Privacy
Last updated 27 September 2026
SnapBuddy records your screen and takes screenshots, so it can see whatever you point it at. This page says exactly what it captures, where that ends up, and what leaves your machine. The short version: in the desktop app and the browser extension, nothing leaves your machine by default except a check for a new version - and in the web app, every capture you take is uploaded to your workspace, because that is where it is kept.
What the desktop app captures
- Screenshots, in three shapes. “Capture screen” takes the entire monitor - not just the window you were looking at. Anything else on that screen at that moment is in the picture. “Window” lists the windows you have open, by title and by application, and photographs the one you pick - including any part of it another window was covering, because it asks that window to draw itself rather than copying what is on the screen. “Region” briefly reads every connected display so it can show you a frozen image to drag on, then keeps only the rectangle you selected.
- Screen recordings of a monitor, a single window, or a region. There is no time limit and no size limit.
- Your microphone, only if you switch it on for that recording. Off by default.
- System audio - everything your computer is playing - only if you switch it on for that recording. Off by default. On a call this records everyone else on it, and their meeting app will not show its own recording indicator, because the capture happens outside it. In many countries and US states, recording someone without telling them is a criminal offence. Tell them first.
- Your camera, only while you open the webcam bubble for a recording. Off by default.
- An interaction track alongside every recording, in a file ending
.events.jsonl. This is always written and cannot be switched off. It contains mouse positions, clicks and the outlines of windows that came to the front. It deliberately contains no keystrokes - not the characters, not the key codes - and no window titles, so nothing in it can reconstruct what you typed or what you had open. - Basic machine details attached to saved notes: your operating system and its version, the app version, your screen resolutions, your language and your time zone.
- What you type into it - your own notes, card names, and the text on annotations.
Where it goes
Everything stays on your computer. Screenshots and notes live in the app’s own storage in your user profile; recordings are ordinary files in a folder you choose. Saving a card writes the picture to a folder you pick, and by default that is all it writes. Press Save files on a card, or set Saving writes to The picture, the notes and the data in Settings, and you also get a Markdown file you can read and a small .capture.json holding the same thing as data. That third file is what lets a coding assistant read the capture without you pasting it in, and it is described under Reading captures from a coding assistant below.
How long we keep things
Nothing you keep expires on a timer. A bug report from last year is still evidence, so we do not quietly delete it. What is limited is how many captures you can hold at once, and that depends on your plan. Reaching that limit stops you adding new ones; it never removes anything you already have.
When you delete something it goes to the Trash, where it stays for 90 days before it is removed for good. Nothing is deleted from your disk while it is in there - the recording file waits with the card, so restoring one actually gives it back. Filter the board to Trash to restore something, or to delete it immediately and skip the wait. Anything past its 90 days is removed the next time the app starts, and after that it is gone: not by us, not by you, not from a backup you did not take. This applies to all three: the desktop app, the web library and the browser extension. Until August 2026 the extension was the exception and this paragraph said so - deleting a card there was immediate and final. It is not any more: its board has the same Trash filter, the same 90 days and the same Restore, and because a browser extension has no moment it “starts”, it clears what is past the window each time you open the board or the popup. One honest difference, and it is in your favour: the extension never deletes a file from your disk, at any point, not even when the 90 days are up. Everything it writes goes to the folder you chose or to your Downloads, and those are yours - so emptying its Trash removes the card and leaves your files exactly where they are.
The web library works the same way, with one addition: the share page stops working the moment you delete what it points at. Something shared by mistake is out of reach at that address immediately, even though the file itself waits out the same 90 days in case you restore it, and restoring brings the link back with it. One honest edge, and it is wider than a share page: every file you store with us also has its own direct address at Cloudflare - each screenshot, each recording, and any downloadable MP4 generated from one - and those addresses do not expire on their own. Anyone who saved one before you deleted can still open that file until it is removed for good. Anything past the 90-day window is removed the next time someone in your workspace opens the library, and the stored files, the streaming copy and any generated MP4 are removed with it.
Use Delete shown on the desktop board to move cards to the Trash in bulk - it acts on exactly what the filter and the search box are currently listing. Nothing is taken off your disk at that point; the files go when the Trash empties. If you have already saved files to your own folder, those are yours and stay where they are, because they were never ours to delete.
The app also keeps a small rolling log - the current run and the one before it - in its own settings folder, to make a crash diagnosable. It records what the app did rather than what you captured: no picture, no video, no note and nothing you typed goes into it. Two things in it do come from you, and they are worth knowing before you send one of these files to us or to anyone else. If you are signed in it writes your email address each time the app starts, and it writes the file path of a recording it kept, could not play, or uploaded - a folder name and a file name, never the recording itself.
What leaves your machine
By default, one thing: a check for a new version. A few seconds after the desktop app starts, it downloads a small file from GitHub that says what the newest release is, and compares it with your copy on your machine. That request tells GitHub your IP address, the same as visiting any web page - your version number is not sent. If there is a newer release the app offers it; nothing is installed without you saying yes.
Uploading and sharing are off until you switch them on. Settings has a checkbox for it, off by default, and nothing leaves your machine until you turn it on and sign in. Once you have, every finished recording is registered with SnapBuddy's own server, under the account you signed in with - or with your own server, if you have put one in the self-hosting settings - and then the video file is sent to whatever upload address that server returns, which may be a third-party video host rather than the server itself. A share link comes back and goes to your clipboard. Anyone with that link can watch the recording. Clearing the checkbox or either field stops it.
Turning a recording into a walkthrough sends pictures, not a video. It is a separate press, on the same Sharing switch, and it is worth reading on its own because what it sends is not what the paragraph above sends. From the interaction track already beside your recording, the app cuts one full-resolution screenshot of your screen for each click, and sends them with the position and the time of every one of those clicks. The list of steps goes to that server; each picture then goes to the storage address it hands back, one at a time, exactly as the video file does. A screenshot of a screen can hold anything that was on it, and is easier to read at a glance than a frame of video. Nothing is sent unless you ask for it, and the same checkbox and fields that stop the recording upload stop this too.
Tags on an uploaded capture are sent as you type them. Labelling a card is a local thing and stays local - until that card has been uploaded. Once it has, the words you put on it go to that same server, on the same Sharing switch as everything above, so that the rest of your workspace can filter by them. It sends the card's whole list of tags, every time you add or remove one. The server adds what it is sent rather than replacing what it already holds, so taking a tag off a card there does not take it off the copy on the server - remove it from your library on the web if you want it gone from the workspace. A card you never uploaded sends nothing, ever - there is nothing on the server for it to belong to. Worth reading on its own because a tag is not a picture or a recording: it is free text you wrote, and people label a bug with the name of the product, the customer or the incident it belongs to.
The marks on an uploaded recording are sent as you draw them. Drawing on a recording is a local thing and stays local - until that recording has been uploaded. Once it has, the marks go to that same server, on the same Sharing switch as everything above, so that the people you share the link with see them over the video. It sends the whole set of marks each time you add, retime or remove one: where each one sits, when it shows and hides, and any words you typed on it. A recording you never uploaded sends nothing, ever. Worth reading on its own because the marks are not part of the video file - the recording itself stays as it was, and these are sent separately, afterwards, so that the person watching can be shown them at the right moment. A caption is free text you wrote about the thing on your screen, and a redaction or a blur records where on that screen something you did not want seen was.
Signing in on the desktop app is optional, and new. You never needed an account to capture, annotate or save, and you still do not - that has not changed. If you press Sign in, the app opens your browser at the server address in Settings and you sign in there, with whatever method you already use. Your password, and a second factor if you have one, are typed into the browser and never reach the app. The browser then hands the app a one-time code, which it swaps with that server for a session. That exchange tells the server your IP address, as any web request does.
While you are signed in, the app checks that the session still exists. It asks the same server when you come back to one of its windows, and at most once every few minutes. It sends the stored token and nothing else - no capture, no filename, no note - and it is how the app notices that you signed out somewhere else instead of going on naming an account you have left. Like any request, it tells that server your IP address, and therefore roughly when you were using the app. If it gets no answer - you are offline, or the server is down - nothing happens and you stay signed in.
What is then kept on your machine, and where. The app stores a refresh token - the thing that keeps you signed in - together with your email address and which plan you are on, in the Windows Credential Manager, not in a file you could open by accident. Your API key, if you use one, moved there too. The short-lived token the app actually makes requests with is held in memory only and is never written down at all. Pressing Sign out deletes the stored entry, not just the session in the running app.
The browser extension
The extension can sign you in, and it can upload one picture at a time when you press Upload on a card. Those are the only two things this extension sends. Signing in happens in your own browser, on our website, with the same password and second factor you would use there - the extension never sees your password. What it gets back is a single-use code it swaps once for a session. Nothing on a card goes with the sign-in, and nothing at all leaves until you press Upload. When you do, that one picture goes to your workspace and is stored in the cloud, and a link to it goes on your clipboard: anyone who has that link can open it. Your note, your tags, your annotations and your developer log stay in this browser, and recordings are not uploaded from the extension at all. Its security policy names exactly one addressand no other, so a picture cannot go anywhere else even by mistake. The extension cannot delete a picture once it has been uploaded - delete it from your library.
It keeps no sign-in credential on your machine. What it holds lasts only as long as your browser is open, and closing your browser signs you out. Nothing is written to disk, so there is nothing there to be stolen and nothing left to revoke. That is a deliberate trade - you sign in again each time you restart your browser - and it is the reason this paragraph can say what it says.
It takes a picture of the visible area of the tab you are on, and it can also snap another window, or a whole screen. That goes through your browser’s own picker: the extension asks, the browser shows you the list, and only what you choose there is in the picture - it cannot pick for you. If you tick keep sharing, that one choice stays live so the next snap needs no second prompt, and the board shows an indicator for as long as it does.
Recording reaches the same three surfaces as snapping. There are two record buttons. Record tab is fixed to the tab you are on and always takes that tab’s audio - you are not asked, because that is what the button is for. Record screen hands you the same browser picker the snap uses and records what you choose there: a tab, another window, or a whole screen. That one takes sound only if you tick the box beside it first, and even then only if your browser will give it for what you picked - a single window commonly will not.
Where a recording does carry sound and other people are in it, you are recording them: on a call that is everyone on it, and their meeting app will not show its own recording indicator, because the capture happens outside it. In many countries and US states, recording someone without telling them is a criminal offence, and your consent is not theirs to give. The extension says so on both buttons rather than in a tooltip. What any of it captures is stored in your browser profile, on your machine.
You can record your microphone with a screen recording, and it is off until you switch it on. It is mixed in alongside whatever sound the shared surface already carried, rather than replacing it, and a microphone hears the room - anyone near the machine, who is on no call and has agreed to nothing. You can add your camera to a screen recording, and it is off until you switch it on. It is drawn into the corner of the picture as a small circle, and it is part of the video rather than a layer over it, so it cannot be removed from a recording afterwards. Refusing your browser’s permission for either stops the recording entirely rather than continuing without it. None of this changes where anything goes: recordings stay in your browser profile - Upload is for pictures, not recordings - and signing in and uploading a picture remain the only two things this extension sends.
The extension’s camera costs frame rate, and the warning is beside the box. With the camera switched on, the whole recording - the screen as well as the bubble - is drawn frame by frame in the SnapBuddy tab, and your browser slows that to about one frame a second whenever that tab is not the one in front, which is most of a normal take. With the camera off, the picture goes straight to the file at full rate.
Developer capture, which is off until you switch it on for one site. When you turn it on for the site you are testing, your browser asks whether to give the extension access to that one site. Nothing is requested when you install it, and turning capture off hands the access back. While it is on for a site, the extension reads that site’s console messages and the addresses, methods, status codes and timings of its network requests, and keeps up to four screenshots taken automatically at moments something failed - only ever of the tab the problem happened in, while that tab is the one you are looking at.
Credentials are removed from the log before it is stored: authorization headers, cookies, and anything shaped like an API key or a token. The screenshots are pictures and nothing can be stripped out of them. All of it is held in memory and cleared when you close your browser, unless you save it onto a card - and none of it is sent anywhere. Signing in and uploading a picture are the only two things this extension sends, and a developer log goes with neither: uploading a card sends the picture and only the picture.
On every site you have not switched it on for, and on every site if you never switch it on at all, the extension runs no code inside the page: the page text, your cookies and anything you type stay out of its reach.
Reading captures from a coding assistant
SnapBuddy ships an MCP server: a small program you can connect to Claude Code, Claude Desktop, Cursor or anything else that speaks the same protocol, so an assistant can read the captures you have already saved to a folder instead of you pasting them in by hand. That program opens files on your disk and hands back what it finds, and nothing it does leaves this computer - the only connection it ever makes is to SnapBuddy itself, on this machine’s own loopback address, and only to pass on a request for a new picture. It is not running at all unless you have added it to that client’s configuration yourself.
Reading is not all an assistant can do any more, and the next section is about the part that takes new pictures. Reading needs only that program and the folder you saved to. Taking a new picture needs SnapBuddy itself running with a switch turned on, and it is refused until then - two different permissions, which is why they are described separately rather than as one feature.
What it changes is who reads your captures, not where they are kept. The moment an assistant asks it something, what it answers with - your note, the page you were testing, and the console messages and request addresses captured from that page - goes to that assistant, and most of them run in the cloud. The file never leaves your disk; the contents do. That is the same trade as pasting a bug report into a chat window, and it is worth knowing that it is the trade. Which assistant, and what that company does with the text, is between you and them.
It can only read what you have saved to a folder with its notes and data files beside it, which is what Save files writes and what the Saving writes setting controls. A save that wrote only the picture is invisible to it. Cards that are still only in the app or in the extension are not on your disk, so it cannot see them, and neither can anything you connect it to.
When an assistant asks for a new capture
SnapBuddy can also let an assistant ask for a capture that does not exist yet, rather than only reading ones you already took. This is off until you turn it on in Settings, under AI agents. While it is off there is nothing listening and nothing to reach.
Asking for a region opens the picker, and your drag is the permission. An assistant can ask; it cannot draw the box. Whatever ends up in the picture is an area you selected with the pointer, on your own screen, in the moment it was taken. There is no second dialog, because the drag already is the answer - and if a picker appears that you did not expect, nothing is captured unless you drag.
Asking for the whole screen is different, and it stays off. That one has no gesture in it, so it needs a separate grant in Settings, and the grant ends when you quit SnapBuddy - it is never remembered between runs. Until you give it, a request for the whole screen is refused.
Every capture an assistant asks for is recorded on your board, marked as theirs. There is no picture taken this way that you cannot find afterwards and see was not yours.
Where the picture goes. The image is handed back to the assistant that asked for it, and most of them run in the cloud - so this is the same trade as the section above, with a sharper edge: what travels is a fresh picture of part of your screen, taken just then, including whatever else was on it inside the area you selected. The file is also saved to your board on this computer. Which assistant, and what that company does with the image, is between you and them.
What can reach it. The program listens only on this computer’s own loopback address - never on your network - and it answers nothing without a secret token SnapBuddy generates and shows you in Settings. Requests that arrive from a web page are refused outright, whatever they carry. You can regenerate the token at any time, which immediately stops anything holding the old one.
Signing in with Google or GitHub
Where a sign-in with Google or GitHub is offered, using it tells that company that you have a SnapBuddy account, because the sign-in happens on their page and they have to be asked whether it worked. We receive your email address and nothing else from them - no contact list, no repositories, no documents, and no permission to act on your account. We do not ask them for anything beyond confirming who you are.
It is a choice, never a requirement. An email address and a password, or a magic link, reach the same account with the same features, and nothing on your side is lost by refusing every provider. If you have already used one and would rather not, changing your sign-in method does not move your captures: they belong to the workspace, not to the button you arrived through.
The web app
The web app takes captures itself, and they are uploaded, not kept locally. Capture and Record ask your browser for a screen: the browser shows you its own picker, and only what you choose there - a tab, another window, or a whole screen - is in the picture or the recording. A recording also carries that surface’s sound where your browser provides it, which on a call means everyone on it, with the same warning as above. Unlike the desktop app and the extension, there is no local board here: a capture is presigned, uploaded, and stored in your workspace as part of taking it, so it leaves your machine as soon as you keep it.
You can add your camera to a recording, and it is off until you switch it on. Tick the camera box before you start and your browser asks whether to let the page see it; what it sees is drawn into the corner of the recording as a small circle. It is part of the video, not a layer on top of it - once a recording exists, the camera cannot be removed from it. If you refuse your browser’s request, nothing is recorded at all, the same as with the microphone. If the camera stops mid-recording - unplugged, or permission withdrawn - the recording carries on without it rather than failing. Nothing new leaves your machine for this: the picture is combined with the screen here, in your browser, and the result travels the same way any recording does.
You can add your microphone to a recording, and it is off until you switch it on. Tick the microphone box before you start and your browser asks whether to let the page listen; what it picks up is mixed into the recording alongside whatever sound the shared surface was already carrying, rather than replacing it. A microphone hears anyone near the machine, not only you - someone else in the room, or a call you are taking out loud - and the same warning as above applies: tell them first. If you refuse your browser’s request, nothing is recorded at all, rather than a recording arriving quietly without the sound you asked for. If you later ask for captions on a recording that carried a microphone, that speech is turned into text with the rest of the audio, and you are warned before you agree - the captions paragraph below says who does that and what is kept.
If you sign in on the web, we store your email address so you can sign in again, and anything you deliberately upload. Sharing is done by an unguessable link; anyone who has the link can open it, so treat one like a password. Who holds it, and where, is below.
What guards that account is held here too. If you set a password, our database provider stores a hash of it and not the password itself. If you turn on a second factor, the secret your authenticator app is set up with is held there as well, and your recovery codes are kept only as digests: each code is shown once, when it is generated, and after that nothing here can print it back. None of it is used for anything but letting you in.
Captions are opt-in, one recording at a time. When you ask for them, Cloudflare, which is already storing that recording, transcribes its audio and attaches the text to the player. You are asked to agree first, and if the recording captured system audio the request says so before you do, because the speech being turned into text may be other people on a call. No searchable copy of the words is kept here: the captions live with the video at Cloudflare, and what this app stores is the language and whether the track is ready.
Three things here can be sent to Anthropic, and each one is a button you press. Asking for one on a capture sends what this app already holds about that capture to Anthropic: its title, type, status and triage state, how long it runs and how large it is, the labels on the marks you drew, and whether the recording had a camera or system audio switched on. The picture, the video and the audio are not sent, and neither is your email address, a share link, or the address of a stored file. What comes back is a draft for you to check, on a page only your own workspace can open.
The three are the bug draft, which writes up a capture as something an engineer can act on; the title and summary, which names what a capture shows; and help with a note, which takes a rough note you have written and turns it into what happened, what you expected, and how to see it again. The first two send only what is described above, which is what this app already holds. The third also sends the words you typed, because rewriting them is the whole point of asking. Nothing goes for any of the three unless you press the button that asks, once, each time. Declining leaves the capture exactly as it was, and none of the three runs on a timer, as you type, or when a page opens.
When you take a capture in the web app, SnapBuddy also records the browser family and version, the language, the time zone and the screen size of the machine that took it, and stores those four values with that capture. They are there because a bug report that cannot say what it was taken on is most of the way to useless, and the composer shows them to you before you save so that what is kept is never a surprise. You can turn them off. The tick box beside them in the composer is on to begin with, and a capture saved with it off is saved with none of the four. Nothing else about the machine is recorded either way: no full browser identifier, no device name, no network address beyond what any web request carries. They are part of the capture, so they are deleted when it is, and exported when it is.
If you ask for early access
The download page has a form rather than a mailing list. If you have asked us for early access, we hold the email address you typed, which of Windows or Mac you ticked, the note you wrote if you wrote one, the date you asked, and which page on this site you were on when you asked. It sits in the same database as everything else described below, it is read by a person rather than by anything automatic, and it is used to write back to you about SnapBuddy and for nothing else. There is no newsletter, no sequence and no third party: the form posts to this service, not to a form company.
Reply to any message we send you and ask us to delete it, and we do, which is the route that matters here because you have no account to delete it from. You can also write to us at the address at the foot of this page and ask what we hold, and the answer is the three things named above. We keep the list while there is still something to tell you about; when there is not, it goes.
Why we are allowed to do this
Almost nothing here needs a legal basis, because almost nothing reaches us: what the desktop app captures stays on your machine, and we never see it.
- Your email address, if you sign in on the web - so the account can exist at all. That is performance of a contract: without it there is no account to log in to.
- What guards your account: your password, and your second factor and recovery codes if you turn one on - the same basis, performance of a contract: an account you can sign in to, and that other people cannot, is the account you asked for. The recovery codes exist so that losing the phone that holds your second factor does not lose the account with it.
- Anything you deliberately upload or share - same basis. You asked for a link; making one requires holding the thing it points at.
- Captions, and any of the AI features named above, if you ask for one: your consent, given for that capture. Every one of them is a button you press, once, for one capture: nothing is sent for any of them unless you ask, and declining leaves the capture exactly as it was.
- Your email address, if you ask for early access: your consent, given by filling in that form. Nothing else is done with it, and replying to ask us to delete it withdraws the consent and removes the row.
- The update check - our legitimate interest in your copy being the fixed one. It downloads a file and sends nothing about you but the IP address any download reveals, and it is the only thing the desktop app sends anywhere by default.
- The bot check on the sign-in pages - our legitimate interest in accounts not being created in bulk by software. It sends nothing about you but the IP address and user agent any page request reveals, and it runs only on those three pages.
- Error reports from our server - our legitimate interest in finding and fixing what breaks. A report carries the error and where in our code it happened, and nothing your browser sent with the request.
No decision about you is made automatically, and there is no profiling. Nothing here is used to score, rank or judge anyone.
Where cloud data is held
Only what you sign in with or deliberately upload ever leaves your machine, with one exception named below: a bot check runs on the sign-in, sign-up and password-reset pages before you type anything. When it does, six companies handle it, each acting on our instructions and none permitted to use it for anything else. Your account and the records about your captures are held by Supabase and the site is served by Vercel. The captures themselves are stored and delivered by Cloudflare: screenshots live in its R2 storage, recordings are processed and streamed by its Stream service, and the MP4 offered for download is generated there. When you, or anyone holding a share link, views a capture, the browser fetches the picture or the video from Cloudflare directly, which sends Cloudflare what any web request carries: an IP address, a user agent, and the address of the page doing the asking. The emails this service sends you, confirming an address, signing you in with a magic link, resetting a password, or telling you that the password, email address, second factor or a sign-in method on your account changed, are relayed by Google, which is handed your email address and what the message says, including any link in it; what it does with mail in transit is covered by its privacy policy. That is a different thing from the sign-in button described above: there, Google acts on its own account with you, and here it carries our mail on our instructions. When our own server hits an error, a report of it is sent to Sentry: the error itself and where in our code it happened. It runs on the server only and nothing of it runs in your browser. The report leaves out your IP address, your cookies, the address of the page you were on and anything else your browser sent with the request; it says only which kind of page it was, and share-link codes and email addresses are taken out of the error before it goes. And Anthropic, which holds nothing of yours and receives nothing unless you press one of the buttons named under The web app above. It then receives only the details listed there, plus, for the note, the words you typed into it.
A bot check runs before you sign in. The sign-in, sign-up and password-reset pages load a challenge from Cloudflare Turnstile, which runs in your browser as the page opens, before you type anything, and whether or not you have an account. Cloudflare receives your IP address, your browser’s user agent and which of our pages you are on, and checks whether the browser looks automated. It is there to stop accounts being created in bulk. We do not receive anything from it but a pass or a fail.
Two more companies are built into this site and are switched off. If they are ever switched on, this is what each would receive. PostHog would be told which pages a signed-in person opens and which features they press. It is mounted behind the sign-in and never on a page you can read without an account - including this one, which measures nobody. OpenAI is the one of the two that would be sent your own material rather than facts about your clicks, so it is worth being exact about which: the audio of a recording, if captions are ever generated for it, and the text of your captures - your notes and what was read from the page - if searching by meaning is ever switched on. Not the pictures, and not the video. OpenAI does not use anything sent through its interface to train its models; it holds it for up to thirty days to check for abuse, and then deletes it. Neither is turned on as this page was last updated, so neither receives anything from you and neither is counted among the six above. Turning either on changes where your data goes, so it changes the date at the top of this page and moves that company into the paragraph above.
The database, including your email address and the records about your captures, is stored in London, United Kingdom (eu-west-2), which is outside the European Economic Area. That is allowed because the European Commission has decided the United Kingdom protects personal data adequately: Implementing Decision (EU) 2025/2574 of 19 December 2025, which runs until 27 December 2031. No further paperwork is needed from you or from us while that stands. If it is ever withdrawn, the fallback is already in place: our database provider’s data processing agreement carries the European Commission’s standard contractual clauses and the UK addendum.
Capture files do not all rest in the same place. Screenshots are stored in a Cloudflare R2 bucket created with a European Union jurisdiction, so those files stay in the EU. Recordings are not: Cloudflare Stream offers no equivalent region control, so a recording is held on Cloudflare’s global network and may rest outside the EEA. We would rather tell you that than round it off. Both are covered by Cloudflare’s data processing agreement, which carries the European Commission’s standard contractual clauses.
Error reports are stored in the European Union. Sentry keeps them in Frankfurt, Germany, for up to 90 days. Sentry staff and some of its service providers outside the EU, in the United States among them, can still reach them; its data processing agreement covers that with the EU-U.S. Data Privacy Framework and, as a fallback, the European Commission’s standard contractual clauses.
What you send to Anthropic is processed in the United States, which is outside the European Economic Area. We ask for that specifically rather than taking whichever data centre is free, so the answer to where your words were read is the same one every time. Anthropic does not use them to train its models. It keeps them for up to thirty days, during which Anthropic may look at them for safety and security, and then deletes them. Nothing reaches them at all unless you press one of the buttons named under The web app above, which is why consent is the reason listed for those features further up this page.
Your rights, and how to use them
Because we are established in the Czech Republic, the GDPR applies to everything above. You can ask us to:
- Show you what we hold about you, and give you a copy.
- Correct anything that is wrong.
- Delete it.
- Restrict what we do with it while a dispute is sorted out.
- Hand it over in a portable form - or to someone else, if that is technically possible.
- Object to anything we do on the basis of legitimate interest, which today means the update check, the bot check on the sign-in pages and the error reports from our server.
Write to the address at the bottom of this page and we will do it within 30 days. There is no charge and you do not have to give a reason.
You can download a copy yourself, from Account → Your data. It is a zip: every row we hold for you as JSON, plus your capture images, their thumbnails, and any walkthrough step images and voiceover audio. The archive does not contain your recording videos. Cloudflare holds those and only ever returns a smaller re-encoded copy, never the file you recorded, so it is not put in the archive and called yours. Save the ones you want from each recording while your account is open. Your password, two-factor secret, recovery codes and API keys are left out on purpose - they are credentials, and a downloaded file holding them turns one lost archive into a lost account.
A workspace you share with other people is listed by name only, without its captures. That is the same boundary deletion draws from the other side: their work is not yours to take, and it is not yours to remove either.
If we get it wrong, you can complain to a regulator, and you do not need our permission or involvement. Ours is the Czech data protection authority, the Úřad pro ochranu osobních údajů (Pplk. Sochora 27, 170 00 Prague 7). You may also complain to the authority in the country you live or work in.
What we do not do
- We do not sell or share your captures, notes or personal information.
- We do not use your captures to train any model.
- We do not track you across other websites.
- There are no ads and no advertising identifiers.
Your choices
- Microphone, system audio and camera are all off unless you turn them on for a particular recording.
- You choose the folder your files are written to, and whether they are written automatically at all.
- You can delete any card, or use Delete shown to delete many at once. Backup writes every card to a single file you keep: the notes, the statuses, the thumbnails, the annotations, the share links and the trash timers. Your recording files are not in it. A recording’s card carries the path to its video and a small thumbnail, never the video, so a backup restored on another machine shows recordings whose files are not there. Copy those yourself if you want them kept.
- To remove everything, delete your cards, then delete the files in your save and recordings folders. A deleted card waits in the Trash for 90 days, so use Delete forever there if you want it gone now. Two things sit outside those folders and are easy to miss: the rolling log and your settings are in the app’s own settings folder, and the refresh token, your email address and your plan are in the Windows Credential Manager, which Sign out clears.
You can delete a web account yourself, from Account → Deleting your account. Nothing goes immediately: it is scheduled, and for 30 days the account keeps working and you can change your mind, which is there so a mistaken press is not final. After that your captures, recordings and the files behind them are removed and we cannot bring them back. Take a copy first if you want one - Account → Your data does it, and once the deletion is done there is nothing left to export. The archive does not contain your recording videos. Save those from each recording before the 30 days are up.
If other people are members of your workspace, deleting your account will not delete the workspace - their work is not yours to remove. Hand the workspace to one of them first, and then your account can go. You can still write to us at the address below instead, for this or for anything else, and we will do it within 30 days.
Children
SnapBuddy is a tool for software teams and is not intended for children under 16. We do not knowingly collect anything from them, and the app has no age or date-of-birth field.
Changes
If this notice changes in a way that affects what is captured or where it goes, the date at the top changes.
Who we are, and how to reach us
SnapBuddy is operated by GC S.R.O., the data controller for the processing described here, registered in the Czech Republic under company number 21384754.
Vinohradská 1511/230PragueCzech RepublicQuestions about this notice, or a request to see or delete your data: legal@snapbuddy.ai. We will respond within 30 days.