How to Screenshot Indian Tax Filing Help Pages With an AI Agent Without Capturing Personal Data
Use public help pages, tightly scoped captures, and pre-capture masks to keep personal tax data out of AI screenshots. Includes runnable Playwright code and a review checklist.
Short answer: Start with the Income Tax Department’s public, signed-out help page. If you need an authenticated screen, navigate to only the relevant error or help area, capture the smallest useful viewport or element, mask known sensitive fields before the screenshot reaches the AI agent, and inspect the actual image before sharing or storing it.
This reduces what the screenshot reveals, but it does not guarantee that every sensitive value has been found or control how a separate AI service handles an image it receives. Check the privacy and retention settings of the specific agent and deployment you use.
1. Why tax portal screenshots need extra care
The Income Tax Department’s My Profile manual lists information that can appear in a profile, including PAN, Aadhaar, contact details, address, bank and demat account details, representative information, and income sources. Its examples also include employer and business details, property addresses, co-owner details, and co-owners’ PAN or Aadhaar information. Treat profile, dashboard, return, and tax-information pages as sensitive even when the field currently in view seems harmless. Income Tax Department: My Profile
The Department’s Login FAQs advise: “As a general precaution, please do not share your login credentials or other sensitive information.” Keep passwords, OTPs, recovery details, and credentials out of screenshots and out of prompts to an agent.
2. The safest capture workflow
- Prefer public, signed-out help content. If the public help article answers the question, use it instead of a logged-in dashboard or return page. This keeps taxpayer records out of the browser view altogether.
- Navigate to the exact issue before capturing. Close unrelated tabs and dialogs. Do not use a desktop screenshot if browser notifications or other account pages could appear. The Department’s co-browsing FAQ distinguishes the active browser view from desktop sharing, which can reveal notifications. Income Tax Department: Co-Browser FAQs
- Limit the screenshot area. Use a viewport or a specific element instead of a full-page capture when possible. A full-page capture can include content below the visible error, including unrelated records.
- Mask before returning the image to the agent. Select the fields you know may reveal identity or account information. A mask hides the selected element’s bounding box in the image; it does not erase data from the page or guarantee that every sensitive item was selected.
- Review the produced image. Check for PAN or Aadhaar, names, phone numbers, email, bank or return details, OTPs, sensitive URL parameters, notifications, and unrelated records. Pay special attention after layout changes or unexpected portal states.
- Minimize retention. If you need to save the image, use a neutral filename, restrict access, and delete it when the task is complete under your organization’s policy. Check the specific AI service’s data handling and retention settings; the Department’s privacy policy describes the Department’s portal, not a separate AI service. Income Tax Department: Privacy Policy
3. Capture and mask with Playwright
This Node.js example captures a selected error area and masks fields selected by CSS. Replace the URL, error selector, and mask selectors with values appropriate to the page. Use it only on a page you are authorized to access. The example assumes an installed Playwright package and browser; it does not sign in, bypass access controls, or discover sensitive fields automatically.
import { chromium } from 'playwright';
const url = process.env.TAX_HELP_URL;
if (!url) throw new Error('Set TAX_HELP_URL to the public help page or authorized page.');
const browser = await chromium.launch({ headless: true });
const page = await browser.newPage({ viewport: { width: 1280, height: 900 } });
try {
await page.goto(url, { waitUntil: 'domcontentloaded', timeout: 30000 });
// Set this to the smallest useful element, such as the error message container.
const target = page.locator('[data-testid="error-message"]');
await target.waitFor({ state: 'visible', timeout: 10000 });
// Use selectors that match sensitive values on this page. Verify them before use.
const mask = [
page.locator('[data-testid="pan"]'),
page.locator('[data-testid="aadhaar"]'),
page.locator('[data-testid="taxpayer-contact"]')
];
await target.screenshot({
path: 'tax-help-error.png',
animations: 'disabled',
mask,
maskColor: '#000000'
});
console.log('Saved tax-help-error.png; inspect it before sharing with an agent.');
} finally {
await browser.close();
}
Playwright’s page screenshot defaults to the current viewport; its fullPage option captures the scrollable page. A locator screenshot captures the matched element, and screenshot options accept a mask list of locators whose bounding boxes receive an overlay. See the Playwright screenshot documentation and Page screenshot API.
For a public help page where the error selector is not known, capture the viewport and apply masks to stable selectors you have confirmed for that page:
await page.screenshot({
path: 'tax-help-viewport.png',
fullPage: false,
animations: 'disabled',
mask: [page.locator('.sensitive-field')],
maskColor: '#000000'
});
Do not assume a locator mask catches values rendered in canvas, browser chrome, notifications, an unexpected modal, or an element whose selector no longer matches. Treat the saved image as untrusted until you inspect it. A visual mask does not remove the underlying page data from the browser, and it does not establish what an AI service logs or retains.
4. Make the capture useful without exposing extra data
- Keep enough diagnostic context: include the error message and, if needed, a non-sensitive heading or form label. Crop out names, identifiers, account balances, and unrelated rows.
- Prefer stable selectors: use IDs, data attributes, or semantic locators tied to the actual interface. Avoid brittle selectors based only on layout position.
- Handle missing elements deliberately: if a mask selector does not match, do not silently assume the page is safe. Check for a changed layout and inspect the result before use.
- Keep credentials out of automation inputs and logs: do not print secrets, OTPs, cookies, or authorization values. Avoid embedding personal data in filenames or URL query strings.
- Capture after the page settles: wait for the specific error or help element rather than relying on a fixed delay where possible. This lowers the chance of capturing a loading state or transient dialog.
5. If you need to send an error screenshot to support
The Department’s helpdesk email format requests screenshots where an error occurs and lists details such as taxpayer name, contact, email, PAN, assessment or financial year, form, and problem details. That document is dated January 2022, so verify the current support channel and its current instructions before sending. Its screenshot guidance is not a reason to include every visible field: crop to the error and remove unrelated sensitive details while preserving enough context for diagnosis. Income Tax Department helpdesk email format
The Department also describes an official co-browsing service. Its FAQ says the taxpayer must approve the request before an agent starts and can end the session. The Department describes co-browsing as limited to the active browser view, in contrast with desktop sharing; it says most co-browsing software has masking for confidential data such as passwords. “Most” does not mean every setup. Ask what is masked and do not disclose secrets. This FAQ describes the Department’s helpdesk service, not an arbitrary AI agent.
6. Troubleshooting
| Problem | Likely cause | What to do |
|---|---|---|
| The screenshot is blank or still loading | The page did not reach the needed state, or the selector was not visible in time. | Wait for the specific help or error element, confirm the URL and page state, and capture again. Do not send an empty image to the agent as if it showed the issue. |
| The mask is missing | The selector did not match, the page layout changed, or the sensitive value is rendered outside the selected element. | Inspect the DOM and selector match, update the locator, and review the resulting pixels. Do not rely on a mask merely because the script completed. |
| The screenshot includes too much information | A full-page or desktop capture included content outside the relevant help area. | Capture a locator or viewport and navigate to the relevant area first. Close unrelated tabs, overlays, and dialogs. |
| The masked area hides the error too | The mask selector is too broad or overlaps the diagnostic text. | Narrow the mask to the sensitive field’s element and capture the error container separately if needed. |
| The page is unexpectedly authenticated | The browser context reused an existing session or cookies. | Use a fresh browser context for public help pages. If authentication is required, make an explicit decision about the data in that session and apply the narrowest capture possible. |
| The agent repeats or stores sensitive details | The screenshot or prompt included sensitive data, or the service has its own logging and retention behavior. | Stop sending the image, follow the service’s controls and incident process, and check its data handling settings. A screenshot mask cannot control a service after image transmission. |
7. Performance, reliability, and cost considerations
For privacy-sensitive captures, reliability means validating the page state and the actual output, not simply getting a successful screenshot call. A targeted locator capture is usually less work than a full-page capture and exposes less unrelated content. Waiting for the exact element is more robust than guessing a delay, but a selector can become stale when the site changes; handle timeouts as a stop-and-review condition.
Playwright runs the browser and capture in your environment, so account for browser installation and runtime in your own deployment. Screenshot storage, agent processing, and any external transmission may have separate costs and policies. The Income Tax Department’s privacy policy does not specify how a third-party agent handles uploaded screenshots. No published statistic quantifying the risk of tax-page screenshot exposure is established by the sources used here.
8. Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server for developers. One GET request returns a PNG, JPEG, WebP, or PDF. For an AI agent, its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, or any MCP client. Read the ScreenshotNeo API documentation.
Example request for a public help page (replace the URL with the public page you need):
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://www.incometax.gov.in/iec/foportal/help -o shot.webp
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://www.incometax.gov.in/iec/foportal/help"},
timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({
access_key: 'YOUR_API_KEY',
url: 'https://www.incometax.gov.in/iec/foportal/help'
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
const fs = await import('node:fs/promises');
await fs.writeFile('shot.webp', Buffer.from(await res.arrayBuffer()));
- Cookie and consent banners are accepted like a visitor, and 60+ known consent platforms, newsletter popups, and chat widgets are removed before the shot; each step can be turned off.
- Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing. Responses include
X-Page-VerdictandX-Billedheaders. - An MCP server lets AI agents take screenshots.
- 1,000 screenshots per month are free with no card; paid plans start at $5 for 3,000. Every feature is on every plan.
ScreenshotNeo captures a URL; do not point it at a signed-in tax page containing personal data unless that is appropriate for your use and you have addressed exposure and handling. For sensitive pages, use a public help URL whenever possible and inspect the returned image before giving it to an agent. Sign up for 1,000 free screenshots a month, with no card required.
9. Frequently asked questions
Can an AI agent see my tax portal details?
If you give an agent a screenshot containing those details, assume the agent can read visible content in the image. What happens to the image after submission depends on that particular service and deployment; check its data handling and retention settings.
How do I hide PAN and Aadhaar in a browser screenshot?
Prefer a public page that does not show them. Otherwise, use screenshot-time masks on confirmed selectors before the image is returned to the agent, then inspect the saved image. Do not treat masking as automatic detection.
Should I use a full-page screenshot?
Only when the full page is necessary and you have checked all of its contents. For a single error or instruction, a viewport or selected element usually exposes less unrelated information.
Does the Income Tax Department’s privacy policy cover an AI agent?
No. It explains the Department’s portal practices. Review the separate AI service’s policy and settings for screenshots you send to it.


