Legal
SnapAction is built to be clear about the tradeoff: selected screenshots are sent for analysis, and account-backed results are synchronized with a local app database on your iPhone. You can delete your SnapAction product account without deleting your shared ReScience sign-in identity.
Effective July 23, 2026 · Privacy notice 2026-07-23
SnapAction asks iOS for Photos access so it can find screenshot assets with PhotoKit. The app tracks which screenshot asset IDs have been scanned and shows screenshot thumbnails in the local gallery.
When you scan a screenshot, the image data is sent to SnapAction's Convex backend for AI analysis through OpenRouter. If a resource name is visible but its URL is missing, the backend can use Serper search and URL verification to find the canonical link. Do not treat scanned screenshots as fully offline processing.
Resource records are synchronized through SnapAction's Convex backend and stored in a local app database on your device. Those records can include title, URL, type, tags, description, metadata, linked screenshot asset IDs, read state, and favorite state. Account deletion covers both the SnapAction-owned cloud records and account-scoped local records.
SnapAction uses Clerk for a shared ReScience sign-in identity, StoreKit 2 for App Store purchases, and Convex to verify entitlements and monthly scan quotas. Convex stores the SnapAction product account, subscription, usage, scan event, feedback, email, and diagnostic records needed to run the service. Deleting SnapAction does not delete the shared Clerk user or unrelated ReScience product data.
Product-specific SnapAction signup begins on ReScience and completes through a signed server-to-server handoff. The handoff identifies the SnapAction product account, the legal-notice versions displayed, and the optional marketing choice made on the signup screen. Sign-in cannot claim a marketing choice, and SnapAction does not store an IP address as consent evidence.
Transactional messages support requested or account-related activity such as waitlist confirmation, account welcome, access granted, and account-deletion completion. They do not depend on marketing consent.
Optional marketing covers product content, version and feature updates, and special offers. These categories default off and require an applied affirmative choice under marketing notice snapaction-marketing-v1, which covers content, version, and offers. Completing signup with the checkbox clear records a decline; abandoning signup creates no SnapAction marketing-preference event.
Marketing messages include visible category and all-marketing unsubscribe controls. SnapAction rechecks the live account, preference, and deliverability state before provider submission. Unsubscribing from marketing does not disable protected transactional messages. A later explicit subscribe action creates new positive evidence; a replayed signup handoff cannot silently re-enable marketing.
SnapAction uses Clerk for shared identity, Convex for the account-backed service and storage, Cloudflare for transactional email, Apple for authentication and App Store subscriptions, and AI/search providers for requested screenshot analysis. Account deletion removes SnapAction-owned data and service links in the scope described below. Apple and other processors can retain limited billing, security, delivery, or service records under their own configured policies, terms, or legal obligations; SnapAction does not claim per-user erasure where a processor does not provide it.
Optional marketing delivery is routed through Postmark only after SnapAction's consent, suppression, health, and campaign-approval gates pass. SnapAction—not Postmark—owns audiences, consent, templates, unsubscribe decisions, and send audit. Provider suppression is an additional deliverability constraint and cannot create marketing consent.
Optional marketing may come from SnapAction or an identified founder or team member using one of these code-owned, SnapAction-controlled @snapaction.ai identities:
Using a founder or team-member sender does not make the message personal correspondence. It remains optional marketing subject to the same consent, category, unsubscribe, and Postmark processing described here.
SnapAction's Postmark configuration uses the provider's default 45-day retention for message content and activity data. The configured retention period is 45 days.
A confirmed deletion blocks the old SnapAction account and removes its account and access records, synchronized resources, scans, digests, chat and owned files, feedback and log uploads, usage records, email preferences, device push identifiers, and account-scoped local data. It does not delete original images from Apple Photos unless you separately use a screenshot-deletion feature and confirm Apple's Photos prompt.
The shared ReScience sign-in identity remains available for unrelated ReScience products. Signing in later can create a new, empty SnapAction account; it does not reopen the deleted account. An explicit Restore Purchases action can restore an eligible subscription entitlement only, never deleted content or settings.
Cleanup can be asynchronous. The app reports an estimated completion window of within 24 hours and uses an opaque status capability for up to eight days to provide the authoritative completion result after sign-out. If cleanup takes longer than the estimated window, status remains accessible and support can help. A best-effort completion email can provide secondary confirmation when a deliverable address is available, but missing, failed, delayed, or expired email delivery never blocks, reverses, or rolls back completed deletion. If automatic Sign in with Apple revocation cannot be completed, SnapAction data deletion continues and the app reports the Apple step as requiring manual action.
Deleting SnapAction does not cancel an auto-renewing App Store subscription or stop Apple billing. Users with an auto-renewing subscription should use Manage Subscription to cancel future billing before deletion. Deletion remains available immediately without canceling first.
SnapAction retains only bounded records needed to finish and confirm deletion, prevent delayed systems from recreating deleted data, protect account security, and keep legally required financial facts. Sensitive bindings for a consumed deletion request last up to 15 minutes after deletion starts, opaque status access up to eight days, and a best-effort completion-email address or payload up to seven days unless erased sooner when its delivery purpose ends.
Completed cleanup evidence is reduced to pseudonymous operational proof: cleanup counters and bounded error codes for up to 30 days, verified storage-deletion evidence for up to 90 days, product-deletion proof for up to 180 days, and deletion security outcomes for up to 365 days. These are maximums; records are removed sooner when their purpose ends.
Marketing preferences, immutable preference events, and signup handoff receipts are retained with the SnapAction account and removed during account deletion. They are consent evidence, not deliverability suppression.
A separate indefinite HMAC-only signup-consent deletion fence prevents an old signed signup handoff from recreating consent after deletion. It stores no raw email, raw identity, or consent decision; it does not block an explicit account recreation or a genuinely new subscribe action. This narrow fence is separate from the 180-day operational product-deletion proof.
Keyed HMAC-only bounce and complaint states can remain after account deletion to protect recipients and sender reputation. They record deliverability safety, not identity or consent, and cannot opt a person into marketing.
Raw email, display name, Clerk or Apple subject, IP address, device token, authorization credential, and raw App Store identifier are not retained as deletion proof. Financial facts can follow Apple, provider, tax, or applicable-law requirements, but do not include deleted SnapAction content. See the account deletion guide for the complete scope and support path.
SnapAction can upload bug reports, scan reports, client logs, and internal TestFlight diagnostics to Convex for debugging. Diagnostic records may include app version, build, iOS version, device model, launch or foreground state, and crash information. Feedback attachments are only sent when you submit them.
The backend schema is for accounts, quotas, scan events, feedback, usage, logs, and subscription verification. It is not a cloud photo library for your screenshots.
ReScience Lab Inc
1007 N Orange Street, 4th Fl 4782, Wilmington, DE 19801
For privacy requests, corrections, or questions, email hello@snapaction.ai .
Start with screenshots you are comfortable sending for AI analysis. Review the deletion guide before creating an account if you need details about product-scoped deletion and retention.