Политика конфиденциальности
Что snakein записывает во время сессии, какие сервисы это обрабатывают, сколько всё хранится и как удалить.
Обновлено 25 июля 2026 г.
1Introduction and scope
This Privacy Policy explains how Snakein ("Snakein," "we," "us," "our") collects, uses, discloses, and protects information when you use the Snakein desktop application, the Snakein web application (the "Web App"), and any related services (together, the "Service").
This Policy applies to registered users of the Service and to visitors of the Snakein website. It does not apply to third-party websites, applications, or services that we link to or that link to us, or to the practices of companies that we do not own or control.
This document is the full policy referenced from the "Privacy & stealth" section of our website, and is incorporated by reference into our Terms of Service. If anything in that on-site summary and this Policy appears to conflict, this Policy controls.
2Who we are
Snakein is currently developed and operated by an individual acting in a personal capacity (the "Operator"), pending the formation of a dedicated legal entity for the business. For the purposes of the EU/UK General Data Protection Regulation ("GDPR") and equivalent laws elsewhere, the Operator acts as the data controller for the personal data described in this Policy, except where explicitly stated otherwise (for example, in Section 10).
You can reach us through our contact page for any question, request, or complaint about this Policy or about how we handle your information.
3Summary (plain language)
This section is a convenience summary only; the full terms in Sections 4 onward govern.
What we do:
- We process your interview audio, transcript, screenshots, and account data solely to run the Service for you: real-time transcription, on-screen AI assistance, and post-call summaries.
- We use a small number of specialized subprocessors (speech-to-text, AI models, file storage, transactional email) strictly to operate the Service, under their standard API terms.
- We let you delete a session at any time; deletion removes the database records and the underlying audio/screenshot files from storage.
- We let you generate a public share link to a specific session at your own choice, and revoke it at any time.
What we don't do:
- We do not sell or rent your personal data, interview content, resume, or transcripts to anyone - not to recruiters, employers, advertisers, or data brokers.
- We do not use your session content to train our own AI models or, to our knowledge, any third party's general-purpose models, beyond what is strictly necessary to generate your real-time answer or summary within that same request.
- We do not report your sessions, scores, or activity back to any employer, school, exam body, or proctoring service.
- We do not run advertising trackers, ad pixels, or third-party marketing analytics on the Web App.
4Information we collect
4.1Account information
When you register, we collect your email address, full name, and a password. Your password is never stored in plain text; we store a salted bcrypt hash of it, and the plain-text password never touches our database. We also store the account creation date, the date your email was confirmed, the date you last changed your password, and your current credit balance.
4.2Interview session content
When you run a session through the desktop overlay, depending on the features you use, we process and store:
- Audio. The full recording of the call (a mix of the captured system audio and your microphone), stored as an audio file linked to your session, plus a waveform summary.
- Transcript. A text transcript of the conversation, produced by real-time speech-to-text and stored against your session indefinitely (until you delete the session).
- Screenshots. Images you capture from your screen during a session (for example, of a shared document, a coding editor, or a question on the call), together with the AI-generated analysis of each screenshot.
- AI-generated answers. The real-time suggestions Snakein generates during your session, along with the underlying prompts built from your transcript, resume, and instructions.
- Session summary. After a session ends, we may generate an AI title, description, topic breakdown, and self-assessment of your performance, in your selected language.
- Session metadata. Start time, duration, the profile used, and the outcome you record for the session (if any).
Important: because Snakein records both sides of a call, this content will typically include the voice, statements, and - if visible on screen - other content belonging to other people on the call (for example, an interviewer). Section 10 explains your responsibilities regarding those other people.
4.3Career context and materials
To power the AI assistant, you may provide us with your resume/CV, supporting materials (documents you upload or paste), a description of the call context, and instructions for how the assistant should behave. This is among the most sensitive information you give us, since a resume alone can reveal your full name, work history, education, and other identifying details. We use it exclusively to generate answers and summaries within your own sessions.
4.4Billing and payment-related information
Snakein does not integrate with a card processor and does not collect or store card numbers, bank account details, or similar payment instrument data. Instead:
- We maintain a credit balance and a per-event usage ledger (timestamp, type of AI operation, technical details of the operation, and the amount charged) tied to your account, so you and we can see how your balance is spent.
- If you top up your balance via cryptocurrency (USDT), we collect the transaction hash you submit, the network, the deposit address, an email address you provide for that request (which may or may not be your account email), and any comment you add. These requests are reviewed and confirmed manually; we do not run automated blockchain monitoring.
- If you redeem a promotional/credit code, we record that redemption against your account; the redemption and your account email may be visible to our administrator through the internal admin tool.
4.5Device and authentication data
- Web sessions are authenticated with an
httpOnlysession cookie containing a signed token. This cookie is not readable by JavaScript and is not used for tracking or advertising. - Desktop sessions use a device-pairing flow: you confirm a pairing code from the Web App, and the desktop app receives a personal access token. That token is encrypted on your machine using your operating system's secure storage (e.g., macOS Keychain) and is never written to disk in plain text. On our servers, we only ever store a one-way cryptographic hash of that token, never the token itself, so we cannot reconstruct it even if our database were compromised. You can revoke any device's access at any time from your account settings, which immediately invalidates that device's token.
- We keep a record of when each device session was created, when it was last used, and when (if ever) it was revoked.
4.6Cookies and similar technologies
We use a small number of strictly functional cookies on the Web App:
- A session-authentication cookie (see 4.5).
- A cookie that remembers your interface language.
- A cookie that remembers your light/dark color-scheme preference.
We do not use advertising cookies, cross-site tracking pixels, or third-party analytics/marketing scripts (such as Google Analytics, Meta Pixel, or similar tools) on the Web App as of the effective date of this Policy. If this changes, we will update this Policy and, where required by law, request your consent before setting non-essential cookies.
4.7Information we do not collect
For clarity: our application code does not log your IP address or browser user-agent string for profiling purposes, we do not build advertising profiles, and we do not purchase or append third-party data about you. Note that, like virtually any online service, our hosting and infrastructure providers may automatically generate standard technical logs (such as request timestamps, error traces, and IP addresses) purely to operate, secure, and troubleshoot the Service - we do not use those infrastructure-level logs for tracking or advertising.
5How we use your information and our legal bases
We use the information above to:
| Purpose | Legal basis |
|---|---|
| Create and administer your account, authenticate you, and provide the Service you asked for | Performance of a contract |
| Transcribe your calls, analyze your screenshots, and generate real-time answers and summaries | Performance of a contract |
| Operate the credit-based billing system and review top-up requests | Performance of a contract; legitimate interest (fraud/abuse prevention) |
| Send you transactional emails (account confirmation, password reset) | Performance of a contract |
| Maintain security, detect abuse, and enforce our Terms of Service | Legitimate interest |
| Comply with legal obligations (e.g., responding to a valid legal request) | Legal obligation |
We do not send marketing or newsletter emails. The only emails we send are transactional (account confirmation, password reset, and similar account notices), delivered through our transactional email provider (see Section 7).
6How your interview content is processed by AI subprocessors
To provide real-time transcription and AI assistance, parts of your session content are necessarily shared with specialized third-party providers that perform those functions for us. Each of them receives only what the specific operation requires; none of them receives your full account profile, and none of them is authorized to use your content for any purpose other than fulfilling our request.
This Policy describes these providers by the function they perform rather than by name. The specific providers, models, and regions we use for a given function may change at any time - for example when a model is retired or becomes unavailable, or when another one performs better, faster, or at a lower cost for that task - and we do not want this Policy to describe an arrangement we have already moved on from. What does not change is the categories of processing set out below and the limits we place on them. If you want to know which providers we rely on at a particular moment, write to us through our contact page and we will tell you.
- Speech-to-text. To transcribe your call in real time, your desktop app streams your microphone and system audio directly to a speech-to-text provider, using a short-lived access token that our server requests on your behalf. Our server never sees this live audio stream in transit; it only receives the resulting text. Separately from this live transcription stream, the final mixed recording of your call is uploaded directly from the desktop app to our cloud file storage (see Section 7) once the call ends, and is retained as described in Section 4.2 so you can play it back and, if you choose, share it. That provider's own privacy terms govern its handling of the live audio stream during transcription.
- Suggested answers. To produce each real-time suggestion, the complete prompt behind it is sent to a third-party language-model provider. That prompt is your resume, your uploaded or pasted materials, your call context and instructions, the transcript of the call up to that moment, the suggestions already made earlier in the same call, and the question being answered. "Power Mode" is an optional, higher-cost mode that you switch on for a single session, on the desktop start screen, before the call begins; it is off by default and never applies to a session you did not enable it for. It changes which model answers you - and may change which provider that model belongs to - but it does not change what is sent or the terms on which it is processed.
- Screenshots. Screenshot analysis happens in two stages, and only the first one ever sees the image. When you capture a screenshot, the image itself is sent from our server to a vision-capable model for one narrow purpose: reading and extracting the text of the question, problem, or document shown on your screen. The output of that stage is text only. The answer that follows is generated separately, from that extracted text - never from the image itself - combined with the same session context described above.
- Summaries and assessments. After a call ends, your transcript and materials are sent to a language-model provider to generate the session title, description, topic breakdown, and self-assessment of your performance.
If a request to one provider fails, we may automatically retry the same request through a different one, so that you are not left without a suggestion mid-call; in that case the same content reaches that other provider as well.
We select providers whose standard API terms state that content submitted through their API is not used to train their models by default. We cannot audit their internal practices, and their own privacy terms - not ours - govern what they do with your content while processing it. These providers operate in a range of countries, which may not be your own and whose data protection laws may differ from those of your home jurisdiction (see Section 11). If the content of a particular call is sensitive enough that this matters to you, do not run that call through the Service.
We do not use your session content, transcripts, resumes, or screenshots to train any model that we operate ourselves.
7Other service providers
- Cloud file storage. Your audio recordings and screenshots are stored as objects in a bucket held with a third-party cloud storage provider. Each file's storage key is derived from your session's identifier and is not guessable in practice, but note that the storage bucket itself is configured for public read access at the object level - access to a specific file is controlled by knowledge of its (effectively unguessable) address, not by a login check at the storage layer. Do not share direct file links with anyone you don't want to have access to that file.
- Transactional email. Account confirmation and password-reset emails are sent through a third-party transactional email delivery provider, which processes your email address and the content of these system emails solely to deliver them.
- Hosting and database. Your account and session records are stored in a managed PostgreSQL database operated by our infrastructure/hosting provider, protected by encryption in transit and the provider's standard encryption at rest.
We do not permit any of these providers to use your data for their own independent purposes, such as advertising or building their own user profiles about you.
8Payments and credit top-ups
We do not accept or store credit card or bank information. The only way to add paid credits to your account is a manual cryptocurrency (USDT) transfer that you initiate and that we confirm by hand, as described in Section 4.4. Because this method relies on a public blockchain, be aware that the transaction itself (amount, wallet addresses, and timestamp) is inherently visible on that public ledger, independent of anything we do - this is a property of the payment method you chose, not information we publish.
9Public share links
You may generate a public, unauthenticated link to a specific session from your dashboard. Anyone who has that link can view that session's title, AI summary, topic breakdown, full transcript, screenshots, and audio recording - without needing an account or logging in. A shared link does not expose your resume/CV or other materials, your private notes, your call context/instructions, your recorded outcome, your identity, your profile, or your credit spend for that session.
Key things to know:
- The link is a long, randomly generated token (192 bits of entropy) that is practically impossible to guess.
- The link does not expire on its own. It remains active until you manually revoke it from your dashboard.
- Anyone with the link - not just people you intend to share it with - can view the content for as long as the link is active. Treat a share link like you would treat the file itself: only send it to people you trust, over a channel you trust, and revoke it once it's no longer needed.
- We do not collect any information about people who view a shared session; we do not know who viewed it, when, or how many times, unless our infrastructure provider's standard server logs happen to record that a request occurred.
10Recording other people: your responsibility
Snakein is built to listen to and record calls, which by their nature usually include one or more other people. You, not Snakein, are the person initiating that recording, and you are solely responsible for complying with all laws that apply to you, to the other participants, and to the platform or context in which the call takes place. This includes, without limitation:
- Wiretapping, call-recording, and interception laws, which in many jurisdictions (including several U.S. states and other countries) require the consent of all parties, not just yours, before a call may be recorded.
- Any confidentiality, non-disclosure, honor-code, exam-integrity, or platform-specific rules that may govern the call or meeting you are recording.
- Data protection obligations you may owe to the other participant as a result of recording and processing their voice, statements, or likeness.
Where a call you record includes another identifiable person's voice, statements, or on-screen content, you act as the data controller for that other person's information under applicable data protection law, and we process it strictly as your service provider, at your direction, for the sole purpose of running the Service for you. We do not independently verify that you have obtained any consent required by law, and we disclaim liability for your failure to do so. If you are not sure whether recording a specific call is lawful or permitted, do not record it.
A note on the overlay's invisibility. The desktop application is designed so that its notes window does not appear in the screen-share output of common video-conferencing platforms, which means the other participants on your call typically have no way of knowing, from what is shown on their own screen, that you are recording, transcribing, or receiving AI assistance during the call. This makes obtaining any consent required by law even more your responsibility, not less - you cannot rely on the other participant noticing the recording and objecting. This invisibility behavior depends on operating-system-level mechanisms that are not guaranteed to keep working: it may not function on every operating system, version, device, or screen-capture method, and it may stop working without notice after an operating system or video-conferencing platform update. We do not warrant that the window or your use of the Service will remain undetected in every circumstance, and we are not liable if it becomes visible or detectable.
11International data transfers
Because our subprocessors (Sections 6 and 7) operate infrastructure in a number of countries, your information will typically be transferred to and processed in countries other than your own, which may have different data protection laws than your home jurisdiction. This applies to the content of your calls: the prompt behind each suggested answer - your transcript, resume, materials, instructions, and the question - is sent to a third-party language-model provider that may be located anywhere its infrastructure operates, and the destination may change over time, including between one session and the next, as described in Section 6. Where required by applicable law (such as the GDPR), we rely on the relevant subprocessor's standard contractual safeguards for international transfers; where no such mechanism is available or required, we transfer data based on the necessity of the transfer to perform the Service you requested.
12Data retention and deletion
- Sessions. A session's transcript, audio, screenshots, and summary are retained until you delete that session from your dashboard, or until you delete your account (see below). Deleting a session removes its database records and permanently deletes the associated audio and screenshot files from cloud storage; this is not a soft delete or an archival flag - the underlying files are removed.
- Incomplete uploads. Sessions that were started but never finished uploading are automatically deleted after 24 hours of inactivity.
- Account data. We retain your account information for as long as your account is active. Full self-service account deletion is not yet available as an in-app feature; to request deletion of your account and all associated personal data, write to us through our contact page, and we will delete it within a reasonable time (no more than 30 days), except for information we are legally required to retain (for example, records needed to resolve a dispute about a credit purchase).
- Billing and usage records. We retain usage-ledger and top-up-request records for as long as reasonably necessary for accounting, fraud prevention, and dispute resolution, even after a session or account is deleted, where retaining that specific record is necessary for those purposes.
13Security measures
We apply reasonable technical and organizational measures appropriate to the sensitivity of the data involved, including:
- Password hashing with bcrypt; passwords are never stored or logged in plain text.
- Device-pairing tokens are stored hashed on the server and encrypted at rest on your device via your operating system's secure key storage.
- All traffic between the desktop app, the Web App, and our API is encrypted in transit (TLS/HTTPS).
- Session cookies are
httpOnlyand, in production,secure, reducing exposure to script-based token theft. - Access to the administrative dashboard (which can view usage, pricing, and top-up requests) is restricted to a specific, pre-approved administrator email address.
- Database schema changes go through reviewed migrations rather than automatic, unreviewed schema synchronization, to reduce the risk of accidental data loss.
No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to or stored by the Service. If we become aware of a security incident affecting your personal data, we will notify you and any relevant authority as required by applicable law.
14Your privacy rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Access - request a copy of the personal data we hold about you.
- Rectification - ask us to correct inaccurate or incomplete data (you can also update your name and email directly in your account settings).
- Erasure - ask us to delete your personal data, subject to the limits described in Section 12.
- Portability - request your data in a structured, commonly used, machine-readable format, for data you provided to us and that we process on the basis of consent or contract.
- Restriction of / objection to processing - ask us to limit certain processing, or object to processing based on legitimate interest.
- Withdraw consent - where we rely on your consent for a specific processing activity, withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
- Lodge a complaint - with your local data protection authority, if you believe we have not handled your data lawfully.
To exercise any of these rights, write to us through our contact page. We may ask you to verify your identity (for example, by contacting us from the email address registered to your account) before acting on a request, to make sure we don't hand your data to someone impersonating you.
15We do not sell your data
Regardless of where you live, we do not sell your personal information, and we do not share it with third parties for cross-context behavioral advertising, for money or other valuable consideration, under any definition of those terms in any applicable law. Depending on your country or state of residence, you may have specific statutory rights that reinforce this commitment (for example, under the EU/UK GDPR or U.S. state privacy laws such as the CCPA/CPRA); to the extent such law applies to you, we will honor the rights it grants, in addition to those already listed in Section 14. You can exercise any of these rights the same way - by writing to us.
16Children's privacy and minimum age
Snakein is intended for use by adults seeking or preparing for professional employment, and is not directed at children. You must be at least 18 years old to create a Snakein account. We do not currently operate an automated age-verification system; by registering, you represent and warrant that you meet this minimum age requirement. If we learn that we have collected personal data from someone under 18, we will delete that account and the associated data.
17Automated processing and AI content reliability
The AI-generated answers and session summaries described in Section 4.2 are generated automatically, but they are informational suggestions intended for your own use during your own call - we do not use them to make any decision about you (for example, we do not use them to approve, deny, rank, or score you for anything), and no automated decision produced by the Service is provided to, or used by, any third party such as an employer.
These AI outputs are produced by third-party language models and may be incomplete, outdated, or factually wrong - this is a known limitation of the underlying technology, not something specific to our implementation. They are provided for your convenience only, are not professional, legal, medical, financial, or career advice, and should never be your sole basis for what you say or do on a live call. You are responsible for independently judging and verifying any suggestion before relying on it.
18Changes to this Policy
We may update this Policy from time to time, for example to reflect a new feature, a new subprocessor, or a change in law. If we make a material change, we will update the "Last updated" date above and, where appropriate, notify you by email or through an in-app notice before the change takes effect. Continued use of the Service after a change becomes effective constitutes acceptance of the revised Policy.
19Governing law
This Policy, and any dispute about our handling of your personal data that is not otherwise resolved by mandatory local data protection law (such as the GDPR for residents of the EU/EEA/UK, or applicable U.S. state law), is governed by the laws of the Republic of Costa Rica, without regard to its conflict-of-laws principles, and subject to the exclusive jurisdiction of the competent courts sitting in San José, Costa Rica.
If you are a consumer resident in the European Union, the United Kingdom, or another jurisdiction that grants you mandatory consumer- or data-protection rights that cannot be limited by contract, nothing in this Section limits those rights, and you may also bring proceedings before the competent court of your own country of residence, or lodge a complaint with your local data protection authority, as described in Section 14.
20Contact us
If you have any question about this Privacy Policy or how we handle your information, write to us through our contact page.