Snaply – Privacy Policy

This Privacy Policy explains how personal data is collected, used, and protected when using the Snaply mobile application (the “Application”).

1. Data Controller

The data controller is:

Mariusz Bugajski Dev
Poland
📧 mariusz@bugajski.dev

2. Legal Basis for Data Processing (GDPR)

Personal data is processed in accordance with Regulation (EU) 2016/679 (GDPR) on the following legal bases:

  • Article 6(1)(b) – performance of a contract (providing access to the Application),
  • Article 6(1)(a) – user consent (where applicable),
  • Article 6(1)(f) – legitimate interest (e.g., improving app performance and security).

3. Scope of Collected Data

The Application collects only the following data:

  • Full name
  • Gender
  • Authentication data (handled via Firebase Authentication)
  • User statistics:
    • number of deleted photos
    • amount of storage space freed

4. Data We Do NOT Collect

The Application does not upload, process, or store user photos on external servers.

All photos remain exclusively on the user’s device.

5. Purpose of Data Processing

Data is processed in order to:

  • provide access to Application features,
  • manage user accounts,
  • display user statistics,
  • handle subscriptions and payments,
  • ensure security and improve performance.

6. Third-Party Services

Firebase (Google LLC)

Used for authentication and basic user data storage.

RevenueCat

Used to manage in-app subscriptions and validate purchases made through Apple.

RevenueCat may process purchase-related data such as subscription status, transaction identifiers, and anonymized device data.

Apple (App Store)

Payments are processed by Apple. Apple may act as an independent data controller according to its own privacy policies.

Sentry (planned)

Used for monitoring application errors and performance. May collect anonymized technical data such as crash reports.

7. Data Transfers Outside the EEA

Some data may be processed outside the European Economic Area (EEA), including by providers such as Google (Firebase) and RevenueCat.

In such cases, data transfers are safeguarded using mechanisms such as Standard Contractual Clauses approved by the European Commission.

8. Data Retention

Personal data is stored for as long as the user maintains an account.

Users may request deletion of their account at any time, which will result in the deletion of their data.

9. User Rights (GDPR)

Users have the right to:

  • access their personal data,
  • rectify inaccurate data,
  • request deletion of data ("right to be forgotten"),
  • restrict processing,
  • data portability,
  • object to processing,
  • withdraw consent at any time (if applicable).

To exercise your rights, contact:

📧 mariusz@bugajski.dev

10. Right to Lodge a Complaint

Users have the right to lodge a complaint with a supervisory authority.

In Poland, this is the President of the Personal Data Protection Office (UODO).

11. Data Security

Data is protected using appropriate technical and organizational measures, including those provided by Firebase and other service providers.

12. Changes to This Privacy Policy

This Privacy Policy may be updated from time to time.

The current version will always be available within the Application or on its website.

13. Contact

📧 mariusz@bugajski.dev