This Policy covers data Snowfairy collects directly, as the platform provider: your organization's Licensee account, your Technicians' accounts, and the Platform's own operational and diagnostic data. It does not cover how your organization itself uses or stores data about your own End Users outside the Platform — that is governed by your organization's own privacy practices, for which you are responsible as the Licensee.
When your organization creates a Licensee account: organization name, billing contact email, branding assets you upload (logo, colors), and seat/plan configuration. When a Technician account is created: their name and email address, managed via Firebase Authentication — we never see or store raw passwords.
For every support Session: a device identifier, Session start/end timestamps, which Technician (or AI, in self-service mode) handled it, and a record of any diagnostic action proposed, approved, and applied. Screen and input data during a live Session travels directly between the Technician's console and the End User's device, encrypted for the duration of the Session — Snowfairy's own servers do not receive or store the video/input stream itself.
Where AI-assisted diagnostics are used, a redacted snapshot of the device's diagnostic state (recent system fault entries, disk space, flagged device or service problems, antivirus status) is generated locally on the End User's device and sent to our AI providers to produce a proposed fix. Before this data leaves the device, it passes through an automated redaction step that strips emails, phone numbers, MAC/IP addresses, and credential-shaped text.
Chat messages exchanged with the AI during a Session are processed by our AI providers (see Section 14) solely to generate that Session's replies, and are retained only for the active conversation window described in Section 13.
The Platform includes an optional, last-resort visual diagnosis feature: a bounded set of local screenshots captured only while an End User explicitly starts a recording, used to help diagnose an issue that could not be explained from other evidence.
Where enabled and used, the emergency local-account-recovery feature processes: the device owner's on-file recovery email, a one-time verification code (hashed, not stored in plain text), and an audit trail of the approval and execution steps. This feature requires both the device owner's own verification and, separately, an authorizing Technician's approval before anything executes; see our Terms of Service Section 7.
An individual applying for a Solo/Freelancer license submits: full name, phone number, billing address, and a government-issued ID photo, used solely to verify eligibility for that license tier. ID photos are stored in a private, access-restricted cloud storage bucket, visible only to platform administrators reviewing the application, and are not used for any other purpose.
Our website and web consoles use a Secure, HttpOnly authentication session cookie for sign-in, standard short-lived Firebase Authentication tokens, and non-personal local-storage UI preferences (such as your light/dark theme choice) that are never transmitted to our servers. We do not use advertising cookies, cross-site tracking, or retargeting pixels.
| Data | Purpose | Legal Basis |
|---|---|---|
| Account & organization data | License delivery, billing, branding configuration | Contract performance |
| Session metadata & audit trail | Service delivery, security, dispute evidence, compliance | Contract / Legitimate interest |
| AI diagnostic snapshots | Generate proposed fixes during a Session | Contract performance |
| Visual-diagnosis screenshots (if sent) | One-time AI analysis, then deleted | Explicit consent |
| Recovery verification data | Emergency account-recovery feature | Contract / Legitimate interest |
| Solo/Freelancer ID photo | License-tier eligibility verification | Contract performance |
We do not sell your personal data, use it for advertising profiling, or share it with data brokers.
Account, license, and Session-usage records may be disclosed to our Payment Processor, the acquiring bank, or a card network's dispute resolution body in the event of a chargeback or fraud allegation, consistent with our Terms of Service Section 15. GDPR Art. 6(1)(f) DPDP Act 2023 §4(1)(b)
Account, license, and Session-metadata are stored in Google Firebase (Firestore + Authentication), on Google Cloud infrastructure. Security measures include TLS 1.2+ encryption in transit, Firebase Security Rules restricting each Licensee's data to its own organization, and multi-factor authentication for platform-administrator access. In the event of a personal data breach posing risk to your rights, we will notify you as required by applicable law. GDPR Art. 33–34 DPDP Act 2023 §8(6)
| Data | Retention |
|---|---|
| Account & organization data | Until account deletion is requested |
| Billing/license records | 7 years (tax & audit compliance) |
| Session audit trail | 90 days from Session date, then automatically deleted |
| AI diagnostic snapshots & chat | Active conversation window only (a few hours), then deleted |
| Visual-diagnosis local screenshots | Deleted immediately after sending/discarding; 24-hour automatic purge for anything left behind |
| Solo/Freelancer ID photo | Duration of application review, then deleted unless license is granted |
| Service | Purpose | Policy |
|---|---|---|
| Google Firebase | Authentication, database, hosting, cloud functions | firebase.google.com/support/privacy |
| Payment processor / MoR (Paddle, outside India) | Payment processing, dispute handling | paddle.com/legal/privacy |
| Payment processor (Razorpay, India) | Payment processing | razorpay.com/privacy |
| Groq / Anthropic (Claude) | AI-assisted diagnostics, including visual diagnosis | groq.com/privacy-policy · anthropic.com/legal/privacy |
| Resend | Transactional email (recovery codes, renewal reminders) | resend.com/legal/privacy-policy |
| Cloudflare | Website & signaling infrastructure | cloudflare.com/privacypolicy |
We do not share your data with any other third party, except as required by law or as part of the dispute-resolution process described in Section 11.
| Jurisdiction | Your Rights |
|---|---|
| India | Access, correction, erasure, grievance redressal within 30 days, right to withdraw consent, right to complain to the Data Protection Board of India |
| EU / EEA | Access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your national supervisory authority (GDPR) |
| United Kingdom | Same as EU GDPR; right to complain to the ICO |
| United States (California) | Right to know, delete, correct, and opt out of sale/sharing (we do not sell or share personal data); we honour Global Privacy Control signals |
| All other locations | We honour reasonable data requests under principles of transparency and fairness |
To exercise any right, email support@snowfairy.ai. We respond within 30 days (45 days for California requests, extendable once with notice). We may verify your identity before acting on a request.
The Platform is a business tool and is not directed at children. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact support@snowfairy.ai and we will delete it without undue delay. DPDP Act 2023 §9 GDPR Art. 8
Our data is stored on Google Firebase infrastructure. Transfers from the EU/EEA rely on Google's Standard Contractual Clauses under GDPR Art. 46(2)(c); transfers from the UK rely on the UK International Data Transfer Agreement. Cross-border transfers for Indian users follow DPDP Act 2023 §16. We do not transfer data to jurisdictions lacking adequate protection without appropriate safeguards.
We may update this Privacy Policy from time to time, posting a new "Last updated" date and notifying you of material changes by email or in-app notice at least 14 days before they take effect.
Privacy & Grievance Officer
Snowfairy AI Labs Private Limited
CIN: U62099UP2025PTC226386
Registered Address: 01, Mohansarai–Mataladai Road, Gangapur (Varanasi), Varanasi, Uttar Pradesh – 221302, India
Email: support@snowfairy.ai · contact@snowfairy.ai — subject line "Privacy Request"
Response: acknowledged within 3 business days; resolved within 30 days (or applicable statutory deadline)
Appointed as Grievance Officer under the Digital Personal Data Protection Act 2023 §13. If your grievance is not resolved within 30 days, you may escalate to the Data Protection Board of India once operational. EU/UK residents may lodge a complaint with their national supervisory authority if unsatisfied with our response. GDPR Art. 77