Privacy Policy
How Snugl collects, uses, and protects your data. Effective date: August 29, 2026.
Who controls this data
Snugl is operated by CodeBrewerz ("we", "us"), registered at Gate No. 218, Bajaj Housing, Rupee Nagar, Pune, Maharashtra 411062, India. For anything about your data — access, correction, export, or deletion — contact ceo@codebrewerz.com. General support questions go to support@codebrewerz.com.
CodeBrewerz is established in India, not the European Union. Where the GDPR requires an EU representative for controllers offering services to people in the EU, ours is: [EU representative name and address — to be appointed]. This notice covers both the EU General Data Protection Regulation and India's Digital Personal Data Protection Act, 2023, which apply to this processing independently of each other.
What we collect, and why
Account data. Email address, a hashed password (or an OAuth link to Google or Microsoft, never a password), and an optional display name. Used to run your account and authenticate you — legal basis: performance of our contract with you.
Link data. Target URLs, short codes or aliases you choose, expiry settings, and timestamps. This is the core of the service — legal basis: performance of our contract with you.
Click events. When a short link is opened, we record that a redirect happened, when, the referring page, and the browser's user-agent string — never an IP address. Used to show you per-day click counts — legal basis: performance of our contract with you (you're shown this data) and our legitimate interest in operating the analytics feature the product is sold on.
Team data. If you invite someone to a shared workspace, we send that email address an invite that discloses your email as the inviter and the workspace's name. Legal basis: performance of our contract with the inviting account, and your legitimate interest in adding teammates.
Security and abuse prevention. An audit log of authentication and authorization events (login, password change, key issuance, membership changes) — no IP address or user-agent — retained 12 months. Legal basis: our legitimate interest in detecting and investigating account compromise.
What we do not do
We run no third-party advertising or cross-site tracking. We do not sell personal data. Click analytics count events; they are not used to build profiles of the people who click, and we never store the IP address of a visitor who follows a short link.
Consent, and marketing email
When you create an account we record that you accepted the Terms of Service and the End User Licence Agreement, which version of each you were shown, and when. We keep that record for as long as the account exists. If either document changes materially, you will be asked to accept the new version before continuing.
Marketing email is separate and entirely optional. The box is never pre-ticked, declining it has no effect on your account, and it is the only thing we do on the basis of consent rather than to run the service you asked for. You can withdraw at any time from the Marketing email setting on your account page — withdrawing is one click, takes effect immediately, and does not require contacting us.
If you signed in with Google or Microsoft you will be asked to accept the agreements the first time you use the account. We do not treat the act of signing in as acceptance.
Cookies
Snugl sets three cookies, all first-party and strictly necessary to run the service — none require consent under ePrivacy rules, and none are used for advertising or cross-site tracking:
session— keeps you signed in to the dashboard.oauth_state— a short-lived value that prevents forged sign-in callbacks when you use Google or Microsoft sign-in.locale— remembers the language you chose.
Who else processes this data
We share data with the following processors, each only for the purpose named, and each under its own data processing terms:
- Cloudflare, Inc. — hosts the application and its database (Workers, D1, KV). Cloudflare is a global infrastructure provider; data may be processed outside India or the EU on Cloudflare's network under its standard contractual safeguards.
- Twilio SendGrid — delivers transactional email (password resets, team invites).
- Lemon Squeezy — our payment processor and Merchant of Record for paid plans; see "Billing" below.
- Google Safe Browsing — checks a target URL against Google's known-threat lists before a link is created. Only the URL is sent, never account data.
- Google and Microsoft — if you choose to sign in with a Google or Microsoft account, they confirm your identity and verified email to us.
Where a processor is located outside India, transfers rely on that processor's standard contractual clauses or equivalent safeguards for international data transfer.
Billing
Paid subscriptions are processed by Lemon Squeezy as Merchant of Record. Card numbers and payment details go directly to Lemon Squeezy and are never stored on our servers. Lemon Squeezy handles invoices, applicable taxes, refunds, and subscription changes through its customer portal.
Storage and retention
Data lives in Cloudflare D1 (a managed SQL database) and Cloudflare KV, not a self-managed server. Retention is bounded per table, not left open-ended:
- Raw click events (which carry referrer and user-agent) are deleted after 90 days regardless of plan — a nightly sweep enforces this.
- Daily click totals (day and count only, no referrer or user-agent) are kept for 30 days on the Free plan, 90 days on Growth, and 365 days on Premium — this is what the dashboard's history charts read from.
- A deleted link's code is deactivated immediately and its row is kept indefinitely so the same short code is never later reused for a different destination — the row itself carries no personal data once its owner's account is erased.
- Expired password-reset tokens, used invite tokens, and expired sessions are purged on the same nightly sweep.
Your rights, and how to exercise them
Subject to the conditions the GDPR and DPDP Act set out, you can ask us to: confirm what data we hold about you and get a copy (access/portability); correct inaccurate data (rectification); delete your data (erasure); or limit how we use it (restriction). You can also object to processing based on our legitimate interest.
Two of these are self-serve, from account settings:
- Download my data exports your account, workspace, and links as a JSON file.
- Permanently delete account erases your email, name, password, linked sign-in providers, sessions, API keys, and — if you're the sole member of your workspace — its links and click history. Your short codes are deactivated rather than deleted outright, so nobody else can register the same code onto a different destination; the deactivated row carries no personal data once this completes.
For anything else, or if you'd rather not use the self-serve tools, email ceo@codebrewerz.com. You can also delete individual links at any time from the dashboard or over the API.
Changes
If this policy changes materially, the revised date above will move and notable changes will be announced on this page before they take effect.