Privacy Policy
Last updated: 8 October 2026
1. Introduction
getSnap.dev ("we", "us", "our") operates the getsnap.dev website and the api.getsnap.dev API service. This privacy policy explains how we collect, use, and protect your information.
2. Information We Collect
Account Information
When you sign up, we collect your email address. This is used to create your API key, send transactional emails, and identify your account.
Usage Data
We log API requests including: the endpoint called, the response status, the response time, and the timestamp. These logs record that a request happened, not what it contained — we do not log the URLs you capture, the HTML you submit, or the bodies of your requests.
Payment Information
Payment processing is handled entirely by Stripe. We do not store credit card numbers or payment details on our servers. See Stripe's Privacy Policy.
Screenshots
Screenshots you capture are stored temporarily on DigitalOcean Spaces CDN. Cached screenshots expire after 24 hours. We do not analyze, sell, or share the content of your screenshots.
Credentials you supply for authenticated captures
The API lets you send your own cookies and HTTP headers so you can capture pages behind a login. For a one-off capture these are used for that request and then discarded.
If you save them in a scheduled capture, we store them. A schedule has to be able to repeat your request, so the options you created it with — including any cookies, headers and webhook secret — are stored in our database until you change or delete that schedule. They are stored as submitted, not encrypted at rest, on a server only the application can reach.
Please treat this as you would any credential handed to a third party: prefer a dedicated, least-privilege account for scheduled captures rather than your own session, and delete the schedule when you no longer need it. Deleting a schedule deletes the credentials stored with it.
3. How We Use Your Information
- To provide and maintain the API service
- To send transactional emails (welcome, upgrade confirmation, support replies)
- To enforce rate limits and usage quotas
- To process payments via Stripe
- To respond to support requests
4. Data Sharing
We do not sell your data. We share data only with:
- Stripe — for payment processing
- Resend — for sending transactional emails
- DigitalOcean — for hosting and screenshot storage
- Cloudflare — for DNS and email routing
Your data also moves in these ways, which are driven by features you choose to use:
- Teams. If you join a team, your captures draw on that team's shared quota, and the team's owner and admins can see per-member usage — how many captures you made and when. Your API key itself is never shown to them. If you do not want your activity visible to a team owner, use a personal account.
- Webhooks. If you configure a webhook URL, we send capture results to that address. You choose the destination, and we have no control over what happens to the data once it arrives.
- Your own S3 storage. If you configure S3 upload, captures are delivered to the bucket you nominate, under your credentials.
- Referrals. If you sign up through someone's referral link, we record the link between your account and theirs so we can apply your discount and credit them when you first pay. We tell the referrer that a referral converted and when. We never tell them who you are.
5. Data Retention
- Account data is retained while your account is active.
- Usage logs (endpoint, status, timing) are deleted automatically after 90 days.
- Cached screenshots expire after 24 hours and are deleted from CDN storage automatically.
- Scheduled capture options, including any cookies, headers or webhook secret saved with them, are retained until you change or delete the schedule.
- Billing records are retained as long as tax and accounting law requires, which is longer than the periods above.
- Referral records linking a referrer to a referee are retained while both accounts exist, because they determine credit already issued.
You can request deletion of your account at any time by contacting support@getsnap.dev.
6. Security
All traffic to getsnap.dev and api.getsnap.dev is encrypted with HTTPS/TLS. Our database is reachable only by the application itself — it is not exposed to the internet — and the application runs as an unprivileged user in a container with no elevated capabilities.
Your API key is a bearer credential: anyone holding it can use your account, so treat it like a password. Keep it server-side, never commit it to a repository and never embed it in a web page. If you need to display a capture in a browser, use a signed render link (POST /v1/render-link), which never contains your key. If a key is exposed, contact support@getsnap.dev and we will revoke it.
We do not store your API key. We keep only a SHA-256 hash of it, which is enough to recognise the key you send but cannot be turned back into the key itself. The practical consequence for you: the key is shown once, at signup, and in your welcome email — save it then, because nobody, including us, can retrieve it afterwards. If you lose it, contact support@getsnap.dev and we will revoke the old key and issue a new one.
7. Cookies
We use no analytics, no advertising pixels and no third-party trackers. Nothing on this site reports your browsing to anyone else.
We set exactly one cookie, and only if you arrive through a referral link:
| Cookie | Purpose | Contains | Lifetime |
|---|---|---|---|
getsnap_ref |
Remembers which referral code brought you here, so the right person is credited if you later sign up | A short referral code (for example A3R76MAV). No personal data and no identifier for you |
30 days |
It is a first-party cookie, is never sent to anyone else, and the site works normally if you block or delete it — you simply will not receive the referral discount. If you arrive without a ?ref= link, no cookie is set at all.
8. Your Rights
You have the right to:
- Access your personal data (via the /v1/usage endpoint)
- Request deletion of your account and data
- Export your usage data
To exercise these rights, contact support@getsnap.dev.
9. Changes
We may update this policy from time to time. Changes will be posted on this page with an updated date.
10. Contact
For privacy questions, contact support@getsnap.dev.