Snag AI
Add to Chrome
LEGAL

Privacy Policy

Last updated June 2025 · Snag AI Chrome Extension

We do not sell your data. We do not use it for advertising. Profile and job data is only sent off your device when you take an action, such as syncing your profile, running an audit, or generating a proposal.

1. Introduction & Data Controller

This Privacy Policy explains how Snag AI ("we", "us", "our") collects, uses, stores, and protects information when you use the Snag AI Chrome Extension and associated backend services. We are committed to protecting your privacy and handling your data with transparency and care.

By using Snag AI, you acknowledge that you have read and understood this Privacy Policy. If you have questions or concerns, you may contact us at support@snagai.pro at any time.

2. Data We Collect and How

Profile data (user-initiated sync): When you click "Sync Profile" on your Upwork profile page (for either a freelancer or an agency profile), the extension reads publicly visible information from that page, including your display name, professional title, Job Success Score, hourly rate, Upwork tier badge, total earnings, total jobs completed, total hours worked, skills list, professional bio/overview, employment history, education, spoken languages, profile photo URL, availability status, and portfolio project titles, descriptions, skills, and attached links. For agency profiles, this additionally includes the agency description, services offered, featured clients, team member listings, and work history specific to the agency page. This data is stored exclusively in your browser's local Chrome storage on your device. It is transmitted to our backend server only when you generate a proposal, run a job audit, or run a profile audit, and only as part of that specific request.

Account email address: When you add your email in Settings, it is stored in Chrome's sync storage (which Chrome may synchronise across your devices if you are signed into Chrome). Your email is sent to our backend to verify your subscription plan status and to track your usage count against your plan limit. It is not used for unsolicited marketing communications.

Job listing data: When you visit an Upwork job page, the extension automatically reads publicly available job data from the page, including job title, description, budget, posted time, client statistics (hire rate, rating, spend, payment verification status), and current proposal/interview counts. This data is processed locally in your browser and is transmitted to our backend only when you click "Write Proposal" or run a job audit for that specific job.

Job audit data: When you run a job audit, the extension reads additional competition and client-history signals from the job page (proposal range, interviewing/hire counts, client spend and verification status) and combines them with your synced profile to generate a scored verdict, concerns, and strengths via our backend.

Profile audit data: When you run a profile audit, the extension sends your full synced profile (including portfolio items, certifications, testimonials, and employment history) to our backend to generate a scored, section-by-section review with specific rewrite suggestions. This is a user-triggered action, subject to your plan's monthly profile audit limit, and works the same way for both freelancer and agency profiles.

Smart job alert filters: Your custom job-matching thresholds (minimum match score, hourly rate, client verification requirements, proposal/interview caps, and similar filters) are stored locally in your browser and used to evaluate job pages you visit. These filters are not transmitted to our servers.

Usage count: We record the number of proposals, job audits, and profile audits you generate in each billing period to enforce your plan's monthly limits. This count is stored on our servers associated with your email address. We do not store the content of generated proposals or audit reports on our servers.

Device ID: A random identifier is generated and stored locally in your browser to prevent abuse of free trial limits on a single device. This ID is not linked to your identity and is not transmitted to our servers.

Technical usage data: We may log basic server-side request metadata (timestamps, error codes) for the purpose of debugging and maintaining service stability. We do not log the content of proposals or profile data beyond what is necessary to process requests.

For users in the European Economic Area, United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Contract performance: processing your email and usage data is necessary to provide you with the subscription service you have purchased, verify your plan, and enforce usage limits.
  • Legitimate interests: we process technical metadata to maintain the security and stability of the Service. We do not override your fundamental rights in doing so.
  • Consent: profile, job audit, and profile audit data is processed based on your explicit action of clicking "Sync Profile", "Audit this job", or "Audit this profile". You can withdraw this by clearing the extension's storage at any time.

4. How We Use Your Data

All data collected is used solely for the following purposes:

  • Proposal generation: your profile data and the job listing data are combined and sent to the Anthropic Claude API to generate a personalised cover letter draft.
  • Job audits: job page signals and your profile data are sent to our backend and the Anthropic Claude API to produce a competition/fit verdict, concerns, and strengths before you spend a connect.
  • Profile audits: your full synced profile is sent to our backend and the Anthropic Claude API to produce a scored, section-by-section review with specific rewrite suggestions and a PDF export.
  • Smart job alerts: your filter thresholds are evaluated locally in your browser against job page data as you browse; this does not require any data to leave your device.
  • Plan verification: your email is used to look up your subscription status via Paddle's billing system to determine which features and usage limits apply to you.
  • Usage enforcement: we track how many proposals, job audits, and profile audits you have generated in the current billing period to enforce the limits of your plan.

We do not sell your data to any third party. We do not use your data for advertising purposes. We do not share your Upwork profile data or job data with any party other than Anthropic (for AI generation and analysis) and our hosting infrastructure providers.

5. Third-Party Services & Data Sharing

Anthropic (Claude API): When you generate a proposal or run an audit, your profile data and job description are transmitted to Anthropic's API to produce the AI response. Anthropic processes this data in accordance with their API usage policies. We have configured our API settings to opt out of data use for model training. Anthropic's privacy policy is available at anthropic.com/privacy.

Paddle: All subscription payments are processed by Paddle, who acts as the Merchant of Record. Paddle collects and processes billing information, payment card details, and transaction records directly. We do not receive or store your payment card information. Paddle's privacy policy governs the handling of payment data and is available at paddle.com/legal/privacy.

Supabase: User account records (email address, subscription plan, usage count, billing status) are stored in a Supabase PostgreSQL database, with encryption at rest and in transit.

Render.com: Our backend API server is hosted on Render. Request processing occurs on Render's infrastructure.

We do not share your data with any other third parties except as required by law (e.g., in response to a valid court order or legal process).

6. Local Storage & Cookies

Snag AI uses Chrome's built-in storage APIs exclusively, specifically chrome.storage.local and chrome.storage.sync. We do not set browser cookies. All profile data, portfolio items, settings, and job filters are stored locally in your browser and are not accessible to websites or other extensions.

chrome.storage.local data stays on your device only. chrome.storage.sync data (your email address and basic settings) may be synchronised by Chrome to other devices where you are signed in, subject to Google's policies for Chrome sync data.

7. Data Retention

Local data: Profile data, portfolio, settings, and filters stored in Chrome's local storage are retained until you clear the extension's storage or uninstall it.

Server-side data: Account records (email, plan status, usage count) are retained for as long as your account is active and for a reasonable period thereafter for legal and accounting purposes. To delete your data, email support@snagai.pro with a deletion request. Our team will manually remove your personal data from our servers within 30 days, except where retention is required by law.

Request logs: Basic server logs (timestamps, response codes) may be retained for up to 90 days for debugging and security purposes. Proposal and audit content is not stored on our servers.

8. International Data Transfers

Snag AI operates globally. When you use the Service, your data may be processed in countries outside your own, including the United States and EU member states. We ensure that any international data transfers are carried out with appropriate safeguards in place, including where applicable the use of standard contractual clauses or equivalent mechanisms recognised by applicable data protection law.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right of access: you may request a copy of the personal data we hold about you.
  • Right to rectification: you may request correction of inaccurate or incomplete data.
  • Right to erasure: you may request deletion of your personal data, subject to certain exceptions.
  • Right to restrict processing: you may request that we limit how we use your data in certain circumstances.
  • Right to data portability: you may request your data in a structured, machine-readable format.
  • Right to object: you may object to processing based on legitimate interests.

To exercise any of these rights, contact us at support@snagai.pro. We will respond within 30 days. You also have the right to lodge a complaint with the data protection authority in your jurisdiction if you believe your data has been processed unlawfully.

10. Children's Privacy

Snag AI is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from a person under 18 without appropriate consent, we will take immediate steps to delete that data.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through the extension interface or by email. We encourage you to review this policy periodically.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us at support@snagai.pro. We take all privacy enquiries seriously and aim to respond within 2 business days.