SnagFrog
Compare Guides Privacy Terms Sign in

Data Processing Agreement

Last updated 7 October 2026

When your users send you reports through SnagFrog, you decide what happens with that data and SnagFrog handles it for you. This page is the agreement that covers it. It is part of the Terms and applies to every workspace; there is nothing to sign.

1. Who and what this covers

This agreement is between Gjorge Karakabakov, who runs SnagFrog (“SnagFrog”, “I”), and the person or company that holds a SnagFrog workspace (“you”). Contact: gorgekara@gmail.com.

It covers personal data in the reports, messages and files that people send you through SnagFrog (“report data”). For that data you are the controller and SnagFrog is your processor. If you are a processor for someone else, SnagFrog is your sub-processor and you pass on their instructions.

It doesn't cover your own account data (your email address, plan and sign-in records). SnagFrog is the controller of that, as the privacy policy describes.

2. What is processed

  • Purpose: receiving, storing, showing and delivering reports about your apps, games and websites, and the conversation that follows.
  • How long: for as long as you have a workspace, plus the periods in section 10.
  • Whose data: people who send you reports, and anyone they mention.
  • What data: name and email address if given; the report text; screenshots, logs and other files; technical details (app version, operating system, device, browser, language, time zone, page address, console errors); later messages.
  • Sensitive data: none intended. The Terms forbid using SnagFrog to collect passwords, payment card details, health data or similar. Free text and screenshots can still contain whatever a reporter chooses to include.

3. Your instructions

SnagFrog processes report data only on your instructions. Your instructions are: these terms, how you set up your workspace, and what you and your teammates do in the dashboard, through the API, or through an AI assistant you connect.

If I believe an instruction breaks data protection law, I'll tell you and may pause that processing. If a law requires SnagFrog to process report data in another way, I'll tell you first unless that law forbids it.

4. Confidentiality

Only people who need access to run the service have it, and they are bound to keep it confidential. Today that is one person.

5. Security

SnagFrog applies the measures listed at the end of this page and keeps them at least as protective as they are now. You're responsible for who you invite to your workspace, for your API tokens, and for what you connect.

6. Companies SnagFrog relies on

You authorise SnagFrog to use these sub-processors for report data:

  • Supabase: database, sign-in and file storage, in Frankfurt, Germany.
  • Netlify: hosts the site and runs the server code in Frankfurt, and keeps standard request logs for a limited time.
  • Resend: sends and receives email (confirmations, replies, notifications), in the United States.
  • Google (Gmail): only for email that reaches SnagFrog without matching a report, which is forwarded to my inbox so it isn't lost.

Each is bound by its own data protection terms, and SnagFrog remains responsible to you for what they do with report data. Before adding or replacing one, I'll update this list and email workspace owners at least 30 days ahead. If you object on reasonable data protection grounds and we can't resolve it, you may cancel and get a refund for the unused part of a period you paid for.

Two companies are not on the list because they never receive report data: Polar handles payments as the merchant of record and sees only your billing details, and Google Analytics counts visits to three public pages without cookies.

Services you connect yourself (GitHub, Linear, Discord, Slack, a webhook address, an AI assistant) aren't SnagFrog's sub-processors. They receive data on your instruction, under your own agreement with them.

7. Data leaving Europe

The database and files stay in the European Union. Email passes through Resend in the United States, and stray mail reaches a Gmail inbox; those transfers rely on the safeguards in those providers' own data processing terms, such as the European Commission's Standard Contractual Clauses.

SnagFrog itself is run from outside the European Union, and I access report data from there to operate and support the service. Where that is a transfer of report data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the Standard Contractual Clauses apply between you and SnagFrog and are part of this agreement. These are the clauses approved by the European Commission's Implementing Decision (EU) 2021/914 of 4 June 2021 (the “Clauses”).

  • Which module: Module Two (controller to processor) where you are the controller, and Module Three (processor to processor) where you are a processor for someone else. You are the “data exporter” and SnagFrog is the “data importer”.
  • Clause 7 (others joining the Clauses later): does not apply.
  • Clause 9(a) (sub-processors): Option 2, general written authorisation, with the 30 days' notice in section 6.
  • Clause 11 (an independent dispute resolution body): the optional wording does not apply.
  • Clause 17 (governing law): the law of Ireland.
  • Clause 18(b) (courts): the courts of Ireland.
  • Annex I.A (the parties): you, with the details on your SnagFrog account, and SnagFrog as named in section 1. Agreeing to the Terms counts as both of us signing the Clauses.
  • Annex I.B (the transfer): as described in section 2; continuous for as long as you use SnagFrog; kept for the periods in section 10.
  • Annex I.C (supervisory authority): the data protection authority that supervises you, or, if you are outside the European Economic Area, the one where your representative is or where most of the people concerned live.
  • Annex II (security): the security measures at the end of this page.
  • Annex III (sub-processors): the list in section 6.

United Kingdom. For report data covered by UK data protection law, the Clauses apply as amended by the UK Information Commissioner's International Data Transfer Addendum (version B1.0), which is part of this agreement too. Its tables are filled in with the details above, and either of us may end it as its Table 4 allows.

Switzerland. For report data covered by Swiss data protection law, the Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner as the supervisory authority, and people in Switzerland able to bring claims where they live.

8. Requests from the people who sent you reports

If a reporter contacts SnagFrog about their data, I pass the request to you and don't answer it for you, beyond telling them it has been passed on.

The dashboard gives workspace owners a tool that finds everything sent from one email address, exports it, and deletes it (Settings → General → “A reporter's data”). Single reports, messages and whole apps can be deleted at any time.

9. If there is a breach

If SnagFrog becomes aware of a breach of security affecting your report data, I'll email workspace owners without undue delay, and within 72 hours where feasible. The email will say what happened, which data and roughly how many people are affected as far as known, what is being done, and how to reach me. I'll keep you updated as more is known.

10. Deletion and copies

  • You can delete reports, apps, one reporter's data or your whole account at any time. Deletion from the live systems is immediate and includes stored files.
  • You can download a copy of one reporter's data with the tool in section 8. For a copy of a whole workspace, email me and you'll have it within 30 days.
  • When a trial ends without a subscription, or a subscription ends, the workspace's apps, reports and files are kept for 90 days and then deleted. Members are emailed at least 14 days before. The workspace and your account stay.
  • Backups kept by the hosting provider expire on the provider's schedule after that.

11. Checking that this is kept

On request I'll give you the information reasonably needed to show that SnagFrog keeps to this agreement. If that isn't enough for an obligation you have, you may audit once a year, on 30 days' notice, during working hours, at your own cost and without access to other customers' data.

12. Help with your own obligations

I'll give you reasonable help with data protection impact assessments and with consulting a regulator, where these concern SnagFrog's processing and you can't do them from what is already published here.

13. How this fits with the Terms

The liability limits in the Terms apply to this agreement, except where the law doesn't allow them to. If this agreement and the Terms disagree about report data, this agreement wins. If the Standard Contractual Clauses apply and disagree with either, the Clauses win.

Security measures

Each line describes what the service does today.

  • In transit: HTTPS everywhere.
  • At rest: the database and file storage are encrypted by the hosting provider. Access tokens for connected issue trackers, and the addresses and signing secrets of Discord, Slack and webhook integrations, are also encrypted by SnagFrog itself.
  • Separation between workspaces: enforced in the database for every table, and checked by automated tests on every change.
  • Files: private, reachable only through links that expire after an hour, and always served as downloads.
  • Sign-in: a one-time email link or Google; no passwords. Session cookies can't be read by page scripts. API tokens are stored only as a one-way hash and stop working when the person who made them leaves.
  • Roles: owners and members. Invites, roles, renaming the workspace and reporter-data requests are for owners only.
  • Abuse limits: every public form and endpoint is rate-limited, using a one-way hash of the IP address and never the address itself.
  • Uploads: file types are restricted by the storage itself, and uploaded content is never shown as a web page.
  • Scripts: a content security policy stops injected scripts from running.
  • Outgoing requests: webhook deliveries can't reach private network addresses.
  • Less data to begin with: query strings and anything that looks like a token are removed from captured page addresses and console errors, home-folder names are removed from file paths, and files a reporter unticks are deleted.
  • Changes to the service: type checks, unit tests and database permission tests run on every change, and each release is checked on a draft before it goes live.

SnagFrog is run by one person and has not had an independent security audit or certification. Found a problem? See security.txt.

Changes

If this agreement changes in a way that matters, the date at the top changes and workspace owners get an email at least 30 days before it takes effect.

SnagFrog by Karakabakov Privacy · Terms · DPA