Engineering · 4 October 2026 · 2 min

Remembering which app you were in when you captured something

Each Jot capture records the app you were in, like "via OUTLOOK.EXE". How it reads the foreground process on Windows, why it happens before the overlay appears, and what it does not record.

A capture without context loses half its meaning a week later. “Check the numbers” - which numbers? Often the answer is “whatever I was looking at when I wrote it”. So Jot records one small piece of context with every capture: the app you were in. In the Today screen and lists, an item shows something like via EXCEL.EXE.

It is a tiny feature with a couple of non-obvious details.

Read it before the overlay appears

The moment Jot’s capture box takes focus, Jot is the foreground window. If you ask Windows “what is the foreground app?” after that, the answer is always Jot.

So the overlay code reads the foreground window before showing itself, at the same instant it saves the handle it will later give focus back to. The comment in overlay.rs is blunt about it: order matters, because the instant our window takes focus it becomes the foreground window. The same rule is behind giving the focus back.

From window to process name

Getting from a window to an app name is three Win32 calls:

  1. GetWindowThreadProcessId turns the window handle into a process ID.
  2. OpenProcess with PROCESS_QUERY_LIMITED_INFORMATION opens a handle to that process.
  3. QueryFullProcessImageNameW returns the full path of its executable, and Jot keeps just the file name.

The access right in step 2 matters. PROCESS_QUERY_LIMITED_INFORMATION is enough to read the image name and, unlike the full PROCESS_QUERY_INFORMATION, is generally grantable even for a process running as another user, such as an elevated app. Microsoft’s documentation on process security and access rights explains the difference. If anything fails, Jot simply records nothing; a missing “via” label is better than a wrong one.

Why the executable name, not the window title

Window titles contain document names, email subjects, web page titles and chat contents. Recording them would quietly turn every capture into a log of what you were reading, which is more than a capture tool should keep. The executable name says “you were in Outlook” without saying which email.

What it does not record

Everything recorded stays in your local database like the rest of the capture.

Is it useful?

More than I expected. Seeing via TEAMS.EXE next to “send the deck” tells you it came from a call. via CODE.EXE next to “fix the import” tells you it was a code thought. It is a small memory cue that costs nothing to collect, at the moment you are least able to add context yourself.

Jot is on the Microsoft Store.

Jot is a quick-capture app for Windows: one hotkey, one line, back to what you were doing. What it is, or what is still unproven.