SnapBuddy

Privacy

Last updated 14 August 2026

SnapBuddy records your screen and takes screenshots, so it can see whatever you point it at. This page says exactly what it captures, where that ends up, and what leaves your machine. The short version: by default, nothing leaves your machine except a check for a new version.

What the desktop app captures

Where it goes

Everything stays on your computer. Screenshots and notes live in the app’s own storage in your user profile; recordings are ordinary files in a folder you choose. Saving a card writes an image and a Markdown file to a folder you pick.

How long we keep things

Nothing you keep expires on a timer. A bug report from last year is still evidence, so we do not quietly delete it. Nor is there any limit today on how many captures you can hold — that is bounded by your own disk. Per-plan limits are planned and none is in force, so nothing of yours is being counted against one.

When you delete something it goes to the Trash, where it stays for 90 days before it is removed for good. Nothing is deleted from your disk while it is in there — the recording file waits with the card, so restoring one actually gives it back. Filter the board to Trash to restore something, or to delete it immediately and skip the wait. Anything past its 90 days is removed the next time the app starts, and after that it is gone: not by us, not by you, not from a backup you did not take.

The web library works the same way, with one addition: the share page stops working the moment you delete what it points at. Something shared by mistake is out of reach at that address immediately, even though the file itself waits out the same 90 days in case you restore it, and restoring brings the link back with it. One honest edge: if a downloadable MP4 was ever generated for a recording, that file has its own address at Cloudflare, and that address does not expire on its own. Someone who saved that exact address before you deleted may still reach the file until the recording is removed for good. Anything past the 90-day window is removed the next time someone in your workspace opens the library, and the stored files, the streaming copy and any generated MP4 are removed with it.

Use Delete shown on the desktop board to move cards to the Trash in bulk — it acts on exactly what the filter and the search box are currently listing. Nothing is taken off your disk at that point; the files go when the Trash empties. If you have already saved files to your own folder, those are yours and stay where they are, because they were never ours to delete.

The app also keeps a small rolling log — the current run and the one before it — in its own settings folder, to make a crash diagnosable. It records what the app did, not what you captured.

What leaves your machine

By default, one thing: a check for a new version. A few seconds after the desktop app starts, it downloads a small file from GitHub that says what the newest release is, and compares it with your copy on your machine. That request tells GitHub your IP address, the same as visiting any web page — your version number is not sent. If there is a newer release the app offers it; nothing is installed without you saying yes.

Uploading and sharing are off until you switch them on. Settings has a checkbox for it and two fields underneath — a server address and an API key — all three empty by default, and nothing leaves your machine until all three are set. Once they are, every finished recording is registered with the address you typed — a server you choose, which need not be ours — and then the video file is sent to whatever upload address that server returns, which may be a third-party video host rather than the server itself. A share link comes back and goes to your clipboard. Anyone with that link can watch the recording. Clearing the checkbox or either field stops it.

The browser extension

The extension makes no network requests at all. It has no permission to reach any website and its security policy contains no remote address, so it cannot send your captures anywhere even by mistake.

It captures the visible area of the tab you are on. It can also record — and although the button is about a tab, the picker your browser shows can also offer another window or a whole screen, and whatever you choose there is what gets recorded, exactly like the desktop app. Recording takes its audio — which on a call means everyone on it, with the same warning as above. It never reads a page’s contents: there is no content script, so the page text, your cookies and anything you type into a site are out of its reach by construction. What it captures is stored in your browser profile, on your machine.

The web app

If you sign in on the web, we store your email address so you can sign in again, and anything you deliberately upload. Sharing is done by an unguessable link; anyone who has the link can open it, so treat one like a password. Who holds it, and where, is below.

Nothing is sent to any AI service today. Transcription and AI summaries are planned; when they arrive they will be opt-in, this page will name the provider before it is used, and you will be told which parts of a capture get sent.

Why we are allowed to do this

Almost nothing here needs a legal basis, because almost nothing reaches us: what the desktop app captures stays on your machine, and we never see it.

No decision about you is made automatically, and there is no profiling. Nothing here is used to score, rank or judge anyone.

Where cloud data is held

Only what you sign in with or deliberately upload ever leaves your machine. When it does, three companies handle it, each acting on our instructions and none permitted to use it for anything else. Your account and the records about your captures are held by Supabase and the site is served by Vercel. The captures themselves are stored and delivered by Cloudflare: screenshots live in its R2 storage, recordings are processed and streamed by its Stream service, and the MP4 offered for download is generated there. When you, or anyone holding a share link, views a capture, the browser fetches the picture or the video from Cloudflare directly, which sends Cloudflare what any web request carries: an IP address, a user agent, and the address of the page doing the asking.

The database, including your email address and the records about your captures, is stored in London, United Kingdom (eu-west-2), which is outside the European Economic Area. That is allowed because the European Commission has decided the United Kingdom protects personal data adequately: Implementing Decision (EU) 2025/2574 of 19 December 2025, which runs until 27 December 2031. No further paperwork is needed from you or from us while that stands. If it is ever withdrawn, the fallback is already in place: our database provider’s data processing agreement carries the European Commission’s standard contractual clauses and the UK addendum. Capture files at Cloudflare are stored and served through its global network. [PLACEHOLDER: name the R2 storage region and the transfer mechanism relied on for Cloudflare before public release; the owner completes this in the final legal pass.]

Your rights, and how to use them

Because we are established in the Czech Republic, the GDPR applies to everything above. You can ask us to:

Write to the address at the bottom of this page and we will do it within 30 days. There is no charge and you do not have to give a reason.

If we get it wrong, you can complain to a regulator, and you do not need our permission or involvement. Ours is the Czech data protection authority, the Úřad pro ochranu osobních údajů (Pplk. Sochora 27, 170 00 Prague 7). You may also complain to the authority in the country you live or work in.

What we do not do

Your choices

If you have a web account and want it and its contents removed, contact us at the address below and we will do it.

Children

SnapBuddy is a tool for software teams and is not intended for children under 16. We do not knowingly collect anything from them, and the app has no age or date-of-birth field.

Changes

If this notice changes in a way that affects what is captured or where it goes, the date at the top changes and the app will say so on next launch rather than changing quietly.

Who we are, and how to reach us

SnapBuddy is operated by Cognitively Group s.r.o., the data controller for the processing described here, registered in the Czech Republic under company number 21384754.

Vinohradská 1511/230PragueCzech Republic

Questions about this notice, or a request to see or delete your data: cognitivelyapps@gmail.com. We will respond within 30 days.