Who we are
Snaply ([Snaply legal entity — name, registration number and registered address]) runs Snaply Agent. We decide how your account data is used, so for that data we are responsible for it. For data about the people using our customers’ apps, the app’s company decides, and we process it for them under our DPA. If you use an app that uses Snaply, contact that company first: it controls your data.
Data about our customers
Account details you give us (name, work email, company), your team’s seats and roles, sign-in sessions (the device and browser used), support tickets, and the language you choose. We do not determine location from IP addresses. For billing, the payment processor you choose holds your card; we keep only its brand, last four digits and expiry, and your invoices.
Data about app users
For our customers we process: device details the SDK reports (operating system, app and SDK version, language, battery, network and VPN state, free storage and memory, text size, accessibility and appearance settings) and, unless the app turns it off, a per-install device identifier; what the app chooses to pass (its user ID, a name, a phone number); a short support code; app sessions; the consent log (each request, the prompt shown and its language, the decision, the time, the user label the app supplied, the device model, the agent and the country, with no IP address); and screenshots, saved live frames and recordings with any annotations, created only after the person on the device taps Allow. Live view is relayed through our servers in memory and is not stored unless an agent saves a frame or a recording. Our customers may add their own tags to a user.
Why we use it
To provide the service you signed up for (performance of our contract); to keep it secure and prevent abuse (our legitimate interest); to bill you and meet tax and accounting duties (legal obligation); and to send service emails. Product-news emails are optional and you can turn them off. We never sell personal data, never use it for advertising, and never train machine-learning models on captures.
Consent on the device
Nothing is captured until the person on the device taps Allow. A screenshot prompt covers one capture or, if the app is set that way, one call. Live view shows a red indicator for as long as it runs, and saving a frame or a recording notifies the device. Remote control needs its own, separate Allow and can be taken back at any moment. Declining is always possible and nothing is captured.
Cookies and browser storage
We set no cookies when you only visit the website, and we have no consent banner because we use no analytics, advertising or tracking cookies. After you sign in or choose a language we use these first-party cookies on snaplyagent.com: snaply_session (keeps you signed in to the dashboard and Agent console; 30 days; HttpOnly, Secure); snaply_staff (the same for Snaply staff; 7 days); snaply_device (a random identifier so a returning browser reuses one session record, never used to profile or fingerprint you; 365 days; created with a session and kept after sign-out); and snaply-lang (your language, set only when you choose one; 365 days). Local storage holds your theme (snaply-theme), the last workspace you opened (snaply-ws) and whether the onboarding card was shown (snaply-onboarded). Short-lived session storage, cleared when the tab closes, holds your language choice on the staff sign-in page, the billing email and company you type at checkout while you add a card, and one-time messages from email links (invitation, email change). We load no third-party scripts, fonts, analytics, error tracking, session replay or chat widgets. If a Stripe-family payment processor is connected, the card step loads Stripe’s scripts from js.stripe.com (with api.stripe.com and hooks.stripe.com) so Stripe can collect your card; otherwise no payment script loads. You can delete cookies and stored data in your browser at any time; you will then be signed out.
Who we share it with
Our sub-processors: Telecom Armenia OJSC (hosting) and Google Workspace (transactional email). The payment processor you choose at checkout receives the billing details it needs, as an independent party under its own terms. Authorities, only when the law requires it, and we push back on requests that are not lawful. A buyer or successor of our business, under the same commitments. We give customers 30 days’ notice before adding or changing a sub-processor. DNS and certificate providers (GoDaddy and Let’s Encrypt) see only our domain name and never customer personal data, so they are not sub-processors.
Where it is stored
The service is hosted in the Republic of Armenia. Captures, recordings and backups are stored encrypted at rest (AES-256-GCM for captures and recordings, GPG AES-256 for backups), and traffic between you and us is encrypted in transit (TLS 1.2+). When data must leave Armenia, for example to deliver email, we transfer it only where the law allows, with the safeguards it requires. Snaply does not store data in the Russian Federation and does not meet Russian data-localisation rules; do not use it to collect the personal data of Russian citizens where those rules apply.
How long we keep it
Captures and recordings: for the retention period your workspace chooses from those your plan offers (30, 90 or 365 days), then erased, with a deletion notice to your webhook. Consent-log entries: kept for the life of the workspace so you can prove consent. They hold the label your app supplied for the user, the device model, the agent, the prompt shown, the decision, the time and the country, and no capture and no IP address. A deletion request erases the user’s captures, recordings and device records and adds an “erased” entry to the log; the earlier entries stay, because they are the proof of consent and the log’s integrity chain depends on them. If you want them not to identify a person, have your app supply a label that does not, such as an internal ID. Account data: while the account exists; deleted from our live systems within 30 days when you close the account or ask us to. If we end your access for breach, it is kept until you ask, and no longer than 12 months. Backups: a nightly encrypted backup is kept for 14 days and then overwritten, so deleted data can remain in backups for up to 14 days; if we restore from a backup, we repeat the deletions made since. Logs: application logs are size-limited and cover days; security logs of connection attempts, which include IP addresses, are kept for up to 90 days. Invoices: as long as tax law requires.
Security and incidents
Per-workspace isolation, least-privilege access with audit logging, two-factor sign-in, a signed and tamper-evident consent log, and masking on the device before anything is sent. Snaply’s staff tools have no access to captures or recordings, and live view passes through our servers in memory without being stored or analysed; only a recording an agent starts after the person consented is stored. Only the infrastructure administrators who run the servers could technically reach them, and they do not do so except to operate the service. If a breach affects personal data we notify affected customers without undue delay, and the authority where the law requires it.
Your rights
You can ask to access, correct or delete your data, to restrict or object to its use, to receive a copy, and to withdraw consent at any time without affecting earlier processing. Customers can delete any app user’s data from the dashboard (Devices & users → Delete this user’s data). Write to privacy@snaplyagent.com; we answer within 30 days. You can also complain to the Personal Data Protection Agency of the Republic of Armenia or to the authority where you live. For app users’ data, we forward your request to the company responsible and help it respond.
Rules in your region
EU, EEA, UK and Switzerland: we rely on the lawful bases above; transfers to Armenia use the European Commission’s Standard Contractual Clauses, with the UK Addendum and the Swiss amendments. United States: we do not sell or share personal information, do not use it for targeted advertising or profiling, and process app users’ data as a service provider to the app’s company; residents of California and other states with privacy laws can use the rights above, and we will not treat anyone differently for doing so. Brazil, Canada, India, Singapore, Australia and other countries: the same rights and safeguards apply, and we answer within 30 days, or sooner where your law requires.
Children
Snaply is not directed at children. Customers must not use it on the device of a child who is below the age at which the law lets a child consent alone (13 to 16 depending on the country) without the consent of a parent or guardian.
Changes and contact
We tell account owners about meaningful changes to this policy before they take effect, and each person on an account accepts the new version at their next sign-in. Corrections that do not change meaning are marked in the version history. Questions or requests: privacy@snaplyagent.com.