SnippKit Logo

Privacy Policy

Effective Date:  |  Last Updated:

This Privacy Policy applies to the SnippKit web application, API endpoints, official Chrome Extension, and developer tools.

SnippKit is committed to protecting developer privacy. We collect only the minimum personal information necessary to provide our services and manage user accounts. We do not sell, rent, or trade your personal information or source code.

Information We Collect

  • Account Profile Data: Email address, username, full name, profile image link, social handles, and profession details supplied during registration or profile updates.
  • Developer Content: Code snippets, scripts, JSON structures, CLI commands, AI prompts, tags, and folder organization.
  • Media & Uploads: Media attached to AI prompts or uploaded content is stored in Supabase Storage.
  • Technical Telemetry: Basic device user-agent, operating system, IP address, request timestamps, and system performance logs.

Chrome Extension Data Policy

Our official Chrome Extension does not collect, track, or store personal data or browsing history. It functions locally using your authenticated session solely to allow you to save selected snippets to your SnippKit account. No data is gathered beyond what is required to save the content you select.

Authentication & Account Management

Authentication on SnippKit is handled securely by Clerk Authentication. Passwordless logins and OAuth single sign-on (SSO) credentials (e.g., GitHub, Google) are authenticated directly by Clerk. SnippKit stores your associated Clerk User ID and primary email address to link your workspace snippets and subscription tier. Plain-text passwords are never stored on our servers.

Code Snippets & Encryption Scope

Private Content: Private snippets, encrypted tasks, and user keys are encrypted at rest in Supabase using AES-256-GCM authenticated encryption with per-user keys and initialization vectors. Private snippets are accessible only by you and explicitly authorized team or group members.

Public Content: Snippets, commands, or prompts marked as Public are intentionally stored unencrypted in Supabase to allow instant URL sharing, community feed display, and search index discovery.

Commands, Gists & Database Infrastructure

All developer content—including snippets, commands, scripts, JSON data, and file attachments—is stored and managed securely within Supabase (Postgres Database and Supabase Storage) using strict access policies and Row-Level Security. Self-destructing links created via features like Ghost Send expire automatically according to configured time-to-live settings.

AI Requests & Model Transparency

AI features (such as Sidr AI, code explanation, and OCR) process prompt requests over encrypted API connections via third-party providers including OpenAI, Google Generative AI (Gemini), and Together AI. Code sent to AI features is processed solely to fulfill your specific generation or explanation request. Private code snippets are not used to train public foundation models. Endpoint access is rate-limited using Upstash Redis limiters.

Cookies & Session Policy

SnippKit uses cookies and session state technologies to support basic functionality:

  • Authentication Cookies: Managed by Clerk to maintain secure user sessions and prevent CSRF attacks.
  • Preference Storage: Remembers your UI theme choices (light or dark mode via next-themes).
  • Analytics: We may use Microsoft Clarity or internal logging to analyze anonymized aggregate performance telemetry without selling data.

Data Export & Portability

Self-service automated data export is not currently enabled directly inside the user dashboard interface. However, users may request a copy of their account data by contacting customer support.

Third-Party Services

We rely on vetted service providers to support platform infrastructure, authentication, database storage, billing, and AI capabilities:

  • Clerk: User identity & authentication management.
  • Supabase: Postgres Database & Storage buckets with Row-Level Security.
  • LemonSqueezy: Payment processing, checkout, subscription billing, and tax compliance.
  • Upstash Redis: High-speed API rate limiting and session throttling.
  • OpenAI / Google Gemini / Together AI: Artificial intelligence APIs.
  • Microsoft Clarity: UX analytics and performance telemetry.
  • Svix: Event webhooks routing.

Privacy & Compliance

We handle user data transparently and align with modern privacy standards:

  • GDPR: Designed to support GDPR privacy principles (right to access, deletion, and data minimization).
  • CCPA: Designed to support applicable CCPA privacy rights.
  • SOC 2: Not currently certified.
  • ISO/IEC 27001: Not currently certified.

Data Retention & Account Deletion

We retain user data for as long as your account remains active. You may delete your account or request account deletion at any time by reaching out to support. Upon account deletion, associated personal data, private snippets, and user keys are removed from active databases.

Changes to this Policy

We may update this Privacy Policy periodically. Continued use of SnippKit following policy updates constitutes acceptance of the revised terms.

Contact Us

For questions or requests regarding this Privacy Policy, contact us at:
Support Email:
Business Address:
Expected Reply Time: