The short version
The app
-
Your screenshots stay on your machine. We can't see them, and we don't want to.
-
No telemetry, no analytics, no ads, no third-party trackers.
-
Mug talks to the internet for two reasons: to check for updates and file bug reports.
This site
-
Everyone - anonymous events
-
With consent - visitor journey info
-
With purchase - OID (individual purchase), TID (volume purchase)
What we collect
From the app itself: nothing. Mug runs entirely on your computer. The screenshots you capture, the annotations you draw, and the folder you save them to never touch our servers, because Mug doesn't have a "send it to us" path to begin with.
We don't know your name, your email, how many screenshots you take, or what's in them. There is no analytics SDK counting your clicks. There is no usage dashboard we look at. We genuinely have no idea how you use the app, and that's by design.
When Mug uses the network
Once a day, Mug asks our update server a single question: "is there a newer version?" To answer it, the request includes your current Mug version and your Windows version (for example, Windows 11 24H2, x64). That's it. No identifier, no fingerprint, no screenshot data.
You can switch this off in Settings โ Updates โ Check automatically. With it off, Mug makes no network requests at all, and you check for updates whenever you feel like it.
What the store sees
If you buy Mug through the Microsoft Store, Microsoft handles the purchase, the payment, and the license. We never see your card number or your billing address. Microsoft's privacy policy covers that transaction, not ours.
What we get back from the store is a tally: how many copies sold. Aggregate numbers, no names attached. Enough to know whether to keep the lights on, not enough to know who you are.
Crash reports
If Mug falls over, it can send us a crash report so we can fix what broke. This is opt-in. Mug asks first, every time, and shows you exactly what's in the report before it sends.
A crash report contains the technical details of the failure: which part of the code broke, your Mug and Windows versions, that sort of thing. It never contains your screenshots or their contents. If you'd rather not send it, don't. Mug works the same either way.
What we never do
-
We never upload, scan, or analyze your screenshots.
-
We never sell, rent, or share data about you, because we don't have any to sell.
-
We never embed third-party advertising or tracking SDKs in the app.
-
We never make you create an account to use what you paid for.
-
We never train an AI on anything of yours. Mug has no AI in it.
The website
This website (mug.win) uses privacy-respecting, aggregate visitor counts so we know whether anyone's reading. No cookies that follow you around, no ad-network pixels, no cross-site tracking. If your browser sends a "Do Not Track" or Global Privacy Control signal, we honor it.
Your rights
Laws like the GDPR and the CCPA give you the right to see, correct, and delete the personal data a company holds about you. The honest answer for Mug is that we hold almost none, so there's very little to hand over or erase.
If you'd still like to ask what we have on you, email hi@mug.win and we'll tell you straight. Mug is not directed at children under 13, and we don't knowingly collect anything from them.
Changes & contact
If this policy changes, we'll update the date at the top and, for anything that actually matters, say so in the app's release notes. We won't quietly start collecting things and bury it in paragraph forty, because there is no paragraph forty.
Questions, doubts, or a gotcha you think we missed: hi@mug.win. A human reads it.
Mug is made by Zum, LLC in Salt Lake City, Utah. This policy is written in plain English on purpose; if any part reads like it was run through a legal blender, that's a bug, and you can report it to hi@mug.win.