Privacy Policy
Privacy Policy — SNAB App & Services
Version 3.0 — March 19, 2026
This privacy policy explains how MONNINGHOFF Labs UG (haftungsbeschränkt) (“we”, “us”, “our”) collects, uses, and protects your personal data when you use the SNAB iOS app (iPhone, Apple Watch, Widget, Share Extension) and related services.
We are committed to processing your data exclusively in Germany and the EU wherever technically possible. By default, no personal data leaves the European Union.
1. Controller
MONNINGHOFF Labs UG (haftungsbeschränkt)
Wehrstr. 3
48151 Münster
Germany
Represented by: Chris Mönninghoff
Email: [email protected]
Court of Registration: Amtsgericht Münster, HRB 22312
VAT ID: DE451176103
2. What SNAB Is
SNAB is a mobile-first application for iOS (iPhone and Apple Watch), including a Widget and Share Extension.
The app is designed to process data primarily on the user’s device. By default, personal data remains on the device unless a feature explicitly requires server-side processing or cloud storage.
SNAB allows users to capture and store information such as voice recordings, documents, images, and text. Based on user input, SNAB processes this data to generate structured outputs such as tasks, events, reminders, lists, and user-defined insights.
Processing may include automated analysis of content to identify relevant information (e.g. deadlines, action items, or categories).
SNAB is designed for users aged 13 and older.
3. Data at a Glance
| Category | Where Stored | Shared with Third Parties? |
|---|---|---|
| Voice recordings, notes, scanned documents | On your device only | No |
| App settings, theme preferences, flow configs | On your device only | No |
| User profile (Apple ID, display name) | Hetzner, Germany | No |
| Tasks, events, reminders, lists, insights | Hetzner, Germany | No |
| Audio/images for AI processing | Hetzner, Germany (deleted after processing) | No |
| Extraction logs | Hetzner, Germany | No |
| Cloud-stored files | Cloudflare R2, EU/Frankfurt | No |
| Email addresses | Hetzner, Germany | No (delivery via AWS SES Frankfurt) |
| Payment information | Apple only (we never receive it) | N/A |
| Feedback messages & screenshots | Hetzner + Cloudflare R2, EU | No |
4. Data We Collect
4.1 Account Data
We use Sign in with Apple exclusively. When you create an account, we receive and store:
- Apple anonymous user ID
- Apple private relay email address (or your real email, depending on your Apple settings)
- Display name (as provided by Apple)
- Device vendor ID (for device identification)
- API key (generated by us for authenticated requests)
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
4.2 Content You Create
When you use SNAB, you create personal content including:
- Voice memos and their transcriptions
- Scanned documents and their OCR text
- Photos imported for processing
- Notes, tasks, events, reminders, and lists (RadarItems)
- Insights — observations, ideas, decisions, rules, questions, focus areas, mistakes, and anti-goals (InsightItems)
- Sub-items, linked items, and metadata (dates, priorities, groups)
Content you create is stored on your device. When you use server-side features (transcription, OCR, extraction, cloud storage), relevant data is transmitted to our servers in Germany for processing.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
4.3 Extraction and Processing Logs
When your content is processed by our AI systems, we store extraction logs containing:
- Transcription text (up to 10,000 characters)
- Extracted actions and insights as structured JSON
- AI model used, processing time, and prompt hash
- Quality tier selected
These logs are used solely for service quality improvement and debugging. They are not shared with third parties.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in maintaining and improving service quality.
4.4 Email Data
- Inbound email capture: Each user receives a personal email address (snab-{handle}-{token}@snab.email). We store verified sender addresses.
- Newsletter: Email address and subscription date. Double opt-in via Mailcow (self-hosted, Germany).
- Transactional emails: Delivery metadata (recipient, status, timestamp) retained for up to 30 days.
Legal basis: Art. 6(1)(b) GDPR for inbound email; Art. 6(1)(a) GDPR (consent) for newsletter.
4.5 Subscription and Payment Data
Subscriptions and purchases are handled exclusively through Apple StoreKit (In-App Purchases). We receive:
- Transaction ID, product ID, subscription dates
- Subscription tier (Free, Trial, Gold, Platinum, coFunder, Ambassador, Business)
We never receive your payment details (credit card number, bank account, billing address). Apple processes all payments.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
4.6 Referral Data
If you participate in the referral program, we store:
- Invite code, referrer and invitee user IDs
- Claim status, reward amounts
- IP address and device information (for fraud prevention)
Rewards: 250 MB for referrer, 100 MB for invitee (max 1 GB total, 90-day expiry, max 4 active invites).
Legal basis: Art. 6(1)(b) GDPR for referral processing; Art. 6(1)(f) GDPR for fraud prevention.
4.7 Feedback Data
When you submit feedback through the app, we store:
- Feedback category and messages
- Screenshots (uploaded to Cloudflare R2, EU/Frankfurt)
- Conversation thread with our team
Legal basis: Art. 6(1)(b) GDPR — service improvement and support.
4.8 Technical Data
For service operation, we process:
- Push notification device tokens (via Apple APNs)
- Storage usage tracking
- Rate limit counters (IP-based: 1 hour; user-based: 10 minutes)
- Server access logs (IP address, timestamp, request URL, user agent) — retained for 7 days
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in service security and stability.
4.9 Data We Do NOT Collect
- Location data
- Contacts or address book
- Calendar data
- Health or fitness data
- Biometric data
- No analytics SDKs (no Firebase, Sentry, Amplitude, Mixpanel, or similar)
- No advertising or tracking frameworks
- No App Tracking Transparency (ATT) required — we do not track you
5. App Permissions
SNAB requests the following device permissions, each only when needed:
| Permission | Purpose | Required? |
|---|---|---|
| Microphone | Recording voice memos for transcription | Only for voice features |
| Camera | Scanning documents for OCR | Only for scan features |
| Photo Library | Importing images for OCR processing | Only for import features |
| Speech Recognition | Offline transcription fallback (Apple on-device) | Only for offline mode |
| Push Notifications | Delivering reminders, event alerts, task notifications | Optional |
No permission is required to use SNAB’s core text-based features.
6. AI and Machine Learning Processing
All AI processing runs on our own infrastructure in Germany. No personal data is sent to external AI providers by default.
6.1 Speech-to-Text (Transcription)
- Technology: Self-hosted Faster-Whisper on our GPU server (Hetzner, Germany)
- Models: Whisper Small (free users), Whisper Turbo (paid users)
- Process: Your audio file is uploaded to our server, transcribed, and the audio file is deleted immediately after processing
- No data sent to OpenAI, Apple, or any third party
6.2 Optical Character Recognition (OCR)
- Technology: Self-hosted PaddleOCR on our GPU server (Hetzner, Germany)
- Process: Your image is uploaded, text is extracted, and the image is deleted immediately after processing
- No data sent to any third party
6.3 Action and Insight Extraction (LLM)
- Technology: Self-hosted Qwen3-14B-AWQ via vLLM on our GPU server (Hetzner, Germany)
- Process: Your transcription or OCR text is analyzed to extract tasks, events, reminders, lists, and insights
- All processing stays within our Hetzner Germany infrastructure
- No data sent to Anthropic, OpenAI, or any external AI provider
- Extraction logs are stored for quality improvement and are not shared with third parties
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (the core service you use SNAB for).
6.4 Planned: Premium AI Option (not yet active)
We plan to offer an optional premium extraction feature using an external AI provider (e.g., Anthropic Claude API, servers in the USA). This feature:
- Is not currently active
- Will require explicit opt-in from you before any data is sent
- Will be clearly marked in the app with credit-based billing
- When active, your transcription text will be sent to the AI provider’s servers
- Safeguards: EU-US Data Privacy Framework, Standard Contractual Clauses (Art. 46(2)(c) GDPR)
We will update this privacy policy before launching this feature.
7. Apple Watch
The SNAB Apple Watch app:
- Records voice memos via the microphone
- Transfers audio files to your iPhone via WatchConnectivity
- Sends metadata: device model, watchOS version, recording duration, flow ID, timestamp
- Audio is deleted from the Watch after successful transfer to iPhone
- Uses
self-carebackground mode only
The Watch app does not collect: health data, location, contacts, or biometric data.
8. Widget and Share Extension
Widget Extension: Performs zero data collection and makes no network requests. It opens the main app via deep links only.
Share Extension: Processes files you explicitly share (max 10 files, max 50 MB each). Files are stored temporarily in the shared App Group container. The Share Extension makes no direct network requests — the main app handles all processing.
9. Cloud Storage
9.1 snab.cloud (Included)
All users receive cloud storage on Cloudflare R2 (EU/Frankfurt):
| Tier | Storage |
|---|---|
| Free | 100 MB |
| Gold | 5 GB |
| Platinum | 15 GB |
| coFunder | 25 GB |
Storage add-ons are available (2 GB, 5 GB, or 10 GB per month). Files are encrypted server-side with AES-256.
9.2 External Cloud Providers (Opt-In Only)
Paid users can optionally connect external cloud storage. When you connect a provider, we store your OAuth refresh token on our servers to access your storage on your behalf. You can disconnect at any time, which revokes our access and deletes the stored token.
| Provider | Scopes | Data Transferred | Safeguards |
|---|---|---|---|
| Google Drive (Google LLC, USA) | drive.readonly | OAuth tokens, file metadata | EU-US DPF, SCCs |
| Dropbox (Dropbox Inc., USA) | Metadata + content read/write, account info | OAuth tokens, file metadata | EU-US DPF, SCCs |
| OneDrive (Microsoft Corp., USA) | Files.ReadWrite.All, User.Read | OAuth tokens, file metadata | EU-US DPF, SCCs |
| iCloud Drive | Local file system access only | None sent to Apple beyond standard iCloud sync | N/A |
Legal basis: Art. 6(1)(a) GDPR — your explicit consent when connecting a provider.
10. Push Notifications
We use Apple Push Notification service (APNs) to deliver reminders, event alerts, task notifications, and referral reward notifications. Your device token is registered with our server. No third-party push service is used.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
11. Infrastructure and Hosting
All infrastructure is located in Germany and the EU.
| Service | Provider | Location | Purpose |
|---|---|---|---|
| API Servers (RS01, RS02) | Hetzner Online GmbH | Germany | Backend API, Galera DB cluster |
| GPU Server (GPU02) | Hetzner Online GmbH | Germany | STT, OCR, LLM extraction |
| Object Storage | Cloudflare R2 | EU/Frankfurt | File storage, email attachments, feedback screenshots |
| DNS / CDN / WAF | Cloudflare | Frankfurt PoP | Website delivery, DDoS protection |
| Transactional Email | AWS SES | eu-central-1 (Frankfurt) | Verification emails, reminder emails |
| Newsletter + Operational Email | Mailcow (self-hosted) | Germany | Newsletter, scan/voice/task emails |
| Monitoring | Hetzner Online GmbH | Germany | Prometheus + Grafana (internal only) |
12. Data Security
We implement the following technical and organizational measures to protect your data:
- Encryption in transit: TLS 1.2+ for all connections
- Encryption at rest: AES-256 server-side encryption for Cloudflare R2 storage
- Authentication: API key-based authentication with signed tokens; OAuth 2.0 for Sign in with Apple
- Email security: DKIM, SPF, and DMARC for all outgoing emails
- On-device protection: iOS Data Protection for locally stored data
- Database: Galera cluster replication for redundancy
- Server hardening: UFW firewall on all servers, non-standard SSH port
- Temporary URLs: R2 signed URLs with 5–15 minute TTL for file access
13. Data Processors (Art. 28 GDPR)
We use the following data processors, each bound by a Data Processing Agreement under Art. 28 GDPR:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
Purpose: Server hosting (API, database, GPU workers, monitoring)
Data processed: All server-side data as described in this policy
Location: Germany
Cloudflare, Inc.
101 Townsend St
San Francisco, CA 94107
USA
Purpose: DNS, CDN, WAF, R2 object storage
Data processed: IP addresses, DNS queries, stored files (encrypted)
Location: EU/Frankfurt for R2; global edge network for CDN
Safeguards: EU-US Data Privacy Framework, EU Standard Contractual Clauses
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy
L-1855 Luxembourg
Purpose: Transactional email delivery (SES)
Data processed: Email addresses, delivery status metadata
Location: Frankfurt (eu-central-1)
Safeguards: AWS Data Processing Addendum, EU Standard Contractual Clauses
Apple Inc.
One Apple Park Way
Cupertino, CA 95014
USA
Purpose: Authentication (Sign in with Apple), push notifications (APNs), payment processing (StoreKit)
Data processed: Apple user ID, device token, transaction IDs
Safeguards: EU-US Data Privacy Framework, Apple Developer Program Agreement
Google LLC (only when you connect Google Drive)
1600 Amphitheatre Parkway
Mountain View, CA 94043
USA
Purpose: Cloud storage integration
Data processed: OAuth tokens, file metadata
Safeguards: EU-US Data Privacy Framework, EU Standard Contractual Clauses
Dropbox, Inc. (only when you connect Dropbox)
1800 Owens Street
San Francisco, CA 94158
USA
Purpose: Cloud storage integration
Data processed: OAuth tokens, file metadata
Safeguards: EU-US Data Privacy Framework, EU Standard Contractual Clauses
Microsoft Corporation (only when you connect OneDrive)
One Microsoft Way
Redmond, WA 98052
USA
Purpose: Cloud storage integration
Data processed: OAuth tokens, file metadata
Safeguards: EU-US Data Privacy Framework, EU Standard Contractual Clauses
14. International Data Transfers
Default: All your data is processed in Germany and the EU. No data is transferred to the United States or other third countries by default.
Transfers to the USA occur only in these cases:
- Apple services (Sign in with Apple, APNs, StoreKit) — required for app functionality. Safeguard: EU-US Data Privacy Framework.
- Cloud storage integrations (Google Drive, Dropbox, OneDrive) — only when you explicitly connect a provider. Safeguard: EU-US Data Privacy Framework + Standard Contractual Clauses (Art. 46(2)(c) GDPR).
- Cloudflare CDN — R2 object storage is EU-only (Frankfurt). CDN edge servers may process requests at US points of presence for website delivery. Safeguard: EU-US Data Privacy Framework + Standard Contractual Clauses.
- Future premium AI extraction — not yet active. When launched, opt-in only. Safeguard: EU-US Data Privacy Framework + Standard Contractual Clauses.
Legal basis for transfers: Art. 45 GDPR (adequacy decision for EU-US DPF participants) and Art. 46(2)(c) GDPR (Standard Contractual Clauses).
15. Data Retention
| Data | Retention Period |
|---|---|
| Local app data | Until you delete it |
| User account and profile | Until you delete your account |
| Audio files (voice memos sent for STT) | Deleted immediately after processing |
| Images (sent for OCR) | Deleted immediately after processing |
| Extraction logs | Until account deletion |
| Insight items | Until you delete them or delete your account (soft delete: 90-day grace period) |
| Cloud-stored files (snab.cloud) | Until you delete them or delete your account |
| Email delivery logs | Maximum 30 days |
| Server access logs | 7 days |
| Referral data | 90 days after invite expiry |
| Newsletter subscription | Until you unsubscribe |
| Rate limit data | IP-based: 1 hour; user-based: 10 minutes |
| Soft-deleted items (trash) | 7 days, then permanently deleted |
| Feedback data | Until account deletion |
16. Account Deletion
You can delete your account at any time from the app settings. Account deletion permanently removes:
- Your user profile, API credentials, and device registrations
- All tasks, events, reminders, lists, and insights
- All extraction logs and feedback data
- All files stored on snab.cloud
- All email addresses and newsletter subscriptions
- All referral data
- Push notification registrations
External cloud provider tokens (Google, Dropbox, OneDrive) are revoked immediately upon deletion.
Deletion is irreversible and completed within 30 days.
17. Data Export (Data Portability)
You can export all your data from the app settings in a machine-readable JSON format. The export includes all tasks, events, reminders, lists, insights, and associated metadata.
This fulfills your right to data portability under Art. 20 GDPR.
18. Your Rights Under GDPR
You have the following rights regarding your personal data:
| Right | Article | Description |
|---|---|---|
| Access | Art. 15 GDPR | Request information about what personal data we process |
| Rectification | Art. 16 GDPR | Request correction of inaccurate or incomplete data |
| Erasure | Art. 17 GDPR | Request deletion of your personal data |
| Restriction | Art. 18 GDPR | Request restriction of processing |
| Data Portability | Art. 20 GDPR | Receive your data in a structured, machine-readable format |
| Objection | Art. 21 GDPR | Object to processing based on legitimate interest |
| Withdraw Consent | Art. 7(3) GDPR | Withdraw any previously given consent at any time |
To exercise any of these rights, contact us at [email protected]. We will respond within one month as required by Art. 12(3) GDPR.
Right to Lodge a Complaint (Art. 77 GDPR)
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent authority for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4
40213 Düsseldorf
Germany
Website: www.ldi.nrw.de
19. Children’s Privacy
SNAB is not intended for children under 12 years of age. We do not knowingly collect personal data from children under 12. If you believe that a child under 12 has provided us with personal data, please contact us at [email protected] and we will promptly delete the data.
20. Legal Bases Summary
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Art. 6(1)(b) — Contract performance |
| Content processing (STT, OCR, extraction) | Art. 6(1)(b) — Contract performance |
| Cloud storage (snab.cloud) | Art. 6(1)(b) — Contract performance |
| Push notifications | Art. 6(1)(b) — Contract performance |
| Subscription management | Art. 6(1)(b) — Contract performance |
| Email capture feature | Art. 6(1)(b) — Contract performance |
| External cloud integrations | Art. 6(1)(a) — Consent |
| Newsletter | Art. 6(1)(a) — Consent |
| Extraction logs for quality improvement | Art. 6(1)(f) — Legitimate interest |
| Server logs and security | Art. 6(1)(f) — Legitimate interest |
| Fraud prevention (referrals) | Art. 6(1)(f) — Legitimate interest |
21. Changes to This Privacy Policy
We may update this privacy policy to reflect changes in our services, technology, or legal requirements. Material changes will be communicated via the app or email before they take effect.
The current version is always available at snab.app/privacy.
22. Contact
For all privacy-related questions and requests:
MONNINGHOFF Labs UG (haftungsbeschränkt)
Wehrstr. 3
48151 Münster
Germany
Email: [email protected]
Münster, March 19, 2026