Privacy Policy

Last updated September 15, 2026

In short: we collect what it takes to sign you in and to store, preview and share your projects — your Google email, name and picture, and the content you create. We use no analytics, advertising or tracking cookies, and we do not sell personal data. Shared pages are public, and their addresses can be discovered through public certificate logs. You can ask us to access, correct, export or delete your data at [email protected].

1. Who we are

This policy explains how SnipRender (“SnipRender”, “we”, “us”) handles personal data when you use the website and editor at sniprender.com, the preview and shared-page domains it serves projects on (such as sniprender.net), its API and its MCP server (together, the “Service”). SnipRender is the controller of the personal data described here. You can reach us at [email protected].

2. Information we collect

Account information from Google

You sign in with Google. With your permission, Google shares your email address, name and profile picture with us (the openid, email and profile scopes). We never see your Google password.

Content you create

The projects you create and everything in them: files, their contents, images and other uploads, project settings, whether a project is shared, and any custom address you choose for it.

Account settings, plan and access

  • Editor preferences, such as auto-save and tab size.
  • The plan your account is on and, where one applies, its end date.
  • Access tokens you create for agents: their name, first characters, creation, last-use and expiry dates. The token itself is stored only as a one-way hash. Preview sessions opened from the editor are stored the same way.
  • For administrators, the email addresses that may open the admin area.

Browser console output from project pages

So that you, or an agent acting for you, can debug a project, the pages a project renders send what their browser console shows — log messages, errors, failed resources — to us, together with the page path and time. These lines come from your own preview and from anyone viewing the project’s shared page. We store them without the viewer’s IP address or browser details, keep at most the newest 500 lines per project, and delete them after 24 hours. The messages are whatever the project’s code writes to the console, so avoid logging personal data in projects you share.

Technical and security logs

Like most websites, our servers and reverse proxies record requests — including IP address, browser user agent, requested address, time and response status — to keep the Service secure, prevent abuse and fix problems. These logs are kept for a limited period and then deleted.

Messages you send us

If you email us, we keep the message and our reply for as long as needed to handle your request.

We do not use analytics or advertising services, we do not track you across other websites, and we do not sell or rent personal data.

3. How we use information

  • To provide the Service: signing you in, storing your projects, running previews and serving shared pages.
  • To apply plan limits and to enforce our Terms of Service and Acceptable Use Policy, including removing content and banning projects.
  • To keep the Service and its users secure: detecting abuse, investigating incidents and preventing fraud.
  • To provide debugging tools, such as reading a project’s console output over MCP.
  • To answer your requests and communicate with you about the Service, including changes to these documents.
  • To comply with legal obligations and respond to lawful requests.

Where the law requires a legal basis for processing, we rely on:

  • Performance of a contract — to provide the Service you signed up for.
  • Legitimate interests — to secure the Service, prevent abuse and improve reliability, balanced against your rights.
  • Legal obligation — where we must keep or disclose information by law.
  • Consent — where required, which you may withdraw at any time without affecting earlier processing.

5. Shared projects are public

When you turn sharing on, anyone with the address can view the project, and anything in it is visible to them. Each shared address — the project’s code or its custom address — receives its own security certificate, and every certificate is published in public Certificate Transparency logs. This means a shared address can be discovered by people you never sent it to, and it stays listed in those logs after you turn sharing off, even though the page itself stops answering. Do not put personal or confidential information in a project you share or in a custom address.

6. Who we share information with

We share personal data only as needed to run the Service, with:

RecipientWhyWhat they receive
GoogleSign-inThe sign-in request; Google’s own privacy policy applies to your Google account.
Our hosting providerRunning our servers and databaseAll data we store, processed on our behalf under contract.
Let’s EncryptSecurity certificates for shared and preview addressesThe address being certified, which becomes public (see section 5).
esm.shDelivering npm packages to React projectsWhen a preview or shared page loads packages, the viewer’s browser requests them directly from esm.sh, which receives the viewer’s IP address and request details.
AI agents you connectActing on your projects over MCPWhatever the tools you allow return, using a token you created. The agent’s provider handles that data under its own terms.
AuthoritiesLegal complianceInformation we are legally required to disclose, or need to disclose to protect people from serious harm.

If SnipRender is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.

7. How long we keep information

InformationKept
Account information and settingsUntil your account is deleted.
Projects and filesUntil you delete them or your account is deleted. A banned project is kept until it is unbanned or deleted.
Access tokensUntil your account is deleted; a revoked token stays listed, as a hash, so you can see it existed.
Preview sessionsThey stop working after a short period without use.
Console output from project pagesAt most 24 hours, and at most the newest 500 lines per project.
Technical and security logsA limited period, then deleted.
Messages you send usAs long as needed to handle your request.

When data is deleted, it is removed from our active database immediately. Copies in backups, where they exist, are removed as those backups are replaced.

8. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy of it;
  • correct data that is inaccurate;
  • delete your data and your account;
  • receive your data in a portable format;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with your local data protection authority.

You can delete projects, files and access tokens yourself at any time. For anything else — including deleting your account — email [email protected] from the address on your account. We may need to confirm your identity, and we respond within 30 days.

9. Security

We protect data with encrypted connections, hashed tokens, previews that run on separate origins from the editor, and access controls on every request. No system is perfectly secure; if we learn of a breach that affects your personal data, we will notify you and the authorities as the law requires.

10. International transfers

Our servers and the services listed above may be located in countries other than yours, which may have different data protection laws. Where required, we rely on appropriate safeguards for these transfers.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the Service changes. The date at the top shows the latest version. If a change is significant, we will tell you before it takes effect, for example in the Service or by email.

13. Contact

Questions or requests about this policy or your personal data: [email protected].