Versão em português

Snabber logo

PRIVACY POLICY – SNABBER

Last updated: September 21, 2026

Your privacy matters to us. This Privacy Policy describes how Snabber collects, uses, shares, stores and protects users' personal data, in accordance with Brazilian Law No. 13,709/2018 (General Data Protection Law – LGPD).

By using Snabber (website, web app, Android and iOS apps, Telegram bot, API and MCP server), you agree to the practices described in this Policy.

This is an English translation of the Portuguese version. In case of any conflict, the Portuguese version prevails.


1. Who we are

Snabber is a personal and small-business finance app that helps users record, organize and analyze their finances.

For the purposes of the LGPD, Snabber acts as the Controller of the personal data processed on the platform.

Data Protection Officer (DPO): Vinicius Andreatta – vinicius@snabber.com.br

General contact: snabbershop@gmail.com


2. What data we collect

2.1 Registration and access data

  • name, e-mail and password (stored only as an irreversible hash)
  • data received from Google or Apple when you use social sign-in (name, e-mail and profile picture)
  • account preferences, such as language, theme and notification settings
  • onboarding information you choose to provide, such as nickname, financial goal and income range

2.2 Financial data

  • transactions, accounts, balances, categories, budgets, goals, investments, card bills and comments that you record or import (for example, CSV and XLSX files)
  • data obtained through Open Finance, via Pluggy, when you connect a financial institution: accounts, balances, transactions, cards, investments and registration data provided by the institution, such as name and CPF

2.3 Usage, device and communication data

  • IP address, device type, browser, operating system and technical access logs
  • your device's push notification token
  • interactions with the app, including browsing recordings made by Microsoft Clarity
  • sign-up source (campaign parameters such as utm_source and referral codes)
  • support messages, and messages, audio and images you send to the Telegram bot
  • questions asked to the AI assistant and the history of AI usage

Snabber does not collect or store:

  • bank passwords or financial institution credentials, which are entered directly in Pluggy's environment
  • full credit card details, which are processed directly by Stripe or Apple

3. How we use the data

  • to operate the app and its integrations
  • to record, sync and organize your financial information
  • to generate analyses, reports, insights, alerts and AI assistant answers
  • to send communications you requested or enabled (e-mails, push notifications and Telegram messages)
  • to process payments and manage subscriptions
  • to provide support, prevent fraud and abuse, and keep the platform secure
  • to measure the effectiveness of marketing campaigns and improve the app's experience and performance
  • to comply with legal and regulatory obligations

Snabber does not sell personal data.


4. Legal basis for processing

  • Performance of a contract (art. 7, V): to provide the service you signed up for or use
  • Consent (art. 7, I): for Open Finance connections, sharing you configure and optional communications
  • Legitimate interest (art. 7, IX): for security, fraud prevention, product improvement and campaign measurement, always respecting your rights
  • Compliance with a legal or regulatory obligation (art. 7, II): for example, keeping tax and access records

5. External connections and partners

To operate, Snabber uses the services below. Each one receives only the data needed for its purpose and processes that data under its own privacy policy.

ServicePurposeData involvedLocation
Pluggy (Open Finance partner)Connection to banks and financial institutions, when you choose to connect an accountAccounts, balances, transactions, cards, investments and registration data provided by the institution (such as name and CPF, the Brazilian taxpayer ID). Bank credentials are entered directly in Pluggy's environment and never reach SnabberBrazil
Google (Gemini)AI assistant, automatic categorization, reports, insights, automated agents, and reading audio and images sent to the Telegram botYour questions and the financial data needed to answer them (descriptions, amounts, dates, categories, accounts, balances, investments and card bills), plus audio and images you send to the botUnited States
Other AI providers (e.g., TypeSafe)We may adopt new AI providers for specific features (such as classification and automated decisions)Only the data needed for the feature, under the same rules as this Policy. This list will be updated before a new provider is adoptedMay include other countries
StripeSubscription payments on the webE-mail, customer identifiers, subscription and plan. Card details are entered on Stripe's page and do not pass through SnabberUnited States
Apple (App Store and Sign in with Apple)Subscriptions in the iOS app and sign-in with ApplePurchase and subscription identifiers; name and e-mail provided by Apple at sign-inUnited States
Google (Sign in with Google)Sign-in with a Google accountName, e-mail and profile picture provided by GoogleUnited States
SupabaseApplication databaseAll data stored by SnabberUnited States
VercelHosting of the website, the web app and scheduled jobsRequest traffic, IP address and technical records (logs)United States
HostingerSending and receiving e-mail (access codes, summaries, billing and support)Name, e-mail, content of support messages and, when you enable them, financial summaries and chartsMay include other countries
TelegramSnabber bot, when you link your accountChat identifier, messages, audio and images you send, and replies containing financial dataOutside Brazil
Firebase Cloud Messaging (Google)Push notifications on your phoneDevice token and notification text, which may include amounts and names of upcoming billsUnited States
QuickChartRendering chart images for e-mails and TelegramChart labels and values, with no identifying dataOutside Brazil
Microsoft ClarityUsage analytics and session recordings to improve the experiencePages visited, clicks, browser information and browsing recordingsUnited States
Google AdsCampaign and conversion measurementBrowser information, advertising cookies and conversion eventsUnited States
OpenAI (ChatGPT Ads)Conversion measurement, only for visitors who arrived through an ad in ChatGPTAd click identifier, browser information and events such as sign-up, trial start, bank connection and subscription (with plan and amount)United States
Embedded content (YouTube, Tally and similar)Videos and forms shown on some pagesIP address and browser information, according to each provider's policyOutside Brazil

We may also share data to comply with a legal obligation, a court order or a request from a competent authority.


6. Artificial intelligence

When you use the AI assistant, automatic categorization, reports, insights or automated agents, the financial data needed for the task is sent to the AI provider (currently Google Gemini) for processing.

  • We do not send your e-mail, password or CPF to the AI provider.
  • Members of shared workspaces are identified to the AI only by their initials.
  • Answers from AI and automated algorithms are informational, may contain errors and do not constitute financial, investment, accounting or tax advice.
  • You can review and correct automatic categorizations at any time and request information about the criteria used in automated decisions (art. 20 of the LGPD).

7. Sharing you initiate

Snabber offers features that let you voluntarily share your data with other people or systems. This sharing only happens through your own action, and you can revoke it at any time.

7.1 Shared workspaces and advisors

When you invite someone to a workspace, that person can see all the financial data in that workspace (accounts, transactions, categories, budgets, investments and reports), according to the access profile you set: administrator, member, read-only or advisor (full or read-only access). Advisors are outside professionals, such as accountants and financial planners, whom you invite. No password is shared, and a workspace administrator can remove access at any time.

7.2 API and MCP server

You can generate API keys or authorize external applications, such as AI assistants compatible with the MCP protocol, to access your data. These applications receive the financial data of the workspaces and permissions you authorize. Once delivered to an external application, the data is processed by it under its own terms and privacy policy, and Snabber has no control over that use. You can revoke keys and authorizations at any time in your account.

7.3 Other channels you enable

When you link Telegram, enable summary e-mails or push notifications, or subscribe to the Snabber calendar in another app, financial information is delivered through those channels. The calendar link works like a password: anyone who has it can see the events.

You are responsible for controlling who you share your data with. Invite only people you trust to your workspaces, grant the lowest access level needed, do not disclose API keys or calendar links, and periodically review and revoke access you no longer use. Snabber is not responsible for how people or applications you authorize use the shared data.

8. Storage and security

  • all communication with Snabber is encrypted in transit (HTTPS/TLS)
  • passwords are stored only as hashes (bcrypt)
  • transaction descriptions and amounts are encrypted at rest (AES-256-GCM)
  • API keys are stored only as hashes
  • access to data is restricted by authentication and workspace permissions

Other data (such as name, e-mail, categories, account names, balances and investments) does not receive additional field-level encryption, but is protected by the security measures of the database and the infrastructure.

Financial data is not accessed manually by the Snabber team, except when strictly necessary for technical support, required by law or authorized by you.

In the event of a security incident that may create a relevant risk or harm to data subjects, we will notify the Brazilian National Data Protection Authority (ANPD) and the affected users, as required by applicable regulations.

No system is 100% secure, but Snabber is committed to continuous efforts to protect users' information.

9. User responsibilities and limitation of liability

You are responsible for:

  • keeping your password, access codes, API keys and calendar links confidential
  • protecting access to your registered e-mail, since it allows account recovery and receives access codes
  • protecting your Google and Apple accounts, when used for sign-in, and the devices where Snabber is open
  • using strong passwords and not reusing them in other services
  • notifying Snabber immediately if you suspect unauthorized access

Snabber is not liable for damages resulting from the leakage, sharing or misuse of credentials under the user's responsibility, including password, access to the registered e-mail, social sign-in accounts, API keys, calendar links or unprotected devices, nor for access by people and applications the user has authorized.

This limitation does not apply to cases of willful misconduct, gross negligence or violation of the LGPD by Snabber, nor to situations in which applicable law, such as the Brazilian Consumer Protection Code, does not allow the exclusion of liability.


10. International data transfer

Some of our providers, including hosting, the database and the AI provider, are located outside Brazil, mainly in the United States. In these cases, the transfer takes place to perform our contract with you and with providers that adopt data protection safeguards, under art. 33 of the LGPD.


11. Data subject rights

Under the LGPD, you can request at any time:

  • confirmation that your data is being processed, and access to it
  • correction of incomplete, inaccurate or outdated data
  • anonymization, blocking or deletion of unnecessary or excessive data
  • data portability
  • information about the entities with which we share your data
  • deletion of your data and withdrawal of consent
  • review of decisions made solely based on automated processing

Requests can be sent to the DPO at vinicius@snabber.com.br. You can also disconnect banks, remove workspace members, revoke API keys and delete your account directly in the app. If you believe your rights have not been respected, you can file a complaint with the ANPD.


12. Data retention and deletion

Personal data is kept:

  • while your account is active
  • for as long as needed to comply with legal, regulatory or tax obligations (such as payment and access records)

You can request deletion of your account and associated data at any time, subject to legal retention periods. When you disconnect a financial institution, Snabber stops receiving new data from it.


13. Cookies and similar technologies

Snabber uses cookies, browser local storage and similar technologies for:

  • essential operation: keeping your session, preferences and theme
  • analytics: understanding how the app is used (Microsoft Clarity)
  • campaign measurement: attributing sign-ups and subscriptions to ads (Google Ads and, for visitors coming from ads in ChatGPT, OpenAI)

Analytics and campaign measurement cookies are only enabled if you accept them in the cookie notice. Essential cookies are required to use Snabber. You can change your choice at any time:


14. Changes to this Policy

This Policy may be updated, for example, when we adopt a new provider or feature. The date of the last update is shown at the top of the document, and relevant changes will be communicated in the app or by e-mail. Continued use of Snabber after the changes means you accept the new version.


15. Contact

For questions, requests or complaints about privacy and data protection, contact the DPO, Vinicius Andreatta: vinicius@snabber.com.br