← Back to home

Last updated: April 2026

Privacy Policy

1. Data Controller

The data controller responsible for processing personal data under GDPR is:

Oliver Strebel-Mark
Emmericher Weg 76a
47574 Goch, Germany
Phone: +49 2822 7139167
Email: support@snaptobuild.app

If you have questions about our privacy practices, please contact us at the email address above.

2. Data We Collect

2.1 Photos and Images

When you use the SnapToBuild app, you upload photos of your DIY projects. These images are stored in Firebase Storage (Google Cloud) and associated with your user account. Photos remain in your project storage and are not automatically deleted after analysis.

2.2 Firebase Authentication Data

When you use the app, an anonymous user ID is created. If you optionally sign in with Apple ID or Google, we additionally receive your email address and optionally your name from the respective provider.

2.3 Analysis Results

AI-generated analysis results (project title, materials list, step-by-step instructions, tools required, etc.) are stored in Google Firestore and associated with your user account.

2.4 Usage Analytics

We use Firebase Analytics (in the app) and PostHog (on the website) to analyze user behavior in aggregate (e.g., which features are used, session duration, pages visited). This data is device-level and is not directly linked to your personal identity.

2.5 Crash and Error Data

In the event of an app crash or error, technical data (device type, OS version, error message, stack trace) is captured by Firebase Crashlytics and Sentry to help us fix bugs and improve the app. Sentry additionally stores performance data (load times, slow transactions).

2.6 Purchase Data

If you purchase a premium subscription, your purchase data is processed by RevenueCat. We only receive your subscription status (active, expired, free trial). Payment information (credit card numbers, etc.) is handled exclusively by Apple (App Store).

3. Purpose of Processing

  • App functionality: Providing the AI-powered DIY project analysis, storing and managing your projects
  • App improvement: Analyzing usage patterns (aggregated, not personal), fixing bugs via crash reports
  • Payment processing: Managing in-app purchases and subscription status

4. Legal Basis (GDPR)

Processing of your personal data is based on the following legal grounds:

  • Art. 6(1)(b) GDPR (Contract performance): Data required to provide app functionality (photos, analysis results, authentication data)
  • Art. 6(1)(f) GDPR (Legitimate interests): Usage analytics and crash data for improving app quality

5. Third-Party Service Providers

We use the following third-party service providers:

  • Firebase / Google Cloud (Alphabet Inc., USA): Authentication (Firebase Auth), data storage (Firestore), image storage (Firebase Storage), usage analytics (Firebase Analytics), crash reports (Firebase Crashlytics), app security (Firebase App Check). Data is processed and stored on servers in the EU (region europe-west1, Belgium). EU Standard Contractual Clauses apply per Art. 46 GDPR. Firebase Privacy
  • Google Cloud Run (Alphabet Inc., USA): Hosting of the app backend (API server) in the EU (region europe-west1, Belgium). Processes API requests including authentication tokens and image data for analysis. All API data is processed within the EU. Google Cloud Privacy Notice
  • OpenAI (OpenAI LLC, USA): Image analysis for AI project evaluation. Images are transmitted server-side to the OpenAI Vision API and are not permanently stored by OpenAI. Standard Contractual Clauses apply. OpenAI Privacy Policy
  • RevenueCat (RevenueCat, Inc., USA): In-app subscription management and purchase history. RevenueCat Privacy Policy
  • Apple (Apple Inc., USA): Sign in with Apple, App Store payment processing, TestFlight beta distribution. Apple Privacy Policy
  • Google (Alphabet Inc., USA): Sign in with Google. Google Privacy Policy
  • Sentry (Functional Software, Inc., USA): Error and performance monitoring in the iOS app. Captures crash reports, stack traces, device and OS information. Standard Contractual Clauses apply. Sentry Privacy Policy
  • PostHog (PostHog, Inc., USA; EU hosting): Web analytics on the snaptobuild.app website. Captures page views, click behavior, and scroll depth. No tracking cookies are used. Data is routed through a first-party proxy and stored on servers in the EU. PostHog Privacy Policy
  • Vercel (Vercel Inc., USA): Hosting of the snaptobuild.app website (Next.js application). Collects server access logs (IP address, browser type, access time). Content is delivered via a global edge network including EU locations. Vercel Privacy Policy
  • Cloudflare (Cloudflare, Inc., USA): DNS management and CDN for snaptobuild.app. Processes DNS queries and routes web traffic. No app user data is transmitted to Cloudflare. Cloudflare Privacy Policy

6. Data Storage and International Transfers

Your data is primarily stored and processed on Google Cloud (Firebase) servers in the EU (region europe-west1, Belgium). The app backend (Cloud Run) also runs in the EU. Web analytics data (PostHog) is stored on EU servers.

Data transfer to the USA occurs with the following services: OpenAI (AI analysis), RevenueCat (subscription management), Sentry (error reports), Apple (authentication and payments). These transfers take place on the basis of the European Commission's Standard Contractual Clauses (SCC) (Art. 46(2)(c) GDPR) or for contract performance (Art. 6(1)(b) GDPR).

For AI analysis, images are transmitted to OpenAI servers (USA). OpenAI does not permanently store data transmitted via its API for training purposes (per OpenAI API terms of service).

7. Deleting Your Data

You can delete your account and all associated data at any time. The account deletion option is available in the app under Settings > Delete Account. The following will be deleted:

  • All images stored in Firebase Storage
  • All projects and analysis results stored in Firestore
  • Your Firebase user account and user ID

Usage analytics (Firebase Analytics) and crash reports (Crashlytics) cannot be individually deleted due to their anonymized or aggregated nature.

8. Your Rights

You have the following rights regarding your personal data:

  • Access (Art. 15 GDPR): Right to obtain information about stored data
  • Rectification (Art. 16 GDPR): Right to correct inaccurate data
  • Erasure (Art. 17 GDPR): Right to deletion (“right to be forgotten”)
  • Restriction (Art. 18 GDPR): Right to restrict processing
  • Data portability (Art. 20 GDPR): Right to receive your data in machine-readable format
  • Objection (Art. 21 GDPR): Right to object to processing based on legitimate interests
  • Complaint: Right to lodge a complaint with a supervisory authority

To exercise your rights, please contact us by email at: support@snaptobuild.app

9. Contact

For questions, comments, or complaints about privacy, please contact us at:

Oliver Strebel-Mark
Email: support@snaptobuild.app

10. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy as needed. The current version is always available at snaptobuild.app/en/privacy. We will notify you in the app of any significant changes.