Security Policy
Last updated: August 3, 2026
This policy summarizes how SnapDraft protects customer data, accounts, payments, and project content (brand references, CSV briefs, generated assets, and Canvas edits).
1. Overview
We take security seriously and use technical, organizational, and operational safeguards to protect the SnapDraft platform and customer data. No internet service can be guaranteed to be completely secure, but we work to reduce risk, monitor abuse, and respond quickly to issues.
This is not a SOC 2 marketing claim page. When certifications or additional diligence artifacts exist, they will be listed here with dates.
2. Infrastructure and access controls
We aim to protect SnapDraft through measures such as:
- Role-based or need-to-know access to internal systems where available.
- Limited access to production data based on operational need (billing, generation failures, account recovery).
- Use of reputable hosting, database, AI, analytics, and infrastructure providers.
- Monitoring for errors, abuse, suspicious activity, and service health.
- Regular updates to dependencies and platform components where practical.
3. Data protection
Customer content may include brand references, CSV captions, prompts, Canvas edits, generated images, and project settings. We use this information to provide and improve the service. We apply reasonable safeguards to protect customer content from unauthorized access, loss, misuse, or disclosure. Customers are responsible for choosing what content they upload and for avoiding unnecessary sensitive information.
4. Payments and Polar
SnapDraft payments are processed by Polar, our Merchant of Record. Polar handles checkout, payment processing, tax, invoices, subscriptions, cancellations, refunds, and payment-related security. SnapDraft does not store full credit card numbers. See polar.sh/legal/checkout-buyer-terms and polar.sh/legal/privacy.
5. Customer responsibilities
Customers are responsible for:
- Using strong, unique passwords and protecting account credentials.
- Restricting access to projects and brand assets to trusted users.
- Reviewing generated visuals before publishing or client delivery.
- Complying with our Terms of Service acceptable-use rules (no adult content, deepfakes, or IP infringement).
- Removing confidential, regulated, or unnecessary personal data from uploads where appropriate.
- Keeping their own devices, browsers, and shared credentials secure.
6. AI and model providers
SnapDraft may use third-party AI model providers and infrastructure services to generate visuals and operate Canvas features. We select providers with security practices appropriate for the service and use them to process prompts, brand references, and related context as needed to deliver the product. Safety filters may block certain prohibited prompts or outputs.
7. Incident response
If we identify a security incident that affects customer data or service availability, we will investigate, take steps to contain and remediate the issue, and notify affected users where required by law or where appropriate.
8. Responsible disclosure
If you believe you have found a security vulnerability in SnapDraft, please contact contact@snapdraft.com. Include enough detail for us to reproduce and investigate the issue. Do not access, modify, destroy, or exfiltrate data that does not belong to you. Do not disrupt the service or test against other users without permission.