Legal
Privacy Policy
What the Snappington app and this website do with your data, in plain words.
The short version
- No telemetry. The app sends no usage data, statistics or analytics. There is no account and no sign-in.
- Your files stay on your PC, unless you upload them somewhere yourself. We never receive your captures, recordings or documents.
- The app goes online only for: an update check at start-up and once a day (you can turn it off), model downloads you agree to, services you connect yourself, and reports you choose to send.
- This website uses no cookies, no analytics and no third-party scripts. If you sign up for the beta, we keep your email address with our host until you ask us to remove it, and never sell it.
- We do not sell or share your personal information, and we do not use it for advertising.
- Questions, or want your data deleted? Write to hello@snappington.app.
This summary is here to help. The full policy below is what applies.
1. Who we are
Snappington is made and published by [OWNER LEGAL NAME], an individual based in [STATE], United States (“we”, “us”). There is no company behind it. We are responsible for the personal information described in this policy (in European terms, we are its “controller”).
Contact: hello@snappington.app, or by post to [MAILING ADDRESS].
This policy covers the Snappington desktop app for Windows during its free public beta (the “app”) and the website at snappington.app (the “site”). It does not cover services you connect to the app yourself, such as an AI provider or an upload destination; their own policies apply to them.
2. What we receive, and what never leaves your PC
We only ever receive four things, and only in the situations described in this policy:
- A problem or crash report, if you choose to send one from the app (section 4.2).
- Your email address and optional answer, if you sign up for the beta on the site (section 5.2).
- Any email you send us.
- The technical data every web request carries, such as your IP address, which our hosting provider handles for us (section 5.1).
Everything else stays on your PC, or goes only where you send it, and is under your control. That includes your captures, recordings, step guides, library, search index, settings, the app’s logs and crash files, and any passwords or keys you enter. Section 3 lists what the app keeps on your PC.
3. What the app keeps on your PC
The app stores these on your computer. We cannot see them. Uninstalling the app does not delete your captures; you can delete them yourself at any time.
- Your captures and projects (
.snptimages and step guides,.snpvvideo projects, and exports), in your library folder (by defaultPictures\Snappington) or wherever you save them. - Information inside your files. A
.snptfile records when it was captured, what kind of capture it was, the display scale, the version of Windows, and, when known, the source app, window title and web address, plus any text recognised in it. It does not record your user name, your computer’s name or a device ID. A.snpvvideo project keeps the original recording (masks apply to exports, not to the project), the recording’s event log and a copy of your desktop wallpaper. Keep this in mind before sending someone a project file rather than an export. - Step capture records the mouse clicks you make while a session is running and not paused: the name and type of the thing you clicked, the app, the window title and, in Chromium-based browsers, the web address. It never stores what you type into a field; if you turn on typed-text placeholders, it stores only a placeholder such as
{{Text 1}}and the field’s label. - Screen recording. While you record, the app notes your mouse movements, clicks and scrolls, the cursor’s shape, and the window in front, so the video editor can place zooms and draw the cursor. By default it only notes window titles and on-screen element names inside the area you record; a setting lets it log the whole desktop. The microphone, system audio and webcam are used only when you turn them on.
- Keystrokes. Key recording is off by default. If you turn it on, “Shortcuts” records keyboard shortcuts and how many keys you typed, but not which; “All keys” also records typed text. Password fields, terminal windows and the Windows sign-in prompt are never recorded. The key log stays in the recording’s project on your PC and is never written into exports.
- Text recognition (Grab Text) uses the text recognition built into Windows, on your PC. The recognised text is stored with the file and in the library’s search index on your PC.
- Smart Redact, Remove Background, captions and noise removal run on your PC. Your images, audio and text are not sent anywhere to do this.
- Settings, in your Windows user profile, including the names of accounts you have connected (for example, the email address of a connected Google account), your chosen devices and presets. A few display preferences are kept in the app’s own browser storage.
- Passwords, tokens and API keys for services you connect, encrypted with your Windows account (Windows Data Protection), so another Windows user cannot read them. In the rare case that Windows Data Protection is not working on your PC, the sign-in details for upload destinations are kept unencrypted in the settings file instead.
- Logs: the app’s diagnostic log (at most about 4 MB, older entries replaced), which includes file and folder paths and the links of files you upload; a list of AI requests (time, service, size and cost; never the content or your key); and a list of what AI assistants asked the app to do. You can view and clear the AI lists in Settings, and open the log folder from Settings.
- Crash files, if the app crashes. They stay on your PC unless you choose to send one (section 4.2).
- The clipboard. By default, a new capture is copied to the clipboard. If you use Windows clipboard history or cloud clipboard, Windows may keep or sync a copy under Microsoft’s terms.
If your Windows profile roams between PCs, or OneDrive backs up your Pictures folder, Windows may copy these files elsewhere. That is controlled by Windows and your organisation or Microsoft settings, not by Snappington.
4. When the app goes online
The app has no telemetry: it does not send usage data, statistics, analytics or advertising identifiers anywhere, and there is no account. It connects to the internet only in the cases below. Every connection is encrypted (HTTPS), except connections you set up to a server on your own PC.
| What | Sent to | When | Your control |
|---|---|---|---|
| Update check: app version, update channel, Windows version and processor type | GitHub | At start-up and every 24 hours | On by default; turn it off in Settings |
| Problem or crash report (you see all of it first) | Us (via Cloudflare) | Only when you press Send | Off unless you send one |
| Remove Background model download | GitHub | First use, after you agree | Optional feature |
| Speech model download for captions | Hugging Face | First use, after you agree | Optional feature |
| Step details and small image crops, or guide text | The AI service you chose, with your own key | Only when you run an AI action | Off by default |
| Files you upload, and sign-in | Slack, Google Drive, OneDrive or your own server | When you connect or upload, or on each capture with a preset you set to upload | Off until you set one up |
4.1 Update check
To tell you when a new beta build is available, the app asks our release page on GitHub (github.com/flubbid/snappington-releases) for the latest version, at start-up and then every 24 hours. The request includes the app’s version, its update channel (for example “beta”), your Windows version and your processor type (for example x64). Like any web request, it also reveals your IP address to GitHub. It contains no identifier for you or your PC, and we do not receive it: GitHub handles it under the GitHub Privacy Statement. Update files are downloaded from GitHub as well.
You can turn the update check off in Settings. If you do, you will need to check the site for new builds yourself, which matters because each beta build has an end date (see the Beta Terms).
4.2 Problem reports and crash reports
If the app crashes, it saves a crash file on your PC. Nothing is sent automatically. When you choose “Report a problem”, or accept the app’s offer to send a crash report, it shows you the complete report first. Only if you press Send does it go to us, at snappington.app/api/report. A report contains:
- the app version, your Windows version and processor type (always);
- what you write in the description;
- your email address, only if you add it so we can reply;
- an excerpt of the app’s log, only if you include it (at most 200 KB, with your home folder paths and anything that looks like a password or key removed first);
- the crash details, only if you include them.
We use reports only to find and fix problems and to reply to you. They are stored with our hosting provider, Cloudflare, and deleted automatically after 180 days. Your IP address is not stored with the report. To stop abuse, the server counts reports per IP address for about an hour, keeping only a scrambled (hashed) form of the address. A log excerpt can still contain file names, links to files you uploaded and the names of services you used, so read it before you send it, or leave it out. Please do not put anything sensitive in the description. If you want a report deleted sooner, email us with the date you sent it and, if you gave one, the email address you used.
4.3 Optional model downloads
Two features need a model file the first time you use them. The app asks before downloading, checks the file’s fingerprint and keeps it on your PC; after that the feature works offline.
- Remove Background: a model of about 5 MB, from GitHub (the open-source rembg project’s release page).
- Captions: a speech-recognition model of about 75–490 MB depending on the size you pick, from Hugging Face. Your audio is transcribed on your PC and is never uploaded.
The download request reveals your IP address to GitHub or Hugging Face, which handle it under their own privacy policies. It contains nothing about you or your files.
4.4 AI with your own key
The app can use an AI model to rewrite, translate or tidy up a step guide. This is off by default and works only with your own API key for Anthropic or for a service that works like OpenAI’s (such as OpenAI, OpenRouter, or a model running on your own PC).
- Nothing from your documents is sent until you turn AI on and agree to a notice that names the service. By default the app also asks before the first run in each document, showing what it will send. (The Test button in Settings sends one short message with no document data, to check your key works.)
- What is sent, only when you run an action: for each step, the details step capture recorded (the name and type of what you clicked, the app, the window title and the web address, but never what you typed); for Rewrite, a small crop around the clicked element, with any redactions on the page already filled in; for Translate and Clean up, the guide’s text.
- What is never sent: steps you have redacted, whole screenshots, and your key to anyone but the service it belongs to.
- Your key is stored encrypted on your PC. Requests go straight from your PC to the service; they do not pass through us, and we never see your key, your data or the answers.
What the AI service does with your data, including whether it keeps it or uses it for training, is governed by your agreement with that service and its privacy policy, not by us.
4.5 Upload destinations
You can connect Slack, Google Drive, OneDrive or your own web server as a place to send captures. Nothing is uploaded until you set one up and send something to it. If you add a destination to a capture preset, every capture you take with that preset is uploaded automatically. Links to uploaded files may be viewable by anyone who has them, depending on the link setting you choose (for OneDrive, the default is “Anyone with the link”). Signing in happens on the service’s own page, in your browser or with a code, and Snappington only receives the access it asks for (for Google Drive and OneDrive, access to the files Snappington creates or its own folder). The tokens are stored encrypted on your PC. Uploads go straight from your PC to that service, which handles your files under its own terms and privacy policy. When you disconnect, the app forgets the tokens and, where the service allows it (Google), withdraws the sign-in.
4.6 AI assistants on your PC (MCP)
You can let AI apps on your PC, such as Claude Desktop, VS Code or Cursor, use Snappington to take captures, read step guides and export files. This is off by default. It works only on your PC, through a connection that only programs running as your Windows user can open; it is not reachable over the network. An assistant you connect can see the titles of your open windows, take captures and read your step guides and their recognised text; steps you have redacted are withheld, and images are rendered with redactions applied. If the app is not running when an assistant needs it, the assistant can start it. When you press Connect for an assistant, the app adds an entry to that assistant’s settings file, after showing you the change and keeping a backup. Everything an assistant asks for is listed in Settings. What the assistant then does with what it receives, including sending it to its own AI service, is governed by that assistant’s terms and privacy policy.
4.7 Windows and Microsoft
The app’s windows are drawn by Microsoft Edge WebView2, a Microsoft component that comes with Windows 11. If your PC does not have it, the installer downloads it from Microsoft. Microsoft keeps WebView2 up to date under Microsoft’s own terms. Windows features such as SmartScreen, clipboard history and OneDrive backup of your folders are controlled by Windows and your Microsoft settings, not by Snappington.
4.8 Links
When you click a link in the app, such as a help page or a sign-in page, it opens in your web browser, and that website’s own policy applies.
5. This website
- No cookies. The site sets none.
- No analytics, no tracking pixels, no advertising, no fingerprinting.
- No third-party requests. Fonts, images and scripts all come from this site.
- One preference, in your browser. If you pick light or dark with the theme button, your browser remembers it in its local storage. It is never sent to us.
5.1 Hosting
The site runs on Cloudflare Pages. To deliver pages and protect the site from attacks, Cloudflare processes the technical data every web request carries: your IP address, the page requested, the time, and your browser’s user-agent and referrer. Cloudflare does this for us as our service provider under its data processing terms. We do not use this data to identify or profile visitors, and we do not turn on long-term storage of request logs. Cloudflare may keep limited security and operational data about requests for a short time, as its privacy policy describes.
5.2 Beta sign-up
If you sign up for the beta, we store:
- your email address;
- your answer to “what do you use screenshots for?”, if you give one;
- that you ticked the box agreeing to be emailed, and when;
- which form you used on the site (for example, the beta page or the download page).
We use it only to email you about the beta and the launch of Snappington, and to understand, in general terms, what people use screenshots for. It is stored with Cloudflare. We keep it until you ask us to remove it, and delete it at the latest [12 months] after the paid version launches. Each email we send will say how to leave the list. We never sell it. We do not store your IP address, browser or country with it. To stop abuse, the form counts sign-ups per IP address for about an hour, keeping only a scrambled (hashed) form of the address.
5.3 Emails you send us
Mail to hello@snappington.app is forwarded by Cloudflare Email Routing, which does not store it, to our mailbox at [EMAIL PROVIDER]. We keep your message and our reply for as long as we need them to deal with your request, and then for up to [24 months] in case you write again.
5.4 Do Not Track and Global Privacy Control
We do not track visitors across websites, and no one else tracks you on this site, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. If your browser sends one, we treat it as a request to opt out of any sale or sharing of your personal information, which we do not do anyway.
6. Why we use your information, and on what basis
Some privacy laws, including the GDPR in Europe and the UK GDPR, ask us to name a legal basis for each use.
| Information | Why | Legal basis | How long we keep it |
|---|---|---|---|
| Problem and crash reports | Fix bugs; reply to you | Your consent, given when you press Send | 180 days, then deleted automatically |
| Beta sign-up | Email you about the beta and launch | Your consent, given when you tick the box | Until you ask us to remove it; at the latest [12 months] after the paid launch |
| Emails you send us | Answer you | Our legitimate interest in answering, or steps you ask us to take | As long as needed, then up to [24 months] |
| Hashed IP counters | Stop spam and abuse | Our legitimate interest in keeping the service working | About one hour |
| Web request data (Cloudflare) | Deliver and protect the site | Our legitimate interest in running a secure site | Short-term, as Cloudflare’s policy describes |
| Update check (sent to GitHub) | Tell you about new builds and fixes | Our legitimate interest in keeping the app up to date and secure; you can turn it off | We receive nothing; GitHub’s policy applies |
We may also keep or disclose information when the law requires it, or to establish, exercise or defend legal claims. You can withdraw consent at any time by writing to us; this does not affect what we did before.
We do not use your information for advertising, we do not build profiles of you, and we make no automated decisions about you that have legal or similarly significant effects.
7. Who we share it with
We do not sell your personal information, and we do not share it for cross-context behavioural advertising (in the words of California law). We have not done so in the past 12 months.
We use these service providers, who handle data for us under contract and only on our instructions:
- Cloudflare, Inc. (United States): hosting the site, storing reports and sign-ups, and forwarding email.
- [EMAIL PROVIDER]: our email mailbox.
GitHub (owned by Microsoft) and Hugging Face receive requests directly from your PC when the app checks for updates or downloads a model. They are not our service providers for that; each handles those requests under its own privacy policy.
We may also disclose information if the law requires it, to protect people’s safety or our rights, or to someone who takes over Snappington, who would have to honour this policy. We would tell you before your information became subject to a different policy.
8. International transfers
We are based in the United States, and Cloudflare, GitHub and Hugging Face process data in the United States and in other countries. Cloudflare stores reports and sign-ups on its global network. If you are in the European Economic Area, the United Kingdom or Switzerland, your information will therefore be processed outside your country. Where the law requires a safeguard for this, Cloudflare’s data processing terms rely on the EU–US Data Privacy Framework and its UK and Swiss extensions, and on the European Commission’s Standard Contractual Clauses with the UK addendum. You can ask us for more information about these safeguards.
9. Your rights
Wherever you live, you can ask us to:
- tell you what personal information we hold about you and give you a copy;
- correct it;
- delete it;
- stop emailing you.
Depending on where you live, you may have further rights. In the EEA, the UK and Switzerland, you may also object to our use of your information, ask us to restrict it, ask for it in a portable format, withdraw consent at any time, and complain to your data protection authority (in the UK, the Information Commissioner’s Office). In US states with privacy laws, including California, you may also have the right to opt out of the sale or sharing of personal information and of targeted advertising and profiling (we do none of these), to appeal a decision we make about your request, and not to be treated differently for using your rights.
How to ask: email hello@snappington.app. We may ask you to confirm the request from the email address it concerns, so we give information only to the right person. Someone you authorise may ask for you if they can show that authority. We will answer within one month, or within the shorter time your local law sets; if a request is complex we may take longer where the law allows and will tell you why. If we turn down a request, we will explain why and how to appeal: reply to our answer, and we will reconsider it within the time your law allows. If you are not satisfied with the appeal, you can contact your state attorney general or data protection authority.
Because we do not have your captures, files, settings or logs, we cannot access, change or delete them for you. You control them directly on your PC.
10. California residents
This section adds the notices California law asks for. In the past 12 months we have collected these categories of personal information, from you directly or from your device:
- Identifiers: your email address (sign-up, reports, emails) and IP address (handled by Cloudflare to deliver the site and its forms).
- Internet or network activity: web request data, such as the page you asked for and your browser type.
- Other information you choose to give us: what you write in a sign-up, report or email, and the technical details in a report.
We use them for the purposes in section 6, disclose them only to the service providers in section 7, and keep them for the periods in section 6. We do not sell or share personal information, we do not use or disclose sensitive personal information to infer anything about you, and we do not knowingly sell or share the personal information of anyone under 16. We do not disclose personal information to third parties for their own direct marketing. To use your rights, see section 9.
11. Children
Snappington and this site are not directed at children. We do not knowingly collect personal information from children under 13, or from anyone under the age at which they can agree to it without a parent where they live (up to 16 in some European countries). If you believe a child has sent us personal information, email us and we will delete it.
12. Security
We keep what we hold to a minimum. Connections to the site, to our report service and from the app are encrypted. Reports and sign-ups are stored with Cloudflare, where only we can reach them. On your PC, the app encrypts passwords, tokens and API keys with your Windows account, and it removes your home folder paths and anything that looks like a password or key from a log before you are asked whether to send it.
No system is perfectly secure. If a breach affects your personal information, we will tell you and the authorities as the law requires.
13. Changes to this policy
When the app or the site changes what it does with data, for example when the paid version adds a licence check, we will update this policy before the change ships, and change the effective date at the top. For significant changes we will also say so in the app’s release notes and, if you signed up for the beta, by email. If we want to use information we already hold in a new way that needs your consent, we will ask first.
14. Contact
[OWNER LEGAL NAME]
[MAILING ADDRESS]
hello@snappington.app
Draft — pending legal review. Effective date: [DATE].