Last updated: September 1, 2026.
This Privacy Policy explains how Ising Digital Sàrl ("we," "us," "Snapari," or "the App") collects, uses, shares, and protects information when you use the Snapari mobile application. By using the App you agree to this Policy and to our Terms of Service.
1. Age requirement (important)
Snapari is for users aged 13 and older. The App carries a 13+ age rating on the App Store, and by using it you confirm you meet this requirement (see the Terms of Service §1). We do not knowingly create accounts for or collect personal information from children under 13, and we do not ask for or store a date of birth. If we learn we have collected information from a child under 13, we will delete it. (See §10.)
2. What we collect
You give us, or we create as you play:
- Captured photos. When you capture a creature (press the shutter), the App takes a photo through your camera. That photo is sent to our servers and to our AI providers to generate your card (see §4). We store a one-way hash (a fingerprint) of the photo to prevent duplicate captures and for abuse-prevention; how long we keep the original photo itself is described in §6.
- Generated content. The AI-generated card art, the composited card image (PNG), and card data (species label, element, rarity, stats, serial number, mint timestamp).
- User-generated content (UGC). The name you give a card, and whether you make your library public.
- Account data. If you sign in with Apple, we receive an Apple-provided identifier (and, only if you choose to share it, your name/email — Apple lets you hide your email). You may also start as an anonymous guest, in which case we generate a random device-linked identifier.
Collected automatically:
- Device & usage data. Device model, OS version, app version, language, coarse region, and in-app events (e.g. capture, reveal, share) for product analytics.
- Approximate location (optional; off by default). Only if you turn it on, the App records a coarse, region-level location (rounded to roughly an 11 km area, so it is never your precise position, street, or home) at the moment you capture. We use it to tag your card with local context — weather and terrain — that shapes gameplay (and, later, battles). Location stays off unless you opt in via an in-app prompt, you can disable it anytime in iOS Settings, and the App works fully without it (your captures simply carry no location context). To look up conditions for the coarse area we use a keyless weather service (Open-Meteo); we do not sell or share your location with advertisers.
- Diagnostics. Crash reports and performance data.
- Advertising (free tier). The App shows rewarded video ads you can choose to watch to earn in-app rewards (Rolls/currency), served by Google AdMob. We serve these ads non-personalized: we do not use the iOS advertising identifier (IDFA) to track you across apps, and we do not ask for App Tracking Transparency permission. To deliver an ad and prevent fraud/abuse, AdMob still receives standard ad-request data (e.g. device type, OS, coarse region, a non-persistent ad request). You are never required to watch ads.
- Purchase data. Subscription/entitlement status and transaction identifiers. We never receive or store your full payment-card details — purchases are processed by Apple.
3. How we use information
- To run the core loop: capture → generate a unique card → reveal → save to your Bestiary.
- To enforce content safety (detect non-animal/abusive images before and after generation).
- To allocate and guarantee your card's one-of-one serial and track rarity.
- To tag captures with coarse local context (weather/region/terrain) that shapes gameplay and future battles — only if you enable location.
- To provide accounts, libraries, sharing, and (later) trading.
- To process subscriptions and in-app purchases and apply your entitlements.
- To measure, debug, secure, and improve the App.
- To comply with law and enforce our Terms.
Legal bases (EEA/UK/Swiss users). Where the GDPR or the Swiss FADP applies, we process your photos, cards, and account data as necessary to perform our contract with you (running the game you signed up for); the optional location context and any optional features on the basis of your consent, which you can withdraw at any time; content-safety moderation, fraud and abuse prevention, analytics, and diagnostics on the basis of our legitimate interests in keeping the App safe, fair, and working; and certain record-keeping where we have a legal obligation.
4. AI processing of your photos
Generating a card requires sending your captured photo to third-party AI services:
- The photo is sent through the OpenRouter API gateway to a vision model — Anthropic (Claude) or Google (Gemini) — to identify the animal, write card content, and act as a content-safety check.
- The photo is sent to fal.ai (FLUX.1 Kontext) to create the cartoonized art.
Content moderation is performed by the Anthropic (Claude) vision step above, which screens the photo for non-animal/abusive content before any art is generated.
These providers process your photo only to perform the service. Anthropic (whose commercial API terms exclude training on customer inputs and outputs) and OpenRouter (whose policy states it does not use inputs or outputs for model training; our account additionally has prompt logging disabled and routing restricted to no-training providers) do not use your photos to train AI models. We do not authorise any provider to use your photos to train AI models, and we do not sell your photos. See the subprocessor list in §5.
5. How we share information
We do not sell your personal information. We share it with service providers ("subprocessors") who process data on our behalf, and as required by law.
| Subprocessor | Purpose | Data shared |
|---|---|---|
| Supabase | App backend: database, authentication, file storage (Zürich, Switzerland) | Account data, cards, hashes, generated images |
| Anthropic (Claude) | Card content + species ID + safety check | Captured photo (transient) |
| OpenRouter | API gateway that routes the card-content request to Claude | Captured photo (transient) |
| fal.ai (FLUX.1 Kontext) | Image-to-image card art | Captured photo (transient) |
| Google (Gemini) | Card content + species ID + safety check, when routed to this model via OpenRouter | Captured photo (transient) |
| Google AdMob | Rewarded video ads (free tier) — non-personalized | Ad-request data (device type, OS, coarse region); no IDFA / cross-app tracking |
| Open-Meteo (only if/when location is enabled — not active in the MVP) | Weather lookup for capture context | Coarse (region-level, rounded) coordinates — no account/identifier |
| Apple | Sign in with Apple; App Store payments | Apple identifier; purchase transactions |
| RevenueCat | Subscription & entitlement management | Anonymous user ID, purchase status |
| PostHog | Product analytics | Pseudonymous usage events, device data |
| Sentry | Crash & error monitoring | Diagnostics, device data |
We may also disclose information to comply with legal process, protect our rights and users' safety, or in connection with a merger or acquisition (with notice where required).
6. Data retention
We keep information for as long as your account is active or as needed to provide the App, then delete or anonymize it. Specifically:
- Generated cards and serials are retained as part of your collection (they are the product) until you delete them or your account.
- Captured source photos are processed to generate your card and are deleted after generation; the hash is retained for dedupe and abuse prevention.
- Diagnostics and analytics are retained on a rolling window of 3 months.
- Capture context (the local hour and — only if you enabled location — the coarse region, weather, and terrain tags) is part of the card and is retained with it; it is deleted when the card or your account is deleted.
- Purchase and subscription records are held by Apple (billing) and RevenueCat (entitlement status) under your Apple ID, not by us. Deleting your Snapari account removes the link to those records but does not delete Apple's billing history or cancel an active subscription (see §8).
7. Security
We use industry-standard measures: encryption in transit, access controls, server-authoritative balances and ownership, and we never ship AI provider keys in the app. No method is 100% secure, but we work to protect your data.
8. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or export your data, and to object to or restrict certain processing.
- In-app account deletion. You can delete your account and all associated data from within the App (as required by the App Store). Open the Bestiary tab, tap the profile icon (top right), scroll to Danger Zone, and tap Delete Account. After confirmation, your Creature collection and account are permanently deleted. Deleting your account does not cancel a subscription: subscriptions are billed by Apple under your Apple ID and keep renewing until you cancel them yourself in iOS Settings → Apple ID → Subscriptions. Contact contact@isingdigital.ch if you need assistance.
- California (CCPA/CPRA), EEA/UK (GDPR), and other regions. You may exercise applicable rights by contacting us at contact@isingdigital.ch. We do not sell or "share" personal information for cross-context behavioral advertising. If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), or the data-protection authority of your country of residence.
- Permissions. You control camera, notification, location, and tracking permissions in iOS Settings; denying camera disables capture. Location is optional and off by default — declining it only removes the local weather/terrain context on your cards; everything else works normally.
9. International transfers
We are based in Switzerland (canton of Vaud), and our primary database and file storage are hosted in Zürich, Switzerland (Supabase). Switzerland is recognized by the European Commission as providing an adequate level of data protection, so processing of EEA users' data in Switzerland requires no additional transfer mechanism.
Some of our subprocessors (§5) process data in the United States. For those transfers we rely on:
- the EU–U.S. Data Privacy Framework, its UK Extension, and the Swiss–U.S. Data Privacy Framework for providers certified under them (e.g. Sentry and PostHog); and
- the EU Standard Contractual Clauses, supplemented by the Swiss addendum and (for UK users) the UK addendum, incorporated in our data-processing agreements with the remaining providers (e.g. Supabase, OpenRouter, RevenueCat, fal.ai, Hive).
The weather lookup (Open-Meteo, §2) involves no transfer of personal data: the service receives only a coarse, rounded coordinate from our servers, with no identifier, and is itself based in Switzerland.
10. Children
The App is not directed to children under 13 and we do not knowingly collect their data. Parents who believe a child under 13 has provided us information may contact contact@isingdigital.ch and we will delete it.
11. Changes to this Policy
We may update this Policy; we will post the new version with a revised "Last updated" date and, for material changes, provide in-app notice.
12. Contact
Ising Digital Sàrl, Switzerland — contact@isingdigital.ch — www.isingdigital.ch
Questions about this document? contact@isingdigital.ch