Snappy ("we", "us", "the app") rates your photos and helps you keep the ones you love. This page explains what we
collect, why, and what control you have over it — in plain language, matched to what the app actually does.
1. The short version
- You can use Snappy without creating an account. We assign your browser/device an anonymous identifier so we
can enforce a free-usage limit.
- Photos you submit are sent to our scoring service to generate a rating. We don't keep them unless you
explicitly save a shot to My Shots.
- If you register or sign in with Google, we store your email so your subscription and saved shots follow
you across devices.
- We never see or store your card details — payments are handled entirely by Stripe.
- We don't run ads. We do use Firebase Analytics and Google Tag Manager to understand how the app and site
are used — see Sections 4 and 6.
- If you use our mobile app, we ask for permission to send you push notifications and store a device token
so we can deliver them — see Section 4.
2. Information we collect
| Data |
When |
Why |
| Photos / camera frames |
Every time you rate a photo or use live scoring |
Sent to our scoring backend to compute a rating. Not retained after scoring unless you save it to
My Shots. |
| Saved shots (My Shots) |
Only if you explicitly save a rated photo |
Stored so you can revisit or download your top picks (My shots). Tied to your account identity,
never to another user's. |
| Anonymous device identifier |
On first visit |
A random, signed token stored in your browser. Used to count free ratings and stop abuse — no name, email,
or device fingerprinting involved. |
| Email address |
Only if you register, log in, or sign in with Google |
Identifies your account so a subscription and saved shots carry over across devices and browsers. |
| Password |
Only if you register with email/password |
Stored as a salted PBKDF2-SHA256 hash (600,000 iterations) — we never store or can see your actual password.
|
| IP address |
Every request |
Hashed with a secret key before storage; used only to cap abuse from a single network, never linked back to
a real IP or shared. |
| Subscription status |
If you subscribe |
Your Stripe customer ID, subscription ID, and plan/status — enough to know you're entitled to unlimited
ratings. Your card number never touches our servers. |
| App preferences |
As you use the app |
Threshold, haptics, sound, and similar settings, stored locally in your browser (localStorage)
— never sent to us. |
3. Facial data, specifically
Every photo or camera frame you submit to Snappy is analyzed by our scoring model, which reads facial features
(things like framing, expression, and angle) to produce a numeric rating. This is "face data" under Apple's App
Store Guidelines, and we want to be explicit about how it's handled:
- What we collect: the photo or camera frame itself, and the numeric score our model derives
from it. We do not extract or store a separate biometric template, faceprint, or identity-matching vector — the
analysis exists only to produce a 0–10 aesthetic score for that single image.
- Processing: the image is sent to our own scoring backend (see Section 6) and run through our
in-house model. It is never sent to any third-party AI vendor, cloud vision API, or facial-recognition
service.
- Retention: if you don't save the shot, the image and any derived face data are discarded
immediately after scoring — we do not keep a copy or a log of the frame. If you explicitly save a shot to My
Shots, the image is retained (see Section 7) until you delete it or delete your account.
- Sharing: face data is never shared with, sold to, or processed by any third party. It stays
within our own infrastructure end-to-end.
- Deletion: you can delete any saved shot at any time from My Shots; deleting your account
removes all saved shots and any face data tied to it.
- Consent: the app asks for your explicit agreement to this face-data processing during
first-run onboarding, before any photo is scored.
4. Analytics & push notifications
Analytics. We use Firebase Analytics (a Google product) to understand how people use Snappy —
things like which screens are viewed and which features get used. This means:
- What's collected: product usage events such as sign-up, login, onboarding completion,
photo scoring (started/completed/failed), saving a shot, sharing, and purchases — plus automatic screen-view
events as you navigate the app.
- Account linkage: if you're signed in, we associate these events with your internal account
ID so we can see usage patterns per account. We do not send your name, email, or photos to Firebase
Analytics.
- No ad tracking: we've disabled Firebase's advertising-identifier (IDFA/ad ID) collection,
so this data is not used for ad targeting or cross-app tracking, and it isn't linked to your identity across
other companies' apps.
- On the web, this is delivered in part via Google Tag Manager, which we use to load and
manage the analytics script on this site — see Section 6.
Push notifications (mobile app). If you use the Snappy mobile app and grant notification
permission:
- We generate a device push token (via Firebase Cloud Messaging) and store it on our servers, tied to your
app installation, so we can deliver notifications to your device.
- You can turn notifications off at any time from your device's system settings; doing so stops delivery,
though we may retain the token until it's no longer valid or you uninstall the app.
5. What we don't do
- We don't run ads or ad-tracking scripts, and analytics data isn't used to target ads at you.
- We don't sell, rent, or share your data with data brokers.
- We don't store your password in plain text, ever.
- We don't store your payment card details — Stripe handles that entirely on its own PCI-compliant
infrastructure.
6. Cookies & local storage
Snappy doesn't use tracking cookies. It uses your browser's localStorage to remember your sign-in
tokens and app preferences on your own device. Clearing your browser's site data will sign you out and reset local
preferences; if you're signed in with an account, your subscription and saved shots are unaffected since they
live on our servers, not your device.
7. Third parties we rely on
- Stripe — processes payments and manages subscriptions. See Stripe's privacy policy.
- Google Sign-In — only if you choose to sign in with Google, to verify your identity. See Google's privacy policy.
- Firebase Analytics & Firebase Cloud Messaging (Google) — powers our in-app usage
analytics and push notification delivery, as described in Section 4. See Google's privacy policy.
- Google Tag Manager — loads and manages the analytics tag on this website. See Google's privacy policy.
- Our own scoring service — processes the photo you submit to produce a rating.
8. Data retention
Photos submitted for scoring are processed and discarded — we don't build a library of your images unless you
choose to save one to My Shots. Saved shots, account details, usage counters, and push notification tokens are
kept for as long as your account is active. If you want your account and its data deleted, contact us (below)
and we'll remove it.
9. Security
Traffic to Snappy is encrypted in transit (HTTPS). Passwords are hashed with PBKDF2-SHA256; session tokens are
short-lived, cryptographically signed JWTs paired with a revocable refresh token, so a stolen token stops working
shortly after and can be invalidated by logging out. Your saved-photo storage identifier is derived independently
from your billing identifier, so the two can't be cross-referenced from either value alone.
10. Children's privacy
Snappy is not directed at children under 13, and we don't knowingly collect information from them.
11. Your rights
You can ask us to access, correct, or delete the data tied to your account at any time. If you're in a region
with additional statutory rights (such as the EEA/UK's GDPR or California's CCPA), those rights apply to you as
well — reach out and we'll accommodate the request.
12. Changes to this policy
If we materially change how we handle your data, we'll update the "last updated" date above and, where
appropriate, notify you in the app.
13. Contact us
Questions about this policy or your data? Email [email protected].