Privacy Policy

Last updated: July 16, 2026

This Privacy Policy explains how PureSnapX collects, uses, stores, and shares information when you use our browser extension, website, paid plans (when available), account features, support, and related services (together, the "Service").

PureSnapX is designed to be local-first: capture, studio editing, and My Snaps library work in your browser by default. You can use core local capture features without creating an account when the backend is not required for that feature.

1. Controller

The data controller for personal data processed by PureSnapX is:

Krzysztof Woźniczek - IT services
ul. Graniczna 2ea/19
54-610 Wrocław, Poland
NIP: 6391914982

Email: support@xpresspurge.com (privacy requests may use the same address)

Website: puresnapx.fun

If you are in the European Economic Area, United Kingdom, or Switzerland, you may contact us at the email above about your data protection rights.

2. Summary

  • Core screenshot capture and studio tools run on x.com / twitter.com in your browser.
  • Captured snaps, settings, and history are stored locally (Chrome storage and IndexedDB) by default.
  • Free use does not require an account for local capture (subject to free-tier limits).
  • Optional Pro / account features may use activation codes, a backend API, and cloud storage of snaps you choose to upload.
  • We do not sell personal data.
  • We do not store full payment card details.
  • When paid checkout is enabled, payments are intended to be handled by Creem (Armitage Labs OÜ) as merchant of record.
  • Backend account, entitlement, and cloud-library infrastructure is designed around Supabase.
  • The marketing website may collect waitlist emails via Loops.
  • The current extension codebase does not ship third-party product analytics or crash-reporting SDKs (for example PostHog, Mixpanel, Amplitude, Sentry).

3. What PureSnapX Does

PureSnapX is a Chrome Manifest V3 extension that:

  • injects Snap actions on X (posts, visible threads, profile pages, analytics pages);
  • captures and renders polished images (and, for Pro, optional WebM thread video);
  • stores local history and library items;
  • optionally activates a paid license via an activation code and manages signed-in devices;
  • optionally uploads snaps to a cloud library and can create public share links for items you make public.

PureSnapX does not post, like, follow, or message on X on your behalf. Exports you choose (download, clipboard, user-controlled post-to-X flows) are under your control.

4. Permissions and Browser Access

The current extension requests these Chrome permissions:

  • activeTab — work with the active tab in the capture flow
  • storage — settings, auth tokens (when used), history metadata, usage counters
  • downloads — save exported files
  • clipboardWrite — copy exports to the clipboard

Host-related access includes:

  • https://x.com/* and https://twitter.com/* — content scripts run only on these sites
  • Twitter media/CDN hosts used for export rendering: pbs.twimg.com, abs.twimg.com, video.twimg.com, ton.twimg.com
  • <all_urls> — required because content-script initiated captures use Chrome's captureVisibleTab() API, which needs broad host access when invoked without a transient activeTab grant from a direct extension UI invocation

Content scripts run only on x.com and twitter.com. Broad host permission is for capture capability, not for injecting UI across the web.

5. Information Processed Locally

Captured and rendered content. When you snap a post, thread, profile, analytics view, or milestone card, the extension may process in your browser: visible post text, author handle/display name, avatars, media URLs, badges, and metrics; profile fields for profile capture; analytics-page metrics for analytics capture; studio choices (theme, frame, caption, annotations, effects, watermark); and rendered image (or video) blobs for export and library save.

Local storage locations.

  • chrome.storage.local — settings, snap history metadata and small thumbnails, auth/session fields when activated, device ID, usage counters, onboarding flags, studio/milestone preferences, templates, and similar state (keys typically prefixed with puresnapx)
  • IndexedDB (PureSnapXDB) — full snap image blobs, thumbnails, and related assets for the local My Snaps library

Uninstalling the extension or clearing extension storage removes local data under browser control.

6. Information Sent Over the Network

Image/media fetch for export. To produce accurate exports, the extension or service worker may fetch media from X/Twitter CDN URLs with credentials omitted so images can be inlined into the rendered output.

Optional backend (when configured and you use account features). The extension may send activation code and device ID to activate a license; refresh tokens and device ID for entitlements; authorization tokens for device list/revoke; metadata and image blobs for cloud library create/list/get/update/delete; and data to create or resolve public share links for snaps you choose to share. After activation, identity reflected locally typically includes userId, email, and plan from the entitlement payload.

Core local capture does not require uploading your feed, DMs, or full browsing history to our servers. Cloud upload happens when you use cloud-library or share features with a configured backend and valid activation.

7. Website Waitlist and Marketing Email

When you join the PureSnapX waitlist on this website:

  • Data collected: email address; optional signup context such as form source; optional list membership in Loops
  • Purpose: waitlist confirmation (including double opt-in if enabled), early access, launch, and product-related email
  • Processor: Loops stores contacts and sends messages on our behalf
  • You may unsubscribe from marketing emails using the link in those messages
  • Contact support@xpresspurge.com for access or deletion requests related to waitlist email

The static marketing site may also receive standard hosting/server logs (IP address, user agent, requested URL, timestamps) from the hosting provider as part of delivering the website.

8. Payments and Billing Data

Paid checkout, when enabled, is designed to be processed by Creem, operated by Armitage Labs OÜ, as merchant of record. Creem may collect and process billing information such as name, email, billing address, payment details, tax location, order and invoice details, purchase status, refund/chargeback status, and fraud-prevention data.

We may receive limited payment-related information needed to activate and manage licenses (for example checkout, order, customer, or product identifiers, plan, status, and customer email).

We do not store your full payment card number.

Creem's processing is also governed by Creem's own notices: Terms, Privacy.

9. Account and Authentication Data

Paid/cloud features may use one-time activation codes, a stable device ID for the installation, refresh tokens and entitlement JWTs stored in local extension storage, and backend records for plan, devices, and entitlement refresh.

The extension auth path is activation-code based (not Google OAuth login inside the extension). Additional website claim/login flows may exist when the backend is live.

We use account data to verify paid access, activate and refresh entitlements, show plan status, enforce plan and device controls, provide support, and prevent fraud or unauthorized sharing.

10. Cloud Library and Public Links

If you use the Pro cloud library with a configured backend, snaps and metadata you save to the cloud are uploaded to object storage via signed URLs and associated with your account. Public share links expose a public view for items you choose to make public — do not mark sensitive material public.

11. How We Use Information

  • provide capture, studio, export, library, and extension features
  • process paid checkout and activate licenses when available
  • authenticate installations and refresh entitlements
  • enforce free-tier limits (for example free snap count) and plan feature gates
  • manage devices and prevent abuse of paid access
  • deliver waitlist and product emails you signed up for
  • provide support
  • secure the Service and comply with legal, tax, accounting, and consumer obligations

12. Legal Bases (GDPR / similar)

  • Contract — to provide the Service, paid access, activation, and support
  • Legitimate interests — security, abuse prevention, reliability, local-first product operation, and basic website delivery logs
  • Consent — marketing emails (waitlist) and optional features that require consent
  • Legal obligation — tax, accounting, consumer protection, fraud, and regulatory requirements

13. How We Share Information

  • Loops — waitlist / marketing email
  • Supabase (when backend is used) — database, storage, edge functions for accounts, entitlements, devices, and cloud library
  • Creem — merchant-of-record checkout when paid checkout is enabled
  • Browser / store providers — Chrome Web Store and Chrome APIs
  • Hosting providers — website hosting and CDN logs
  • Legal, compliance, or business-transfer recipients where required or appropriate

We do not sell personal data.

14. International Transfers

We are based in Poland. Providers may process data in other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses, processor agreements, adequacy decisions, or other lawful mechanisms.

15. Retention

  • Local extension data: until you delete it, clear storage, or uninstall
  • Waitlist email: until you unsubscribe / request deletion, or we delete inactive lists
  • Account / entitlement records: while access is active and a reasonable period afterward
  • Checkout / tax / payment records: as required for legal, accounting, tax, fraud, and disputes
  • Cloud snaps: until you delete them or request deletion
  • Support messages and security logs: limited operational periods

16. Your Rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, data portability, withdraw consent, and lodge a complaint with a supervisory authority. In Poland, you may contact the President of the Personal Data Protection Office (UODO).

To exercise rights, email support@xpresspurge.com. We may need to verify your identity.

17. California and Other Regional Rights

We do not sell personal information and do not knowingly share personal information for cross-context behavioral advertising. If CCPA/CPRA or similar laws apply, contact support to make a request.

18. Security

We use reasonable measures appropriate to a small software product, including local-first processing for core capture, HTTPS for backend calls when configured, signed entitlement tokens, signed upload URLs for cloud blobs, and not storing full payment card details. No method of transmission or storage is completely secure.

19. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16.

20. X Content and Third-Party Content

Captures may include third-party content visible on X. You are responsible for how you use, share, or publish exports. Processing visible page content in-browser is necessary to provide the product.

21. Changes

We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last updated" date and, where appropriate, notice on the website or extension.

22. Contact

Krzysztof Woźniczek - IT services
ul. Graniczna 2ea/19
54-610 Wrocław, Poland
NIP: 6391914982

Email: support@xpresspurge.com

Website: puresnapx.fun

23. Third-Party References