Privacy Policy
What Snapfiled collects, where it goes, and how long it stays.
The short version
You photograph a business card, a door-knock sheet, an adjuster's card or an estimate and send it to Snapfiled. We send that image to an AI model provider to read it — Anthropic's Claude, and DeepSeek where a cheaper first pass has been switched on. We store the image and the fields read out of it, you check the fields we flagged, and we file the result into the CRM you connected. We do not sell anything to anybody, and we do not use your captures to train models.
Most of the personal data in Snapfiled is not yours. It belongs to the homeowner on the lead sheet and the adjuster on the card. That shapes everything below: for that data you are the controller and we are your processor, and you are the one who has to have a reason to be processing it.
1. Who we are
Snapfiled is operated by [COMPANY_LEGAL_NAME — not configured], [COMPANY_ADDRESS — not configured]. For anything in this document, write to [email protected].
2. Two different sets of people
- Customers and their crews
- The contractor or agent who signs up, and the people they invite. We are the controller of this account data: we decided to collect it and we decide what to do with it.
- People whose details appear in a photograph
- The homeowner, the adjuster, the referral partner, the person who wrote their number on a sign-in sheet. We hold their data only because a customer sent it to us, and only to do what that customer asked. For them, our customer is the controller and Snapfiled is the processor — see the Data Processing Addendum.
3. What we collect
Account data
- Your name, email address, phone number and role.
- Your business name, trade, timezone and phone-number region.
- Sign-in records: a session token, the time, your IP address and your browser's user-agent string. Sign-in links are single-use and expire in twenty minutes.
- API keys you create — stored as a SHA-256 hash and a short display prefix, never in full.
Channel data
-
Your Snapfiled inbox address,
<your-org>@in.snapfiled.com, and the texting number assigned to you if you use one. - The allow-list of email addresses and phone numbers permitted to send captures in. Anything from an address not on that list is refused, which is a privacy control as much as a spam control.
Capture content — the sensitive part
- The photographs, PDFs and screenshots you send, exactly as sent.
- The email address or phone number that sent them, the subject line, the message body, and the provider's message identifier.
- For captures made with the browser extension, the text selected and the URL of the page it came from.
- The fields read out of the document: names, job titles, company names, phone numbers, email addresses, postal addresses, claim and policy numbers, adjuster details, dates, measurements, amounts and free-text notes — whatever was on the paper.
- The model's raw response, its confidence, which fields it was unsure about, the model name, token counts and the cost of the call.
Connection data
- Which CRM you connected and the credential for it. Credentials are encrypted with AES-256-GCM before they are written to the database and are never shown back to you in full — see Security.
- What we sent to your CRM and what it sent back, kept so a failed push can be diagnosed.
Operational data
- An audit trail of account actions: who invited whom, who approved which record, who changed a setting.
- Per-hour counts of how many captures each sender sent, so one wrong number cannot run up an AI bill.
- Monthly capture and cost counters for billing.
- Server logs. They carry URLs, org and capture identifiers and error text — not photographs, and not CRM credentials.
There are no third-party analytics scripts, no advertising pixels and no tracking cookies. The only cookie Snapfiled sets is the session cookie that keeps you signed in.
4. Sending your images to an AI model provider
This is the part a customer most deserves to know without reading our source code, so it gets its own section.
When a capture is processed, the full contents of the image and any text
that arrived with it are transmitted over TLS to an AI model provider's API, which returns
the structured fields. As shipped, that provider is
Anthropic PBC (the Claude API, model deepseek-v4-flash-vision-exp).
This deployment also has DeepSeek enabled as a cheaper first pass on straightforward documents. Documents routed to it are processed by DeepSeek, whose API is operated from China. Handwritten notes, insurance documents, measurement sheets and contracts skip the cheap pass and always go to Claude.
Anthropic's published API terms state that inputs and outputs submitted through the API are not used to train its models, and that inputs are retained only for a limited period for abuse monitoring. That is Anthropic's commitment under their agreement with us, not a promise we can independently enforce; the current terms are the authority. Snapfiled itself never uses your captures to train anything.
If you are not willing for a document to be read by an AI provider, do not photograph it. There is no local-only extraction mode today, and we would rather say that plainly than bury it.
5. Why we process it
- To do the job you asked for — read the document, show you the fields, file the record. Performance of our contract with you.
- To keep the service standing up — rate limits, abuse prevention, debugging. Our legitimate interest in running a service that works.
- To bill you, if you are on a paid plan.
- To meet legal obligations, such as keeping records of deletions.
For the personal data inside your photographs, the lawful basis is yours to hold, not ours. We process it on your documented instructions.
6. Who else sees it
A current list, with what each one actually sees, is on the Subprocessors page. In summary: the AI model provider sees the image; your CRM receives the approved record; our hosting provider holds the server; the SMS and email carriers see messages in transit. Nobody else. We do not sell personal data, and we do not share it for advertising.
We would disclose data if legally compelled. If that happens and we are permitted to tell you, we will.
7. Where it lives
Snapfiled runs on a single virtual private server: the application, the Postgres database and — unless object storage is configured — the photographs on its own disk. Traffic to the site is TLS-encrypted. This is a small deployment, honestly described in Security, including what that means for redundancy.
8. How long we keep it
- Photographs. Image retention is currently set to keep photographs indefinitely
(
FILE_RETENTION_DAYS=0). They are deleted when you delete the capture, or when you delete your organisation. - Captures, extracted records and push history. Kept until you delete them or delete your organisation. They are your working records.
- Account and audit data. Kept for the life of the account. The audit trail is what answers "who approved this record".
- Sign-in links and sessions. Links expire in twenty minutes and can be used once. Sessions last thirty days or until you sign out.
- Deletion records. When something is deleted we keep a log line — what kind of thing, its identifier, when, why and at whose request. It contains no names, addresses or numbers, and it outlives the deleted data on purpose, so a deletion can be evidenced later.
- Backups. A deletion removes data from the live system immediately. Database backups are rotated, so a copy can persist in a backup image until that image ages out.
9. Your rights
If you hold a Snapfiled account, you can do the two big ones yourself, right now, without asking us: Settings → Your data exports everything your organisation holds as a JSON file, and deletes the whole organisation — files included — on a typed confirmation.
Depending on where you live you may also have rights to correct data, restrict or object to processing, and to complain to a supervisory authority. Write to [email protected] and we will answer within 30 days. We do not charge for this and we will not make you jump through hoops.
10. If your details are in someone's photograph
If you are a homeowner, an adjuster or anyone else whose card or details a Snapfiled customer photographed, and you want that data corrected or deleted: write to [email protected]. We hold that data on behalf of the business that captured it, so in most cases we will identify the customer holding it and pass your request to them, and we will help them action it. If they will not, tell us — that is a term of their agreement with us, not a courtesy.
11. Children
Snapfiled is a tool for businesses. It is not directed at anyone under 16 and we do not knowingly collect their data. If a photograph contains a child's details, delete the capture; if you cannot, write to us and we will.
12. Changes
If we change this policy in a way that matters — a new subprocessor that sees capture content, a new purpose, a shorter retention — we will email account owners before it takes effect. The date at the top is the version in force.