Privacy Policy
Last updated: 25 July 2026
This policy explains what personal data SnapAI Editor ("we", "us") collects, why, and the rights you have over it. It applies to the SnapAI Editor website and service. We comply with the Australian Privacy Act 1988, and for users in the European Economic Area and United Kingdom, the GDPR and UK GDPR.
1. What we collect
Account data: your name, email address and hashed password (or Google account identifier if you sign in with Google). Content: images you upload and the edited results, plus the text prompts you submit. Billing data: your subscription status and payment history — card details are held by Stripe, our payment processor, and never touch our servers. Usage data: credit transactions, edit counts, login streaks, and standard server logs (IP address, browser type, timestamps) kept for security and rate limiting.
2. Why we process it
We process your data to provide the service (performance of contract): storing your account, running the AI edits you request, tracking credits and delivering results. We process billing data to charge for subscriptions and comply with tax law (legal obligation). We process security logs to prevent abuse (legitimate interest). We send transactional email — receipts, password resets, low-credit warnings — as part of operating your account. We do not sell your personal data, and we do not use your images to train AI models.
3. AI processing
When you request an edit, your image and prompt are transmitted to our AI processing partners (Stability AI and/or Clipdrop by Jasper) solely to generate your result. These providers process the data as our service providers under their API terms and do not retain your images for training under the API tiers we use. If a prompt or image violates a provider's content policy, the request is rejected and your credits refunded.
4. Storage and retention
Images and account data are stored with Supabase (hosted on AWS). Your edits remain stored until you delete them or your account. Server logs are retained for up to 90 days. When you delete your account, your profile, images, edit history and credit ledger are permanently deleted; invoice records are retained only as long as tax law requires.
5. Your rights
You can access and export all of your data at any time from Settings → Privacy → "Download my data" (GDPR Art. 15 & 20). You can correct your name in Settings, delete individual edits from your dashboard, and delete your entire account and data from Settings → Privacy (GDPR Art. 16 & 17). You may also object to processing or lodge a complaint with your supervisory authority — in Australia, the OAIC; in the EU, your national data protection authority.
6. Cookies and local storage
We use browser local storage for one purpose only: keeping you logged in (your session tokens) and remembering a referral code you arrived with. We set no advertising or third-party tracking cookies.
7. International transfers
Our infrastructure providers (Supabase/AWS, Stripe, Resend, Stability AI, Clipdrop) may process data outside your country. Where GDPR applies, transfers rely on adequacy decisions or Standard Contractual Clauses maintained by those providers.
8. Security
Passwords are hashed by Supabase Auth (bcrypt). All traffic is encrypted in transit (TLS). Database access is protected by row-level security and service-role isolation. Payment data is handled exclusively by Stripe, a PCI-DSS Level 1 provider.
9. Children
SnapAI Editor is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
10. Changes and contact
We will notify account holders by email of material changes to this policy. Questions or requests: contact us at the support email listed in your account emails, and we will respond within 30 days.