Legal
Privacy Policy
How Devino Solutions collects, uses, and protects your data when you use Snapvisor. Last updated: 2026-08-02.
Who we are
Snapvisor is a visual regression testing service operated by Devino Solutions ("we", "us", "our"). This policy covers the Snapvisor website (snapvisor.io), the application (app.snapvisor.io), the REST API (api.snapvisor.io), and the MCP server (mcp.snapvisor.io). If you have any question about this policy, email us at [email protected].
Information we collect
- Account information — your name, email address, and organization details when you create an account or team.
- Authentication identifiers — when you sign in with GitHub, GitLab, or Google, we store the identifiers those providers return so we can link your account. We never receive your provider password.
- Project data you upload — the screenshots, build metadata, and repository/branch information your CI or the SDKs send for visual comparison.
- Payment information — billing is handled by Stripe. We store subscription and plan status, not your full card number.
- Usage and diagnostics — product analytics and error reports that help us understand how the service is used and fix problems (see Service providers below).
- Approximate location — Google Analytics derives a coarse, region-level location from your IP address when you use the application. We do not collect precise or device GPS location, and we do not use location for advertising.
How we use your information
- To provide, operate, and secure the Snapvisor service.
- To process your screenshots and produce the visual diffs and status checks you request.
- To manage your subscription, billing, and account.
- To communicate with you about your account, support requests, and service changes.
- To monitor, debug, and improve the reliability and performance of the service.
Service providers we rely on
We use a small set of third-party processors to run Snapvisor. Each receives only the data needed for its function:
- Stripe — payment processing and subscription management.
- PostHog — product analytics, hosted by us on our own infrastructure, so these events do not travel to a third-party analytics vendor.
- Google Analytics 4 — usage measurement in the application. Unlike the other providers here, Google Analytics loads from Google's own servers and your browser contacts Google directly, so Google receives your IP address and derives the approximate location described above. It runs in the application only, not on this marketing site.
- Sentry — error monitoring and diagnostics.
- Backblaze B2 (S3-compatible object storage) — where your uploaded screenshots and diffs are stored.
- GitHub, GitLab, and Google — authentication and, for GitHub and GitLab, posting build status checks to your repositories.
Cookies and sessions
When you sign in, we use a server-side session to keep you authenticated. We use cookies for that session and for essential product functionality. Product analytics and Google Analytics set additional identifiers, including cookies, to measure usage.
Data retention
We retain your account data and uploaded project data for as long as your account is active or as needed to provide the service. You can delete your account yourself from your account settings, or ask us to delete your data by emailing [email protected]; we will delete it, apart from the two exceptions described next and anything we are required to keep to meet a legal obligation.
Two things outlive a deletion, and we would rather say so here than let you discover it later. Your user record is kept as an anonymous placeholder — stripped of your email address and sign-in identities — so that shared history on teams you belonged to stays intact, and we do not currently expire it. Separately, deleting your account removes every record that points at your uploaded screenshots, but the underlying files in our object storage are not individually erased by that operation and we do not publish a fixed period after which they are purged; email us if you need those erased. Deleting your account sets out the full list of what is removed and what is kept.
Your rights
You can request access to, correction of, export of, or deletion of the personal data we hold about you by contacting [email protected], and you can delete your account without asking us — see Deleting your account. Because Snapvisor is built on an open-source engine, you can also self-host it if you prefer to keep all data on your own infrastructure — see Open source.
Security
We protect data in transit and at rest, restrict access to your data, and rely on the providers listed above for hardened payment and storage infrastructure. No online service can guarantee absolute security, so please use a strong, unique password and keep your access tokens confidential.
Changes to this policy
We may update this policy as the service evolves. When we do, we will revise the "Last updated" date at the top of this page. Continued use of Snapvisor after a change means you accept the updated policy.
Contact us
Questions about privacy or your data? Email [email protected] or visit our Support page. See also our Terms of Service.