Privacy Policy
Snapzap (the “Service”) is an iMessage extension provided by FutureForce OÜ, a company registered in Estonia under registry code 16205299, with its registered office at Mannimae/1, Pudisoo kula, 74626 (“we”, “us”, “our”). We are the controller of the personal data described in this Privacy Policy.
This Privacy Policy explains what data we collect, why we collect it, on what legal basis, how long we keep it, who we share it with, and what rights you have. Terms defined in our Terms and Conditions have the same meaning here unless stated otherwise.
How the Service Works
Snapzap turns a photo you select into a jigsaw puzzle and sends it to the person you are messaging, inside your iMessage conversation. The recipient must solve the puzzle within the time limit set on it in order to see the photo. If the time limit expires before the puzzle is solved, the puzzle burns and the photo is not shown.
Your photo is not sent to our servers. It is encrypted on your device, and only the encrypted data is uploaded to our cloud storage, where it is deleted automatically after 24 hours. The key that would open it never reaches us. The section “Encryption” below explains how this works.
The puzzle link is normally sent through your iMessage conversation. You may also share it in another way, but the recipient will still need the Snapzap app installed on their iPhone or iPad, and the link must still be valid, in order to open the puzzle.
Data We Collect
We do not require you to create an account. We do not ask for your name, your email address, your telephone number, or any other contact details, and we do not collect them. The Service runs inside Messages, and Apple does not give us your Apple Account, your phone number, your email address, or the identity of the person you are messaging.
We collect the following data through the Service:
- The encrypted data of your puzzle. We receive the photo you select only as encrypted data, which we store so that the puzzle can be delivered to the recipient. We do not receive the photo itself, and we do not receive the photo library on your device; only the individual photo you select for a puzzle is used, and only in encrypted form.
- Puzzle metadata. A random identifier for the puzzle, its time limit, the number of pieces, and the time at which it was created. This data is needed to deliver the puzzle and to burn it when its time limit expires. It does not identify you.
- Technical connection data. When your device connects to our servers, it sends your IP address, the approximate country derived from that IP address, your user agent, and standard request headers. This data is necessary to deliver the Service and to keep it secure.
Encryption
Before anything leaves your device, the photo is encrypted on the device itself using AES-GCM with a 128-bit key. A new key is generated on your device for each puzzle. Only the resulting encrypted data is uploaded to our cloud storage.
The key is never uploaded with it. It is carried in the part of the puzzle link that follows the “#” symbol, which by the design of the web is never sent to any server: not to ours, not to your network provider, and not to any website, even if the link is opened in a browser. The key travels from your device to the recipient's device inside the link itself, and remains on the client at all times. When the link is sent through iMessage, that transfer is additionally protected by Apple's own end-to-end encryption.
The photo can therefore be seen only by you and by the person who receives the link containing the key. Nobody else can see it, and that includes us: we hold encrypted data and no means of opening it. We cannot view your photo, we cannot restore it, and we cannot disclose it to any third party, including in response to a legal request. If you share the link with someone other than the intended recipient, that person will be able to open the puzzle, so you should share it only with the person it is meant for.
No Advertising and No Analytics
The Service contains no advertising. We do not use advertising providers, we do not use an advertising identifier, and we do not build a profile of you.
We do not use analytics or crash reporting services. We do not use Google Analytics for Firebase, Firebase Crashlytics, or any comparable product. We do not collect usage data such as launches, screens opened, or features used, and we do not record which photos you send, to whom you send them, or whether they were solved.
Legal Bases for Processing
Where the General Data Protection Regulation applies, we rely on the following legal bases:
- Performance of a contract. To provide the Service to you, including storing and delivering your encrypted photo and the metadata of the puzzle, and administering your premium subscription.
- Legitimate interests. To keep the Service secure and to prevent abuse of the Service. We have assessed that these interests are not overridden by your rights and freedoms.
- Legal obligation. To retain transaction records for the period required by accounting and tax law.
We do not rely on consent, because we carry out no processing for advertising or analytics purposes.
Special Category Data
A photo you send may reveal data that Article 9 of the General Data Protection Regulation treats as a special category, including data concerning your sex life or sexual orientation. Because every photo is encrypted on your device with a key we never hold, we cannot determine the content of any photo and we do not process it by reference to its content. You decide what you send and to whom.
Subscriptions
Premium subscriptions are purchased and processed by Apple through the App Store. We do not receive or store your payment card details or your billing information. We receive only the subscription status and the transaction identifier issued by Apple, which we use to confirm your entitlement to premium features. Payments are governed by Apple's privacy policy.
Network and Security Provider
All requests to our servers pass through the network of Cloudflare, Inc., which acts as our processor. Cloudflare processes technical request data on our behalf, including your IP address, the approximate country derived from that IP address, request headers, your user agent, and the requested URL, solely in order to deliver, secure, and accelerate the Service. Cloudflare does not receive the encryption key and cannot view your photos. Cloudflare's privacy policy is available at cloudflare.com/privacypolicy.
Where Your Data Is Stored
The encrypted puzzle data and the puzzle metadata we store are held on servers located within the European Union. This applies to every user of the Service, irrespective of the country from which the Service is used.
Cloudflare may process technical request data outside the European Economic Area, including in the United States. Where it does so, those transfers are made under the safeguards provided for in Chapter V of the General Data Protection Regulation, in particular the standard contractual clauses adopted by the European Commission. Details are set out in the privacy policy linked above.
How Long We Keep Your Data
- Encrypted puzzle data and puzzle metadata. Deleted automatically once the puzzle has been solved or has burned, and in any event no later than 24 hours after the puzzle is created. Deletion is carried out by an automated process and does not require a request from you.
- Server and security logs. Deleted automatically 24 hours after they are recorded. These logs contain technical request data only; they contain no puzzle data.
- Subscription records. Retained for as long as your subscription is active, and afterwards for the period required by applicable accounting and tax law.
No data stored on our servers, other than subscription records retained under the preceding paragraph, is kept for longer than 24 hours.
Abuse Prevention
We operate automated systems that protect the Service against abuse, tampering, and unauthorised access. Because photos are encrypted on your device and we do not hold the key, these systems operate on technical request data only, such as request rate, request headers, and the size and pattern of requests. They cannot inspect the photos you send. Where they detect activity indicating a possible violation, they may restrict or block access, in order to stop and prevent breaches of our Terms and Conditions.
If your access has been restricted or blocked by an automated decision, you may contact us at the address given below to express your point of view, to obtain a review of the decision by a member of our staff, and to contest the decision.
Age
We do not ask for your date of birth and we do not receive it, or any other account data, from Apple. We carry out no advertising or analytics processing, so we do not process your age category for those purposes either.
Your Rights
Where the General Data Protection Regulation applies, you have the right to request access to your personal data, to request its rectification or erasure, to request the restriction of its processing, to object to processing carried out on the basis of our legitimate interests, and to receive the data you have provided to us in a structured, commonly used, and machine-readable format.
Because we do not collect a name, an email address, a telephone number, or any other identifier that would allow us to link stored data to you as an individual, and because the data we hold is encrypted with a key we do not possess, we cannot identify your data from a request alone. In that case we may ask you for additional information that allows us to locate the data concerned. Where we cannot identify you, we may be unable to act on the request, as provided for in Article 11 of the General Data Protection Regulation. In any event, the data concerned is deleted automatically within 24 hours.
You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee. You may also lodge a complaint with the supervisory authority of the country in which you live.
Security
We implement appropriate technical and organisational measures to protect your data. Photos are encrypted on your device with a key that never reaches our servers. Traffic between the app and our servers is additionally encrypted in transit, including the connection between our network provider and our origin servers.
The Service also applies a system-level protection that prevents a solved photo from being captured by a screenshot or a screen recording on the recipient's device. This is a technical measure and not a guarantee: it cannot prevent the recipient from photographing the screen with another device, and it may be defeated by a modified or jailbroken device or by a future change to the operating system. You should send a photo only to a person you trust, and you should assume that anything you send may be retained by that person.
No method of transmission over the internet and no method of electronic storage is entirely secure, and we cannot guarantee absolute security.
Links to Other Sites
The Service may contain links to other sites. If you follow a third-party link, you will be directed to a site that we do not operate. We therefore encourage you to review the privacy policy of any site you visit. We have no control over, and accept no responsibility for, the content, privacy policies, or practices of any third-party site or service.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be published on this page, and the date at the top of this policy will be updated accordingly. We encourage you to review this page periodically.
Contact Us
If you have any questions or requests concerning this Privacy Policy or your data, please contact us at [email protected].