Legal

Privacy policy

Effective August 12, 2026

The short version

We collect the minimum needed to run the service. Your images are processed on snipmat's own servers, deleted automatically on a schedule, never used to train models, and never sold. There are no advertising or analytics trackers on this site.

What we collect

Account data: your email address, a hashed password (we can't read it), and passkey public keys if you add them. Service data: the images you upload, the processed results, and job metadata like filenames, sizes, and timestamps. API keys are stored hashed. If you buy something, Stripe processes the payment — we receive your subscription status and a customer reference, never your full card number. If you write to us through the contact form, we keep the message. For security and rate limiting we process IP addresses and basic request metadata.

How we use it

To run the service: process your images, keep your history, serve downloads, fulfill purchases, and answer support messages. To protect the service: rate limiting and abuse prevention. To reach you: transactional email only — verification links, password resets, and receipts. We don't send marketing email, and we don't sell or rent your data to anyone.

Your images

Images are processed on snipmat's own infrastructure — they are not sent to third-party AI providers. We do not use your images or results to train models. Download links are time-limited. Images delete automatically on the schedule below, and you can delete any image, or your whole account, sooner.

How long we keep things

Images — anonymous useDeleted 7 days after processing
Images — free accountsDeleted after 30 days
Images — Pro accountsDeleted after 90 days
Account detailsUntil you delete your account
Billing recordsAs long as tax and accounting law requires
Support messagesUntil resolved, then archived
Security and rate-limit logsShort-lived and rotated automatically

Cookies and local storage

We use essential cookies only: session cookies that keep you logged in. Your browser's local storage holds small preferences like your theme choice. There are no third-party advertising or analytics cookies. If that ever changes, this policy will change first.

Who else touches the data

Three categories of service providers, each only for their job: Amazon Web Services hosts the service and stores images; Stripe handles payments; an email delivery provider sends transactional email. If you connect a third-party app through MCP or OAuth, that app can use your account within the access you approved — you can revoke it any time in Settings → Connected apps. Beyond that, we disclose data only if the law requires it.

Where the data lives

The service is hosted in the United States, so your data is processed and stored there regardless of where you use it from.

Security

Traffic is encrypted in transit. Passwords, API keys, and verification tokens are stored hashed. Download links are signed and expire. Access to production systems is restricted. No system is perfectly secure, but minimizing what we keep — and deleting it on a schedule — is the biggest protection we can give you.

Your rights

You can see and download your images from My Images, manage your details in Settings, and delete your account yourself — deletion removes your images, keys, and connected apps. If you want a copy of your data, a correction, or a deletion we haven't automated, or you want to exercise rights under GDPR, CCPA, or similar laws, contact us and we'll respond.

Children

The service isn't directed at children under 13, and we don't knowingly collect their data. If you believe a child has an account, contact us and we'll delete it.

Changes and contact

When this policy changes, we'll update this page and its effective date, and notify account holders by email about material changes. Questions: the contact form or support@snipmat.com.