Oak Donut Privacy Policy

Effective and last updated: September 17, 2026 Published by Kalidonis LLC

Plain-language summary

Oak Donut processes user-requested webpage captures on your device. Screenshot content is not uploaded to, collected by, sold by, or retained by Kalidonis LLC. The Oak Donut extension contains no analytics. The public Oak Donut website uses Google Analytics as described below. If you or your organization uses Oak Donut Pro, limited account, subscription, and license information is processed to provide and verify paid access; capture content remains local.

1. Scope

This policy describes how the currently released Oak Donut browser extension handles information when you use its full-page capture and local export features in Google Chrome. It also describes analytics on the public Oak Donut website at oakdonut.com.

This policy is specific to Oak Donut. Other Kalidonis LLC websites, contact forms, and services may be governed by separate disclosures.

Public website analytics

The public Oak Donut website uses Google Analytics 4 with measurement ID G-5Q3WPP2VZP to understand page visits and improve the website. Google Analytics may process the page visited, referring page, browser and device details, approximate location derived from the network address, engagement events, and identifiers stored in first-party cookies or similar browser storage. Google processes that information under its own privacy terms.

Website analytics is separate from the Oak Donut extension. It does not receive screenshot pixels, captured page content, captured page URLs, extension activity, local preferences, diagnostics, license keys, or Site Batch data. Those items are not sent to Google Analytics by the extension or website.

Visitors can limit analytics through browser privacy or cookie controls or by using the Google Analytics opt-out browser add-on. Blocking analytics does not prevent use of the public website or the extension.

2. Information the extension can access

Only after you select Oak Donut and initiate a capture, the extension can temporarily access the active webpage to:

  • read page and viewport dimensions;
  • read and change scroll coordinates while capture is in progress;
  • identify fixed and sticky elements to reduce repeated content;
  • inspect limited rendered structure needed for capture-quality checks;
  • capture visible webpage pixels through the browser; and
  • restore the page after completion, failure, or cancellation.

Visible webpage content, including sensitive information visible on screen, can necessarily appear in the screenshot you request.

3. Information Oak Donut does not intentionally access

No payment-card information in the extension

The Free extension does not require an account. The extension does not request or receive payment-card details. Stripe processes payment details when a customer purchases or manages a Pro subscription.

No browsing surveillance

Oak Donut does not access or retain your general browsing history, cookies, authentication tokens, or activity across unrelated tabs.

No page-content extraction

Oak Donut does not intentionally collect form values or export page text. Limited structural checks may inspect rendered attributes and accessible-name availability, but those checks return generic counts or status labels rather than page contents.

No analytics or advertising

The extension contains no telemetry, advertising, behavioral tracking, or third-party analytics SDK.

User-initiated support diagnostics

If you select Diagnostics, the extension creates a local plain-text report containing the extension and browser versions, generic platform and feature state, and up to 10 allowlisted generic error codes from the current browser session. The file is not created or transmitted automatically. It excludes screenshot pixels, page URLs, page titles, page text, filenames, discovered URLs, CSV contents, accessibility findings, browsing history, credentials, license keys, and organization identifiers. You can review the file before choosing whether to share it with support.

4. How capture data is handled

  • Captured pixels remain in temporary extension memory while the image is assembled.
  • PNG and PDF generation occurs locally in the browser.
  • An output file is created only through a download you initiate.
  • Oak Donut does not maintain a screenshot history.
  • Screenshot pixels, page text, and form values are not transmitted to Kalidonis LLC.

After download, the file is controlled by you and may be affected by your browser, operating system, backup, synchronization, or device-management settings. Those systems are outside Oak Donut’s control.

5. Browser permissions

PermissionPurpose
activeTabTemporarily access only the active webpage after you explicitly invoke Oak Donut.
contextMenusAdd Capture this scrollable area to the right-click menu on websites. Choosing it grants the same temporary access to that tab as clicking the Oak Donut button.
scriptingRun the packaged measurement, scrolling, quality-check, and restoration controller on the selected page, and — for area capture — find and highlight the scrollable area you right-clicked.
downloadsSave user-requested PNG, PDF, Capture Report, CSV, or diagnostics files to the device.
storageRetain local preferences, a short-lived signed entitlement, and one bounded metadata-only Site Batch recovery checkpoint; read organization-managed license settings; briefly hold which tab and frame you right-clicked, in memory only.

Oak Donut does not use remote executable code. Site Batch declares optional HTTP and HTTPS website access so Chrome can display a runtime permission request for the domain the user enters. Access is requested only after that user action and only for the selected hostname and any explicitly included child subdomains; ordinary single-page capture does not receive permanent access to every website. Approved website access remains in the browser until the user revokes it from Site Batch or Chrome's extension settings. Area capture uses the same optional access in one other case: when the area you right-click is inside a frame embedded from a different website — an app shown inside an online-store admin, for example — Chrome asks for access to that frame's website only. Nothing is fetched; the access lets Oak Donut scroll and measure that frame. A pending area request holds the tab, the frame, and both addresses without their query strings, in memory only. It can be used for ten minutes and is removed when the capture finishes or is cancelled, when the tab closes, when a later area capture finds it expired, or when the browser closes. Discovery omits browser credentials by default; using a current signed-in website session requires an explicit selection. Each response is limited to 5 MB and discovery stops after two minutes.

6. Pro subscription and licensing data

When a customer purchases or uses Oak Donut Pro, Kalidonis LLC may process:

  • organization name and billing-contact email;
  • an internal organization ID and a one-way hash of the organization license key;
  • Stripe customer, subscription, product, price, payment-status, renewal, and cancellation identifiers or status information;
  • the purchased tier and maximum managed-user band;
  • the Chrome extension ID supplied during a license check; and
  • limited service security and error logs, such as request time, network address, response status, and service errors.

The extension sends the organization ID, organization license key, and extension ID to the Oak Donut entitlement service only when it must obtain a signed entitlement. The service compares a one-way hash of the key and returns a signed result. The signed result is cached locally for a limited period so a temporary network outage does not immediately disable Pro.

License checks do not include screenshot pixels, page URLs, page titles, page text, CSV manifests, WCAG results, browsing history, cookies, form values, or authentication tokens.

Stripe processes payment information under its own privacy terms. Cloudflare hosts the entitlement service and subscription-status database. Browser and device-management providers process deployment settings under the organization’s arrangements with those providers.

Kalidonis LLC retains active organization and subscription records while needed to provide Pro. After cancellation, limited billing, transaction, security, dispute, and compliance records may be retained for the period reasonably required by law and legitimate business needs. Locally cached entitlements expire automatically according to their signed expiration and offline-grace dates and can also be removed by uninstalling the extension or clearing its data.

7. Collection, retention, sharing, and sale

Kalidonis LLC does not receive, collect, store, retain, share, or sell screenshot content through the extension. The extension does not communicate with a Kalidonis LLC capture-processing server or third-party capture API. Pro licensing requests communicate only with the entitlement service described above.

Because Kalidonis LLC does not receive screenshot content, there is no server-side screenshot history to retrieve or delete.

Your rights over data held by Kalidonis LLC

Oak Donut Free transmits no personal information to Kalidonis LLC, so there is no account, profile, capture history, or usage record held about you, and consequently nothing for Kalidonis LLC to access, correct, export, or erase on request. Everything the extension retains is stored in your own browser profile. Clear it using the in-product controls — clear recent discovery history, discard an interrupted batch, remove a local viewport profile — or by uninstalling the extension, which removes all of it.

When Oak Donut Pro launches, the organization licensing and billing records described in section 6 will be held by Kalidonis LLC as controller, and rights over those records may be exercised through the contact page in section 13.

8. Local preferences

Oak Donut may retain non-sensitive preferences within the browser profile, such as an export format, sanitized Downloads subfolder, selected viewport profile ID, and up to 20 locally created CSS viewport profiles. A viewport profile contains only a safe label, bounded width and height, stable ID, origin, optional description, and schema version; users can remove local profiles in Site Batch. Site Batch can retain up to five recent anonymous discovery manifests for no more than 30 days, including the selected domain and discovered URLs, and provides a clear-history control. A discovery that used your signed-in website session is never saved to this history, because its results can include private page addresses; use Save Current CSV to keep that list instead. URLs with common authentication, token, signature, password, key, or session query parameters are excluded from the history that is retained. When a user intentionally switches websites to authorize a saved batch, that pending URL list can also remain locally for up to 30 minutes.

During an active batch, the extension stores one versioned local recovery checkpoint containing selected URLs, sanitized capture settings, queue states, attempt counts, and completed Capture Records. This permits Resume, Export Partial Results, and Discard/Restart after an interruption. The checkpoint never contains screenshot pixels, canvases, Blob URLs, HTML, page text, form values, credentials, or license values. It is removed when the batch completes, is intentionally cancelled, is discarded, or reaches its 24-hour expiry.

Up to 10 allowlisted generic diagnostic error codes can be retained in browser-session storage for no more than seven days. They are cleared when the browser session ends and are not transmitted unless you intentionally share the locally downloaded diagnostics file.

Browser profile synchronization, backup, or enterprise management may affect locally stored extension preferences and is controlled by the browser or organization rather than Kalidonis LLC.

For Pro, the browser profile may also retain a signed entitlement containing the organization ID, tier, allowlisted capabilities, typed limits, token/key identifiers, issue time, expiration time, and offline-grace limit. It contains no capture content or payment details. Optional managed restrictions, versioned organization CSS viewport profiles, and a default profile ID remain in browser policy and are not sent as capture activity.

9. Browser marketplaces

Google and Microsoft may process extension installation, update, performance, review, and marketplace information under their own privacy policies. Kalidonis LLC does not control marketplace-level processing.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

10. Oak Donut Pro and future changes

Oak Donut may add account administration, invoices, purchase orders, team assignment, or additional deployment controls. Any material change to the categories of information processed or the purposes described here will be disclosed before it takes effect. Screenshot pixels and captured webpage contents are intended to remain local when Pro licensing is used.

11. Security

Oak Donut uses a local-processing design, packaged Manifest V3 code, narrow browser permissions, and bounded capture operations. No security measure can guarantee absolute protection. Additional technical information and vulnerability-reporting instructions are available on the Oak Donut Security page.

12. Changes to this policy

Material changes will be reflected by updating the date above. A new disclosure and any required consent will be provided before Oak Donut begins materially different data processing.

13. Contact

Privacy questions may be submitted through the Kalidonis LLC contact page.

Name-change preference

Oak Donut stores a small local record of whether this installation upgraded from Kapture IT, when the name-change notice was first displayed and whether it was dismissed. It keeps the familiar toolbar icon until that first view and prevents repeated announcements. This preference stays on your device and is not sent to Kalidonis LLC.