Notes for IT and security reviewers

One page with the facts a reviewer needs before allowing ClarShot in a team: what it is, what it can reach, where data goes, and how to check each claim yourself.

Applies to ClarShot version 1.0.0 · Updated 16 September 2026

At a glance

What it isA browser extension (Manifest V3) for screenshots, screen recording and annotation. Runs in Chrome, Edge, Brave and other Chromium browsers, Chrome 123 or newer.
ProviderROEM NOSIS SRL, operating as Voicu.app, Cluj-Napoca, Romania. Full identification on the Legal page.
DistributionChrome Web Store and Microsoft Edge Add-ons, updated through the store like any other extension. No separate installer, no sideloading.
Network activityNone. The free extension makes no requests to any server, ours or anyone else's. No update checks of its own, no license checks, no fonts or scripts fetched at runtime.
Accounts and sign-inNone. Nothing asks who the user is.
Telemetry, analytics, crash reportingNone, and no opt-in version of it either.
Where data is storedOnly in the browser profile on the device: the extension's own storage for preferences, and the browser's local database (IndexedDB) for captures in progress, the last 10 exported images and recordings in progress. Exported files go to the Downloads folder or the clipboard.
Host permissionsNone. No "read and change all your data on all websites", no site-specific access.
Remote codeNone. Everything ships inside the package; Manifest V3 forbids remotely hosted code.
Third-party servicesNone embedded in the extension. This website has no cookies, trackers or third-party scripts.
PriceFree. A paid Pro tier will come later for presentation polish, as a one-time purchase with an offline license key; it will not add network activity. Pricing principles.
Contactsupport@clarshot.com, answered by a person.

What happens when someone captures

  1. The user clicks the toolbar icon or presses a shortcut. The browser grants the extension access to that one tab, for that one action.
  2. The capture opens in the editor, which is a page inside the extension. Annotation, blur and crop happen there, on the device.
  3. The user exports: a file in the Downloads folder, or an image on the clipboard. The last 10 exported images stay in the popup's Recent list, on the device, until removed.

Where the file goes afterwards is the user's decision. ClarShot has no server that could receive it. If the Downloads folder is synced by OneDrive, Google Drive or Dropbox, that service, not ClarShot, may upload the file under its own policy.

Permissions, and what is not requested

These six permissions appear on the install prompt. Each one maps to a visible feature.

PermissionUsed for
activeTabCapturing the tab the user is looking at, only when they click ClarShot or press a shortcut.
scriptingDrawing the selection overlay and scrolling the page for full-page capture, injected on demand into that tab and removed when done.
tabCaptureRecording the current tab's video and audio, only when the user starts a tab recording.
offscreenRunning the recording pipeline in a hidden extension page, which Manifest V3 requires.
downloadsSaving exports to the Downloads folder when the user clicks Download.
storageKeeping preferences and the Recent list on the device. Never synced, never sent.

Not requested: host permissions of any kind, access to browsing history, bookmarks, cookies or other extensions, OAuth scopes to Google, Microsoft or any third party, and no background access to tabs the user did not act on. Recording a window or the whole screen uses the browser's built-in screen-sharing chooser; the user's choice in that dialog is the consent, and it needs no extra permission.

How to verify these claims yourself

Allowing or blocking it for a team

ClarShot is a normal store extension, so it is governed by the same policies as any other. In Google Admin or Windows Group Policy, Chrome's ExtensionInstallAllowlist and ExtensionInstallForcelist policies take the extension ID; Microsoft Edge has the same policies under the same names. Updates arrive through the store; there is no separate update channel to allow.

Microsoft Edge Add-onsExtension ID feaihccglhmfpdlgppkfepchihdghmih. For a force-install entry, append the Edge store update URL: feaihccglhmfpdlgppkfepchihdghmih;https://edge.microsoft.com/extensionwebstorebase/v1/crx
Chrome Web StoreListed here as soon as the Chrome Web Store listing is published.

Data retention on the device

Limits worth knowing

Documents

Privacy promise and policy · Terms · Legal notice · Questions: support@clarshot.com