Privacy Policy
Last updated: June 2, 2026
1. Who We Are
SocialSnap.io ("we", "us", or "our") operates the SocialSnap.io website and service. This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding that data. For any privacy-related questions, contact us at rasel@raselmahadi.com.
2. Data We Collect
We collect the following categories of personal data:
- Account data — your email address and, if you set one, a display name. Collected when you sign up.
- Usage data — the YouTube channels you subscribe to, summaries you open, and on-demand summarize requests you make.
- Billing data — subscription plan and billing history. Payment card details are handled entirely by Stripe and never stored on our servers.
- Contact data — name, email, and message content when you submit the contact form.
- Technical data — IP address, browser type, and device information collected automatically via server logs and Supabase Auth.
We do not collect sensitive personal data such as government IDs, financial account numbers, or health information.
3. How We Use Your Data
We use your data to:
- Create and manage your account and authenticate your sessions.
- Monitor your subscribed YouTube channels and generate AI summaries.
- Deliver summary emails and transactional notifications to your inbox.
- Process payments and manage your subscription via Stripe.
- Respond to contact form submissions and support requests.
- Detect and prevent fraud, abuse, and security incidents.
- Improve the Service through aggregate, anonymised usage analysis.
We do not use your data for advertising, and we do not sell your personal data to third parties.
4. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract — processing necessary to provide the Service you signed up for.
- Legitimate interests — security monitoring, fraud prevention, and aggregate analytics.
- Legal obligation — where we are required to retain records by law.
5. Third-Party Services
We share data with the following third-party processors to operate the Service:
- Supabase — database and authentication. Your account data and usage records are stored here.
- Anthropic (Claude) — AI model used to generate video summaries. Video transcript text is sent to Anthropic for processing. No other personal data is shared.
- YouTube Data API — used to fetch channel and video metadata for channels you subscribe to.
- Resend — transactional email delivery. Your email address is shared to send summary and notification emails.
- Stripe — payment processing. Stripe handles all billing data under their own privacy policy.
- Inngest — background job orchestration. No personal data beyond what is needed to trigger jobs is shared.
All processors are contractually required to protect your data and use it only as directed by us.
6. Data Retention
We retain your account data for as long as your account is active. When you delete your account — either from your Profile settings or by contacting us — your personal data (account details, channel subscriptions, reading history, and preferences) is deleted immediately and permanently. Billing records may be retained for up to 7 years where required by applicable law. Anonymised, non-identifiable usage data may be retained for service improvement purposes.
7. Cookies and Tracking
We use strictly necessary cookies to maintain your authenticated session via Supabase. We do not use third-party advertising cookies or tracking pixels. No analytics cookies are set at this time.
8. Your Rights
Depending on your location you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — request correction of inaccurate data.
- Erasure — request deletion of your personal data.
- Portability — request your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Restriction — request that we limit how we use your data.
You can exercise your right to erasure directly by deleting your account from your Profile settings. This immediately and permanently removes all personal data we hold about you.
For all other rights, or if you need assistance, email us at rasel@raselmahadi.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encrypted connections (HTTPS), access controls, and regular review of our security practices. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
10. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the "Last updated" date when we do. For material changes, we will notify you by email or a prominent notice on the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact
For any questions or concerns about this Privacy Policy or how we handle your data, please contact us at rasel@raselmahadi.com.