Privacy Policy
At SnapFrame, we respect your privacy and are committed to protecting your personal data. This Privacy Policy details our practices concerning data collection, processing, storage, and your rights under the General Data Protection Regulation (EU) 2016/679 (GDPR) and California Consumer Privacy Act (CCPA).
Key Privacy Commitments
Your raw screenshots and canvas rendering execute directly in your browser canvas.
Optional AI captioning tools never use your screenshots to train public AI models.
We do not sell, rent, or trade your personal information to any third parties.
You can delete your projects or request complete account erasure at any time.
1Data Controller
MTLG Labs (Alexandr Motologa) operates as the Data Controller under Article 4(7) of the GDPR for the personal data collected through the SnapFrame website (https://snapframe.store) and associated services.
MTLG Labs Data Protection & Legal Office
Operator: MTLG Labs (Alexandr Motologa)
Email: privacy@snapframe.store
GitHub Security: Security Advisory Hub
2Information We Collect
We process personal and non-personal data strictly as required to provide our screenshot creation service:
- Account & Authentication Data: When registering or logging in via Google OAuth, GitHub OAuth, or Email & Password (managed through Google Firebase Authentication), we receive your unique User ID (UID), email address, display name, and avatar URL. Passwords are never stored directly by us and are securely salted and hashed by Firebase.
- Project & Design Data: Project metadata (project name, created/updated timestamps, device presets, layer coordinates, headlines, colors, and layout configurations). For Guest and Free users, projects are stored strictly locally in your browser storage (
localStorage). For SnapFrame Pro subscribers, project data is securely synchronized and backed up to encrypted Google Cloud Firestore databases under your authenticated user ID. - Uploaded Screenshots & Images: App screenshots and media uploaded to the canvas are rendered client-side in HTML5 Canvas. If cloud sync or asset hosting is active, image assets are stored securely in encrypted object storage.
- Voluntary Community Reviews & Testimonials: If you choose to submit a rating or product feedback via your Account Settings, we store your review text, chosen role title, rating, and verified status in Google Cloud Firestore. To protect your personal privacy, full names are automatically anonymized for public display (e.g.
Mar***** Lin*****) to prevent public web scraping while showcasing genuine verified community feedback. You may edit or delete your review at any time from your Account Dashboard. - Telemetry & Usage Diagnostics: Anonymized interaction events (e.g. template clicks, export trigger counts) collected via privacy-configured analytics to diagnose application performance and improve usability.
3Legal Bases for Processing (GDPR Art. 6)
We process your data strictly under the following legal bases:
Contractual Necessity (Art. 6(1)(b))
To deliver screenshot generation, project persistence, canvas editing, and 4K asset exporting.
Legitimate Interest (Art. 6(1)(f))
To maintain application stability, prevent malicious abuse, and secure authenticated user sessions.
Explicit Consent (Art. 6(1)(a))
When you invoke optional AI caption generation or opt-in analytics tracking.
4AI Tools & Machine Learning Processing
SnapFrame provides optional AI tools (Vision Auto-Pilot, Copywriter, Multi-Language Translation, and ASO Metadata Optimizer) powered by API providers (Google Gemini, OpenAI, Groq, and Mistral):
- Text prompts or image previews submitted to AI features are processed in real-time strictly to return the generated captions, translations, or design layouts.
- Data transmitted to these AI providers is governed by enterprise API terms that explicitly prohibit using customer data to train foundational models.
- You can use the entire SnapFrame editor without activating AI features.
5Third-Party Subprocessors
We work with trusted, GDPR-compliant infrastructure partners under Data Processing Addenda (DPA):
| Subprocessor | Purpose | Data Location | Compliance Mechanism |
|---|---|---|---|
| Paddle.com (Merchant of Record) | Payment processing, recurring subscriptions, tax compliance, invoicing | UK / EU / US | PCI-DSS Level 1, GDPR DPA, SCCs |
| Google Cloud / Firebase | Authentication, Firestore database, hosting | EU / US | EU Standard Contractual Clauses (SCCs) |
| Vercel Inc. | Edge application delivery and serverless execution | Global Edge Network | ISO 27001, SOC 2, SCCs |
| Google Gemini API | Optional AI multimodal vision and captioning | US / Global | Google Cloud Enterprise Terms |
| PostHog | Product analytics and error reporting | EU Cloud | GDPR Compliant Analytics DPA |
Payment Data Security: SnapFrame does not store or process raw credit card numbers or payment credentials on our servers. All financial transactions and payment data are handled directly and securely by Paddle.com in full compliance with PCI-DSS Level 1 security standards.
6Your Rights under GDPR and CCPA
Under the GDPR (Articles 15–22) and CCPA/CPRA, you possess comprehensive rights over your personal data:
Request a copy of all personal data and project records associated with your account.
Request complete deletion of your account and all associated cloud project data.
Export your projects, screenshots, and metadata in standard formats (ZIP, PNG, JSON).
Update or correct any inaccurate personal details or account email addresses.
To exercise any of these rights, contact us at privacy@snapframe.store. We will respond within 30 days without any fee.
7Data Retention & Security Measures
We implement industry-grade technical and organizational security measures (TOMs) under Article 32 of GDPR:
- All web traffic is encrypted with Transport Layer Security (TLS 1.3).
- Database records and authentication tokens are encrypted at rest with AES-256.
- Local projects stored in your browser persist only on your device until manually cleared.
- Cloud-synchronized project data for registered accounts is retained until you delete the project or close your account.
- Anonymous / Guest Accounts Auto Clean-up: In accordance with data minimization policies and Firebase standards, anonymous accounts older than 30 days are automatically deleted. When auto clean-up is active, anonymous usage will no longer count towards usage or billing quotas. You can link your guest session to Google or GitHub at any time to preserve your projects permanently.
8Cookies & Local Storage
SnapFrame uses essential local storage keys to store your editor preferences (active language, dark/light theme, recent projects). We do not deploy third-party advertising cookies or cross-site tracking beacons.
9Contact & Inquiries
For privacy questions, data requests, or complaints, please reach out to our team:
Email: privacy@snapframe.store
EU Supervisory Authority: You have the right to lodge a complaint with your local European Data Protection Authority (DPA) if you believe our processing infringes the GDPR.