Privacy Policy
This Privacy Policy describes how Snitch ("we", "us", or "our") collects, uses, and shares information when you use our alert monitoring service.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address (for OAuth providers)
- Name and profile picture (from OAuth providers)
- Telegram user ID (for Telegram authentication)
- Telegram username (for display purposes)
1.2 Usage Data
We automatically collect:
- Channels you monitor
- Keywords you configure
- Alert history and matched messages
- Login timestamps and session information
- IP addresses and user agents (for security)
1.3 Telegram Data
When you connect your Telegram account:
- We access messages from channels you explicitly monitor
- We store matched message snippets as alerts
- We may translate message content using third-party services (if enabled)
- Session data is encrypted and stored securely
1.4 Billing Information
For paid subscriptions:
- Billing is managed through invoices by your organization administrator
- We store subscription status and billing history
2. How We Use Your Information
We use collected information to:
- Provide and maintain the service
- Monitor channels and generate alerts
- Send notifications (dashboard, Telegram, webhooks)
- Process payments and manage subscriptions
- Improve and optimize the service
- Prevent fraud and ensure security
- Comply with legal obligations
3. Data Retention
We retain data for the following periods:
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| Alerts | 30 days (configurable by organization) |
| Activity logs | 90 days |
| Security events | 14-30 days |
| Session data | 7 days after expiry |
Automated cleanup processes run daily to enforce retention policies. You can request immediate deletion of your data at any time.
4. Data Sharing
4.1 Third-Party Services
We share data with the following third parties:
- OAuth Providers (Google, GitHub, Discord) - Authentication only
- DeepL/Google Translate - Message translation (if enabled by you)
- Mistral AI (Paris, France) - AI-powered synonym suggestions for keyword creation (if enabled by org admin, data processed within the EU)
- Telegram - Message access via their API
4.2 Legal Requirements
We may disclose information if required by law, court order, or government request.
4.3 Business Transfers
In the event of a merger, acquisition, or sale, user data may be transferred to the new owner.
5. Data Security
We implement security measures including:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest for sensitive data (AES-256)
- Optional end-to-end encryption for alerts
- Two-factor authentication (TOTP, WebAuthn)
- Regular security audits
- Rate limiting and abuse prevention
- Secure session management
6. Your Rights
You have the right to:
Request a copy of your data
Download your alerts and settings
Update inaccurate information
Request account and data deletion
Receive data in structured format
Object to certain processing
To exercise these rights, please contact us or use the settings page in your account.
8. Children's Privacy
Our service is not intended for children under 13. We do not knowingly collect information from children under 13. If you believe we have collected such information, please contact us.
9. International Data Transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: support@snitch.fyi
- Through the support feature in the application
12. Consent Tracking
We track your consent for specific features that require explicit agreement:
- Telegram API credentials usage
- Translation service API usage
- Webhook notifications
You can view and manage your consents in your account settings.