Back to home
Legal

Privacy Policy

How Snaptryx collects, uses and protects your data — made in Germany and GDPR-minded.

Last updated: 19 July 2026

01Data controller

The controller responsible for the processing of personal data described here is Snaptryx, operated by Vitalii Sili, Allgäuer Str. 92, 81475 München, Germany (see our Imprint for full details).

For any question about this policy or your personal data, contact us at privacy@snaptryx.com. We have not appointed a Data Protection Officer, as we do not meet the criteria in Art. 37 GDPR; privacy enquiries are handled by the controller directly.

02Data we collect

Account data: your name, email address and hashed password; your organisation(s) and role; and, for paid plans, billing details processed by our payment provider (we do not store full card numbers).

Usage data: the captures, PDFs, visual-diff runs and monitors you create, including the URLs you submit and the resulting screenshots and documents; render metadata (timestamps, status, sizes); API keys you generate (stored only as a hash); and product events used to operate and secure the service.

Technical data: IP address, device/browser information, and log data generated when you use the service or its API — used for security, rate-limiting and debugging.

Content you submit: when you ask us to capture or monitor a URL, we fetch that page and store the resulting image/PDF on your behalf. You are responsible for ensuring you are entitled to capture the content you submit.

03How we use your data

To provide the service: authenticate you, render and store captures/PDFs, run visual diffs and monitors, and deliver results and notifications you configure.

To bill and account for usage: meter renders, apply plan limits, and process subscription payments and invoices.

To secure and improve the platform: detect and prevent abuse, enforce rate limits and quotas, diagnose errors, and maintain reliability.

To communicate with you: transactional email (confirmations, password resets, billing, and service notices) and, only where permitted, product updates.

05Cookies & analytics

The application uses strictly necessary cookies to keep you signed in (authentication tokens) and to remember basic preferences such as language and theme. These are required for the service to function.

The public demo on this website verifies that requests come from a real browser using a bot-protection challenge, which may set a short-lived token for that purpose.

For usage statistics we operate our own self-hosted instance of Matomo (matomo.laborune.com); your data is not shared with any third-party analytics provider. Matomo is configured in a privacy-preserving, cookieless mode: it sets no tracking cookies, anonymises your IP address before storage, and honours your browser’s “Do Not Track” setting (when enabled, no analytics data is collected). Because the processing is anonymised, cookieless and used only to understand aggregate traffic and improve the service, it is carried out on the basis of our legitimate interests (Art. 6(1)(f) GDPR) and does not require a consent banner.

If you are signed in to the portal, an internal, non-identifying account reference may be associated with your analytics activity so that we can measure the overall funnel from visit to sign-up to subscription. We do not use your name or email address for analytics. You can opt out of analytics at any time by enabling “Do Not Track” in your browser.

06Processors & sub-processors

We use a small number of vetted providers who process data on our behalf under data processing agreements. As of the “last updated” date these include: our payment provider Stripe (subscription billing and payment processing); our email provider Brevo (transactional email delivery); Cloudflare (the Turnstile bot-protection challenge on our contact form, which receives your IP address and browser information when the challenge loads); and self-hosted infrastructure operated by us in Germany for application hosting and object storage.

We keep this list current and require each processor to provide appropriate safeguards. A full, up-to-date sub-processor list is available on request at privacy@snaptryx.com.

07International transfers

Snaptryx is made in Germany and operated on German infrastructure; we keep personal data in Germany (within the EU/EEA).

Where a processor (for example, a payment or email provider) processes data outside the EEA, that transfer is protected by an appropriate safeguard under Chapter V GDPR — typically the European Commission’s Standard Contractual Clauses and, where relevant, supplementary measures.

08Data retention

Captured screenshots in your Library are retained according to your plan’s retention window and then automatically deleted; visual-diff baselines are retained until you delete the project, because a baseline may be compared months later.

Account data is retained for as long as your account is active. After you delete your account or organisation, we remove or anonymise associated data within a reasonable period, except where we must retain certain records (for example, invoices) to meet legal obligations.

Server logs are retained for a limited period for security and debugging and then rotated out.

09Your rights

Under the GDPR you have the right to access your personal data; to have inaccurate data rectified; to have data erased; to restrict or object to processing; to data portability; and, where processing is based on consent, to withdraw that consent at any time.

Many of these you can exercise directly in the app (edit your profile, delete captures, or delete your organisation). For anything else, contact privacy@snaptryx.com and we will respond within the statutory time limits.

10Security

We apply technical and organisational measures appropriate to the risk: encryption in transit (HTTPS), access controls and least-privilege internal access, encryption of sensitive secrets at rest, hashed passwords and API keys, and protections against server-side request forgery when fetching the URLs you submit.

No system is perfectly secure, but we work continuously to protect your data and to detect and respond to incidents.

11Contact & complaints

For any privacy request or question, email privacy@snaptryx.com.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. For us that authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.

Questions about this page? Email hello@snaptryx.com.