By the Fantyzo team · Fantyzo- A StateExamPass LLC company
Gyazo has been an important screenshot tool for a great many people, ourselves included. We have respect for the team behind it, and we appreciate their decision to publicly explain what happened and what they are doing in response.
But incidents like this naturally leave users asking an important question:
What are you doing to protect my screenshots, my account, and my identity?
That is a fair question.
And it is one we believe every cloud-based screenshot service should be prepared to answer.
What we are taking seriously at Fantyzo
After reviewing Gyazo's notice regarding the incident, we took another close look at the security assumptions behind Fantyzo.
Several principles stand out.
Uploads must be treated as hostile input
A screenshot upload may look harmless, but any public upload service is part of the application's attack surface.
Fantyzo is being designed with the assumption that uploaded content and upload requests must never simply be trusted.
Upload handling should be tightly constrained, validated, and separated as much as practical from privileged application and database functions.
A screenshot service should assume that someone, somewhere, will eventually try to abuse its upload path.
We do.
Share links should not reveal themselves
Fantyzo screenshots are private by default.
Saving an image does not automatically make it public.
A user must deliberately choose to share it.
When a share is created, the resulting share identifier should be difficult to predict, non-sequential, and revocable. A private image should not become discoverable simply because someone has learned something about another image, account, or database record.
That philosophy is reflected in one of the principles behind Fantyzo:
Deleted should actually mean deleted
Deleting an image should not simply remove the visible file while leaving behind enough metadata to reconstruct sensitive information indefinitely.
That means thinking about the complete lifecycle of an image: the original object, share references, thumbnails, extracted data, associated metadata, and other derived records.
Fantyzo's retention and deletion policies are being designed around that full lifecycle rather than treating deletion as merely hiding an object from view.
Metadata can be sensitive too
Sometimes the screenshot itself is not the only sensitive information.
OCR text, EXIF information, filenames, source information, device data, timestamps, and other metadata may reveal information a user never intended to publish.
Fantyzo treats that distinction seriously.
If we store sensitive derived information, it should receive privacy protection appropriate to the underlying screenshot—not be regarded as harmless simply because it is “metadata.”
Account sessions are security credentials
Passwords are only one part of account security.
Active sessions, recovery credentials, device identifiers, authentication tokens, and other account-security information can also become valuable targets.
Fantyzo is designed around strong authentication, session controls, revocation capability, and limiting the amount of reusable credential material wherever practical.
Security should not end when a user successfully logs in.
Private by default is not just a feature
This point matters deeply to us.
Fantyzo does not assume that something you save is something you intend to publish.
Those are two different actions.
Your screenshot remains private until you explicitly choose to share it.
That design decision predates the recent Gyazo incident, but events like this reinforce why we believe it is the right model.
Privacy should be the default state.
Sharing should be a deliberate action.
Security is not a finish line
We do not believe any responsible software company should say, “Our system cannot be breached.”
That would be neither realistic nor honest.
What we can do is design Fantyzo so that security and privacy are treated as engineering requirements rather than marketing language.
We can minimize unnecessary data exposure.
We can build systems so that compromised components do not automatically grant access to everything else.
We can make authentication stronger.
We can make sharing deliberate.
We can make deletion meaningful.
And when the security community—or our colleagues elsewhere in the industry—learns something the hard way, we can learn from it too.
To people looking for an alternative
If recent events have caused you to reconsider how and where you store screenshots, we understand.
We have been on that side of the screen ourselves.
Fantyzo exists in part because we believed screenshot tools could offer users greater control over what is private, what is shared, and how their content is handled.
We intend to keep earning that trust.
For the current product rules and controls, see Privacy, Account Security, Private Saving & Sharing, and Storage & Retention.