Effective September 1, 2026
Privacy Policy
This page explains what information Sneh collects, why we collect it, and the choices you have. We’ve kept it short on purpose — if something here is unclear, write to us and we’ll fix the wording.
What we collect
Account information: your email address, and your profile details if you sign in through Google or GitHub. Your projects: the prompts you write, the files you attach, the chat messages you exchange with Sneh, the apps generated from them, and screenshots Sneh takes of your own running app to check its work. If you add API keys in the Secrets tab, we store them so your app can use them.
Data your app collects from its visitors. Apps built with Sneh can save what visitors submit — a waitlist email, a contact form — to Sneh Data, a store we run on your behalf. If you switch on Care, a small script in your deployed app also reports uncaught errors (the message and stack trace), the page path, the referring page, and a page-speed measurement, so we can tell you when something is wrong. We do not record your visitors’ IP addresses and we set no cookies in your app. Because this describes your visitors rather than you, you should mention it in your own app’s privacy notice; we hold it only to provide the service to you.
Product analytics: we record a small set of first-party events such as landing-page visits, project starts, brief approvals, previews, and deployments. These events may include the page, referral campaign tags such as source, medium, campaign, creative, and keyword, a temporary browser-session identifier, your account or project identifier when signed in, and basic product state. We do not intentionally include advertising-network click identifiers, your prompts, generated code, form contents, or payment details in product analytics.
How we use it
We use this information to run the service: to authenticate you, to build and deploy the apps you ask for, and to keep everything reliable. We also use it to understand where Sneh breaks or feels slow, so we can improve it. We do not sell your data, and we do not use it to sell ads.
Processors
We rely on a small set of providers to run Sneh, and each only sees what it needs to do its job.
- Supabase — authentication, our database, and file storage. This is where your account, projects, messages, files and secrets live.
- Vercel — hosts Sneh, runs each project’s build sandbox, and hosts the apps you deploy. Vercel’s AI Gateway also routes model requests.
- AI model providers — your prompts, attached files, generated code and app screenshots go to the model you select (or that Sneh selects on Auto) to produce the output you asked for. Depending on the model, that is Anthropic, OpenAI, Google, Meta, Moonshot AI, xAI, Alibaba, or Z.ai, reached through Vercel AI Gateway under those vendors’ API terms. The provider for each model is shown in the model picker.
- Dodo Payments — checkout and payment status, as merchant of record. We receive the payment identifier and the account and pack identifiers needed to add credits, never your full card details.
- Mixpanel — receives the same first-party product events described above (marketing page views, sign-in and sign-up outcomes, project milestones, deployments, top-ups), keyed to your account and browser-session identifiers. Never your email, name, prompts or code.
- Google — sign-in if you use it, and the Google Ads tag for measuring which ads lead to a sign-up or purchase. The conversion carries your account identifier and, for a purchase, the amount and payment identifier.
- GitHub — sign-in if you use it.
- Composio — only if you connect an outside account (Slack, Gmail, GitHub and similar) under Connectors. Composio holds that connection on your behalf, keyed to your account identifier, and the data a connected tool reads or writes passes through it.
- Expo (EAS) — only if you build a native mobile app. Your project’s files are uploaded to Expo’s build service and the resulting app is hosted there.
Cookies
Sneh uses authentication cookies to keep you signed in. For first-party product analytics, the browser stores campaign attribution in session storage and mirrors a random session identifier in a first-party session cookie so activity before and after sign-in can be measured as one journey. Both expire with the browser session. We also keep a few preferences in your browser’s local storage — your theme, the sign-in method you used last, and whether you have seen the welcome offer. They contain no personal data and you can clear them at any time.
We also load the Google Ads tag to measure which ads lead to a sign-up or a completed purchase. Advertising and analytics storage are denied by default for visitors in the EEA, the UK, and Switzerland, so no Google advertising cookies are set there. In US states with comprehensive privacy laws we allow the tag to count the conversion but deny ad personalisation and the sharing of ad user data, and we honour the Global Privacy Control signal everywhere — if your browser sends it, the tag is fully denied. We do not sell your personal information, and we never use ad trackers to profile what you build.
Mixpanel, which we use to understand how people move through Sneh, runs entirely on our servers. No Mixpanel library loads in your browser, so it sets no cookies and no browser storage of its own, and we do not send it your IP address. The events it receives are the same first-party ones described above, identified by the session identifier and your account id — never your email, your name, your prompts, or your code.
Retention & deletion
We keep your account and project data for as long as your account is active. You can delete a project from its card on the home screen, and delete your whole account from your profile. Deleting a project or an account removes its chat history, files, and stored data, and takes down any site it had published — so the live URL stops working and the app stops collecting anything further.
Beyond that: Care telemetry from your deployed apps is deleted after 30 days; product analytics events are kept for up to two years; and backups age out on their own cycle within 30 days of deletion.
Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it — and we will not treat you differently for asking. If you are in California, Colorado, Connecticut, Virginia, Texas, Oregon, or another US state with a comprehensive privacy law, that includes the right to know what we collect and why, the right to opt out of targeted advertising, and the right to appeal if we turn a request down. We do not sell personal information and we do not use it to make decisions with legal effects about you.
Delete your account yourself from your profile, or write to hello@sneh.ai for anything else. We reply within 45 days. To opt out of ad measurement, turn on Global Privacy Control in your browser — we honour it automatically — or ask us by email.
Children
Sneh is not for children under 13, and we do not knowingly collect their information. If you believe a child has given us personal information, write to us and we will delete it.
Contact
Questions about this policy, or a request about your data? Write to hello@sneh.ai.
This document is provided for transparency and is not legal advice; it will be reviewed by counsel before general availability.