Last updated: August 10, 2026
This policy explains what data Text Snip: the desktop application and this website, operated by Andrew Lupu ("I", "me"), collects, why, and what I do with it. I've tried to keep it readable; if anything is unclear, ask me.
1. The most important part
Text recognition runs locally on your computer. When you snip a region of your screen, the image is processed by the OCR engine built into Windows, on your device. I never receive your screenshots, and I never receive the recognized text, it goes straight to your clipboard.
The only exception: optional online features. If you enable translation or AI features, the captured text (never the image) is sent to the respective service to do that job, only at the moment you use the feature, and is not stored by me.
2. What I collect when you create an account
- Email address: required to create and secure your account and used for sign-in, confirmation, password reset, purchase and other essential account messages.
- Name and profile picture: only if you sign in with Google, and only to display them back to you in the app and on this site.
- Plan status: whether your account has Premium, so your features unlock on any device you sign in to.
- Marketing preference and consent record: whether you chose to receive product news and offers, together with the date, source and version of the notice shown to you.
Accounts and the data above are stored in a self-hosted Supabase database on a virtual private server rented from netcup. Supabase provides the open-source authentication and database software, while netcup provides the server infrastructure.
Product news and promotional emails are optional. They are sent only if you actively tick the separate marketing box. Creating an account does not require this choice. You can withdraw it at any time from the Account page or through the unsubscribe link in every marketing email. Essential account, security and purchase emails are not marketing and may still be sent when needed.
3. What stays on your device
- Your settings and preferences.
- Your clipboard history of snips (if you enable it), stored locally, never synced to me.
- Your sign-in session token, so you stay logged in between launches.
4. What I don't do
- No analytics or telemetry inside the desktop app.
- No third-party advertising in the app or on the site, and no selling or sharing of your data with data brokers.
- No reading of your screen except during the snip rectangle you explicitly draw.
5. Third-party services
- Supabase: open-source account authentication and database software that I self-host; account data is not sent to Supabase's hosted platform.
- netcup: virtual private server infrastructure used to self-host account and authentication data.
- Google: only if you choose "Sign in with Google"; Google shares your name, email and avatar with me as part of sign-in.
- Translation providers: only when you use the translation feature; they receive the captured text to translate it.
- Lemon Squeezy: my payment processor for Premium purchases; payment details are handled entirely by them and never touch my servers.
- Resend: email-delivery provider for account messages and, only when you opt in, product news and offers.
- Microsoft Clarity: website analytics, heatmaps and session replay on this website only (not in the app). If you consent, Clarity may use pseudonymous identifiers and record page visits and interactions such as clicks, scrolls and mouse movements. Sensitive content is masked by default.
- Google Fonts: this website loads the Inter typeface from Google's CDN.
6. The app's network connections
The desktop app talks to the internet only for: signing in and refreshing your session, checking your plan status, redeeming promo codes, checking for app updates, and the optional online features described above. Each of these sends the minimum necessary data.
7. Cookies & local storage on this website
This site does not use advertising cookies and never sells your data. Analytics are opt-in: on your first visit a cookie banner asks for your consent, and Microsoft Clarity (website analytics, heatmaps and session replay, which may set cookies and pseudonymous identifiers and record page visits, clicks, scrolls and mouse movements) loads only if you choose Accept. Sensitive content is masked by default. Choosing Decline keeps Clarity off; to change your mind, clear this site's storage and the banner returns. When you sign in on the account page, your session is kept in your browser's local storage so you stay logged in, this is strictly necessary and not covered by the banner, and signing out removes it. The desktop app itself contains no analytics or telemetry.
8. Data retention & deleting your account
I keep your account data for as long as your account exists. You can permanently delete your account and all associated data at any time from the Account page, click "Delete account" and confirm with your email address. Deletion is immediate and cannot be undone. You can also email lupu.andrew@gmail.com and I'll delete it manually, normally within 7 days.
If you opt in to marketing, the active preference is kept until you withdraw it or delete your account. Marketing queue records that contain your email address or display name are deleted 90 days after they are sent or skipped. Consent and withdrawal audit records are kept while your account exists and are deleted with the account, unless a longer period is required by law or needed to establish or defend legal claims. After withdrawal, you are removed from active marketing immediately. Purchase or security records may be retained longer where required by law or needed to establish or defend legal claims.
9. Legal bases, choices & your rights
Account authentication, Premium access and requested support are processed because they are necessary to provide the service or take steps you request. Security and fraud prevention rely on legal obligations or legitimate interests, as applicable. Marketing emails and optional website analytics rely on your consent.
You may withdraw marketing consent at any time, object to direct marketing, and ask to access, correct, erase, restrict or export your personal data where the law provides these rights. Withdrawing consent does not affect earlier lawful processing. Contact lupu.andrew@gmail.com. You may also lodge a complaint with the Romanian data-protection authority (ANSPDCP).
10. Security
Connections to my services use TLS encryption. Passwords are hashed by my authentication provider and are never visible to me. Access to account data inside my systems is restricted by row-level security, so each account can only ever read its own records.
11. Children
Text Snip is not directed at children under 16, and I do not knowingly collect data from them.
12. Changes to this policy
If I change this policy in a meaningful way, I'll update the date at the top and, for significant changes, note it in the app or by email.
13. Contact
Andrew Lupu, lupu.andrew@gmail.com