Privacy Policy

Last updated: September 1, 2026

Who we are and how to contact us

Snapset (the "Service") is operated by Eden Jarmon, a licensed sole proprietor (Osek Murshe) registered in Israel, Business no. 322374729 (the "Operator"). The Operator is the controller of the personal data described here, and the owner of the database within the meaning of the Israeli Privacy Protection Law, 5741-1981. All privacy matters, including requests to exercise your rights, can be sent to ejarmon.design@gmail.com. No data protection officer is appointed, because the Service does not meet the thresholds that require one; the Operator answers privacy enquiries personally.

Which laws this policy follows

This policy is written to satisfy, together, the Israeli Privacy Protection Law, 5741-1981, its regulations and Amendment No. 13 to that Law, in force since August 2025, and Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR). The Service is offered in English, Hebrew, Spanish, French and German and is deliberately made available to users in the European Union, so the GDPR applies to that use. Where the two regimes differ, the Operator applies the standard that gives you more protection.

What data we collect and why

Only data that the Service actually needs is collected. In practice this means:

  • Account data: your email address and display name, your interface language, and your marketing consent state. Purpose: creating and operating your account, signing you in, and contacting you about the Service.
  • Uploaded screenshots and captured URLs: images you upload and web addresses you ask the Service to capture on your behalf. Purpose: producing the mockups you request.
  • Generated mockups: the images the Service produces for you, together with the generation settings used, so a series can be reviewed and re-run. Purpose: delivering and storing your results.
  • Credit and payment records: purchases, subscription state, credit balance and movements, invoice records, and the buyer country resolved from the IP address of the request together with how it was resolved. Purpose: charging you correctly, issuing lawful tax documents and applying the right VAT treatment.
  • Coupon redemptions: which coupon was used, by which account, and when. Purpose: honouring the discount and preventing abuse.
  • Marketing consent state and timestamps: whether you opted in, when, and when you withdrew. Purpose: proving that consent was given as the law requires.
  • Technical logs: IP address, browser and device information, timestamps, requested actions and error records. Purpose: keeping the Service available, diagnosing faults, and detecting abuse and fraud.

Full payment card details are never received or stored by the Operator; they are entered directly with the payment provider. The Operator does not intentionally collect special categories of data, and you should not upload screenshots containing them.

Legal bases under the GDPR

Each purpose rests on a specific legal basis under Article 6 of the GDPR:

  • Performance of a contract, Article 6(1)(b): creating and running your account, generating mockups, storing your projects, and billing you for what you buy.
  • Compliance with a legal obligation, Article 6(1)(c): keeping accounting and tax records, issuing invoices, retaining evidence of consent, and responding to lawful requests from authorities.
  • Consent, Article 6(1)(a): marketing email and any non-essential cookie or similar storage. Consent is optional, and you can withdraw it at any time without affecting the lawfulness of processing carried out before you withdrew it.
  • Legitimate interests, Article 6(1)(f): securing the Service, preventing fraud and abuse of credits and coupons, and maintaining technical logs. The Operator balances these interests against your rights and keeps the data involved to a minimum.

Under Israeli law, the corresponding basis is your informed consent to the terms of this policy when you register and use the Service, together with the Operator's legal duties.

Cookies and local storage

The Service keeps a small amount of information in your browser. This is the full inventory of what it sets:

  • Authentication session: keeps you signed in between pages and reloads. Strictly necessary.
  • Theme preference: remembers light or dark mode. Strictly necessary for the interface to render as you chose.
  • Language preference: remembers the locale you selected. Strictly necessary.
  • Region cache: stores the region resolved for pricing and tax display, so it is not looked up on every page. Strictly necessary.
  • Accessibility settings: stores the adjustments you make in the accessibility widget. Strictly necessary.
  • Cookie consent record: stores your consent choice, the time it was given and the policy version it applies to. Strictly necessary, and required so we do not ask you again.

No analytics storage and no advertising or marketing storage are in use today. If that ever changes, the categories described in the next section will be activated, the policy version will be raised, and you will be asked again before anything non-essential is set.

Your consent choice and how to change it

On your first visit, a small notice at the bottom of the page lets you accept all categories, allow essential storage only, or open the settings panel and decide per category. Rejecting is exactly as easy as accepting, one click, and the notice never blocks reading or scrolling. The categories are Essential, which is always on because the Service cannot work without it, Analytics, which is off by default, and Marketing, which is also off by default. Neither optional category runs anything today. Your choice is stored with a timestamp and a policy version, and it is mirrored to your account when you are signed in so it follows you across devices. You will only be asked again if no valid record exists, if the policy version changes materially, or if your record is more than twelve months old. You can change your mind at any time through the "Cookie settings" link in the footer of every page.

Who receives your data

Data is never sold. It is shared only with service providers acting as processors on the Operator's documented instructions, each for a defined role:

  • Hosting, database, authentication and file storage: Lovable Cloud, running on Supabase infrastructure. Holds account data, projects, images, credits and payment records.
  • AI image generation: OpenAI. Your uploaded screenshots, or the regions of them you select, are transmitted to be processed into mockups, together with the prompt describing the scene. Business API processing is not used to train the provider's models.
  • Website capture: the capture provider that renders a public web address into a screenshot when you ask the Service to capture a URL. It receives the address, not your account content.
  • Payment processing and tax documents: Tranzila. Receives the transaction data needed to take payment and to issue an invoice or receipt. Card details go to it directly.
  • Email delivery: Resend. Receives your email address and the message content for transactional and, where you consented, marketing email.
  • IP geolocation: the geolocation service queried to resolve the country of a request for pricing and VAT purposes. Receives the IP address of the request only.

Data may also be disclosed where the law requires it, for example to a competent authority or a court, and to professional advisers bound by confidentiality.

International transfers

Some of these providers operate outside Israel and outside the European Economic Area, principally in the United States. Transfers out of the EEA are made on the basis of appropriate safeguards under Chapter V of the GDPR, in practice the European Commission's Standard Contractual Clauses in the provider's data processing agreement, or an adequacy decision where one covers the provider. Transfers out of Israel are made in accordance with the Privacy Protection Regulations (Transfer of Data to Databases Abroad), 5761-2001. A copy of the safeguards relied on for a given provider can be requested by email.

How long we keep data

Data is kept only as long as it serves the purpose it was collected for:

  • Account data, projects, uploaded screenshots and generated mockups: for as long as your account exists. Deleting a project deletes its images.
  • Accounting, invoicing and tax records, including the buyer country and the basis on which it was resolved: seven years, as required by Israeli tax and bookkeeping rules. These records survive account deletion because the law requires it.
  • Consent records, both marketing and cookie consent: for as long as the consent is relied on and for a reasonable period afterwards, as evidence that it was properly obtained.
  • Technical and security logs: a short period, normally no more than twelve months, unless a specific security incident requires keeping them longer.

You can delete your account from the profile page in the product. Deletion removes your account, projects, uploaded screenshots and generated images, and anonymises what must be retained for legal reasons.

Your rights

Under the GDPR and, in their Israeli equivalents, under sections 13 and 14 of the Privacy Protection Law as expanded by Amendment No. 13, you have the right to:

  • Access the personal data held about you and receive a copy of it.
  • Have inaccurate, incomplete or outdated data corrected.
  • Have your data erased where there is no lawful reason to keep it.
  • Restrict processing while a dispute about accuracy or lawfulness is resolved.
  • Receive the data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Object to processing based on legitimate interests, including profiling, and to object to direct marketing at any time.
  • Withdraw any consent at any time, through the unsubscribe link in every marketing email, the cookie settings link in the footer, or by writing to us.

To exercise any of these rights, write to ejarmon.design@gmail.com. The Operator answers within one month, and will say so if that period needs to be extended for a complex request. You may also complain to the Israeli Privacy Protection Authority, or, if you are in the EU, to the supervisory authority of your country of residence, place of work, or the place where you believe an infringement occurred.

Security

The Operator applies security measures aligned with the Privacy Protection Regulations (Data Security), 5777-2017, and with Article 32 of the GDPR: encryption in transit, encryption at rest for stored files, row-level access rules so an account can only reach its own data, private storage buckets with time-limited access links, least-privilege administrative access, secrets held outside the codebase, and audit logging of privileged actions. Access to production data is limited to the Operator. No system can be guaranteed absolutely secure, and the measures are reviewed as the Service changes.

Data breaches

If a security incident affecting personal data occurs, the Operator will investigate immediately, contain it, and notify the competent authority within 72 hours of becoming aware of it where the GDPR requires notification, as well as the Israeli Privacy Protection Authority where Israeli law requires it. Where the incident is likely to create a high risk to your rights, you will be told directly and without undue delay, in plain language, along with what happened and what you can do.

Automated decision-making

The Service uses artificial intelligence to generate images, but it does not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 of the GDPR. No credit scoring, eligibility scoring or automated account decisions are made about you.

Children

The Service is a professional design tool and is not intended for or directed at children. Accounts require the user to be 18 or over under the Terms of Service, and in no case will the Service knowingly process the data of anyone under 16, the relevant age for consent to information society services under Article 8 of the GDPR. If we learn that a child's data has been collected, it will be deleted promptly. A parent or guardian who believes this has happened can write to ejarmon.design@gmail.com.

Marketing communications

Marketing email is sent only with your prior explicit consent, in line with section 30A of the Israeli Communications Law (Bezeq and Broadcasting), 5742-1982, and with the GDPR. Transactional messages about your account, purchases and invoices are not marketing and are sent regardless, because they are part of the contract. You can withdraw marketing consent at any time from your profile, through the unsubscribe link in every message, or by writing to ejarmon.design@gmail.com.

Changes to this policy

This is version 2.0 of the policy; the date it last changed is shown at the top of this page. Minor clarifications are published here and take effect on publication. Where a change is material, for example a new category of data, a new purpose, a new processor or the introduction of analytics or marketing storage, the consent version is raised, the consent notice is shown again, and you are asked to make your choice afresh. The binding version is always the one published in the Service. Policy version 2.0

This document is provided for general information and was prepared with automated assistance; it does not constitute legal advice.

Skip to main content