Privacy Policy
Last updated: 1 September 2026. This policy describes how Snaptix (https://snaptix.ai) collects, uses, stores, shares and protects information you provide when using the service, including data we receive from Google APIs.
What we collect
- Account: email and name from your sign-in provider or email OTP flow.
- Workspace data: files you upload (e.g. spreadsheets), spreadsheets you choose to connect from a linked Google or Microsoft account, derived cleaned copies we store for charts and analysis, and metadata such as column types and row counts.
- Connected-source credentials: OAuth access and refresh tokens for accounts you connect, and any keys or connection strings you enter for other sources (e.g. a database or a Google service-account file).
- AI usage: when you run a briefing, chat, or digest, relevant portions of your workspace summary or tables are sent to our AI provider to generate text. Do not upload regulated or highly sensitive data unless your agreement with us allows it.
- Billing: if you subscribe, our payment provider (Razorpay) processes payment data under their terms. We do not store card numbers.
How we access and use Google user data
If you connect a Google account, Snaptix requests only the scopes below and uses the data received from them only to deliver the features you asked for. We do not request or use Gmail, Calendar, Contacts, Photos or location data.
- openid and email — we read your Google account's email address and user identifier, and use them solely to identify which Google account a connected source belongs to, to display it in the app, and to reconnect it when a token expires.
- Google Drive (drive.readonly) — we read your Drive file list in order to show you a browsable list of your spreadsheets (Google Sheets, .xlsx, .xls and .csv files) so you can pick which ones to import. Once you pick a file, we read the contents of that file only in order to import its rows into your workspace, and we re-read it when you or a scheduled sync refreshes that source. We do not read, index, download or analyse any other file in your Drive, and we never write to, modify or delete anything in your Drive.
What we store. For each source you import we store a derived copy of that spreadsheet's contents (a cleaned table plus metadata such as column names, types and row counts) in our application database and object storage, because that copy is what powers your dashboards, briefings and chat answers. We also store the Google OAuth refresh token for the connection so scheduled syncs can run without asking you to sign in again. We store no other Drive content.
What we do not do. We do not use Google user data for advertising or ad personalisation, we do not sell it, we do not use it to build advertising or credit profiles, and we do not use it to train, fine-tune or develop generalised AI or machine-learning models — ours or anyone else's. Our staff do not read your Google user data except with your explicit permission (for example when you ask us for support), where required for security purposes such as investigating abuse or a suspected incident, or to comply with applicable law.
If you connect Google Analytics or BigQuery, you supply a Google service-account key yourself and we use it only to run the read-only queries needed to build the report or dataset you configured.
Who we share, transfer or disclose data to
We do not sell your data or Google user data, and we do not share it with advertisers or data brokers. We share it only with the following service providers, only to the extent needed to run Snaptix, and only under contracts that require them to protect it and to use it solely to provide their service to us:
- OpenAI (AI processing): when you run a briefing, chat or digest, the relevant portions of your workspace data — which may include data imported from Google Sheets or Drive — are sent to OpenAI's API to generate the response. OpenAI processes this as our service provider under the OpenAI API terms and does not use API data to train its models.
- Cloud hosting and storage: our application servers, managed PostgreSQL database and S3-compatible object storage (Amazon S3 or Cloudflare R2), which hold your account record, imported datasets and encrypted credentials.
- Razorpay (payments): receives your billing details if you subscribe. Google user data is never sent to our payment provider.
- Email delivery: our transactional email provider sends sign-in codes and digests to your address.
We may also disclose information if we are legally required to do so, or where necessary to investigate fraud, abuse or a security incident. If Snaptix is ever involved in a merger or acquisition, we will give you notice before your data becomes subject to a different privacy policy. In every case, any transfer of information received from Google APIs remains subject to the Limited Use requirements described below.
How we protect your data
- In transit: all traffic between your browser, our servers and Google's APIs is encrypted with HTTPS/TLS. The app is served over HTTPS only.
- At rest: our database and object storage are encrypted at rest by the hosting provider.
- Credentials and tokens: Google and Microsoft OAuth refresh tokens, service-account keys and any other connection secrets are additionally encrypted at the application layer with authenticated envelope encryption (AES-based Fernet) before they are written to the database, using keys held outside the database and rotatable without downtime. A database dump alone therefore does not expose your connected accounts. Tokens and secrets are never written to logs and are never sent to the browser.
- Access control: every dataset is scoped to the workspace that owns it and every API request is authenticated and authorised against that workspace, so one customer cannot read another's data. Administrative access to production systems is limited to staff who need it, is individually credentialed, and is used only for the purposes listed above.
- Minimisation: we request read-only scopes, import only the files you select, and keep no copy of Drive content you have not imported.
No system is perfectly secure, but if we become aware of a breach affecting your data we will notify you and any regulator as required by applicable law.
Retention and deletion
We keep imported data for as long as the source exists in your workspace. You can remove an individual source at any time in the app; removing it deletes the stored copy of that spreadsheet's data and, for a connected source, the stored OAuth credentials for that connection.
To delete your entire account and workspaces, use Account → Delete account while signed in. That removes your user record, owned workspace data and stored connection credentials from our application database and deletes the associated uploaded and derived files from our storage. Backups and operational logs may persist for a limited period, typically no more than 30 days, before they age out.
You can also revoke Snaptix's access to your Google account at any time from myaccount.google.com/permissions. Revoking stops all further access to your Drive; to also delete data already imported, remove the source or delete your account as described above.
Limited Use disclosure
Snaptix's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to certain processing. You can export or delete most data yourself in the app; for anything else, email us at the address below and we will respond within the period required by applicable law.
Changes to this policy
If we make a material change to how we handle your data, we will update the date at the top of this page and, where the change is significant, notify you in the app or by email.
Contact
For privacy requests or questions about this policy, email hello@snaptix.ai.