Privacy Policy
Last updated September 15, 2026
1. Who we are
This policy explains how SnipRender (“SnipRender”, “we”, “us”) handles personal data when you use the website and editor at sniprender.com, the preview and shared-page domains it serves projects on (such as sniprender.net), its API and its MCP server (together, the “Service”). SnipRender is the controller of the personal data described here. You can reach us at [email protected].
2. Information we collect
Account information from Google
You sign in with Google. With your permission, Google shares your email address, name and profile picture with us (the openid, email and profile scopes). We never see your Google password.
Content you create
The projects you create and everything in them: files, their contents, images and other uploads, project settings, whether a project is shared, and any custom address you choose for it.
Account settings, plan and access
- Editor preferences, such as auto-save and tab size.
- The plan your account is on and, where one applies, its end date.
- Access tokens you create for agents: their name, first characters, creation, last-use and expiry dates. The token itself is stored only as a one-way hash. Preview sessions opened from the editor are stored the same way.
- For administrators, the email addresses that may open the admin area.
Browser console output from project pages
So that you, or an agent acting for you, can debug a project, the pages a project renders send what their browser console shows — log messages, errors, failed resources — to us, together with the page path and time. These lines come from your own preview and from anyone viewing the project’s shared page. We store them without the viewer’s IP address or browser details, keep at most the newest 500 lines per project, and delete them after 24 hours. The messages are whatever the project’s code writes to the console, so avoid logging personal data in projects you share.
Technical and security logs
Like most websites, our servers and reverse proxies record requests — including IP address, browser user agent, requested address, time and response status — to keep the Service secure, prevent abuse and fix problems. These logs are kept for a limited period and then deleted.
Messages you send us
If you email us, we keep the message and our reply for as long as needed to handle your request.
We do not use analytics or advertising services, we do not track you across other websites, and we do not sell or rent personal data.
3. How we use information
- To provide the Service: signing you in, storing your projects, running previews and serving shared pages.
- To apply plan limits and to enforce our Terms of Service and Acceptable Use Policy, including removing content and banning projects.
- To keep the Service and its users secure: detecting abuse, investigating incidents and preventing fraud.
- To provide debugging tools, such as reading a project’s console output over MCP.
- To answer your requests and communicate with you about the Service, including changes to these documents.
- To comply with legal obligations and respond to lawful requests.
4. Legal bases
Where the law requires a legal basis for processing, we rely on:
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to secure the Service, prevent abuse and improve reliability, balanced against your rights.
- Legal obligation — where we must keep or disclose information by law.
- Consent — where required, which you may withdraw at any time without affecting earlier processing.
5. Shared projects are public
When you turn sharing on, anyone with the address can view the project, and anything in it is visible to them. Each shared address — the project’s code or its custom address — receives its own security certificate, and every certificate is published in public Certificate Transparency logs. This means a shared address can be discovered by people you never sent it to, and it stays listed in those logs after you turn sharing off, even though the page itself stops answering. Do not put personal or confidential information in a project you share or in a custom address.
6. Who we share information with
We share personal data only as needed to run the Service, with:
| Recipient | Why | What they receive |
|---|---|---|
| Sign-in | The sign-in request; Google’s own privacy policy applies to your Google account. | |
| Our hosting provider | Running our servers and database | All data we store, processed on our behalf under contract. |
| Let’s Encrypt | Security certificates for shared and preview addresses | The address being certified, which becomes public (see section 5). |
| esm.sh | Delivering npm packages to React projects | When a preview or shared page loads packages, the viewer’s browser requests them directly from esm.sh, which receives the viewer’s IP address and request details. |
| AI agents you connect | Acting on your projects over MCP | Whatever the tools you allow return, using a token you created. The agent’s provider handles that data under its own terms. |
| Authorities | Legal compliance | Information we are legally required to disclose, or need to disclose to protect people from serious harm. |
If SnipRender is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.
7. How long we keep information
| Information | Kept |
|---|---|
| Account information and settings | Until your account is deleted. |
| Projects and files | Until you delete them or your account is deleted. A banned project is kept until it is unbanned or deleted. |
| Access tokens | Until your account is deleted; a revoked token stays listed, as a hash, so you can see it existed. |
| Preview sessions | They stop working after a short period without use. |
| Console output from project pages | At most 24 hours, and at most the newest 500 lines per project. |
| Technical and security logs | A limited period, then deleted. |
| Messages you send us | As long as needed to handle your request. |
When data is deleted, it is removed from our active database immediately. Copies in backups, where they exist, are removed as those backups are replaced.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy of it;
- correct data that is inaccurate;
- delete your data and your account;
- receive your data in a portable format;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- lodge a complaint with your local data protection authority.
You can delete projects, files and access tokens yourself at any time. For anything else — including deleting your account — email [email protected] from the address on your account. We may need to confirm your identity, and we respond within 30 days.
9. Security
We protect data with encrypted connections, hashed tokens, previews that run on separate origins from the editor, and access controls on every request. No system is perfectly secure; if we learn of a breach that affects your personal data, we will notify you and the authorities as the law requires.
10. International transfers
Our servers and the services listed above may be located in countries other than yours, which may have different data protection laws. Where required, we rely on appropriate safeguards for these transfers.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the Service changes. The date at the top shows the latest version. If a change is significant, we will tell you before it takes effect, for example in the Service or by email.
13. Contact
Questions or requests about this policy or your personal data: [email protected].