CSCapture Signoff
Privacy ยท free public beta

What the free beta processes and stores.

The single-URL proof tool processes the public URL you submit and returns screenshots and technical observations directly to your browser. It does not persist that submitted URL, page HTML, page text, or screenshots in the service database. Your browser may save the latest proof locally for a later visual comparison.

To enforce free limits without storing raw IP addresses, the service converts Cloudflare's network address signal into a keyed, pseudonymous hash. Proof-limit hashes are scoped to the current UTC day; workspace-limit hashes are retained for up to 30 days. Usage rows contain only the hash, event kind, status, page count, Browser milliseconds, coarse error code, optional beta account ID, internal-test marker, and timestamps.

A self-serve beta workspace stores the project name and submitted public URLs in private Cloudflare D1. It stores screenshots, evidence manifests, hashes, capture status, and page decisions in private Cloudflare R2 and D1 so an owner can create a client review link and compare one later capture. Free workspace access expires after seven days, supports one active project of up to three pages, and uses a six-page capture quota.

Each workspace receives a separate access token. Only its hash is stored in D1; the plaintext token stays in the current browser tab's session storage and is sent only as an authorization credential. Reviewers do not need an account. The beta does not ask for or store reviewer names or email addresses. Review tokens are stored as hashes, expire after seven days, can be revoked, and are limited in use.

Free beta projects use a seven-day retention setting and can be deleted immediately after an active capture finishes. Invited research pilots may use a 30-day setting. Deletion removes project database records and private stored artifacts. A daily job removes expired projects and public-beta usage rows older than 30 days. Backups and infrastructure logs may persist for a limited period under Cloudflare's service practices.

Coarse product events contain an event name, short source label, numeric value, time, and internal-test marker. A separate cost ledger keeps page count, Browser milliseconds, stored bytes, status, account ID, and run ID after a project is deleted so quotas and abuse budgets cannot be reset by deletion. These records do not contain submitted URLs, screenshots, HTML, page text, project names, approval tokens, reviewer identity, cookies, form values, or credentials.

Cloudflare provides hosting, Turnstile anti-abuse verification, Browser Rendering, D1, R2, Queues, DNS, and security infrastructure and therefore processes network requests, IP-level security signals, and stored service data on our behalf. The service does not set advertising or cross-site tracking cookies. Do not submit logged-in pages, credentials, localhost, private network targets, or pages you are not permitted to access.

Paid workspace subscriptions are processed by Creem, which handles billing identity and payment information. Capture Signoff does not receive card details. We store subscription, transaction and event identifiers, paid periods and plan state to grant access, reconcile renewals and prevent duplicate processing. The delivery email address is encrypted in the billing ledger. Resend processes the recipient address and access-key message for delivery; failed delivery is retried. Workspace keys are stored as hashes, and paid keys expire with their paid access period. Keys are never put in URLs or product-event logs.

Access-key emails are branded Capture Signoff and sent through the operator's verified formsuite.dev domain. Paid projects use a 30-day retention setting. Billing records are kept separately from project evidence for subscription support and reconciliation; deleting a project does not delete its payment record. For access or deletion questions, contact support@capturesignoff.com.