SnapWhereBack to SnapWhere

Privacy Policy

Last updated: October 10, 2026

SnapWhere ("we", "us") operates https://snapwhere.app (the "Service") and is the data controller for the information described below. This policy explains what we collect, why we collect it, who else processes it, how long we keep it, and the rights you have — including the rights granted by the EU and UK General Data Protection Regulation (GDPR).

1. Who We Are

SnapWhere is an independent product operated from https://snapwhere.app. For any privacy question or rights request, write to support@snapwhere.app.

If you are in the EEA or the UK and you are not satisfied with how we handle your data, you can also complain to your national supervisory authority (in the UK, the Information Commissioner's Office).

2. Information We Collect

  • Photos and item data: the photos you take of drawers, boxes or objects, plus the item names, notes and tags you enter or confirm.
  • Device key: a random identifier stored in this browser's local storage. SnapWhere has no accounts, no logins and no passwords, so we never ask for your name.
  • Email address: only when you buy a license, so we can send you the license key and the receipt.
  • License and payment metadata: license key, plan and payment status. Card details go directly to our payment provider — we never see or store your full card number.
  • Usage data: pages visited, session duration, browser and device type, referring page, and country derived from your IP, collected with Umami, a cookieless anonymous analytics tool. We do not run session-recording or heatmap tools.
  • Technical logs: IP address, user agent and timestamps, kept by our hosting provider for security and troubleshooting.

3. How We Use Your Data

  • To provide, operate and improve the Service;
  • To recognize the items in your photos and return search results (see AI Processing);
  • To process payments and send transactional emails (receipts, license keys, service notices);
  • To keep the Service secure and prevent abuse;
  • To understand aggregate usage patterns. We do not sell your data, we do not build advertising profiles, and we do not use it for advertising.

4. Legal Basis for Processing (GDPR)

  • Contract (Art. 6(1)(b)): storing your photos, items and locations, running search, and delivering your license — this is the Service you asked for.
  • Legitimate interests (Art. 6(1)(f)): keeping the Service secure, preventing abuse, and measuring aggregate usage. We use cookieless, anonymous analytics and no advertising identifiers, so the impact on you is minimal.
  • Consent (Art. 6(1)(a)): for anything you give us voluntarily beyond what the Service needs (for example, when you email us). You can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): keeping payment and tax records for the period the law requires.
  • Sending a photo to the vision model is part of delivering the feature you triggered and rests on contract; it is additionally restricted by the processor terms described in section 5.

5. AI Processing

When you ask SnapWhere to identify a container (or to reverse-look-up a single object), that photo is transmitted through OpenRouter to a third-party vision model, which returns the list of items it sees.

Your photo is used only to produce that list for you. It is not used to train or fine-tune any model, it is not added to any dataset, and it is not published or sold.

Retention by our processors: OpenRouter and the underlying model provider may keep API request logs, which can include the image, for a limited period of up to 30 days, strictly for abuse detection, fraud prevention and troubleshooting, after which they are deleted. We cannot obtain a contractual zero-retention guarantee on the free model tier we currently use — if zero retention is a requirement for you, write to us and we will move your usage to a paid tier with contractual zero-retention terms.

No human being reviews your photos, except in the rare case where a processor investigates a suspected abuse incident under its own policy.

Processing location: the vision inference runs on infrastructure operated by OpenRouter and its model providers, which may be outside your country (see International Transfers).

6. Your Rights

How to exercise them: email support@snapwhere.app from the device you use SnapWhere on and include the device key shown in Settings. We answer within 30 days, and there is no charge unless a request is manifestly unfounded or excessive.

What we delete: containers, items, rooms, photos and the license activation for that key. What we keep: the payment record (amount, date, email, license key) for as long as tax and accounting rules require, because we cannot erase a completed financial transaction.

  • Access — get a copy of the data tied to your device key. Export it yourself in Settings, or ask us.
  • Rectification — edit item names, notes, tags, container names and rooms directly in the app at any time.
  • Portability — download everything in a machine-readable CSV (Settings → Export CSV).
  • Erasure — delete individual containers and their photos in the app, or ask us to delete everything tied to your device key.
  • Restriction and objection — ask us to pause processing while we review your request.
  • Withdraw consent — at any time, where processing is based on consent.
  • Complain — to your local supervisory authority (EEA) or the ICO (UK).

7. Sub-processors

We use a small set of vetted providers. Each one processes your data only on our instructions and under a data processing agreement where they offer one:

8. Data Retention & Deletion

  • Photos and items: kept until you delete them. Deleting a container removes its photo from storage right away, and from encrypted backups within 30 days.
  • Photos are private: they live in a private storage bucket and the app loads them only through short-lived signed URLs that expire after 15 minutes, issued after we verify the container belongs to your device key.
  • License and payment records: kept for the period tax and accounting law requires (typically 7 years), even after you delete your containers. They contain only email, license key, amount and date.
  • Server and request logs: kept by our hosting provider for up to 30 days.
  • We do not silently delete inactive data today: if you stop using SnapWhere, your data stays until you delete it or ask us to.

9. Cookies & Local Storage

Essential local storage: your random device key, kept in this browser so you stay connected to your containers.

Analytics: Umami runs cookieless and sets no cookies, stores no persistent identifier and does no cross-site tracking. It loads in production only.

We set no advertising cookies, we run no session-recording or heatmap scripts, and we do not track you across other websites. Because no non-essential cookies are used, no cookie banner is required.

10. International Data Transfers

Your data may be processed outside the country you live in, including in the United States, by the sub-processors listed above. Those transfers are covered by each provider's data processing agreement and, where applicable, the European Commission's Standard Contractual Clauses.

11. Security

All traffic is encrypted in transit (HTTPS). Photos are stored in a private bucket that is never publicly readable, and the app can only reach them through expiring signed URLs. Every database query is filtered by your device key, and the database grants no read access to anonymous clients. Access to production systems is limited to the people who operate SnapWhere.

If you believe you have found a security problem, email support@snapwhere.app and we will investigate.

12. Children

SnapWhere is not directed at children under 16, and we do not knowingly collect their data. If a child's data reaches us, write to us and we will delete it.

13. Changes

We may update this policy. Material changes will be announced on the site, and the date at the top always shows the current version.

14. Contact

Questions about this policy or your data: support@snapwhere.app