Privacy policy
This privacy policy explains how Digital Ventures Conglomerate Limited ("Snag," "we," "us," or "our") collects, uses, shares, and protects information in connection with Snag, our bug-capture and automated-fix platform (the "Service"). It covers our website, browser extension, embeddable widget, and web dashboard.
1.Two kinds of data, two roles
Snag handles data in two distinct capacities, and it is important to understand which applies:
- Account data — Snag is the controller. This is information about our customers and their team members: names, emails, workspace and billing details, and how they use the dashboard. This policy governs how we handle it.
- Capture data — the customer is the controller, and Snag is the processor. When an end user files a bug report through a customer's extension or widget, the report may contain information about that end user or their session. Our customer decides what is captured and why; we process it on the customer's behalf under our agreement with them. If you are an end user (a "reporter") and want to exercise privacy rights over a report you filed, please contact the organization whose site you were using; we will assist that organization as its processor.
2.Information we collect
Information you provide
- Account and contact data — name, email address, and the workspace you create. Authentication is handled through Google/Firebase sign-in; we receive your email and a user identifier, not your Google password.
- Billing data — processed by Stripe. We store a customer identifier and subscription state; we do not store full payment-card numbers.
- Support and communications — messages, bug reports, and feedback you send us.
Capture data (submitted by reporters, on a customer's behalf)
A bug report may include console logs, network request/response metadata, a session replay of the page, screenshots, reproduction steps, the page URL, and browser and device information. Where the customer requires it, a reporter's email may be collected so the customer can follow up.
Repository data (accessed by the agent)
When a customer enables the coding agent, it reads the connected repository to analyze an issue and propose a fix. This access happens in an isolated, single-tenant execution environment that is destroyed after each run. Repository access uses a short-lived, per-run installation token that is not stored.
Information collected automatically
- Usage data — pages and features used, actions taken, and timestamps.
- Device and log data — IP address, browser type, and approximate (city-level) location derived from IP.
- Cookies and similar technologies — used for sign-in sessions and, on our marketing site, product analytics (see Section 8).
3.How we use information
- To provide, operate, secure, and improve the Service;
- To route bug reports into the integrations a customer connects and to run the agent the customer enables;
- To authenticate users, prevent fraud and abuse, and enforce our terms;
- To process payments and manage subscriptions;
- To send transactional messages (security, billing, and service notices) and, where permitted, product updates;
- To understand usage in aggregate and improve the product; and
- To comply with legal obligations.
4.How we share information
We share information only as needed to run the Service:
- With subprocessors that provide infrastructure on our behalf, under contractual data-protection obligations (see Section 5);
- With integrations you connect — for example, the Jira or GitHub account you authorize — to deliver reports and open pull requests;
- For legal reasons — to comply with law, respond to lawful requests, or protect the rights, safety, and security of Snag, our users, and the public;
- In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to this policy; and
- With your direction or consent — where you ask us to share, or agree to it.
We may share aggregated or de-identified information that cannot reasonably be used to identify you.
5.Subprocessors
We rely on the following categories of subprocessors. A current list is available on request to admin@dvcllc.io.
| Subprocessor | Purpose |
|---|---|
| Google Cloud Platform | Cloud hosting, storage, and database (US regions) |
| Stripe | Payment processing and subscription billing |
| Google (Gemini models) | Automated field mapping and the coding agent; not used to train models on your data |
| Atlassian / Jira | Issue routing — only if you connect it |
| GitHub | Issue routing and pull requests — only if you connect it |
We provide at least 30 days' notice of a new subprocessor where required by our customer agreements, and a customer may object on reasonable data-protection grounds.
6.Data retention
We keep information only as long as needed for the purposes above:
- Capture data — retained for 90 days from capture, then automatically deleted, or deleted or anonymized earlier on the customer's request or on workspace closure, except where retention is required by law.
- Repository source — not retained; the execution environment is destroyed after each agent run.
- Account data — retained while your workspace is active and for a reasonable period afterward.
- Billing records — retained as required for tax and financial-recordkeeping obligations.
- Analytics and logs — retained for a limited period, then aggregated or deleted.
7.Security
We implement technical and organizational measures designed to protect information, including encryption in transit and at rest, strict per-tenant isolation of every record and stored artifact, least-privilege access, short-lived per-run tokens for repository access, and default in-browser masking of captured PII. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you discover a vulnerability, please contact admin@dvcllc.io.
8.Cookies and analytics
Our sign-in uses cookies necessary to keep you logged in. On our marketing website we use privacy-respecting product analytics to understand traffic and improve the site. You can control cookies through your browser settings; disabling some cookies may affect functionality. We do not respond to "Do Not Track" browser signals, as there is no common standard for them.
9.International data transfers
We operate in the United States, and information we handle is processed and stored in the United States and other jurisdictions where our subprocessors operate. If you access the Service from outside the United States, you understand that your information may be transferred to and processed in the United States. Where we act as a processor for a business customer, a data processing addendum is available on request.
10.Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise a right over account data, email admin@dvcllc.io with the subject "Privacy request"; we will verify your identity and respond within the time required by applicable law (generally within 45 days). To exercise a right over capture data you submitted as a reporter, contact the organization whose site you were using — they are the controller, and we will assist them. You can unsubscribe from non-essential email at any time using the link in the message; we may still send transactional messages about your account, security, or billing.
11.California privacy rights (CCPA/CPRA)
California residents have the right to know what personal information we collect and how we use and disclose it; to request deletion or correction; to opt out of "sale" or "sharing" (Snag does not sell or share personal information as those terms are defined); to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights. To submit a request, email admin@dvcllc.io with the subject "California privacy request." You may use an authorized agent with proof of authorization. We will verify your identity before responding.
12.Nevada privacy rights
Nevada residents may submit a request directing us not to sell certain personal information. Snag does not sell personal information, but you may confirm this or submit a request by emailing admin@dvcllc.io.
13.Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact admin@dvcllc.io and we will delete it.
14.Changes to this policy
We may update this policy from time to time. For material changes we will provide notice by email or in-product. The "Last updated" date above reflects the most recent version, and your continued use of the Service after changes take effect constitutes acceptance.
15.Contact
For any question about this policy or your data, contact:
Digital Ventures Conglomerate Limited
1704 Frediani Court, Mount Prospect, IL 60056
admin@dvcllc.io