Privacy, in plain language.
Last updated 12 August 2026. BestCapture is designed so its core capture, annotation and text-recognition workflow happens on your Mac. Cloud features are optional and are only used when you choose to upload or share.
What stays on your Mac
Screen selection, screenshot editing and OCR use macOS frameworks on your device. BestCapture does not automatically upload your screen, captures or recognised text. Native Share can send a selected capture to the destination you explicitly choose.
Account and licence data
When you create an Alcanca account, we process your email address, authentication identifiers, display-name information you provide, product membership, licence status and registered-device information. The same account may be used across Alcanca products. Access is determined by the product entitlements attached to your account, including standalone licences and bundle subscriptions such as Alcanca Suite.
BestCapture Cloud
Captures you explicitly upload are stored in a private Supabase Storage bucket together with metadata such as filename, dimensions, size and creation time. Access is restricted to your authenticated user ID. You choose whether a new share link expires after 1, 7 or 30 days and may limit it to 1, 10 or 50 views. An unrestricted active link can be opened by anyone holding it until it expires, is individually revoked or reaches its optional view limit.
You may instead restrict a link to specific people. In that case, we store the email addresses you enter with the link and require the viewer to sign in with a matching, confirmed Alcanca account before showing the capture or accepting collaboration. The link owner remains authorised. Recipient addresses are visible only to the owner and authorised server processes, are never exposed by the public link, and are deleted with the link.
If the owner enables viewer feedback, anyone holding the active link can submit a display name, comment, one-level reply or supported emoji reaction. On the full share page, a viewer may also choose to record a camera-and-microphone reply to a visible root comment. BestCapture requests browser permission only after the viewer presses Record, keeps the recording local while it is reviewed, and uploads it only after Send. A reply is limited to 45 seconds and 15 MB, stays inside the same private-link conversation and inherits the root comment's playback time. Embeds can play an existing reply but do not receive camera or microphone permission.
For feedback we store a one-way hash of a random, HttpOnly browser identifier to keep activity associated with that browser; it is not an email address or IP address. A sent video reply is stored as a separate private object with its format, size and duration. The owner can read, mark as read or delete feedback threads, including their video objects, and can disable comments or reactions separately for each link.
The owner may add an optional button label and HTTPS destination to a private link. We store those values with the link and show them to its viewers. Selecting the button opens the destination as an external website, whose operator may process data under its own privacy terms.
Billing
Stripe processes payment details, billing addresses, tax identifiers, invoices and subscription events. Alcanca stores Stripe customer and subscription identifiers, plan, status and billing-period dates; we do not store full card details.
Infrastructure providers
We use Supabase for authentication, database and private object storage; Stripe for billing; and Cloudflare for website delivery and security. Each provider processes data under its own contractual and security commitments.
Retention and control
You can delete cloud captures from your account and individually revoke their share links. Billing and security records may be retained where required for accounting, fraud prevention, dispute resolution or legal obligations. To request account access, correction or deletion, contact privacy@alcanca.com.
Security and transfers
Data is encrypted in transit and the providers encrypt hosted data at rest. This is not a claim of end-to-end encryption: Alcanca's authorised server processes can access cloud data when required to operate, secure or support the service.
Changes
Material changes will be published here with a new effective date. Mandatory consumer and data-protection rights are not limited by this policy.