Privacy Policy

Last Updated: October 17, 2025

This Privacy Policy ("Policy") describes how Snitchnotes and its affiliates ("Snitchnotes," "we," "us," or "our") collect, use, disclose, and protect personal information in connection with the Snitchnotes website, mobile applications and related services (collectively, the "Service"). By using the Service you consent to the collection, use, disclosure, and transfer of your information as described in this Policy.

1.Controller / Contact Information

Controller: Moss Studios d/b/a Snitchnotes

Primary Contact (privacy): hello@mosslabs.co

Backup Contact / Support: contact@mosslabs.co

Address: 2803 Philadelphia Pike, Suite B #1702, Claymont, DE 19703, USA

If you are an EU/EEA resident and would like to contact our Data Protection Officer (if applicable) or exercise GDPR rights, contact hello@mosslabs.co.

2.Scope and Applicability

This Policy applies to personal information collected by Snitchnotes in connection with the Service. It does not apply to information collected by third parties (including through third-party websites or services linked from the Service) or to information collected offline unless we state otherwise. Separate terms or policies may apply to specific features.

3.Definitions

Personal Data / Personal Information: Any information that identifies or can reasonably be associated with an identified or identifiable individual.

User Content: Content you upload, submit, store, or generate via the Service (e.g., PDFs, audio files, notes, quiz results, transcripts).

AI Providers / AI Processors: Third-party providers engaged to process or analyze User Content using machine learning or generative AI models (examples listed in Section 8).

Service Providers: Third parties that perform services on our behalf (hosting, authentication, payments, analytics, email, etc.).

4.Categories of Personal Information We Collect

We collect personal information in the following categories:

4.1 Information You Provide

Account registration data: name, email address, username, profile picture, sign-in information (including via Google OAuth).

Billing & payment: billing name and address, transaction metadata (note: card numbers and full payment instrument details are processed by third-party payment processors and are not stored by us).

User Content: notes, source files (PDFs, text, audio), transcripts, quiz answers, annotations, tags, and any content you provide to be processed by our AI features.

Support & communications: messages, feedback, and other support communications you send to us.

Marketing preferences and opt-ins.

4.2 Information Collected Automatically

Usage and telemetry: pages/screens viewed, features used, timestamps, session duration, error and crash logs, performance metrics.

Device & connection data: IP address, device identifiers, operating system, browser type and version, referrer, and mobile carrier info.

Cookies and tracking technologies as described in Section 13.

4.3 Information from Third Parties

Authentication providers (e.g., Google) may provide basic profile information when you authenticate.

Publicly available information and lawful sources we may combine with your data.

5.Purposes and Lawful Bases for Processing

We process Personal Information for the following purposes and with the following lawful bases (where applicable):

Providing and operating the Service: account creation, authentication, storage and retrieval of User Content, generating AI summaries/quizzes — lawful basis: performance of a contract.

AI processing of User Content: to generate summaries, quizzes, transcripts, or other AI outputs as requested by you — lawful basis: performance of a contract and/or your consent.

Billing & payments: to process subscriptions and refunds — lawful basis: performance of a contract and compliance with legal obligations.

Communications & support: to respond to inquiries and send transactional or security messages — lawful basis: legitimate interest / performance of a contract.

Research, product improvement & analytics: to improve features and perform internal research (including model improvements where permitted) — lawful basis: legitimate interests (balanced against your rights).

Fraud detection & security: to prevent abuse and secure the Service — lawful basis: legitimate interests and compliance with legal obligations.

Legal compliance: to comply with legal obligations and law enforcement requests — lawful basis: compliance with legal obligations.

Marketing (where you consent): to send promotional messages and newsletters — lawful basis: consent.

If we rely on consent for specific processing, you may withdraw consent at any time (see Section 16).

6.Third Parties, Disclosures, and Subprocessors

We disclose Personal Information to the following categories of recipients:

6.1 Service Providers & Infrastructure

Hosting & Database: Supabase (database/auth), Fly.io (compute/hosting), Google Cloud (storage/other services).

Payments: third-party payment processors (e.g., Stripe, Apple App Store, Google Play) — we only receive transaction metadata, not raw card numbers.

Email & Communications: third-party email providers and notification services for transactional and marketing emails.

Analytics & Monitoring: analytics and crash-reporting providers for product and performance insights.

Customer Support: ticketing and support providers to deliver customer service.

We require these providers to act as processors under contract and to implement appropriate technical and organizational measures.

6.2 AI Providers (Examples)

We use external AI providers to process User Content when you request AI features. These providers may process text, audio, or other content you submit. Examples include (but are not limited to):

  • OpenAI (GPT family)
  • Anthropic (Claude family)
  • Google / Gemini
  • Meta / Llama family (including services built on Meta models)
  • Llama-based third parties / hosted Llama models
  • ElevenLabs (speech-to-text / text-to-speech)
  • Other third-party model hosts and inference providers (including cloud providers or specialized AI vendors)

When you use an AI feature, your User Content or excerpts of it will be transmitted to the selected AI provider for processing. We take steps to limit what is sent (for example, sending only the specific text or audio required to fulfill the request), and we contractually require our AI providers to follow confidentiality and data security requirements. However, model behavior and provider policies may vary; please see Section 8 for further details.

6.3 Legal and Safety Disclosures

We may disclose Personal Information as necessary to comply with legal obligations, to enforce our Terms of Service, to protect the rights, property, or safety of Snitchnotes or others, or in connection with a merger, sale, reorganization, or asset transfer.

7.AI Processing — Detail, Safeguards, and Provider Practices

Because Snitchnotes is an AI-driven product, this section describes how we handle AI processing and the safeguards we implement.

7.1 What is sent to AI providers

The specific content you request to be processed (text excerpts, document text, audio clips, metadata necessary to process the request).

Minimal contextual metadata (e.g., language, requested operation) to ensure correct processing.

We do not send unrelated account credentials or payment card numbers to AI providers.

7.2 Provider Use, Retention, and Training

Where possible and subject to contractual terms, we require AI providers to: (i) process data only to provide the requested services, (ii) delete the data after a limited retention period, and (iii) refrain from using the data to train their models.

However, some AI providers may by default retain or use the data for service improvement unless restricted by contract or account configuration. We will disclose provider-specific retention/training practices upon request. If you require that an AI provider not retain or use your data for training, please contact privacy@snitchnotes.app to discuss options and available configurations.

7.3 Risk Mitigation

We minimize the Personal Information sent to AI providers and encourage users to avoid submitting highly sensitive data.

Data in transit to AI providers is encrypted in transit (TLS).

We rely on contracts (Data Processing Agreements), Standard Contractual Clauses (SCCs) where required, and other safeguards to govern international transfers.

7.4 Examples of AI usage in Snitchnotes

Summarization and note generation from uploaded PDFs or audio.

Quiz generation from notes.

Text-to-speech and speech-to-text transformations (e.g., ElevenLabs).

Conversational assistant that answers questions about your notes.

8.International Transfers

Your information may be processed or stored in the United States or in other jurisdictions where our service providers operate. Where we transfer Personal Information from the EEA/UK/Switzerland to countries that do not have an adequacy decision, we implement appropriate safeguards such as EU Standard Contractual Clauses (SCCs) and additional technical and organizational measures. By using the Service, you consent to such transfers.

9.Data Retention

We retain Personal Information only as long as necessary for the purposes set out in this Policy, or as required by law:

Account data & User Content: retained while your account exists and for a reasonable period thereafter (typically up to 30 days after deletion) unless otherwise requested or required to be retained for legal reasons. You may request deletion; see Section 16.

Backups & logs: infrastructure backups and logs may be retained for up to 180 days or longer if required for legal, audit, or security purposes.

Analytics & aggregated data: retained in de-identified or aggregated form for product improvement indefinitely.

Billing & transaction records: retained for up to 7 years for tax and accounting compliance unless law requires otherwise.

If you request deletion of your account and data, we will delete or anonymize data within a reasonable time frame, except for data we are required to retain (e.g., for fraud prevention or legal compliance).

10.Security

We implement commercially reasonable administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of Personal Information. Examples include encryption in transit (TLS), access controls, periodic security testing, and vulnerability management.

Important: No system is completely secure. We cannot guarantee absolute security. If we become aware of a data breach that affects your rights or your Personal Information, we will notify you and regulators as required by applicable law.

11.Cookies and Tracking Technologies

We and third-party partners use cookies, web beacons, local storage and similar technologies to provide and improve the Service, analyze usage, and deliver personalized content or advertising. Cookies fall into categories:

Strictly necessary cookies — required for core functionality.

Performance & analytics cookies — to measure and analyze use.

Advertising & targeting cookies — to provide tailored ads (only if you opt in where required).

You may control cookie settings via your browser or device settings and, where applicable, our cookie consent tool. Disabling some cookies may affect functionality.

12.Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect Personal Information from children under 13. If you believe we have collected data from a child under the applicable minimum age, please contact hello@mosslabs.co and we will take steps to delete that data. If your institution requires higher minimum ages, you must comply with that policy.

13.Automated Decision-Making & Profiling

We may use automated processing (including AI) to provide features (e.g., generate recommendations, quiz difficulty adjustments). The outputs are intended to assist and are not final determinations of legal rights or eligibility. If you are an EU/EEA resident and would like to object to automated decision-making that produces legal or similarly significant effects, contact hello@mosslabs.co to request human review.

14.Your Rights & Choices

14.1 EU / EEA / UK (GDPR) Rights

Where applicable, you have the right to: access, rectify, erase, restrict processing, portability, object, and withdraw consent. To exercise rights, contact hello@mosslabs.co. We will verify your identity before responding. We may need to retain certain data where required by law.

14.2 California Residents (CCPA / CPRA)

If you are a California resident, you have the right to: request disclosure of categories and specific pieces of Personal Information we collected, request deletion (subject to exceptions), opt out of sale (we do not sell Personal Information), and non-discrimination for exercising rights. To submit a request, contact hello@mosslabs.co or call the number provided in Section 17 if applicable. We will verify requests according to law.

14.3 Other Jurisdictions

Residents of other jurisdictions may have similar rights. Contact hello@mosslabs.co for information on rights and how to exercise them.

14.4 Account Controls

You may: update account information, download your User Content and certain account data, and delete your account from account settings or by contacting support. Deleting your account will remove access and will trigger deletion of User Content except to the extent backups and logs remain as described in Section 9.

15.Verification & Fraud Prevention

To protect privacy and security, we may ask for information to verify identity before fulfilling a data rights request. We will only request information reasonably necessary for verification.

16.How to Submit Requests

Submit requests to: hello@mosslabs.co. For account or billing support use hello@mosslabs.co. Include a description of the requested action and your account details. We will respond within applicable legal timeframes (e.g., 30 days under GDPR; 45 days under CCPA/CPRA with extensions where permitted). We may decline requests that are manifestly unfounded or excessive.

17.International Transfers & Legal Mechanisms

By using the Service, you agree your data may be transferred to and processed in jurisdictions other than your country (including the USA). Where required by law we implement safeguards such as Standard Contractual Clauses, Binding Corporate Rules, or other lawful transfer mechanisms. Contact hello@mosslabs.co for a copy of the safeguards.

18.Data Processing Agreements & Subprocessors

We enter into Data Processing Agreements (DPAs) with vendors acting as processors. A non-exhaustive list of subprocessor categories and primary vendors is available upon request by contacting hello@mosslabs.co. We will provide at least 30 days' notice for the addition of new essential subprocessors where required by contract or law.

19.Mergers, Acquisitions, and Business Transfers

If Snitchnotes is involved in a corporate transaction (merger, sale, acquisition, bankruptcy), Personal Information may be transferred as part of the transaction. We will notify affected users where required by law.

20.Third-Party Services & Links

The Service may contain links to third-party websites, plugins, or services. This Policy does not apply to third parties. We encourage you to review the privacy policies of third parties before providing them with Personal Information.

21.Changes to this Policy

We may update this Policy from time to time. For material changes, we will notify you by in-app notice, email, or conspicuous notice on the Service before the change takes effect. The "Last Updated" date at the top reflects the effective date.

22.International Residents — Supervisory Authorities & Complaints

If you are in the EU/EEA/UK and believe we have not addressed your privacy concern, you have the right to lodge a complaint with your local supervisory authority.

23.Disclaimer / Limitations

We strive to protect your privacy but cannot guarantee absolute security. We recommend you avoid uploading extremely sensitive personal information (e.g., social security numbers, health records) unless strictly necessary and legally permitted.

24.Representative Examples of Subprocessors & AI Providers

This list is illustrative and may change; contact hello@mosslabs.co for the current list and DPA details.

Infrastructure & Storage: Supabase, Fly.io, Google Cloud Platform (GCP)

Authentication: Google OAuth, Supabase Auth

AI / ML / Inference / Speech: OpenAI (ChatGPT / GPT family), Anthropic (Claude), Google (Gemini), Meta (Llama and Llama-based services), Llama-hosting vendors, ElevenLabs (text-to-speech / speech-to-text), and other specialized AI providers and model hosts.

Payments & Billing: Stripe, Apple App Store, Google Play Billing

Email & Notifications: Third-party email providers (e.g., SendGrid, Postmark)

Analytics & Monitoring: Google Analytics, analytics and crash reporting tools (names may vary)

Customer Support: Support ticketing and CRM platforms

We require subprocessors to maintain appropriate safeguards. Where an AI provider's policy permits or requires retention or use of data for model improvement, we will disclose such practices on request and seek contractual assurances where feasible.

25.How We Will Handle Sensitive or Special Categories of Data

You should avoid uploading sensitive personal information (e.g., health data, biometric identifiers, government ID numbers). We do not seek or intend to collect special category data. If we are required to process such data (e.g., under specific user instructions), we will obtain explicit consent where required by law and implement heightened security safeguards.

26.Contact & Notices

For privacy inquiries, DPA requests, data subject requests, or to request a list of subprocessors or copies of DPAs/SCCs, contact: hello@mosslabs.co

If you do not receive a response within a reasonable period, you may also contact contact@mosslabs.co.

27.Effective Date

This Policy is effective as of the "Last Updated" date at the top of this page.

Acknowledgment: By using Snitchnotes you acknowledge that you have read and understood this Privacy Policy and consent to our collection, use, transfer, and disclosure of your Personal Information as described herein.

Snitchnotes - Sistema di studio potenziato dall'AI