Privacy Policy

Last updated: 22 May 2026

This policy explains what personal data we collect when you use GameSnap (getgamesnap.com and app.getgamesnap.com), how we use it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Croatian Personal Data Protection Act.

Who is the data controller?

GameSnap is operated by Co Digit d.o.o., based in Croatia. For privacy questions, contact marino@codigit.hr.

What data we collect and why

Account data

When you create a GameSnap account, we collect your email address and a securely hashed password. We use this to authenticate you and to contact you about your account if needed. Lawful basis: contract performance (GDPR Art. 6(1)(b)).

Game screenshots you upload

Screenshots you upload are sent to our AI provider (Anthropic) so we can generate help for your level. The image is processed in real time and is not stored long-term on our servers. We do not use your screenshots to train models. Lawful basis: contract performance.

Payment data

Payments for paid subscriptions are handled by Stripe. We never see or store your card details. We store a Stripe customer ID and your subscription status so we know what features to give you access to. Lawful basis: contract performance.

Usage events

We record anonymous events (you uploaded a photo, you got help, you clicked subscribe) along with a session identifier so we can understand how the service is used, enforce the free tier, and debug issues. If you arrived via an ad, we capture the Google Click ID (gclid) and UTM parameters so we can measure which campaigns bring real users. Lawful basis: legitimate interest in operating and improving the service (GDPR Art. 6(1)(f)); for marketing tracking specifically, consent (GDPR Art. 6(1)(a)).

Technical data

Our hosting provider (Netlify) and database (Supabase) automatically log IP addresses, user-agent strings, and request metadata for security, fraud prevention, and reliability. These are kept for a short period and then deleted. Lawful basis: legitimate interest.

Analytics and advertising

If you consent via our cookie banner, we use Google Analytics 4 and Google Ads to measure how visitors discover and use GameSnap. See our Cookie Policy for the full list. Lawful basis: consent.

Who we share data with (sub-processors)

We use the following sub-processors to operate the service. We select them with care and have data processing agreements (DPAs) in place where required.

  • Supabase — database and authentication (EU region).
  • Anthropic — AI processing of game screenshots (United States; transfer covered by Standard Contractual Clauses and EU-U.S. Data Privacy Framework).
  • Stripe — payment processing (Ireland / United States).
  • Netlify — website hosting and CDN (United States; EU-U.S. Data Privacy Framework certified).
  • Google — Analytics and Ads (United States; EU-U.S. Data Privacy Framework certified). Only loaded with your consent.

How long we keep your data

  • Account data: until you delete your account, or after 24 months of inactivity.
  • Usage events: rolling 24 months.
  • Uploaded screenshots: processed in real time and not stored long-term.
  • Payment records: retained for the period Stripe and Croatian tax law require (typically up to 11 years for invoices).
  • Technical logs: typically up to 30 days.

Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Erase your data (“right to be forgotten”);
  • Restrict or object to certain processing;
  • Receive a copy of your data in a portable format;
  • Withdraw consent at any time (e.g. for analytics or advertising) by re-opening the cookie banner.

To exercise any of these rights, email marino@codigit.hr. We respond within 30 days.

Right to complain

If you believe we have mishandled your personal data, you have the right to complain to the Croatian Personal Data Protection Agency (AZOP). Their contact details are available at azop.hr.

International transfers

Some of our sub-processors are based outside the European Economic Area (notably in the United States). Where this is the case, we rely on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses to ensure your data receives an equivalent level of protection.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the date at the top and notify you in the app if relevant.