Legal

Privacy Policy

Last updated: 22 April 2026

1. Who we are

SnapForge AI(“SnapForge”, “we”, “us”) is operated by Jakub Minařík, registered in the Czech Republic as a self-employed VAT-registered entrepreneur (OSVČ plátce DPH). You can reach us at support@example.com.

This policy describes how we handle personal data when you use our service at https://snapforge.co. We are the data controller for personal data you provide when using SnapForge.

2. What data we collect

  • Account data — email address and optional display name you provide when signing in.
  • LeadConnector OAuth tokens — access + refresh tokens for sub-accounts you connect. Stored encrypted at rest; used only to install snapshots on your behalf.
  • Snapshot data — vertical, business name, city, website URL you enter; scraped public data from the website URL; generated snapshot payload.
  • Billing data — handled by Stripe; we store only your Stripe customer ID, plan, and subscription status. We never see card numbers.
  • Usage data — server logs (request path, timestamp, error traces) retained up to 30 days for debugging and abuse prevention.

3. Why we process it (lawful bases under GDPR)

  • Contract performance — to provide the service you subscribed to (Art. 6(1)(b) GDPR).
  • Legitimate interest — to keep the service secure, prevent abuse, and improve reliability (Art. 6(1)(f) GDPR).
  • Legal obligation — tax, accounting, invoicing (Art. 6(1)(c)).

4. Third-party processors (subprocessors)

We share data with the following service providers:

  • Supabase (PostgreSQL hosting + authentication) — EU region (Frankfurt).
  • Vercel (application hosting, CDN) — global edge network.
  • Stripe (billing, payments) — PCI-DSS certified.
  • Resend (transactional email delivery).
  • LeadConnector (third-party CRM you authorize us to connect to) — we never access data beyond what your OAuth scopes grant.
  • Firecrawl (optional public website scraping when you request a snapshot) — used to read the publicly-available content of URLs you provide.
  • Anthropic (Claude) — AI model provider used to rewrite per-client email, SMS, funnel, and pipeline copy at snapshot-generation time. Scraped public-website content and business-context fields (name, city, vertical) you enter are sent as prompt inputs. Anthropic does not train models on data submitted through their API (per their published commercial terms). We do not send OAuth tokens, contact personal data, or any CRM sub-account data to Anthropic.

All AI-generated copy is produced by Anthropic Claude. SnapForge never claims that generated copy is human-written, and we actively prevent the model from inventing statistics, review counts, or testimonials (unverifiable details are left as {{variables}} for the agency to fill in before deploy).

Each processor has their own privacy policy. We rely on their GDPR compliance and standard contractual clauses where data leaves the EEA.

5. International transfers

Primary data storage is in the EU (Supabase Frankfurt). Some processors (Vercel, Stripe) may process data in the US under EU-US Data Privacy Framework certifications or Standard Contractual Clauses. By using SnapForge, you understand and consent to this routing.

6. Retention

  • Account data: until you delete the account (or 24 months of inactivity).
  • OAuth tokens: until the sub-account uninstalls the app.
  • Snapshot payloads: until you delete them or the account closes.
  • Billing records: 10 years (Czech tax law).
  • Server logs: 30 days.

7. Your rights

Under GDPR, you have the right to:

  • Access the data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your data in a portable format
  • Object to processing based on legitimate interest
  • Lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů, uoou.cz)

To exercise any of these rights, email us at support@example.com. We respond within 30 days.

8. Cookies

We use only essential cookies required for authentication (Supabase session). We do not use analytics or advertising cookies.

9. Children

SnapForge is a B2B service for marketing agencies. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, please contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. Material changes will be announced via email to account holders at least 30 days before taking effect. The “Last updated” date at the top always reflects the current version.

11. Contact

Questions, requests, or complaints: support@example.com