, your projects, and your uploaded images, which you can also do yourself at any time under Settings, Security
- Restrict or object to a particular use of your data
Our legal basis for processing account and billing data is performance of our contract with you (running your account and subscription) and our legitimate interest in operating the service securely; where required, we rely on your consent. Send requests to support@screenmocks.com. We'll respond within 30 days, and we won't charge a fee for a reasonable request.
Children's Privacy
ScreenMocks is a professional tool for app developers and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has created an account, contact us and we'll delete it.
Security
We use industry-standard measures, encrypted connections, hashed passwords, per-account security rules on every stored document and file, and restricted access to production systems, to protect the data we hold. Secrets that could act on your behalf, such as an App Store Connect key, are encrypted at rest with no path that reads them back. No method of transmission or storage is perfectly secure, so we can't guarantee absolute security, but we treat your data as if it were our own.
International Users
ScreenMocks is operated from Egypt and available worldwide. Our infrastructure providers (Vercel, Firebase/Google Cloud, Lemon Squeezy, Zoho, OpenAI) may process data in the United States, the EU, or elsewhere, so your information may be processed in a different country than the one you live in. Where that involves a transfer of EU/UK personal data outside those regions, we rely on the standard contractual clauses or an equivalent safeguard used by that provider. We take reasonable steps to protect your data wherever it's processed.
Changes to This Policy
We'll update this page when what we actually do with your data changes, not on a schedule. The "Last updated" date at the top reflects the latest revision. If a change is material, we'll email account holders before it takes effect.
Contact Us
Questions about this policy or your data: support@screenmocks.com.
Questions about this page? Email support@screenmocks.com.