Privacy policy
What Snap AI Studio collects, why, which providers process it, which cookies it sets, how long data is kept and how to access or delete it.
Last updated
On this page
This policy explains what Snap AI Studio (snapaistudio.com) collects when you use it, why, who processes it for us and what you can do about it. Snap AI Studio is operated by GrubGuru Ltd., a company registered in British Columbia, Canada ("we", "us"). Questions go to [email protected].
The short version: we collect what we need to run your account, your generations and your payments. We do not sell personal data, we do not run advertising trackers, Google Analytics runs only if you accept analytics cookies, and we do not use your photos, prompts or results to train AI models.
What we collect
Account details. Your email address. If you sign up with a password, we store only a scrypt hash of it, never the password itself. If you sign in with Google, Google shares your name, email address and profile picture, and we store the account link and tokens Google returns so the sign-in keeps working.
What you create. The prompts and settings you submit, the files you upload (photos, and video or audio for the tools that take them), and the images, videos and audio the models return. Photos often show faces, including faces of people other than you; the Terms say whose photos you may upload.
Credits and billing. Your plan, subscription status and billing period, your credit balance, and a ledger of every credit grant, charge and refund. Stripe handles checkout and stores your card details; we never see or store your card number. We keep the Stripe customer and subscription ids that link your account to Stripe.
Your own API key. If you save an OpenRouter or fal key in your account, it is stored encrypted (AES-256-GCM) and never sent back to your browser.
Password resets. When you ask for a reset link, we store a hash of the one-time token and its expiry time, not the token itself.
Safety records. When a prompt is blocked by our content checks, or a model provider's safety filter rejects a generation, we keep a record of the prompt, the reason, the model and the time. We use these records to pause accounts that keep sending blocked requests and to review abuse.
Reports. If you report a shared result in the gallery, we store the reason and any note you add, with your account id, or a keyed hash of your IP address if you are signed out, so each person can report an item once.
Request data. Our servers and Cloudflare process standard request data (IP address, browser user agent, the page requested) to deliver pages and block abuse. The app also uses your IP address in memory to rate limit sign-in and sign-up attempts; apart from the hashed form stored with a signed-out report, it does not write your IP address to the database.
Usage statistics, when analytics are enabled. Cloudflare Web Analytics counts page views and page load times without cookies, local storage or any identifier that follows you across sites, so it runs without asking. If you press Accept in the cookie notice, Google Analytics also records the pages you view, your browser and device type, an approximate location derived from your IP address, and product events: account created and sign-in (with the method), generations started and finished (with the tool, model, credits spent and whether they succeeded, never the prompt or the photo), shares and downloads, and the pricing page, checkout and payments (with the plan and amount, never card details). When you are signed in, Google Analytics also receives your account id, a random string that is not your email, so your activity on different devices counts as one person. Renewals, refunds and failed payments are reported by our server using the same identifier, and only while your Accept stands. If you choose Essential only, Google Analytics does not load and our server reports nothing to it.
We do not run face recognition or build biometric profiles. Photos are processed only to produce the result you asked for.
How we use it
- To run the service: create your account, sign you in, run generations, store your results and show them to you.
- To bill you: take payments through Stripe, add credits, and refund credits automatically when a generation fails.
- To keep the service safe: rate limits, fraud and abuse prevention, and checking prompts, uploads and results against our content policy, automatically or by review.
- To support you: answer your emails and investigate problems with a job.
- To set prices: we record what each generation cost us at the gateway, so credit prices cover real costs.
- To improve the site: page view counts, and Google Analytics statistics if you accepted them, show which pages and tools people use and where sign-up or checkout gets stuck.
- To send service emails: a welcome note, password reset links, one receipt per payment, failed payment notices, subscription changes, refund confirmations and content-policy notices. We also send one product email, a reminder if you have not generated anything two days after signing up. It has an unsubscribe link, and you can turn product emails off or on from your account page.
If you are in the European Economic Area or the United Kingdom, our legal bases are: performing our contract with you (running your account, generations and billing), our legitimate interests (security, abuse prevention, support and improving the service), legal obligations (for example tax records), and your consent where we ask for it.
AI gateways and model providers
When you press Generate, your prompt, settings and input files go to the gateway that serves the model you picked: OpenRouter for most image and video models, fal for lipsync, speech, music, upscaling, background removal and some image models. The gateway runs the model itself or passes the request to the model's developer or a hosting partner. The models on Snap AI Studio come from Alibaba, Black Forest Labs, ByteDance, Clarity AI, fal, Google, hexgrad, Kuaishou, Microsoft, MiniMax, OpenAI, Recraft, Runway, Sourceful, Stability AI, Sync Labs, xAI and ZhengPeng7.
We send your content to these providers only to produce your result, not for training. Their own policies govern how long they keep request data; some keep it for a limited time to monitor abuse. Their policies are linked in the table below.
If you saved your own OpenRouter or fal key, jobs on that gateway run under your own account with that provider and its terms apply to them.
Who can see your data
- You. Your uploads and results are private to your account.
- The public gallery, only if you choose. When you press Share to gallery on a result, the output, the model name and your prompt appear on the gallery. Your name and email are never shown. You can unshare at any time. Anyone can report a shared item, and we can hide or remove it.
- Our administrators. A small number of administrators can see jobs and files to run the service, investigate problems and enforce the content policy.
- Service providers. The companies below process data for us, each only for the purpose listed.
- Authorities. We disclose data when the law requires it, or when needed to protect someone's safety or our rights.
- A buyer. If Snap AI Studio is sold or merged, your data moves with it and this policy continues to apply.
| Provider | What it does for us | Where | Their policy |
|---|---|---|---|
| Hetzner | Servers that run the app and the database | Finland (EU) | Privacy policy |
| Cloudflare | DNS, network security and delivery for all traffic; R2 storage for uploads and generated files; account emails such as password reset links, receipts and subscription notices; Web Analytics page view counts, when enabled, without cookies | Global network, company in the United States | Privacy policy |
| OpenRouter | AI gateway for image and video models: receives prompts, settings and input images | United States | Privacy policy |
| fal | AI gateway for lipsync, speech, music, upscaling, background removal and some image models: receives prompts, settings and input files | United States | Privacy policy |
| Stripe | Checkout, subscriptions, invoices and the billing portal | United States and Ireland | Privacy policy |
| Sign in with Google, only if you choose it | United States | Privacy policy | |
| Google Analytics | Usage statistics: pages viewed and a few product events. Loads only when analytics are enabled and you press Accept in the cookie notice | United States | Privacy policy |
Cookies
Snap AI Studio sets cookies needed to sign you in and keep sign-in secure. When analytics are enabled, the cookie notice also asks whether you accept Google Analytics cookies (_ga and _ga_*). They are set only after you press Accept; before that, and if you choose Essential only, Google Analytics does not load and sets nothing. There are no advertising cookies.
| Cookie | Purpose | Lasts |
|---|---|---|
authjs.session-token | Keeps you signed in. A signed token with your account id, not a tracking id. | 30 days, renewed while you use the site |
authjs.csrf-token | Protects the sign-in forms against cross-site request forgery. | Until you close the browser |
authjs.callback-url | Remembers which page to return to after sign-in. | Until you close the browser |
authjs.pkce.code_verifier, authjs.state | Secure the Google sign-in handshake. Set only when you use Google. | 15 minutes |
_ga | Google Analytics: a random id that tells repeat visits from the same browser apart. Not linked to your account. Set only after you press Accept. | 2 years |
_ga_* | Google Analytics: keeps track of the current visit. Set only after you press Accept. | 2 years |
On the live site the names carry a __Secure- or __Host- prefix, which tells the browser to send them only over HTTPS.
Cloudflare, which sits in front of the site, may set strictly necessary security cookies (such as __cf_bm) when it screens traffic for bots. Stripe's checkout and billing portal run on Stripe's own domain and set Stripe's cookies there, under Stripe's policy.
Cloudflare Web Analytics, when enabled, sets no cookies and stores nothing on your device, so it needs no consent and runs for every visitor.
The site also uses browser storage: session storage holds your draft prompt and the photo you picked before signing in, so they survive the sign-in step, and is cleared when you close the tab. Local storage remembers your cookie choice.
Blocking the sign-in cookies in your browser stops sign-in from working; everything else keeps working. You can change your cookie choice at any time with the button below. Choosing Essential only stops Google Analytics and deletes its cookies from this site.
How long we keep data
- Account, prompts, uploads, results and safety records: while your account is open. There is no delete button for individual generations yet; email us and we will delete specific items, or your whole account.
- Credit ledger and billing status: while your account is open. Stripe keeps invoices and payment records as tax and accounting law requires, and we may keep payment records we are legally required to keep.
- Password reset tokens: stored as a hash and valid for a short time only.
- Google Analytics data: kept in Google Analytics for up to 14 months, then deleted automatically.
- Rate limit counters: held in memory only, never written to disk, and cleared when the server restarts.
- Backups: deleted data can remain in database backups for up to 30 days until they rotate out.
Your choices and rights
You can do these yourself:
- Unshare any result from the gallery.
- Remove a saved API key on your account page.
- Accept or refuse analytics cookies, or change your choice later, with Cookie settings in the Cookies section.
- Cancel or change your subscription and download invoices in the billing portal (Account, Invoices and billing).
For everything else, email [email protected] from the address you sign in with: a copy of your data, a correction, deletion of specific generations, or deletion of your account. We verify the request comes from the account holder and answer within 30 days. Deleting your account removes your profile, generation history, uploads and results and cancels any subscription. Unused credits are lost when an account is deleted, as the Terms explain.
Depending on where you live, you may also have the right to restrict or object to processing, to data portability, and to withdraw consent. You can complain to your local data protection authority, or in Canada to the Office of the Privacy Commissioner of Canada.
International transfers
We are based in Canada. The app and database run on Hetzner servers in Helsinki, Finland. Some of the providers above are in the United States, so your data may be processed there. Where the law requires it, we rely on the transfer safeguards those providers offer, such as the European Commission's Standard Contractual Clauses.
Security
Traffic is encrypted with HTTPS. Passwords are hashed with scrypt, saved API keys are encrypted, provider keys stay on our servers and are never sent to your browser, and stored files reach their owner through access checks or short-lived signed links (a result you share to the gallery becomes public). No system is perfectly secure; if a breach affects your data, we will tell you as the law requires.
Children
Snap AI Studio is for people aged 18 or older. We do not knowingly collect data from anyone younger, and we delete accounts we learn belong to someone under 18. Photos of children may be uploaded only by their parent or legal guardian, within the limits in the Terms.
Changes to this policy
When this policy changes, we update the date at the top. For material changes we will tell signed-up users by email or with a notice on the site before the change takes effect.
Contact
GrubGuru Ltd., operator of Snap AI Studio. Email [email protected]. For help with uploads and file privacy, see Uploading photos in the help center.