Privacy Policy
This Privacy Policy explains how InfoSnap collects, uses, stores, shares, protects, and deletes personal data when users use the InfoSnap website, mobile app, browser extension, APIs, and related services.
InfoSnap is a personal knowledge and search product. Users can save snaps, search them, ask SnapBot questions, generate recaps, and share selected snaps with groups.
For privacy questions, data-rights requests, account deletion requests, support requests, or security-related reports, contact contact@infosnap.ai.
This Privacy Policy applies to the InfoSnap website, Flutter mobile app, browser extension, backend APIs, Cloudflare Worker services, admin/support tooling, and communications related to the service. It does not apply to third-party websites, apps, social platforms, or content sources that InfoSnap links to or fetches from at the user's request.
InfoSnap uses Google sign-in through Supabase Auth. InfoSnap collects and stores:
InfoSnap does not operate a password login flow for users. Authentication is Google OAuth through Supabase.
When a user saves content, InfoSnap collects and stores the content and related metadata needed to make that snap usable. This includes:
Snap records and extracted text are stored in Supabase. Uploaded files, screenshots, webpage captures, thumbnails, generated media, and audit CSV files are stored in Azure Blob Storage. Search/vector representations are stored in Cloudflare Vectorize and related cache layers used by the search system.
InfoSnap creates derived data so users can search, summarize, and revisit saved content. This includes:
Derived data is personal data when it is created from a user's snaps, searches, or account activity.
When users use group features, InfoSnap collects and stores:
When a snap is shared with a group, active group members can see the shared group snap information and related display metadata.
InfoSnap stores plan, quota, usage, and billing-related records, including plan code, plan status, billing period dates, plan limits, monthly usage counters, usage events, billing event metadata, and provider identifiers when a billing provider is configured.
When push notifications are enabled, InfoSnap stores Firebase Cloud Messaging device tokens and related fields such as platform, app version, device ID, enabled status, last-seen timestamp, and update timestamp. InfoSnap uses this data to send upload updates, group invites, shared snap notices, reactions, and app notifications.
InfoSnap collects operational data to secure, debug, and operate the service. This includes:
Search traces and diagnostic records can include user queries, snippets, answer previews, filenames, or error details, so InfoSnap treats them as sensitive operational data.
InfoSnap uses personal data for these purposes:
For users in the European Economic Area, United Kingdom, and other regions with similar legal-basis requirements, InfoSnap relies on the following legal bases:
| Legal basis | How it applies |
|---|---|
| Contract | To create and manage accounts, save snaps, provide search, operate SnapBot, provide groups, send service notifications, enforce quotas, and deliver the service requested by the user. |
| Consent | For optional actions such as signing in with Google, enabling push notifications, saving third-party links, using optional AI features, and receiving non-essential communications where consent is required. |
| Legitimate interests | To secure the service, prevent abuse, debug errors, improve reliability, maintain audit records, understand service performance, and protect users and InfoSnap. |
| Legal obligation | To comply with applicable laws, tax/accounting duties, valid legal requests, and regulatory obligations. |
InfoSnap uses AI and document-processing services to provide product features. InfoSnap sends relevant parts of user content, filenames, source URLs, extracted text, search queries, snippets, metadata, prompts, or audio/video data to service providers when needed to produce embeddings, parsed documents, titles, summaries, rankings, transcriptions, recaps, search answers, and related outputs.
InfoSnap is not end-to-end encrypted. The server must be able to read content for AI, search, recap, extraction, thumbnailing, group sharing, and support features. Users should not save content in InfoSnap if they require a system where InfoSnap cannot process plaintext content.
InfoSnap does not sell user snap content. InfoSnap does not operate an advertising network based on user snap content.
InfoSnap uses third-party infrastructure and service providers to operate the product.
| Provider or service | Role in InfoSnap | Types of data processed |
|---|---|---|
| Supabase | Authentication, database, realtime, row-level access controls, session validation | Account data, snap records, extracted text, metadata, group data, billing/usage records, trace tables, auth/session data |
| Cloudflare | Website hosting, Worker APIs, edge processing, cache/KV, Durable Objects, Vectorize, AI, rate limiting | Requests, auth tokens during validation, content processed by Workers, embeddings/vector metadata, caches, operational logs |
| Azure Blob Storage | Storage for uploaded files, thumbnails, generated media, and audit CSV files | Uploaded files, screenshots, webpage captures, thumbnails, audit records, related metadata |
| TensorLake | Document parsing and conversion | Temporary access links to uploaded documents, filenames, extracted document text/markdown |
| Groq | LLM inference for titles, cleanup, summaries, relevance checks, SnapBot, generated outputs, and transcription in supported flows | User-requested content, extracted text, search queries, snippets, prompts, generated outputs, audio/video data where transcription is invoked |
| Voyage AI | Search reranking | Search query text and candidate snippets or document text used for ranking |
| Google sign-in, YouTube metadata/transcript enrichment, Firebase Cloud Messaging, OAuth token exchange | Google account identity, sign-in tokens, YouTube source URLs/video IDs, notification tokens, message payloads | |
| SendGrid | Email delivery for invites and service emails | Email addresses, email content, delivery metadata |
| Social and web source platforms | Public metadata, oEmbed, captions, transcripts, thumbnails, and page fetches for user-saved URLs | Source URLs selected by users, public page/post metadata, thumbnails, captions, transcripts, fetched webpage content |
| Image proxy/cache services | Stabilizing display of third-party thumbnails that block direct loading or expire | Third-party image URLs and thumbnail bytes needed for app display |
InfoSnap shares data in these ways:
InfoSnap does not sell personal data or user snap content.
InfoSnap uses technical and organizational measures designed to protect user data, including:
Snap content is encrypted in transit over HTTPS and encrypted at rest by the cloud database and cloud storage providers. InfoSnap does not currently apply separate app-layer encryption to snap content before storing it, and InfoSnap is not end-to-end encrypted.
The Flutter app reads selected data directly from Supabase using the user's authenticated session. Owner-scoped reads apply to notes, user plans, monthly usage, usage events, billing events, and notifications. Authenticated users can read plan limits and user profiles. Plan limits do not contain snap content. User profiles contain account/profile data such as email, display name, and avatar URL.
Group tables are readable according to group membership policies. Shared group snap records include display metadata such as title, tag, file type, thumbnail, and related group activity fields, and are visible to active group members.
InfoSnap uses cookies and similar technologies, including browser storage and mobile app secure/session storage, for these purposes:
InfoSnap does not use advertising cookies. InfoSnap does not use third-party advertising trackers to sell or monetize user snap content.
Users are responsible for the content they save, upload, share, or ask InfoSnap to process. Users must have the legal right to save, upload, process, and share content submitted to InfoSnap, including files, screenshots, webpages, Instagram URLs, YouTube URLs, LinkedIn URLs, other social posts, and web content.
Users must not upload, save, or share content that violates third-party intellectual property rights, privacy rights, platform terms, confidentiality obligations, or applicable law. Group sharing should be used only for content the user is allowed to disclose to the group members.
InfoSnap keeps personal data only for as long as needed to provide the service, secure the product, comply with law, resolve disputes, and enforce agreements. The standard retention schedule is:
| Data type | Retention period |
|---|---|
| Account and profile data | Until the account is deleted, plus any period required for legal, tax, security, or dispute purposes. |
| Snaps, uploaded files, extracted text, thumbnails, and snap metadata | Until the user deletes the snap or deletes the account, subject to backup and operational retention. |
| Derived search, AI, vector, recap, and cache data | Until the related snap/account is deleted or the data is refreshed, rebuilt, or no longer needed for the feature. |
| Operational logs and diagnostic traces | Up to 90 days, unless needed longer for security, fraud prevention, debugging, legal, or abuse investigations. |
| Audit records | Up to 1 year, unless needed longer for security, legal, fraud prevention, or dispute purposes. |
| Backups and disaster recovery copies | Up to 30 days after deletion or replacement, unless provider backup systems require a longer recovery cycle. |
| Billing, quota, and transaction-related records | As long as required for tax, accounting, legal, billing, and dispute purposes. |
| Support and privacy request correspondence | As long as needed to handle the request and maintain a record of the resolution. |
Users can delete individual snaps and bulk-delete snaps through app flows. Delete flows remove the database record and attempt to remove associated file blobs, thumbnail blobs, vectors, and usage events where applicable. Some logs, audit records, cached data, backups, generated summaries, and provider-side records can remain for the retention periods above.
Users in the European Economic Area and United Kingdom have privacy rights under GDPR and UK GDPR, subject to legal limitations. These rights include:
Users can exercise these rights by contacting contact@infosnap.ai. InfoSnap will verify the request and respond within the time required by applicable law.
For users in India, InfoSnap handles personal data in line with applicable Indian privacy law, including the Digital Personal Data Protection Act, 2023 where applicable. Indian users can request to:
Withdrawing consent can limit or disable features that require the relevant data, such as Google sign-in, push notifications, AI processing, search, or group sharing.
InfoSnap uses cloud and API providers that operate globally. Personal data can be processed in India, the United States, Europe, and other regions where InfoSnap's service providers operate infrastructure or subprocessors.
Where required by applicable law, InfoSnap relies on contractual safeguards, provider data-processing terms, and other lawful transfer mechanisms to protect personal data transferred across borders.
InfoSnap is not designed for children. Users should not use InfoSnap if they are not old enough to consent to use the service under applicable law. If InfoSnap learns that it collected personal data from a child without proper consent, InfoSnap will delete that data as required by law.
InfoSnap can update this Privacy Policy when the product, providers, legal requirements, or data practices change. The updated policy will show the effective date. Continued use of InfoSnap after an updated policy takes effect means the user accepts the updated policy, where permitted by law.
Privacy, data-rights, account deletion, general support requests, and security-related reports: contact@infosnap.ai.