Snipp Privacy Policy
Last updated: 16 July 2026
1. Introduction
This Privacy Policy describes how personal data is processed when you use the Snipp mobile application (the "App") and the website trysnipp.app (the "Website"). Snipp is designed to minimize data collection. The App does not require an account, and the subscription information you manage in the App is stored on your device and, if you enable synchronization, in your personal iCloud storage. This document explains what data is processed, for which purposes, on which legal bases, and the rights available to you.
2. Data controller
The data controller for the processing described in this policy is Matteo Giovene (VAT no. IT01846360335), based in Piacenza, Italy. For any question about this policy or to exercise your rights, write to hello@trysnipp.app.
3. Data stored on your device and in your iCloud
The information you enter in the App, including subscription names, prices, billing cycles, renewal dates, notes, payment method labels and your display name, is stored locally on your device.
If you purchase Snipp Pro and enable iCloud Sync (disabled by default), this information is synchronized to your private iCloud database operated by Apple (CloudKit) in order to make it available on your other devices and to preserve it if you reinstall the App. This data is protected in accordance with Apple's iCloud security practices. The developer has no access to it, and it is never transmitted to the developer's servers. Your display name may also be stored in your iCloud key-value storage when iCloud is available on your device. Synchronization can be disabled at any time in the App settings.
Home screen widgets access a copy of this data that is shared locally between the App and the widget on the same device.
4. Data we collect
4.1 Usage analytics
The App uses PostHog, an analytics service hosted in the European Union (Frankfurt, Germany), to collect pseudonymous information about how the App is used.
The App generates a random identifier, stores it in the device Keychain and derives a SHA-256 hash from it. This hashed identifier is used to distinguish installations. It is not linked to your name, email address, Apple ID or the Apple advertising identifier (IDFA), and the developer cannot use it to identify you personally. Because it is stored in the Keychain, it persists if the App is reinstalled and may be shared across your own devices through iCloud Keychain.
The following information is associated with this identifier:
- product interaction events, such as opening the App, completing onboarding, adding or cancelling a subscription within the App, using the import feature, viewing the paywall, purchasing Snipp Pro, opening a notification and the outcome of catalog updates;
- the screens viewed within the App and application lifecycle events (installation, update, open, background);
- technical information provided by the analytics SDK: device model, operating system version, App version, system language, screen size and the country derived from your IP address (precise location is never collected);
- the answers given during onboarding: the selected goal, whether you believe you have forgotten subscriptions, the estimated number of subscriptions and the estimated monthly spend;
- for subscription-related events: the catalog identifier of the service and the billing cycle; custom subscription names, notes and payment methods are never transmitted;
- for the purchase of Snipp Pro: price, currency and product identifier;
- crash and error reports, including stack traces;
- feature flag and experiment assignments used for the gradual rollout of features;
- the result of Apple Search Ads attribution described in Section 4.3.
All monetary amounts included in analytics events are converted to euro and rounded to the nearest whole euro.
Analytics collection can be disabled at any time in the App under Settings → Privacy. The choice takes effect immediately.
4.2 Purchase data
Snipp Pro is a one-time purchase processed by Apple through the App Store. The developer does not receive your name, billing address or payment details. To validate purchases and restore your entitlement across devices, the App uses RevenueCat. RevenueCat receives the pseudonymous device identifier described in Section 4.1 and App Store transaction data: product identifier, price, currency, timestamps and the App screen from which the purchase flow was started.
4.3 Advertising attribution
Snipp is advertised on Apple Search Ads, Meta platforms (Facebook and Instagram) and TikTok. To measure the effectiveness of these campaigns, the App processes the data described below. The App does not access the Apple advertising identifier (IDFA) and for this reason does not display the App Tracking Transparency prompt. The developer does not sell personal data and does not share it with data brokers.
Apple Search Ads. At first launch, the App requests an attribution token from Apple's AdServices framework and submits it to Apple's Attribution API. Apple's response indicates whether the installation originated from an Apple Search Ads campaign and, if so, contains the campaign, ad group, keyword and ad identifiers and the country of the ad impression. This result is stored together with the usage analytics described in Section 4.1.
Meta and TikTok. The App integrates the Meta SDK and the TikTok Business SDK, which report the following conversion events: installation of the App, completion of onboarding and purchase of Snipp Pro (price, currency and product identifier). In the course of delivering these events, the SDKs transmit technical device data, such as IP address, device model and operating system version, to Meta Platforms Ireland Ltd and TikTok Technology Ltd, which process it in accordance with their own privacy policies. The subscription data you enter in the App is never included in these events.
SKAdNetwork. Install attribution additionally relies on Apple's SKAdNetwork framework, which provides aggregate campaign statistics without identifying individual users.
4.4 Server logs and infrastructure
The App downloads its catalog of subscription services, plans, prices and logos from the developer's servers and content delivery network. Requests to the catalog service include the App version and the pseudonymous device identifier, which is used for rate limiting and abuse prevention. Downloads of catalog files and logos from the content delivery network do not include App-level identifiers.
As with most Internet services, the servers produce standard technical logs (IP address, user agent, requested resource, timestamp) that are retained for a limited period by the hosting providers. Server errors are monitored through Sentry, which is configured not to collect personal information. Exchange rates are retrieved from the public feed of the European Central Bank; these requests do not contain identifiers.
5. On-device processing of imports
When you import subscriptions from screenshots, PDF documents, emails or bank statements, text recognition and classification are performed entirely on your device, using Apple's Vision framework and, on supported devices, Apple's on-device language models. The imported files and images are not uploaded to the developer's servers or to any third party. The App uses the system photo and file pickers and therefore has access only to the individual items you select.
6. Data we do not collect
The App does not require an account and does not collect your email address, contacts, photo library, precise location or advertising identifier. The optional display name is stored only on your device and in your iCloud. The subscription data you manage in the App is never transmitted to the developer's servers.
7. Purposes and legal bases (GDPR)
| Processing activity | Purpose | Legal basis |
|---|---|---|
| Operation of the App, catalog delivery, purchase validation | Providing the service | Contract, Art. 6(1)(b) |
| Usage analytics and crash reporting | Improving the App and fixing defects | Legitimate interest, Art. 6(1)(f), with an in-app opt-out |
| Advertising attribution | Measuring advertising campaigns | Legitimate interest, Art. 6(1)(f) |
| Rate limiting and server logs | Security and abuse prevention | Legitimate interest, Art. 6(1)(f) |
| Retention of purchase records | Compliance with tax and accounting obligations | Legal obligation, Art. 6(1)(c) |
8. Recipients of data
| Provider | Purpose | Location and safeguards |
|---|---|---|
| Apple Inc. | App Store, payments, iCloud/CloudKit, Search Ads attribution | According to your Apple account region |
| PostHog | Usage analytics, crash reports, feature flags | European Union (Frankfurt, Germany) |
| RevenueCat, Inc. | Purchase validation and entitlements | United States, Standard Contractual Clauses |
| Meta Platforms Ireland Ltd | Advertising campaign measurement | Ireland; onward transfers under Meta's privacy policy |
| TikTok Technology Ltd | Advertising campaign measurement | Ireland; onward transfers under TikTok's privacy policy |
| Railway Corp. | Backend hosting | European Union (Netherlands) |
| Cloudflare, Inc. | Content delivery network for the catalog | Global network; serves catalog content only |
| Sentry (Functional Software, Inc.) | Server error monitoring, personal data collection disabled | European Union (Germany) ingestion |
| Netlify, Inc. | Website hosting | Standard access logs only |
Personal data is not sold and is not shared with third parties for purposes other than those described in this policy.
9. International data transfers
Analytics data and backend infrastructure are located in the European Union. Where a provider processes data outside the European Economic Area (RevenueCat, and where applicable Meta, TikTok, Cloudflare and Netlify), transfers are based on Standard Contractual Clauses or an adequacy decision of the European Commission, as documented by each provider.
10. Data retention
- Subscription data remains on your device and in your iCloud for as long as you keep it. Deleting the App and disabling synchronization removes it in accordance with Apple's standard mechanisms.
- Analytics data is retained only as long as it is necessary for the statistical and product purposes described in Section 4.1 and is subsequently deleted or aggregated. You can request deletion at any time.
- Server logs are retained for a limited period and rotated by the hosting providers.
- Purchase records are retained for as long as required by applicable law.
11. Your rights
Under the GDPR you have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to data portability. Requests can be sent to hello@trysnipp.app.
Please note that because the data described in this policy is pseudonymous, the developer is generally not able to determine which data relates to you. In order to act on a request concerning analytics data, additional information may be required to locate it (Art. 11 GDPR). The most direct way to stop analytics collection is the in-app setting described in Section 4.1.
You also have the right to lodge a complaint with the Italian supervisory authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) or with the supervisory authority of your place of residence.
12. The Website
The Website (trysnipp.app) is a static website. It does not set cookies, does not use analytics or tracking tools, and loads all resources, including fonts, from its own domain. It is hosted by Netlify, which keeps standard access logs.
13. Changes to this policy
Changes to this policy will be published on this page, updating the date shown at the top. The current version is always available at trysnipp.app/privacy. In the event of material changes, notice will be given in the App or in the release notes.
14. Contact
Matteo Giovene
hello@trysnipp.app