Legal
Privacy Policy
Snitch reads public conversations on your behalf, which means it handles personal data about people who are not our customers. This page sets out what we collect, why, how long we keep it, and what you can ask us to do.
Last updated 4 September 2026
1Who is responsible
Snitch Intelligence Ltd, London, United Kingdom, is the controller for data about our own customers. Reach us at hello@heysnitch.com.
For the public mentions collected against your keywords, you are the controller and we act as your processor. Our processing terms are in the Terms of Service.
2What we collect
| Category | What | Why |
|---|---|---|
| Account | Name, email address, and the Google account id if you sign in with Google. | To create your account, sign you in and contact you about the service. |
| Workspace | Team members, roles, projects, keywords and category settings. | To run the product you configured. |
| Public mentions | Post text, URL, publication time, and the public author's handle, display name, avatar URL and follower count where the platform exposes it. | This is the service: finding and sorting public mentions of your keywords. |
| Approvals | Which person approved which drafted action, and when. | So there is an audit trail for anything posted from your account. |
| Integrations | OAuth tokens for Slack and Linear, stored encrypted. | To deliver alerts and create issues where you asked us to. |
| Billing | Plan, subscription status and billing identifiers from our payment processor. | To take payment and apply plan limits. We never see or store your full card number. |
| Operational | Request logs, API key usage timestamps, error traces and audit events. | To keep the service secure, debug faults and investigate abuse. |
3What we do not collect
Snitch reads only what is publicly visible. It does not read private messages, private groups, closed communities, or anything behind a login. We do not buy personal data from brokers, and we do not combine mention data across customers to build profiles of individuals.
4People who are mentioned
If Snitch collected a public post of yours because it matched a customer’s keyword, that customer decides how long it is kept. You can write to hello@heysnitch.com and we will pass your request to them, or act on it directly where the law makes us responsible.
If you delete the original post on the source platform, tell us and we will remove our copy.
5Legal bases
Where GDPR or UK GDPR applies we rely on: performance of a contract, for running your account; legitimate interests, for securing the service, preventing abuse and processing public mentions so our customers can manage their reputation; compliance with legal obligations, where we must keep records or respond to lawful requests; and consent, where we ask for it, such as for marketing email. You can object to processing based on legitimate interests at any time and withdraw consent at any time.
6Who we share with
We share data with service providers who process it on our instructions, and with no one else except where the law requires it. Current subprocessors:
- Cloudflare — application hosting and database
- Resend — sign-in links and alert email
- Stripe — payment processing
- Google — sign-in, and the YouTube Data API
- Reddit — public post and comment search
- X/Twitter — public post and comment search
- Slack and Linear — only where you connect them
- OpenAI - classifier and draft generation
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
7International transfers
Our providers may process data outside your country. Where personal data leaves the UK or EEA, we rely on an applicable adequacy decision or regulation. Where none applies, we use approved safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, or the European Commission’s Standard Contractual Clauses, as applicable.
8How long we keep it
- Account content and workspace data: for as long as the account is open, then deleted or anonymised within 30 days of closure.
- Mentions: until you delete them, or your workspace is closed.
- Audit events and approval records: for the life of the account and 24 months after closure, because they exist to show who approved what and to investigate misuse or disputes.
- Billing and accounting records: for six years after the end of the financial year they relate to, or longer where tax or accounting law requires.
9Security
Traffic is encrypted in transit. API keys are stored only as SHA-256 hashes and can be revoked at any time. Integration tokens are encrypted at rest. Access to production data is limited to people who need it, and administrative actions are recorded as audit events.
No system is perfectly secure. If a breach affects your data we will notify you and any regulator within the time the law requires.
10Your rights
Depending on where you live you may have the right to access, correct, delete, export or restrict your personal data, to object to certain processing, and to withdraw consent. Write to hello@heysnitch.com and we will respond within the statutory period. You can also complain to your data protection authority.
11Cookies
Snitch sets a session cookie so you stay signed in, and a short-lived cookie to protect sign-in against cross-site request forgery. These are strictly necessary and cannot be turned off while you are using the product. We do not currently use analytics or marketing cookies.
12Changes
We will post any update here and change the date at the top. If a change is significant we will tell you by email before it takes effect.
Questions about this document? Write to hello@heysnitch.com. See also Privacy Terms