Privacy-first by design

Privacy Policy

SnapFetch is built around a simple promise: we collect as little as technically possible to deliver a fast, reliable downloader. This Privacy Policy explains in detail what information is processed when you use SnapFetch, why it is processed, how long it is kept, and the rights you have under global privacy laws including the GDPR, the UK GDPR, the CCPA/CPRA and Brazil's LGPD.

Last updated · May 2026

01 Section

1. Introduction

SnapFetch ("SnapFetch", "we", "our", "us") operates a suite of free, browser-based tools that help creators, marketers, journalists, students and researchers save publicly accessible media from social platforms such as Instagram, Facebook, Twitter/X, Pinterest, LinkedIn and YouTube. We do not require accounts, do not display third-party advertising trackers, and do not sell or rent personal data to anyone.

This policy applies to all SnapFetch web properties, sub-pages, tools, blog articles and APIs ("the Service"). By using the Service you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please discontinue use of the Service.

Where this policy refers to "personal data" we mean any information that, alone or combined with other information, can identify a natural person, as defined under Article 4(1) of the GDPR.

02 Section

2. Information we collect

SnapFetch is designed to be functional without collecting personal data. The minimal information we touch falls into three categories:

  • Submitted URLs — the public links you paste into our tools, processed in memory only.
  • Technical request metadata — IP address, country code, user-agent string, HTTP status code and request latency. Stored for up to 7 days for abuse prevention, then permanently deleted.
  • Local browser preferences — light/dark theme and language choice, stored in your own browser via localStorage. Never transmitted to our servers.
03 Section

3. URL processing

When you submit a URL, our edge function validates that the link points to a supported public resource and then opens a short-lived HTTPS request to the originating platform to fetch metadata or stream the media file back to your browser.

Submitted URLs are never written to a database, never logged in a way that ties them to your IP address, and never shared with third parties. Once the response is delivered, the URL is discarded from memory.

04 Section

4. Temporary download handling

SnapFetch operates as a stateless pass-through. Files are streamed directly from the source platform to your browser; we do not store copies of downloaded videos, images, audio tracks, thumbnails or carousel PDFs on our infrastructure.

If a transient cache is created at the CDN layer for performance reasons (for example, to serve large files efficiently), that cache is purged within minutes and never contains identifiers linking the file to you.

05 Section

5. Cookies policy

SnapFetch uses a strictly limited set of first-party cookies and local-storage entries:

  • theme — remembers your light/dark preference. First-party, 12 months, no personal data.
  • consent — records whether you have dismissed the cookie banner. First-party, 12 months.
  • We do not set advertising, retargeting or cross-site tracking cookies, and we do not embed pixels from Meta, X, TikTok, Google Ads or similar networks.
06 Section

6. Analytics usage

We use a privacy-respecting, cookie-less analytics layer that aggregates page-view counts, referrers and country codes without storing personal identifiers. We do not run Google Analytics, Meta Pixel, Hotjar, Mixpanel or any similar product that builds individual user profiles.

Aggregate analytics help us understand which tools and guides creators rely on so we can prioritise improvements.

07 Section

7. Advertising policy

SnapFetch may display non-personalised contextual advertising in the future to keep the Service free. If and when advertising is enabled, this policy will be updated to disclose the ad networks involved, the data they receive (such as page URL and coarse country location), and the controls you have to opt out.

Until that update is published, no advertising scripts, retargeting pixels or affiliate trackers run on SnapFetch pages.

08 Section

8. Third-party services

We rely on a small number of trusted infrastructure providers to operate the Service:

  • Cloudflare — DDoS protection, edge caching and TLS termination.
  • Lovable Cloud / Supabase — managed database and edge functions for non-personal operational data only.
  • Source platforms — Instagram, Facebook, Twitter/X, Pinterest, LinkedIn and YouTube, when fetching the public media you request.
  • Each provider acts as a data processor bound by appropriate data-processing agreements and Standard Contractual Clauses where required for international transfers.
09 Section

9. Hosting & infrastructure

SnapFetch runs on a serverless edge network distributed across multiple regions to deliver low latency worldwide. Servers automatically route your request to the closest edge node. No persistent database row is created for an end-user's download request.

All traffic between you and SnapFetch is encrypted with TLS 1.3. Internal service-to-service traffic uses mutually authenticated TLS.

10 Section

10. Data retention

We follow a strict data-minimisation schedule:

  • Submitted URLs — discarded from memory immediately after the response is delivered.
  • Downloaded media — never stored on our servers.
  • Anonymous request logs — auto-expire after 7 days.
  • Aggregated, non-identifiable analytics — retained up to 24 months for trend analysis.
  • Contact-form correspondence — retained for up to 24 months for support continuity, then deleted.
11 Section

11. GDPR rights (EEA & UK)

If you are located in the European Economic Area, the United Kingdom or Switzerland, you have the following rights under the GDPR and the UK GDPR:

  • Right of access (Art. 15) — request a copy of any personal data we hold.
  • Right to rectification (Art. 16) — correct inaccurate data.
  • Right to erasure (Art. 17) — request deletion of your data.
  • Right to restriction of processing (Art. 18).
  • Right to data portability (Art. 20).
  • Right to object to processing (Art. 21).
  • Right to lodge a complaint with your local supervisory authority.
  • To exercise any of these rights, email privacy@snapfetch.app. Because SnapFetch holds almost no personal data tied to individuals, most requests are satisfied by default.
12 Section

12. CCPA / CPRA rights (California)

California residents have additional rights under the California Consumer Privacy Act, as amended by the CPRA:

  • Right to know what personal information is collected, used, shared or sold.
  • Right to delete personal information held by us or our service providers.
  • Right to correct inaccurate personal information.
  • Right to opt-out of the sale or sharing of personal information (we do not sell or share).
  • Right to limit the use of sensitive personal information (we do not process any).
  • Right to non-discrimination for exercising your CCPA rights.
13 Section

13. Children's privacy

SnapFetch is not directed at children under 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact privacy@snapfetch.app and we will delete it promptly.

14 Section

14. International users

SnapFetch is offered globally. By using the Service from outside your home country, you understand that your request metadata may be processed in regions outside your jurisdiction, including the United States and the European Union. We rely on Standard Contractual Clauses and equivalent safeguards for international data transfers where required.

15 Section

15. Security practices

We protect the Service with industry-standard controls including:

  • TLS 1.3 encryption on all public endpoints.
  • Principle of least privilege for internal credentials.
  • Automated dependency vulnerability scanning on every deployment.
  • DDoS mitigation, rate limiting and bot detection at the edge.
  • Periodic review of third-party processors and sub-processors.
  • No long-term storage of personal data reduces our breach surface to near zero.
17 Section

17. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in law, technology or our practices. Material changes will be highlighted at the top of the page with a new "Last updated" date and, where appropriate, an in-product notice. Continued use of the Service after a change constitutes acceptance of the revised policy.

18 Section

18. Contact information

Privacy questions, GDPR/CCPA requests and concerns can be sent to privacy@snapfetch.app. For all other inquiries, please use the Contact page. We aim to respond to verifiable privacy requests within 30 days, as required by applicable law.

Questions about this policy?

Reach out and we'll respond within one business day.