Privacy Policy

Privacy Policy — SNAB App & Services

Version 3.0 — March 19, 2026

This privacy policy explains how MONNINGHOFF Labs UG (haftungsbeschränkt) (“we”, “us”, “our”) collects, uses, and protects your personal data when you use the SNAB iOS app (iPhone, Apple Watch, Widget, Share Extension) and related services.

We are committed to processing your data exclusively in Germany and the EU wherever technically possible. By default, no personal data leaves the European Union.


1. Controller

MONNINGHOFF Labs UG (haftungsbeschränkt)
Wehrstr. 3
48151 Münster
Germany

Represented by: Chris Mönninghoff
Email: [email protected]
Court of Registration: Amtsgericht Münster, HRB 22312
VAT ID: DE451176103


2. What SNAB Is

SNAB is a mobile-first application for iOS (iPhone and Apple Watch), including a Widget and Share Extension.

The app is designed to process data primarily on the user’s device. By default, personal data remains on the device unless a feature explicitly requires server-side processing or cloud storage.

SNAB allows users to capture and store information such as voice recordings, documents, images, and text. Based on user input, SNAB processes this data to generate structured outputs such as tasks, events, reminders, lists, and user-defined insights.

Processing may include automated analysis of content to identify relevant information (e.g. deadlines, action items, or categories).

SNAB is designed for users aged 13 and older.


3. Data at a Glance

CategoryWhere StoredShared with Third Parties?
Voice recordings, notes, scanned documentsOn your device onlyNo
App settings, theme preferences, flow configsOn your device onlyNo
User profile (Apple ID, display name)Hetzner, GermanyNo
Tasks, events, reminders, lists, insightsHetzner, GermanyNo
Audio/images for AI processingHetzner, Germany (deleted after processing)No
Extraction logsHetzner, GermanyNo
Cloud-stored filesCloudflare R2, EU/FrankfurtNo
Email addressesHetzner, GermanyNo (delivery via AWS SES Frankfurt)
Payment informationApple only (we never receive it)N/A
Feedback messages & screenshotsHetzner + Cloudflare R2, EUNo

4. Data We Collect

4.1 Account Data

We use Sign in with Apple exclusively. When you create an account, we receive and store:

  • Apple anonymous user ID
  • Apple private relay email address (or your real email, depending on your Apple settings)
  • Display name (as provided by Apple)
  • Device vendor ID (for device identification)
  • API key (generated by us for authenticated requests)

Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

4.2 Content You Create

When you use SNAB, you create personal content including:

  • Voice memos and their transcriptions
  • Scanned documents and their OCR text
  • Photos imported for processing
  • Notes, tasks, events, reminders, and lists (RadarItems)
  • Insights — observations, ideas, decisions, rules, questions, focus areas, mistakes, and anti-goals (InsightItems)
  • Sub-items, linked items, and metadata (dates, priorities, groups)

Content you create is stored on your device. When you use server-side features (transcription, OCR, extraction, cloud storage), relevant data is transmitted to our servers in Germany for processing.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

4.3 Extraction and Processing Logs

When your content is processed by our AI systems, we store extraction logs containing:

  • Transcription text (up to 10,000 characters)
  • Extracted actions and insights as structured JSON
  • AI model used, processing time, and prompt hash
  • Quality tier selected

These logs are used solely for service quality improvement and debugging. They are not shared with third parties.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in maintaining and improving service quality.

4.4 Email Data

  • Inbound email capture: Each user receives a personal email address (snab-{handle}-{token}@snab.email). We store verified sender addresses.
  • Newsletter: Email address and subscription date. Double opt-in via Mailcow (self-hosted, Germany).
  • Transactional emails: Delivery metadata (recipient, status, timestamp) retained for up to 30 days.

Legal basis: Art. 6(1)(b) GDPR for inbound email; Art. 6(1)(a) GDPR (consent) for newsletter.

4.5 Subscription and Payment Data

Subscriptions and purchases are handled exclusively through Apple StoreKit (In-App Purchases). We receive:

  • Transaction ID, product ID, subscription dates
  • Subscription tier (Free, Trial, Gold, Platinum, coFunder, Ambassador, Business)

We never receive your payment details (credit card number, bank account, billing address). Apple processes all payments.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

4.6 Referral Data

If you participate in the referral program, we store:

  • Invite code, referrer and invitee user IDs
  • Claim status, reward amounts
  • IP address and device information (for fraud prevention)

Rewards: 250 MB for referrer, 100 MB for invitee (max 1 GB total, 90-day expiry, max 4 active invites).

Legal basis: Art. 6(1)(b) GDPR for referral processing; Art. 6(1)(f) GDPR for fraud prevention.

4.7 Feedback Data

When you submit feedback through the app, we store:

  • Feedback category and messages
  • Screenshots (uploaded to Cloudflare R2, EU/Frankfurt)
  • Conversation thread with our team

Legal basis: Art. 6(1)(b) GDPR — service improvement and support.

4.8 Technical Data

For service operation, we process:

  • Push notification device tokens (via Apple APNs)
  • Storage usage tracking
  • Rate limit counters (IP-based: 1 hour; user-based: 10 minutes)
  • Server access logs (IP address, timestamp, request URL, user agent) — retained for 7 days

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in service security and stability.

4.9 Data We Do NOT Collect

  • Location data
  • Contacts or address book
  • Calendar data
  • Health or fitness data
  • Biometric data
  • No analytics SDKs (no Firebase, Sentry, Amplitude, Mixpanel, or similar)
  • No advertising or tracking frameworks
  • No App Tracking Transparency (ATT) required — we do not track you

5. App Permissions

SNAB requests the following device permissions, each only when needed:

PermissionPurposeRequired?
MicrophoneRecording voice memos for transcriptionOnly for voice features
CameraScanning documents for OCROnly for scan features
Photo LibraryImporting images for OCR processingOnly for import features
Speech RecognitionOffline transcription fallback (Apple on-device)Only for offline mode
Push NotificationsDelivering reminders, event alerts, task notificationsOptional

No permission is required to use SNAB’s core text-based features.


6. AI and Machine Learning Processing

All AI processing runs on our own infrastructure in Germany. No personal data is sent to external AI providers by default.

6.1 Speech-to-Text (Transcription)

  • Technology: Self-hosted Faster-Whisper on our GPU server (Hetzner, Germany)
  • Models: Whisper Small (free users), Whisper Turbo (paid users)
  • Process: Your audio file is uploaded to our server, transcribed, and the audio file is deleted immediately after processing
  • No data sent to OpenAI, Apple, or any third party

6.2 Optical Character Recognition (OCR)

  • Technology: Self-hosted PaddleOCR on our GPU server (Hetzner, Germany)
  • Process: Your image is uploaded, text is extracted, and the image is deleted immediately after processing
  • No data sent to any third party

6.3 Action and Insight Extraction (LLM)

  • Technology: Self-hosted Qwen3-14B-AWQ via vLLM on our GPU server (Hetzner, Germany)
  • Process: Your transcription or OCR text is analyzed to extract tasks, events, reminders, lists, and insights
  • All processing stays within our Hetzner Germany infrastructure
  • No data sent to Anthropic, OpenAI, or any external AI provider
  • Extraction logs are stored for quality improvement and are not shared with third parties

Legal basis: Art. 6(1)(b) GDPR — performance of a contract (the core service you use SNAB for).

6.4 Planned: Premium AI Option (not yet active)

We plan to offer an optional premium extraction feature using an external AI provider (e.g., Anthropic Claude API, servers in the USA). This feature:

  • Is not currently active
  • Will require explicit opt-in from you before any data is sent
  • Will be clearly marked in the app with credit-based billing
  • When active, your transcription text will be sent to the AI provider’s servers
  • Safeguards: EU-US Data Privacy Framework, Standard Contractual Clauses (Art. 46(2)(c) GDPR)

We will update this privacy policy before launching this feature.


7. Apple Watch

The SNAB Apple Watch app:

  • Records voice memos via the microphone
  • Transfers audio files to your iPhone via WatchConnectivity
  • Sends metadata: device model, watchOS version, recording duration, flow ID, timestamp
  • Audio is deleted from the Watch after successful transfer to iPhone
  • Uses self-care background mode only

The Watch app does not collect: health data, location, contacts, or biometric data.


8. Widget and Share Extension

Widget Extension: Performs zero data collection and makes no network requests. It opens the main app via deep links only.

Share Extension: Processes files you explicitly share (max 10 files, max 50 MB each). Files are stored temporarily in the shared App Group container. The Share Extension makes no direct network requests — the main app handles all processing.


9. Cloud Storage

9.1 snab.cloud (Included)

All users receive cloud storage on Cloudflare R2 (EU/Frankfurt):

TierStorage
Free100 MB
Gold5 GB
Platinum15 GB
coFunder25 GB

Storage add-ons are available (2 GB, 5 GB, or 10 GB per month). Files are encrypted server-side with AES-256.

9.2 External Cloud Providers (Opt-In Only)

Paid users can optionally connect external cloud storage. When you connect a provider, we store your OAuth refresh token on our servers to access your storage on your behalf. You can disconnect at any time, which revokes our access and deletes the stored token.

ProviderScopesData TransferredSafeguards
Google Drive (Google LLC, USA)drive.readonlyOAuth tokens, file metadataEU-US DPF, SCCs
Dropbox (Dropbox Inc., USA)Metadata + content read/write, account infoOAuth tokens, file metadataEU-US DPF, SCCs
OneDrive (Microsoft Corp., USA)Files.ReadWrite.All, User.ReadOAuth tokens, file metadataEU-US DPF, SCCs
iCloud DriveLocal file system access onlyNone sent to Apple beyond standard iCloud syncN/A

Legal basis: Art. 6(1)(a) GDPR — your explicit consent when connecting a provider.


10. Push Notifications

We use Apple Push Notification service (APNs) to deliver reminders, event alerts, task notifications, and referral reward notifications. Your device token is registered with our server. No third-party push service is used.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract.


11. Infrastructure and Hosting

All infrastructure is located in Germany and the EU.

ServiceProviderLocationPurpose
API Servers (RS01, RS02)Hetzner Online GmbHGermanyBackend API, Galera DB cluster
GPU Server (GPU02)Hetzner Online GmbHGermanySTT, OCR, LLM extraction
Object StorageCloudflare R2EU/FrankfurtFile storage, email attachments, feedback screenshots
DNS / CDN / WAFCloudflareFrankfurt PoPWebsite delivery, DDoS protection
Transactional EmailAWS SESeu-central-1 (Frankfurt)Verification emails, reminder emails
Newsletter + Operational EmailMailcow (self-hosted)GermanyNewsletter, scan/voice/task emails
MonitoringHetzner Online GmbHGermanyPrometheus + Grafana (internal only)

12. Data Security

We implement the following technical and organizational measures to protect your data:

  • Encryption in transit: TLS 1.2+ for all connections
  • Encryption at rest: AES-256 server-side encryption for Cloudflare R2 storage
  • Authentication: API key-based authentication with signed tokens; OAuth 2.0 for Sign in with Apple
  • Email security: DKIM, SPF, and DMARC for all outgoing emails
  • On-device protection: iOS Data Protection for locally stored data
  • Database: Galera cluster replication for redundancy
  • Server hardening: UFW firewall on all servers, non-standard SSH port
  • Temporary URLs: R2 signed URLs with 5–15 minute TTL for file access

13. Data Processors (Art. 28 GDPR)

We use the following data processors, each bound by a Data Processing Agreement under Art. 28 GDPR:

Hetzner Online GmbH

Industriestr. 25
91710 Gunzenhausen
Germany Purpose: Server hosting (API, database, GPU workers, monitoring) Data processed: All server-side data as described in this policy Location: Germany

Cloudflare, Inc.

101 Townsend St
San Francisco, CA 94107
USA Purpose: DNS, CDN, WAF, R2 object storage Data processed: IP addresses, DNS queries, stored files (encrypted) Location: EU/Frankfurt for R2; global edge network for CDN Safeguards: EU-US Data Privacy Framework, EU Standard Contractual Clauses

Amazon Web Services EMEA SARL

38 Avenue John F. Kennedy
L-1855 Luxembourg Purpose: Transactional email delivery (SES) Data processed: Email addresses, delivery status metadata Location: Frankfurt (eu-central-1) Safeguards: AWS Data Processing Addendum, EU Standard Contractual Clauses

Apple Inc.

One Apple Park Way
Cupertino, CA 95014
USA Purpose: Authentication (Sign in with Apple), push notifications (APNs), payment processing (StoreKit) Data processed: Apple user ID, device token, transaction IDs Safeguards: EU-US Data Privacy Framework, Apple Developer Program Agreement

Google LLC (only when you connect Google Drive)

1600 Amphitheatre Parkway
Mountain View, CA 94043
USA Purpose: Cloud storage integration Data processed: OAuth tokens, file metadata Safeguards: EU-US Data Privacy Framework, EU Standard Contractual Clauses

Dropbox, Inc. (only when you connect Dropbox)

1800 Owens Street
San Francisco, CA 94158
USA Purpose: Cloud storage integration Data processed: OAuth tokens, file metadata Safeguards: EU-US Data Privacy Framework, EU Standard Contractual Clauses

Microsoft Corporation (only when you connect OneDrive)

One Microsoft Way
Redmond, WA 98052
USA Purpose: Cloud storage integration Data processed: OAuth tokens, file metadata Safeguards: EU-US Data Privacy Framework, EU Standard Contractual Clauses


14. International Data Transfers

Default: All your data is processed in Germany and the EU. No data is transferred to the United States or other third countries by default.

Transfers to the USA occur only in these cases:

  1. Apple services (Sign in with Apple, APNs, StoreKit) — required for app functionality. Safeguard: EU-US Data Privacy Framework.
  2. Cloud storage integrations (Google Drive, Dropbox, OneDrive) — only when you explicitly connect a provider. Safeguard: EU-US Data Privacy Framework + Standard Contractual Clauses (Art. 46(2)(c) GDPR).
  3. Cloudflare CDN — R2 object storage is EU-only (Frankfurt). CDN edge servers may process requests at US points of presence for website delivery. Safeguard: EU-US Data Privacy Framework + Standard Contractual Clauses.
  4. Future premium AI extraction — not yet active. When launched, opt-in only. Safeguard: EU-US Data Privacy Framework + Standard Contractual Clauses.

Legal basis for transfers: Art. 45 GDPR (adequacy decision for EU-US DPF participants) and Art. 46(2)(c) GDPR (Standard Contractual Clauses).


15. Data Retention

DataRetention Period
Local app dataUntil you delete it
User account and profileUntil you delete your account
Audio files (voice memos sent for STT)Deleted immediately after processing
Images (sent for OCR)Deleted immediately after processing
Extraction logsUntil account deletion
Insight itemsUntil you delete them or delete your account (soft delete: 90-day grace period)
Cloud-stored files (snab.cloud)Until you delete them or delete your account
Email delivery logsMaximum 30 days
Server access logs7 days
Referral data90 days after invite expiry
Newsletter subscriptionUntil you unsubscribe
Rate limit dataIP-based: 1 hour; user-based: 10 minutes
Soft-deleted items (trash)7 days, then permanently deleted
Feedback dataUntil account deletion

16. Account Deletion

You can delete your account at any time from the app settings. Account deletion permanently removes:

  • Your user profile, API credentials, and device registrations
  • All tasks, events, reminders, lists, and insights
  • All extraction logs and feedback data
  • All files stored on snab.cloud
  • All email addresses and newsletter subscriptions
  • All referral data
  • Push notification registrations

External cloud provider tokens (Google, Dropbox, OneDrive) are revoked immediately upon deletion.

Deletion is irreversible and completed within 30 days.


17. Data Export (Data Portability)

You can export all your data from the app settings in a machine-readable JSON format. The export includes all tasks, events, reminders, lists, insights, and associated metadata.

This fulfills your right to data portability under Art. 20 GDPR.


18. Your Rights Under GDPR

You have the following rights regarding your personal data:

RightArticleDescription
AccessArt. 15 GDPRRequest information about what personal data we process
RectificationArt. 16 GDPRRequest correction of inaccurate or incomplete data
ErasureArt. 17 GDPRRequest deletion of your personal data
RestrictionArt. 18 GDPRRequest restriction of processing
Data PortabilityArt. 20 GDPRReceive your data in a structured, machine-readable format
ObjectionArt. 21 GDPRObject to processing based on legitimate interest
Withdraw ConsentArt. 7(3) GDPRWithdraw any previously given consent at any time

To exercise any of these rights, contact us at [email protected]. We will respond within one month as required by Art. 12(3) GDPR.

Right to Lodge a Complaint (Art. 77 GDPR)

If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent authority for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4
40213 Düsseldorf
Germany
Website: www.ldi.nrw.de


19. Children’s Privacy

SNAB is not intended for children under 12 years of age. We do not knowingly collect personal data from children under 12. If you believe that a child under 12 has provided us with personal data, please contact us at [email protected] and we will promptly delete the data.


Processing ActivityLegal Basis
Account creation and managementArt. 6(1)(b) — Contract performance
Content processing (STT, OCR, extraction)Art. 6(1)(b) — Contract performance
Cloud storage (snab.cloud)Art. 6(1)(b) — Contract performance
Push notificationsArt. 6(1)(b) — Contract performance
Subscription managementArt. 6(1)(b) — Contract performance
Email capture featureArt. 6(1)(b) — Contract performance
External cloud integrationsArt. 6(1)(a) — Consent
NewsletterArt. 6(1)(a) — Consent
Extraction logs for quality improvementArt. 6(1)(f) — Legitimate interest
Server logs and securityArt. 6(1)(f) — Legitimate interest
Fraud prevention (referrals)Art. 6(1)(f) — Legitimate interest

21. Changes to This Privacy Policy

We may update this privacy policy to reflect changes in our services, technology, or legal requirements. Material changes will be communicated via the app or email before they take effect.

The current version is always available at snab.app/privacy.


22. Contact

For all privacy-related questions and requests:

MONNINGHOFF Labs UG (haftungsbeschränkt)
Wehrstr. 3
48151 Münster
Germany
Email: [email protected]


Münster, March 19, 2026