Legal
Privacy policy
Snap Back processes photographs of people, which are especially sensitive personal data. This policy explains exactly what is stored, where, for how long, and who else is involved.
Last updated: August 7, 2026
1. Data controller
Manuel Somoza Vázquez, domiciled in Sarria, Lugo, Spain, tax ID (NIF) 34310301M. Contact for data protection matters: info@snapback-ai.com.
2. Data processed
| Data | Source | Necessary for |
|---|---|---|
| Email address | Provided at sign-up | Identifying the account and communicating issues |
| Password | Provided at sign-up | Authentication. Stored hashed; no one can view it in plain text |
| Google identifier, if that method is used | Google, at sign-in | Passwordless authentication |
| The original uploaded photograph | Uploaded by the user | Generating the result and displaying it in the history |
| The generated image | Produced by the Service | Delivering and retaining the result |
| Chosen decade and style, and generation date | User action | Sorting and describing the history |
About facial images. Photographs are processed to generate a new image, not to identify or verify anyone's identity. No biometric templates are extracted or stored, no facial recognition is performed, and images are not cross-referenced between users.
Images are not used to train models, either our own or third parties'.
3. Purposes and legal bases
- Providing the service (generating, delivering and retaining the images): legal basis, performance of the contract.
- Managing the subscription and billing: performance of the contract and compliance with tax and accounting legal obligations.
- Security and abuse prevention (technical logs of errors and access): legitimate interest in keeping the service operational and free of prohibited uses.
- Service-related communications (account confirmation, change notices): performance of the contract.
No automated decisions with legal effects on the user are made, nor is profiling carried out for advertising purposes.
4. Who else is involved
To provide the service, the following providers are used; they act as data processors and are bound by contract:
| Provider | Function | Data accessed |
|---|---|---|
| Supabase | Authentication, database and file storage | Email, credentials, images and history metadata |
| OpenAI | Image generation | The original photograph, during the processing of each request |
| Vercel | Running the web application | Technical connection data |
| Stripe | Subscription billing | Billing data. Card data is handled directly by the payment gateway; the Service never receives or stores it |
Outside these cases, data is not shared with third parties, except where required by law or requested by a competent authority.
5. International transfers
Some of these providers are established in the United States, so photographs and associated data may be processed outside the European Economic Area. These transfers are covered by the Standard Contractual Clauses approved by the European Commission and, where applicable, by the EU-U.S. Data Privacy Framework.
6. Retention periods
- Original photographs and generated images: retained for as long as the account remains active, so the user can view and download them from their history.
- Account data: for as long as the account is active.
- Billing data: for the periods required by tax and commercial regulations, even after the account is closed.
- After account deletion: deletion is immediate. Deleting the account destroys the original photographs, the generated images and the history records, with no grace period or courtesy copy. Only data subject to a legal retention obligation is kept.
The user can delete their account by themselves, at any time and without intermediaries, from My account. The action is irreversible.
7. Security measures
- Images are stored in a private store, never at a public URL.
- Access is controlled at the database level through row-level policies: each user can only read their own generations and their own files.
- Downloads are served through signed links with an expiry, which stop working after a limited time.
- Communications travel encrypted via TLS.
8. User rights
The user can exercise the rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw consent when processing is based on it. The right of erasure can be exercised directly from My account. For everything else, simply write to info@snapback-ai.com from the address associated with the account.
If you believe your data has not been processed correctly, you can file a complaint with the competent supervisory authority. In Spain, this is the Spanish Data Protection Agency (Agencia Española de Protección de Datos).
9. Minors
The Service is not aimed at anyone under 18, and uploading photographs of minors is not permitted. If an account or image found to violate this condition is detected, it will be deleted. Anyone aware of such a case can report it to info@snapback-ai.com.
10. Cookies
Only technical cookies necessary to keep the session signed in are used. No analytics, advertising or third-party tracking cookies are used, so no consent is requested for their use.
11. Changes to this policy
Any change will be published on this page with a new update date. Changes that substantially affect processing will also be communicated by email.
