Calibrated Vision, LLC ("we," "us," or "our") operates SnapFree (https://www.snapfree.ai), a financial wellness platform. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our service.
We believe in transparency about data practices, especially when it comes to your financial information. Please read this policy carefully.
2. How We Use Your Information
2.1 Providing and Improving Our Services
- Analyzing your debt obligations and financial situation to provide coaching
- Providing personalized debt repayment strategies and educational guidance
- Tracking your progress toward debt reduction goals
- Generating spending analysis and budget insights
- Improving the accuracy and helpfulness of the AI Coach
- Maintaining, troubleshooting, and improving the performance of our Services
2.2 Account and Service Management
- Creating and managing your account
- Processing subscription payments
- Sending service-related communications (account confirmations, billing notifications, security alerts, and product updates)
- Enforcing our Terms of Service and fair use policies
2.3 Safety and Compliance
- Detecting and preventing fraud, abuse, or unauthorized access
- Monitoring AI Coach interactions for safety (including crisis detection and guardrail compliance)
- Complying with legal obligations
2.4 What We Do NOT Do With Your Information
- We do not sell your personal information. We have not sold personal information in the preceding 12 months and do not intend to do so.
- We do not use your information for advertising. We do not serve ads, and we do not share your data with advertisers or ad networks.
- We do not use your financial data to make lending, insurance, or employment decisions. SnapFree is a coaching tool only.
3. AI Coach and OpenAI
Our AI Coach feature is powered by OpenAI's API. This section explains exactly what data is shared, how, and what protections are in place.
3.1 What Data Is Sent to OpenAI
When you send a message to the AI Coach, the following is transmitted to OpenAI's API to generate a response:
- Your message — the text you type to the AI Coach
- Conversation history — recent messages in your current session, so the AI can maintain context
- A summary of your financial data — if you have connected financial accounts via Plaid, a processed summary of your debts (institution name, last 4 digits of account number, balances, APRs, minimum payments) and spending categories may be included to personalize coaching
We do NOT send to OpenAI:
- Full account numbers (only last 4 digits)
- Raw Plaid API responses
- Your email address, password, or payment information
- Individual transaction details (only category-level spending summaries)
3.2 How OpenAI Handles Your Data
- No model training: OpenAI does NOT use data sent through their API to train their AI models. Your conversations and financial data are not used to improve OpenAI's systems.
- Data retention: OpenAI retains API inputs and outputs for up to 30 days solely for trust and safety monitoring (abuse detection), after which it is deleted.
- Encryption: All data sent to OpenAI is encrypted in transit using TLS.
- Your data ownership: You retain ownership of your inputs and outputs when using the AI Coach.
For more information, see OpenAI's API Data Usage Policy at: https://openai.com/policies/api-data-usage-policies
3.3 Conversation Storage
We store your AI Coach conversation history in our database (hosted on Supabase) to: provide continuity across sessions (so the AI can reference previous discussions); enable you to review your past conversations; monitor for safety and quality; generate session summaries for future context. You may request deletion of your conversation history at any time (see Section 9).
4. How We Share Your Information
We share your information only in the following limited circumstances:
4.1 Service Providers
We use the following categories of service providers to operate SnapFree:
| Provider Category | Provider | Purpose | Data Shared |
|---|
| Financial data aggregation | Plaid | Connecting your financial accounts | Your financial account credentials (handled by Plaid directly) |
| AI processing | OpenAI | Powering the AI Coach | Messages, conversation history, financial summaries (see Section 3) |
| Database hosting | Supabase | Storing account and conversation data | All stored data (encrypted at rest) |
| Hosting and delivery | Vercel | Serving the SnapFree application | Standard web request data (IP, headers) |
| Payment processing | Stripe | Processing subscription payments | Payment method details (handled by Stripe directly) |
| Customer support chat | Tidio | Providing support chat on the Support page | Support messages, chat metadata, and technical/device data needed to operate chat sessions |
Each service provider is bound by their own privacy policies and data protection commitments.
4.2 Legal Requirements
We may disclose information if required by law, court order, subpoena, or government request, or if we believe disclosure is necessary to: comply with applicable law or legal process; protect the rights, property, or safety of Calibrated Vision, LLC, our users, or the public; detect, prevent, or address fraud, security, or technical issues.
4.3 Business Transfers
In the event of a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice within our Services of any change in ownership or use of your personal information, as well as any choices you may have regarding your information.
4.4 With Your Consent
We may share your information for other purposes with your explicit consent.
5. Cookies and Analytics
5.1 Essential Cookies
We use essential cookies that are necessary for the operation of SnapFree, including: Authentication cookies to keep you logged in during your session; Security cookies to support security features and detect malicious activity. If you use support chat on our Support page, Tidio may also set cookies or similar local storage needed to maintain your chat session and deliver support functionality.
5.2 Analytics
We may use analytics tools to understand how users interact with SnapFree so we can improve our Services. Analytics data is collected in aggregate and is not used to personally identify you. If we add third-party analytics tools (such as Vercel Analytics, PostHog, or similar), we will update this section to reflect the specific tools in use and any data they collect.
5.3 No Advertising Cookies
We do not use advertising cookies, tracking pixels, or any third-party advertising technology for ad targeting. We do not participate in ad networks or retargeting programs. Our use of Tidio is limited to customer support chat.
6. Data Security
We implement industry-standard security measures to protect your information:
- All data is encrypted in transit using TLS 1.2 or higher
- All consumer financial data is encrypted at rest
- Plaid access tokens are encrypted at the application level before storage
- Passwords are hashed using industry-standard algorithms (never stored in plaintext)
- Access to production data is restricted to authorized personnel only
- Multi-factor authentication is available for account access
- Regular security assessments and dependency vulnerability scans are performed
- Full account numbers are never stored — only masked identifiers (last 4 digits)
No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
7. Data Retention
We retain your information as follows:
| Data Type | Retention Period |
|---|
| Account information | Until you delete your account |
| Conversation history | Until you delete your account or request deletion |
| Financial data (from Plaid) | Refreshed each session; historical snapshots retained until account deletion |
| Payment records | As required by tax and accounting regulations (typically 7 years) |
| Usage/analytics data | Up to 24 months in aggregate form |
| Guardrail and safety logs | Up to 12 months for safety monitoring |
When you delete your account or request data deletion, we will securely delete your personal information within 30 days, except where retention is required for legal, regulatory, or legitimate business purposes (such as maintaining payment records for tax compliance or retaining safety logs).
8. Data Breach Notification
In the event of a data breach that compromises your personal information, we will:
- Notify affected users via the email address associated with their account
- Provide notification as promptly as possible and in compliance with applicable state and federal breach notification laws (including California Civil Code § 1798.82, which requires notification without unreasonable delay)
- Describe the nature of the breach, the types of information involved, and the steps we are taking in response
- Provide guidance on steps you can take to protect yourself
9. Your Rights and Choices
Regardless of where you live, you have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information, including conversation history and financial data
- Data portability: Request your data in a portable, machine-readable format
- Withdraw consent: Disconnect your financial accounts at any time through the app settings
- Opt-out: Opt out of any non-essential data processing
How to exercise your rights:
- In-app: Delete your account or disconnect financial accounts through your account settings
- By email: Contact us at privacy@snapfree.com
- Response time: We will respond to verified requests within 30 days (or 45 days if an extension is necessary, with notice to you)
We will not discriminate against you for exercising any of these rights.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
10.1 Categories of Personal Information Collected
| Category | Examples | Collected? | Source |
|---|
| A. Identifiers | Email address, name, IP address | Yes | You, automatic collection |
| B. Personal information (Cal. Civ. Code § 1798.80) | Name, financial account information | Yes | You, Plaid |
| C–J | N/A | No | — |
| K. Inferences | Debt prioritization suggestions, spending patterns | Yes | Derived from Plaid and conversation data |
| L. Sensitive personal information | Financial account information, account login credentials | Yes | You, Plaid |
10.2 Your CCPA/CPRA Rights
- Right to know what personal information we collect, use, disclose, and sell
- Right to delete your personal information
- Right to correct inaccurate personal information
- Right to opt-out of the sale of personal information — we do not sell your data
- Right to opt-out of sharing for cross-context behavioral advertising — we do not share your data for this purpose
- Right to limit use of sensitive personal information — we use sensitive personal information (financial data) only to provide our Services, which is a permitted purpose under the CPRA
- Right to non-discrimination for exercising your privacy rights
10.3 How to Submit a Request
To submit a CCPA/CPRA request, contact us at privacy@snapfree.com. We will verify your identity before processing your request, typically by confirming your email address and account ownership. You may also designate an authorized agent to submit a request on your behalf. We may require verification of the agent's authority.
11. Other State Privacy Rights
Several other U.S. states have enacted comprehensive privacy laws that may apply to you, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and others. If you are a resident of one of these states, you generally have rights similar to those described in Section 10, including the right to access, delete, and correct your data, and to opt out of certain processing activities. To exercise any state privacy rights, contact us at privacy@snapfree.com.
12. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR).
12.1 Legal Basis for Processing
We process your personal data based on: Consent — which you provide when you create an account and connect your financial accounts through Plaid (you may withdraw consent at any time); Contractual necessity — processing necessary to provide the Services you've requested; Legitimate interests — processing necessary for our legitimate interests (e.g., security monitoring, service improvement), where those interests are not overridden by your rights.
12.2 Your GDPR Rights
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right not to be subject to automated individual decision-making (note: SnapFree's AI Coach provides suggestions only — all financial decisions are made by you)
- Right to lodge a complaint with a supervisory authority
12.3 International Data Transfers
Your data is processed and stored in the United States. We ensure appropriate safeguards are in place for international data transfers, including standard contractual clauses approved by the European Commission, to protect your data during such transfers.
12.4 Data Controller
Calibrated Vision, LLC is the data controller responsible for your personal data. For GDPR inquiries, contact: privacy@snapfree.com
13. Children's Privacy
SnapFree is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at privacy@snapfree.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will:
- Post the updated policy on our website with a new effective date
- Notify you via the email address associated with your account at least 14 days before the changes take effect
- Provide a summary of what changed
Your continued use of SnapFree after the updated policy takes effect constitutes your acceptance of the changes. If you do not agree with the changes, you should stop using our Services and delete your account.