The short version. Your phone reads the text in a screenshot first. The screenshot (or PDF) and that text are then sent securely to our server, which asks Google's Gemini AI to explain it and saves the result to your history. Your screenshot is deleted as soon as the analysis is finished — that is the default, and you do not have to do anything to get it. The explanation stays in your history; the picture does not. If you would rather keep the file, Settings → Data retention lets you keep it for 7, 30, 90 or 365 days instead. On a paid plan you can also keep an individual original: after a scan we ask, and if you say yes we convert it, encrypt it and keep it until you delete it — Pro includes 1 GB, Business 2 GB, and you can buy more. On the free plan we never keep it. We never sell your data, and your screenshots are not used to train AI models unless you switch that on. You can delete any analysis, all stored screenshots, or your whole account at any time. If you are on Snap AI Business Pro and connect a mailbox, our email provider Data2Sales AI holds that mailbox's app password (encrypted) and runs the mailbox for us, and we keep a copy of the last 30 days of its recent messages — removing the connection deletes both at once. WhatsApp messages are different: they are kept on your phone, not on our servers. We hold one only until your phone collects it, at most 24 hours, and then it is gone — which is why a new phone or a reinstall starts from the last 24 hours. While Snap AI Business Pro is active, Data2Sales AI is also given your profile details (name, contact email, WhatsApp number, country and address, profile photo) so they can identify and support you; nothing of that is sent if you are not on that plan. If you use Money & Savings, the expenses, bills, budgets, goals and statement transactions you keep are held on your account and nowhere else — account and card numbers are stored masked to the last four digits, any statement we hold is encrypted with a key of its own and deleted as soon as its numbers are read, and any receipt, bill or statement you do choose to keep is encrypted on our storage with its own key so that it can only be opened through your own signed-in session, and we never read your email for receipts unless you switch that on yourself.
1. Who we are
This policy covers the SnapAI mobile app (Android package org.reviewindia.snapai) and the service behind it at snapai.reviewindia.org. SnapAI is developed and operated by Review India ("we", "us"). You can reach us at sohosoftech@gmail.com.
2. What we collect
Your account
- An account is created automatically the first time you open the app, so you can try it without signing up. It has no name, email or phone number until you add one. To create it, the app sends a random identifier it generated for this installation; our server does not store it. It is not a hardware or advertising identifier.
- Email sign-in: your email address. We email you a six-digit code to prove it is yours.
- Google sign-in: the name and email address on your Google account, which Google shares with us when you choose to sign in.
- Sign in with Apple (iOS only): the email address (which may be an Apple private relay address) and name Apple shares with us.
- WhatsApp sign-in: your mobile number. We send a six-digit code to it on WhatsApp.
- Your profile, once you sign in: when you sign in, we ask for your name, country, postal address, a contact email and your WhatsApp number, and a profile photo, before you continue. They are used for your account and your business profile. Whichever of the email or number you signed in with is already verified and cannot be changed there; the other one is kept as a contact detail only and is never used to sign in. Your postal address is stored encrypted. You can change these details at any time in Profile → Edit profile details. If you never sign in, we do not ask for any of them.
- Your profile photo: the photo you choose, from your camera or your gallery. The app crops it to a square and re-encodes it on your phone, which removes its location and other hidden metadata, and our server re-encodes it again as a small image. It can be seen by anyone who has its link, and is shown in the app next to your name. If you signed in with Google or Apple, the picture on that account is used until you choose another.
- Settings saved to your account: your language, whether to keep screenshots at all (they are deleted straight after analysis unless you choose otherwise), whether you want news and updates from us, and your choice about using screenshots to improve SnapAI.
What you choose to analyse
- Screenshots and photos you pick from your gallery, take with the camera or open from your files. Before upload the app re-encodes each image as a new JPEG from its pixels, which removes EXIF metadata such as GPS location and camera details.
- PDF documents you pick (up to 10 MB and 20 pages). PDFs are uploaded exactly as they are, including any metadata inside the file.
- Text read from the image on your phone. This is sent together with the image so the analysis is more accurate. It is used for that analysis and is not stored on our servers.
Anything visible in what you upload reaches us. Screenshots often contain sensitive information, such as bank details, messages, addresses or ID numbers, so please only analyse what you are comfortable sending.
Originals you choose to keep
By default your screenshot or PDF is deleted the moment the analysis is finished, and on the free plan that always happens. If you are on Pro or Business, we ask after each scan whether you would like to keep that one file. If you say yes:
- the image is converted to WebP (a PDF stays a PDF), which also removes any remaining metadata;
- it is encrypted on our servers before it is written — a fresh key for every file, itself protected by our application key — and given a random file name that says nothing about what is in it;
- it counts towards your storage allowance: 1 GB with Pro, 2 GB with Business, plus any extra storage you buy;
- it is kept until you delete it. There is no clock on it.
You can see everything you have kept, and delete one file, several or all of them, at Profile → Storage. Deleting the analysis deletes its original too, and deleting your account deletes every one of them along with the keys that open them. We only ever show you a kept file through a link that expires in five minutes; there is no public address for it.
You can change your mind for good in Settings → Data retention: “Always keep originals”, “Ask each time” (the default) or “Never keep originals”. With “Ask each time”, a file you do not answer about is deleted automatically after 30 minutes.
If your plan or your extra storage ends, your kept files become read-only straight away — you can still open and delete them — and are deleted 30 days later. We warn you 14 days and 3 days before that, in the app and by notification. We never delete a kept file without warning you first, and a failed payment on its own never starts that countdown.
Results and history
- The result of each analysis: its title, summary, category, risk level, and the details extracted (such as dates, amounts, names, links and suggested next steps), plus which tool you used, the language and the time.
- Whether you saved an analysis, and your "Was this helpful?" ratings.
- Searches you make in your history are sent to our server to find matching analyses. They are not stored.
- Reminders you set from a result are scheduled on your phone. A copy (title, note, time and the analysis it came from) is also saved to your account.
- Feedback you send from Settings: your rating, your message and the app version.
Purchases
SnapAI Pro is sold through Google Play (or the App Store on iOS). We never see your card or bank details. Our purchase processor, RevenueCat, tells our server your subscription status, product, period, renewal and expiry dates and the store's transaction events. RevenueCat receives your SnapAI account number (not your name, email or phone) and the name of the screen from which you opened the upgrade page.
Usage and technical data
- How many analyses you have used in total and any bonus analyses (from watching an ad or sharing the app), so we can apply the free plan's limit.
- A device identifier, so the free sign-up credits are given only once per phone, even when the app is uninstalled and reinstalled. On Android this is the app's Android ID, which is specific to SnapAI on your phone and is not your advertising ID; on iPhone it is a random identifier kept in your phone's keychain. We do not store the identifier itself: we store only a one-way, keyed hash of it, together with a record that the phone's free credits were given out and counters of bonus credits earned on it. It is used only for this (fraud prevention and app functionality), is never shown in the app, and is not shared with anyone. Because this record holds no personal data and is not linked to your name, email or phone number, it is kept when you delete your account; otherwise deleting an account would give the free credits back.
- The app version, sent with each request.
- Your IP address. It is used for security and rate limiting, and is stored briefly with a sign-in code request until that code is used or expires.
- Server logs recording technical events (for example your account number, the category of an analysis, how long it took and error codes). Logs do not contain your screenshots, the text read from them or your results.
Push notification tokens
If you allow notifications, the app registers with Firebase Cloud Messaging (Google) and sends us the token that names your installation, together with your platform, app version and language, so that we can deliver a notification to it. Your reminders are still local notifications created on your own phone and need none of this.
The token is a delivery address for one app on one phone, not an identifier we can read anything else from. It is kept only while it works: it is replaced when Firebase rotates it, it is moved with you if you sign in or out, it is deleted if Firebase tells us it is dead, and it goes with your account when you delete it. You can turn notifications off in your phone's settings or in the app at any time, and nothing is sent to you afterwards.
What we do not collect
We do not collect your contacts, your location, your calendar, your call log or recordings of your voice. SnapAI has no analytics or crash-reporting SDK.
3. What stays on your phone
- Text recognition (OCR) runs on your phone using Google ML Kit's on-device recogniser. The text it reads is kept, encrypted, on your phone for your 50 most recent analyses so you can copy it, and is removed when you delete that analysis or sign out.
- Voice search uses your phone's own speech recogniser. SnapAI never receives or stores audio; only the recognised words go into the search box. Your phone's speech service (for example Google's) handles the audio under its own privacy terms.
- Reminders and the "call from Anny" alert are scheduled and read aloud on your phone with its text-to-speech engine.
- Add to calendar opens your own calendar app with the event filled in. SnapAI cannot read your calendar.
- Exports (a result as PDF, your history as CSV) are created on your phone and shared only where you choose.
- Your theme, home screen layout and a copy of recent history for offline use.
4. How we use it
- To analyse what you send and show you the result and your history.
- To run your account: sign-in, settings, reminders, the free plan's limit and your subscription.
- To keep the service secure and working: preventing abuse, rate limiting, investigating errors and answering support requests.
- To contact you about your account or a request you made.
We do not sell your personal data, and we do not use your screenshots or results for advertising.
5. AI processing
Analyses are performed by Google's Gemini API. Our server, not your phone, sends Google the image or PDF, the text your phone read from it, the tool you chose and your language, and receives the result. Google processes this content to provide the analysis to us under its Gemini API terms, and may keep it for a limited period, for example to detect abuse.
AI can make mistakes. Results are information to help you, not professional advice; see our Terms of Service.
Price comparison (Google Search)
If you ask SnapAI to find a better price for a product you scanned, our server sends Google's Gemini API, with Google Search, only the product details already read from your screenshot (brand, model, variant, the listed price and shop) and the country to search in. Your screenshot is not sent again, and nothing that identifies you is sent. Google uses the prompt and the result to provide the search and may keep them for a limited period for debugging and abuse detection, as its Gemini API terms describe.
The prices and links that come back, and Google's "Search Suggestions" shown with them, are kept with that one result in your own history so you can open it again, and are deleted after 30 days, when you delete the analysis, or when you delete your account. They are never shown to anyone else. We do not record which price, link or suggestion you tap.
A result may also show "Also search" buttons — links we build ourselves to a shop's own search page for the product read from your screenshot. Nothing about you is sent to the shop when the button is shown; opening one is an ordinary visit to that shop's website, governed by its own privacy policy. Where such a link is an affiliate link the result says so; we may then earn a commission at no extra cost to you, and it never changes the order of the price list, which is by price only.
Pro Headshot (OpenAI)
Pro Headshot, a feature for SnapAI Pro subscribers, turns a selfie into a professional headshot. Only use a photo of yourself. When you use it, our server:
- re-encodes your photo, which removes its location and other hidden metadata, and asks Google's Gemini API to check that it shows exactly one face;
- sends the photo and the style, background and clothing you chose to OpenAI's image API, which creates the headshot. OpenAI acts as our service provider. Under OpenAI's API terms, data sent through its API is not used to train its models, and OpenAI may keep it for up to 30 days to detect abuse before deleting it;
- deletes your selfie from our servers as soon as the headshot has been made, or has failed;
- keeps the headshots for 30 days (or your shorter data-retention period, at least one day), then deletes them automatically. You can delete one sooner in the app.
OpenAI is used for Pro Headshot only. Nothing else you do in SnapAI is sent to OpenAI.
Using screenshots to improve SnapAI
Settings → Privacy has a switch, "Use my screenshots to improve SnapAI". It is off by default. While it is off, your screenshots and results are not used to train or improve AI models. If you turn it on, you allow us to use them to improve the service; we record when you changed the setting, and you can turn it off at any time. Today we do not use any user's screenshots for training.
6. Business Inbox (email, WhatsApp and the CRM)
The Business Inbox comes with Snap AI Business Pro. It lets you connect a business email account, or a WhatsApp number, so you can read and answer customer messages inside SnapAI with AI help, and keep your customers in a CRM. If you are not on that plan and never connect an account, nothing in this section applies to you — we hold no mailbox details and no messages.
How you get it
It is part of the Snap AI Business Pro subscription, bought through Google Play (and, in future, the App Store) like any other in-app subscription. We never ask for card details ourselves. There is also a free one-day trial, which needs no card and can be taken once per account and once per phone. The separate Email and WhatsApp packs we used to sell are no longer offered; if you still hold one it keeps working exactly as before, and everything in this section applies to it too. Either way the plan is then activated for you on Data2Sales AI, our communication infrastructure provider (see below).
The CRM
When you save a customer — from a conversation, from a visiting card you scanned, or by typing one in — their name, phone, email, company and your notes are held by Data2Sales AI, who run the CRM for us. We keep no lead details ourselves: only a pointer to the record, which conversation or scan it came from, and a one-way hash of the number and address so the same person is not saved twice. SnapAI never reads your phone's address book and asks for no contacts permission. Deleting your account deletes what we hold, and the records at Data2Sales AI are released with your plan.
Connecting an email account
To read your mail we need your mail server's details and a password for it:
- We ask for an app password — a separate password your mail provider issues for one app, which you can revoke at any time without changing your main password. Gmail, Outlook, Zoho and most business hosts all offer one. Please do not use your main account password.
- The password is encrypted before it is stored, is never shown again (not even to you, and not to our staff), never appears in any of our logs, and is used for two things only: fetching your recent mail and sending the replies you choose to send.
- We connect to your mail server over an encrypted (TLS) connection and check its certificate.
- We do not use Gmail or Outlook sign-in for this. That route would require us to hold a far wider permission over your Google or Microsoft account; an app password is narrower and you can withdraw it yourself in seconds.
What we fetch and keep
- Only your Inbox, only the most recent 50 messages, and only from the last 30 days. We do not read other folders and we do not fetch your archive.
- For each message we keep the sender's name and address, the recipient, the subject, the date and the plain text of the body, shortened if it is very long. Formatted (HTML) mail is converted to plain text before it is stored.
- Attachments are never downloaded. We record only the file name, so you can see that something was attached.
- We open your Inbox in read-only mode, so nothing we do marks your mail as read, moves it or deletes it on your own mail server.
WhatsApp packs
A WhatsApp number is connected by scanning a QR code; the connection itself lives with Data2Sales AI, not with us.
Your WhatsApp messages are kept on your phone. They are stored in SnapAI on the device you use them on, and that is the only copy there is of your chat history. Our servers hold a WhatsApp message only until your phone collects it — at most 24 hours. While it is waiting it is encrypted, and it is deleted the moment your phone confirms it has it; anything no phone ever collects is deleted automatically after 24 hours. We do not keep a copy afterwards, we cannot search your chats, and nobody here can read them.
What we do keep about a WhatsApp conversation is the customer's number, when the chat last moved and anything you linked it to in the CRM — so that a reply can be addressed and the chat can be found. No message text, no subject, no preview.
What this means for you. A new phone, or reinstalling the app, starts your chats from the last 24 hours: there is nothing older for us to send, because we did not keep it. The app tells you this on the screen where you connect a number and under an empty chat list. Deleting the app deletes your chats with it.
Attachments are fetched from Data2Sales AI on demand, passed straight through to your phone and never stored by us.
AI in the inbox
When you ask for a summary, a draft reply, a lead check or a follow-up, we send Google's Gemini API the recent messages of that one conversation and nothing else — no other conversation, no contact list, and nothing from the rest of your SnapAI account.
A draft is only ever a draft. Nothing leaves your mailbox or your WhatsApp number because SnapAI decided it should: a draft waits until you read it and press send.
Auto-reply, if you switch it on. Snap AI Business Pro includes an assistant that can answer a customer for you. It is off by default and there is a switch for it in Business settings. While it is on, Data2Sales AI answers from the facts you typed there — what your business does, your hours, your FAQs, your tone, and the things you told it never to say — using the recent messages of that one conversation. Turn the switch off and it stops at once. If your plan does not cover auto-reply the switch cannot be turned on at all.
Data2Sales AI
The communication service behind the packs is run for us by Data2Sales AI, acting as our processor. It receives your SnapAI account number, which pack you bought and when it expires, and — for WhatsApp — your WhatsApp connection and the messages you send through it. If you connect a mailbox, Data2Sales AI also runs it for us: your app password is passed to it once, over an encrypted server-to-server connection, and stored there encrypted (we keep no copy); it fetches your recent mail, sends the replies and emails you write (with any attachments, which are not kept), and keeps your drafts and read / archived state. It deletes the password and the stored mail when you remove the mailbox.
Your profile details go with it, but only while a pack is active. So that the people running the service can identify, support and contact you about the mailbox or WhatsApp number they are operating for you, we also send Data2Sales AI the details on your profile: your full name, your contact email address, your WhatsApp / phone number, your country and postal address, and your profile photo. They are sent when the pack is activated and again whenever you change them, and they are marked as coming from SnapAI.
This happens only if you are on Snap AI Business Pro (or still hold one of the Business Inbox packs we used to sell). If you are not, none of it is sent — not your name, not your number, not your photo. If the plan ends, we stop sending changes. Data2Sales AI holds these details as our processor, to run the service and support you, and for nothing else; they are deleted when you delete your SnapAI account.
How long we keep it, and how to stop
- Remove a connection in the app and its stored messages, and its saved password, are deleted immediately, in that same moment.
- Messages are kept only while your pack is active. If the pack ends, your history stays readable for 30 days so you can reactivate, and is then deleted.
- Nothing is kept beyond your pack's conversation-history window in any case.
- Deleting your SnapAI account deletes every connection, message and pack record we hold.
7. Money & Savings
Money & Savings turns receipts, bills and bank statements into a record of what you spend, so you can see where your money goes and set a budget. It is optional: if you never open it, none of what follows applies to you.
It is budgeting help, not financial advice. SnapAI adds up your own figures and explains what it sees. It is not financial, tax or investment advice, it never tells you what to buy or where to put your money, and any saving it points out is a possible saving, never a promise.
What we keep
- Expenses and receipts — the merchant, amount, currency, date, category, payment method and any note you add.
- Bills and subscriptions — who it is to, how much, when it is due or renews, and the reference printed on it.
- Budgets and savings goals — the amounts you set and what you have put aside.
- Bank statement imports — the transactions read out of a statement you upload: date, description, amount and the bank’s own reference.
Account and card numbers
We store them masked to the last four characters, and that happens as the value is saved, so there is no way into this part of SnapAI that can keep a full card or account number. The statement and receipt readers mask what they read as well.
Bank statements you upload
Every statement we hold is encrypted. A CSV, a PDF and a photo are all scrambled with a key made fresh for that one file, and that key is itself locked with our server's own key and kept in the database — never next to the file. Somebody who walked off with our file storage would have noise. The file is stored under a random name that says nothing about you, your bank or the month, and there is no link to it that anyone can simply open: the only way back to it is a request from your own signed-in app, through a link that lasts five minutes, and we unscramble it as we send it. If even one byte of a stored file has been altered, it will not open at all — we would rather show you nothing than show you something that had been changed.
It is deleted as soon as the transactions have been read, unless you have chosen to keep files for 7, 30, 90 or 365 days in Settings → Data retention — and in that case it is deleted when you confirm or throw away the import. The file and its key are deleted together, so a copy in a backup is unreadable rather than private.
We do not keep your account or card number. A bank statement prints them in the middle of the description of a payment; we shorten every long number to its last four digits as the transactions are read, and they never appear in our logs.
Nothing an import finds is added to your records until you have looked at it and said yes. Until then it sits in a review list you can edit, reject or throw away, and throwing it away leaves your expenses exactly as they were.
Reading your email for receipts — only if you switch it on
If you have a Business Inbox Email Pack and a mailbox connected, you can switch on email receipts in Money settings. It is off unless you turn it on, we record when you turned it on, and you can turn it off again at any time.
- It reads only the messages the Business Inbox has already stored for you. It opens no new connection to your mail provider and uses no extra password.
- It looks for receipts, bills and renewal notices and records the merchant, amount and date it found — not the message, and not its attachments. Nothing from your mailbox is copied into this part of the app.
- By default it asks: the receipt it found waits on screen until you confirm it. You can choose to have confident ones saved automatically instead.
- Turn it off and we stop reading, and the record of your permission is cleared with it.
Alerts
Bill reminders, budget warnings, renewal notices, savings progress and the weekly and monthly summaries are each a separate switch, and every one starts off. When you do turn them on, everything due on a day is gathered into one notification at the hour you choose, and never during the quiet hours you set.
How long we keep it, and how to stop
- Your expenses, budgets, goals, bills and subscriptions stay until you delete them or delete your account.
- An expense, a whole statement import, a found receipt, a budget, a goal, a bill or a subscription can each be deleted on its own, at any time.
- Deleting your SnapAI account deletes all of it, and any statement file still held goes before the records do.
- Nothing your spending teaches SnapAI about categorising your receipts is ever used for anybody else’s account.
8. Refer & earn, and your public page
Inviting a friend
Every account gets a short invite code. It is random — it is not made from your name, your email or anything else about you — and it is shown only to you, in Profile → Refer & earn, until you choose to share it.
When a friend joins with your code, you earn credits inside SnapAI: some when they have signed up on their own phone and finished their first scan, and more if they later take a paid plan. Credits are not money. They have no cash value, they cannot be withdrawn or transferred, and we never pay anybody for a rating or a review. Daily and monthly limits apply, and credits are taken back if a purchase is refunded or if a referral turns out not to be genuine.
What we keep about a referral, and why
- Who invited whom — the two account ids, the code used, when it happened, and what it earned. Your friend sees none of your details; you see their first name only, never their email or their number.
- A one-way, keyed hash of the phone each side used, and of the internet address the code was entered from. These are the same kind of irreversible hash described in “Usage and technical data” above: we cannot turn one back into a device or an address, they are never shown in the app, and they are never shared. They exist for one reason — to stop one person inviting themselves over and over for free credits — and without them we could not offer the rewards at all.
A referral record is deleted when the account that made it is deleted. If you delete your account while somebody you invited is still being counted, that referral is closed and any credits it paid are taken back.
Your public page — off unless you turn it on
You can choose to publish a page at https://snapai.reviewindia.org/u/your-handle. It is off by default on every account. Nothing about you is published until you pick a handle and save it.
When it is on, the page shows:
- the display name you chose;
- the profile photo you uploaded;
- a business name, a city and one line about yourself — each optional, each typed by you for this page;
- your invite link.
It never shows your email address, your phone or WhatsApp number, your postal address, your country, your plan, your credit balance, or anything at all about what you have analysed. The page is served by our own servers; nothing on it is sent to anyone else. It also asks search engines not to index it, so turning it on makes your link shareable — not you searchable.
You can edit it or take it down at any time from Profile → Refer & earn → Public profile. Taking it down stops the page working immediately and frees your handle for somebody else. Deleting your account does the same.
9. The WhatsApp API
Snap AI Business Pro includes a WhatsApp API (documentation) so your own systems can send order updates and one-time codes from the WhatsApp number you connected here. If you never create an API key, nothing in this section applies to you.
What it handles is your customers' data, not yours, and we keep as little of it as a delivery receipt allows:
- We store the number each message went to, so a delivery status can be filed against it and so one number cannot be hammered. It is never given back in full: the API answers with a masked number.
- We do not store the message. Not the text, not the media, not the one-time code — a code is kept only as a one-way keyed hash, is destroyed by five wrong guesses, and is consumed the moment it is verified.
- The request log records no content. One row per call: which key, the method, the route pattern rather than the path (so it carries no ids), the status, how long it took, and the internet address it came from. It is kept for 30 days. It is deliberately useless for reading anybody's messages.
- A webhook you register is stored with its address and its signing secret, the secret encrypted. What we post to it carries ids, statuses and a masked number — never message text and never a code, because a mistyped address must not be able to send a customer's content to a stranger.
- The key itself is never stored. We keep a one-way hash; the secret is shown once, when you create it, and never again.
Deleting your account deletes all of it at once — the keys, the webhooks and their secrets, the send records including those numbers, and the request logs with their addresses — rather than waiting for the 30-day sweep. You can also revoke any key from the app at any time.
10. Who we share it with
We share data only with the service providers that run SnapAI for us, only for that purpose, and when the law requires it. We do not sell it.
| Provider | What for | What they receive |
|---|---|---|
| Google (Gemini API) | AI analysis | The image or PDF, the text read from it, the tool and language |
| OpenAI (Image API) | Pro Headshot only | The selfie you choose (without its metadata) and the style options |
| Hostinger | Hosting our servers, database and stored screenshots | Everything held on our servers |
| Data2Sales AI Business Studio, and WhatsApp (Meta) | Delivering WhatsApp sign-in codes | Your mobile number and the code |
| Data2Sales AI | Running the business inbox (email and WhatsApp) and the CRM that come with Snap AI Business Pro, if you are on it | Your account number, which plan you are on, and — for WhatsApp — your connection and the messages you send and receive on it (they reach your phone through us, and we keep them for at most 24 hours on the way); for email, your mailbox's app password (stored encrypted) and the messages it fetches and sends. While the plan is active, also your profile details so they can identify and support you: your name, contact email address, WhatsApp / phone number, country and postal address, and profile photo. Nothing of this is sent for an account that is not on it. |
| Your own mail provider | Reading and sending your business email, if you connect a mailbox | Your app password, used by Data2Sales AI over an encrypted connection |
| Our email provider | Delivering email sign-in codes | Your email address and the code |
| Google (Sign-In) | Google sign-in | Google confirms your identity to us |
| RevenueCat | Processing subscriptions | Your account number, purchase and subscription events |
| Google Play / Apple | Taking payment | Your purchase, under the store's own terms |
| Google AdMob | Ads for free users, only if ads are switched on (see below) | Advertising ID, IP address and device information |
| Google (Firebase Cloud Messaging) | Delivering notifications, if you allow them | The push token for your installation, and the notification we ask it to deliver |
We may also disclose information if required by law or a valid legal order, to protect the safety of our users or others, or as part of a merger or sale of the business, in which case this policy would continue to apply to your data.
11. Advertising
SnapAI includes Google's Mobile Ads SDK (AdMob) so that free users can be shown ads, including an optional "watch an ad for a bonus analysis". Ads are currently switched off, and while they are off the ads SDK is not started. If we switch ads on:
- SnapAI Pro subscribers never see ads.
- Where the law requires it (for example in the EEA, the UK and Switzerland), Google's consent form asks for your permission first, and "Ad privacy choices" in Settings lets you change it. Without consent, ads are not personalised.
- Google may use your device's advertising ID. You can reset or delete it in your phone's settings (Settings → Privacy → Ads on most Android phones).
- Your screenshots, results and account details are never shared with advertisers.
12. How long we keep it
| Data | How long |
|---|---|
| Uploaded screenshots and PDFs | Deleted as soon as the analysis finishes. This is the default for every new account: the file is removed from our servers the moment the result has been produced, not at the end of the day — and it is removed just the same when the analysis fails in a way that re-sending the same file could not fix. If an attempt fails for a reason a retry could fix (our AI service was briefly unavailable, for example), your file is kept for a short while so that "Try again" has something to send, and it is deleted when that attempt finishes. If you would rather keep your files, Settings → Data retention offers 7, 30, 90 or 365 days; an automatic clean-up then runs every night and deletes files past your period. "Delete all my stored screenshots" deletes them all immediately, whatever your setting. |
| Originals you chose to keep (Pro and Business) | Until you delete them. There is no expiry on a file you deliberately kept. They are stored encrypted, count towards your storage allowance (1 GB with Pro, 2 GB with Business, plus any extra storage you bought), and can be deleted one at a time or all at once from Profile → Storage. Deleting the analysis, or your account, deletes them at once — along with the keys that open them. If your plan or your extra storage ends they become read-only immediately and are deleted 30 days later, with warnings 14 days and 3 days beforehand; we never delete one without warning you, and a failed payment alone never starts that countdown. A file you were asked about and did not answer is deleted after 30 minutes. |
| Pro Headshot selfies | Deleted from our servers as soon as the headshot is made, or the attempt fails. |
| Pro Headshot results | 30 days, or your shorter data-retention period (at least one day). Deleting a headshot, or your account, deletes it at once. |
| Text read from a screenshot | Not stored on our servers. On your phone, until you delete the analysis or sign out. |
| Analysis results and history | Until you delete them or your account. Only the screenshot expires; the result stays. A deleted analysis disappears at once and its screenshot is deleted straight away; the record itself is permanently deleted 30 days later (so an accidental deletion can be undone through support). |
| Price comparisons (the prices and links found for one result) | 30 days, then deleted automatically. Deleting the analysis, or your account, deletes it at once. Searching again replaces it. |
| Business Inbox messages (if you connect a mailbox) | Only while your pack is active, and never beyond your pack's conversation-history window. Removing the connection deletes them immediately; if the pack ends they are kept for 30 days so you can reactivate, then deleted. |
| Business Inbox mailbox password | Held only by Data2Sales AI, encrypted, until you remove that connection or delete your account — whichever comes first. We keep no copy. |
| Money & Savings records (expenses, bills, budgets, goals, subscriptions, imported transactions) | Until you delete them or your account. Account and card numbers are stored masked to the last four characters. |
| Bank statements you upload | Encrypted while we hold them, under a key made for that one file. Deleted as soon as the transactions have been read if your data-retention setting is the default, and on confirming or discarding the import otherwise. The file and its key go together. A kept statement or receipt is only ever opened by your own signed-in app, through a link that expires in five minutes. |
| Email receipts found for you (only if you switched them on) | The merchant, amount and date we found, until you confirm, dismiss or delete it — and in any case only while the message itself is in your Business Inbox: when that message goes, so does this. |
| WhatsApp messages (Business Inbox) | On your phone, not on our servers. We hold a message only until your phone collects it — at most 24 hours, encrypted — and delete it the moment your phone confirms it has it. We keep the customer's number, when the chat last moved and any CRM link, for as long as your pack is active. Deleting the app deletes your chats with it; a new phone starts from the last 24 hours. |
| WhatsApp API send records and one-time codes | Only if you created an API key. The receipt for a send — which key, when, what kind, the number it went to, what happened to it — and one-time-code rows (the code itself only as a one-way hash, destroyed on five wrong guesses and consumed when verified). No message text or media is stored at all. Deleting your account deletes all of it at once. |
| WhatsApp API request log | 30 days. One row per call: the key, the method, the route pattern (not the path), the status, the duration and the internet address. No request or response body, no number, no code. Deleting your account deletes it at once rather than waiting for the sweep. |
| Push notification token | While it works. Firebase replaces it when it rotates, we move it if you sign in or out, we delete it if Firebase tells us it is dead, and it goes with your account when you delete it. |
| Account, settings, reminders, feedback, usage | Until you delete your account. |
| Profile details (name, country, postal address, contact email, WhatsApp number) | Until you change them or delete your account. Deleting your account deletes them at once. |
| Profile photo | Until you replace it or delete your account. Replacing it deletes the old one; deleting your account deletes it at once. |
| Sign-in codes | Stored only in scrambled (hashed) form, with the requesting IP address. They expire after 10 minutes and are deleted once used or expired. |
| Consent history for the "improve SnapAI" switch | Kept with a de-identified record after account deletion, as evidence of what you agreed to. |
| Purchase and subscription event records | Kept as billing records for as long as the law requires, including after account deletion. |
| Server logs | For a limited period, for security and troubleshooting. |
What happens when you delete your account is explained on the Delete your account page.
13. Your choices and rights
- See and export your data: your history is in the app. Export it as a CSV file (History → Export history) or a single result as a PDF. For a copy of anything else we hold, email us.
- Correct it: change your name, photo, country, address, contact email or WhatsApp number in Profile → Edit profile details, or email us if anything else about your account is wrong.
- Delete it: delete one analysis from its result or from History; delete every stored screenshot in Settings → Data retention; or delete your whole account in Profile → Account → Delete account. You can also ask us to delete it by email.
- Change your mind: switch "Use my screenshots to improve SnapAI" off, change how long screenshots are kept, turn off news and updates, or turn off notifications and the camera, microphone and other permissions in your phone's settings.
- Complain: contact us first (below). You may also have the right to complain to a data protection authority, including the Data Protection Board of India.
We will respond to requests within 30 days. We may need to confirm that the request comes from the account holder, for example by asking you to write from the email address on the account.
14. Security
- All traffic between the app and our servers is encrypted with HTTPS.
- Your sign-in token and the text read from screenshots are kept in your phone's encrypted storage (Android Keystore / iOS Keychain).
- Screenshots are stored privately, outside the public website, in a folder per account. The app can only view one through a link that expires after five minutes.
- Receipts, bills and bank statements kept by Money & Savings are encrypted on our storage, each file with its own key, and the key is stored separately from the file. The file’s name says nothing about what it is. Opening one needs your own signed-in session and a link that expires after five minutes — there is no public or shareable link to it. Deleting it destroys the key as well as the file, so no copy anywhere can be read afterwards.
- Originals you chose to keep are encrypted on our storage in the same way: a fresh key for every file, protected by our application key and stored on the file’s own record, with a random file name that says nothing about the content. What sits in the storage bucket is unreadable on its own — it cannot even be recognised as a picture. Opening one needs your own signed-in session and a link that expires after five minutes. Deleting it destroys the key with the file.
- Our AI and other service keys are held only on our servers, never in the app.
- Our team's admin tools show statistics, not screenshots. Viewing the text of an individual result is possible only for support or abuse investigations, and each view is recorded in an audit log.
No system is perfectly secure. If we learn of a breach that affects your data, we will notify you and the authorities as the law requires.
15. Children
SnapAI is not directed at children under 13, and we do not knowingly collect personal data from them. If you are under 18, please use SnapAI only with the involvement of a parent or guardian. If you believe a child has given us personal data, contact us and we will delete it.
16. International transfers
Our service providers, including Google and OpenAI, may process data in countries other than yours, such as the United States. We rely on their contractual commitments to protect it.
17. Changes to this policy
We will update this page when our practices change and change the "last updated" date at the top. If a change is significant, we will also tell you in the app before it applies.
18. Contact and grievances
For privacy questions, requests or complaints, email sohosoftech@gmail.com. Review India is responsible for your data under this policy.