how sneka handles your personal data.
Sneka AB ("Sneka", "we", "us", or "our") respects your privacy. This policy explains what personal data we collect when you use the private preview of the Sneka services (the "Service"), why we use it, who helps us process it, how long we keep it, and the rights you have over it.
This is a plain-language summary of our current practices. For a procurement or compliance review, contact info@sneka.ai.
1. Who is the controller?
Sneka AB, a company organised under the laws of Sweden, is the data controller for personal data processed about you in connection with the Service.
You can reach us at info@sneka.ai.
2. What we collect
We collect only what we need to operate the Service:
- Account data. Your name, email address, profile picture, and
authentication identifiers from an identity provider you choose, such as Google.
- Service data. The repositories, prompts, comments, bug reports, public
questions, votes, and other content or actions you ask the Service to store or process.
- Operational telemetry. IP addresses, user agents, timestamps, security
audit events, and request or delivery records used to operate and secure the Service.
- Cookies and browser storage. The complete catalog, including
sneka_session, __Host-sneka-browser-request-…, gilly_vk, sneka_locale, sneka_consent, sneka.publicFlags.v1, sneka.commsVisible.v1, sneka.notificationsVisible.v1, sneka.suite.me.v1, diffinite:diff-mode, sneka.spindel.pending-report.v1, gilly.pending.handoff, and gilly.visitor, appears in our Cookie Policy. It states the setter, purpose, lifetime, and consent class for each entry.
We do not sell personal data, and we do not run third-party advertising or behavioural-tracking cookies on Sneka surfaces. Runtime fonts are served by Sneka; loading a Sneka page does not send a font request to Google.
3. Why we use it
We use the data above to:
- authenticate you and enforce account and product access;
- run the workflows you request and store the outputs you ask us to store;
- prevent duplicate votes, abuse, and security incidents;
- operate, monitor, debug, and secure the Service; and
- communicate with you about your account, security, and material changes.
We do not use private repository content to train shared machine-learning models. Optional measurement remains off unless and until you opt in through the consent controls described in the Cookie Policy.
4. Who we share it with
We use these subprocessors only as needed to provide the Service:
| Provider | Purpose | Data involved |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting, networking, and backups | Service data and operational telemetry |
| Google LLC | Google sign-in when you choose it | Authentication identifiers and basic account profile |
| Porkbun LLC | SMTP delivery for account and service email | Recipient address and email content |
| Slack Technologies, LLC | Operational notices for preview access, bug reports, and content flags | Contact or report data included in the notice |
We also share data with an integration provider you deliberately connect, strictly as needed to perform the integration you requested. We may disclose data to an authority when compelled by valid legal process, after taking reasonable steps to narrow the request.
5. How long we keep it
Account and service data stays while your account is active unless a shorter period below applies. Auth and Gilly enforce these deletion windows through hourly retention sweeps. Each service runs its first sweep when it starts.
| Data | Retention period |
|---|---|
| Browser sessions | Deleted after expiry; the default is 30 days and no session chain may continue past 90 days |
| Gilly measurement events | 90 days |
| Bug reports | 12 months (365 days) |
| Persona browser requests | Deleted after their individual expiry time |
| Resolved preview-waitlist records | 12 months (365 days) from creation, once claimed |
| Security audit log | 24 months (730 days) |
Backups age out through their normal rotation. We may retain a narrowly scoped record longer when law requires it or when needed to establish, exercise, or defend a legal claim.
6. Deleting your account
A self-serve account wipe is available in Settings → Privacy. You can also request help at info@sneka.ai.
The wipe erases your profile, settings, sessions, consent records, and private product data. Public Gilly verdicts and the questions on them will remain as part of the public record, but their owner will be changed to the neutral deleted account identity, with no link back to your former profile. Security audit records will remain only for the 24-month period above.
If you want a specific public question removed as content, include its URL in your request to info@sneka.ai.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise a right, contact info@sneka.ai.
If you are in the European Economic Area or the United Kingdom, you may also complain to your local supervisory authority.
8. Changes
We update this policy as the Service evolves. The "Last updated" date reflects the current version. We also notify account holders of material changes by email.