Guides / Your screen

What happens to my screen?

4 min readCites 1 record

Fig. 6. The capture stays on the device. One line of text leaves.

In brief

Your screen is read on your device and forgotten there. The capture goes straight into the operating system’s own OCR, on the machine, and is destroyed after the text comes out. The claim text you selected is the only thing that ever travels: one field, in one small request. Every sentence on this page is checked against the shipping code, and the page tells you how to catch us lying.

The path of a pixel#

When you draw a box, the app asks the OS for exactly that rectangle of the framebuffer. On macOS that is a single call, CGDisplayCreateImage, scoped to the rect you drew. The pixels go directly into Apple’s Vision framework (VNRecognizeTextRequest), which runs on your Mac’s own silicon. On Windows the same job is done by the system’s OcrEngine, and the source file says it plainest: “local only, never network.” Out comes text. The bitmap is disposed. There is zero code in either app that writes the capture to disk or serializes it into a request; the image lives for the milliseconds OCR needs, in memory, on your machine.

Highlighting text instead of drawing a box is even shorter: the selected string is read directly, and no capture happens at all.

The transmission, in full#

Here is the entire request body the app sends when you check a claim:

One JSON field. Alongside it ride the request headers that make the call yours: your public key, a timestamp, a nonce, and a signature made on your device. The private key behind that signature is derived from a recovery phrase generated on your machine, and it stays there. What returns is the report: the gap, the friction, the testimony, the same artifact you can read in any published record. The pixels stay on the machine. The report is the only thing that comes back.

What is kept, and for how long#

Precision beats reassurance, so here is the inventory. Server-side, Nolemy keeps: your public key and the handle derived from it (identity here is a key, and an account with an email address is a thing we refuse to have); the claim text you checked and the report the engine generated for it, which is what makes publish-by-reference possible later; and, for abuse control, a one-way peppered hash of the requesting IP. The raw address is discarded; the hash is useless for geography and useful only for rate limiting.

A check stays private to you unless you publish it: it lives in the server’s check cache, keyed to your public key, and appears on no public page and in no search index. Publishing is the one irreversible act in the product, and it is loud, deliberate, and signed.

The honest limits#

Three edges, stated plainly. First: the claim text itself does leave your machine, by definition, since a live search runs on it. Highlight a sentence containing your own account number and that sentence travels. The tool reads what you point it at; point it at claims. Second: DRM-protected video frames come back empty. The OS blanks protected surfaces before any app, including this one, can see them. Third: the OCR is the operating system’s, so its accuracy ceiling is Apple’s and Microsoft’s, and tiny text gets upscaled before reading precisely because a blurry ₹499 reads as ₹799 otherwise. That upscaling also happens on your device.

The objection#

Verified against the shipping code on 2026-07-09: ScreenCaptureController and OCRProcessor (macOS), WindowsOcrService (Windows), BackendManager (request body). Storage claims match the published privacy policy. The proxy test in section 05 is reproducible by anyone.