Skip to main content

    Privacy Policy

    Global GDPR-Compliant Version

    Last updated: 17 January 2026

    1. Introduction

    SnapFacts ("we", "our", "us") is a free public fact-discovery platform committed to protecting your privacy. We follow strict data-minimization principles and comply with major global privacy regulations, including:

    • EU/EEA GDPR
    • UK GDPR & Data Protection Act
    • California CCPA/CPRA
    • Canada PIPEDA
    • Australia Privacy Act
    • Norway Personal Data Act
    • Other applicable international privacy standards

    This Privacy Policy explains what information we collect, why we collect it, and how we protect it.

    By using SnapFacts.eu, you agree to this Privacy Policy.

    2. Data Controller

    The data controller responsible for your personal data is:

    SnapFacts

    Operated by: Helge Andresen

    Location: Oslo, Norway

    Email: snapfacts.eu@gmail.com

    3. Information We Collect

    SnapFacts is designed to operate with no user accounts, no tracking cookies, and minimal data collection.

    3.1 Data stored locally on your device (not sent to us)

    The following information is stored only in your browser's localStorage, never on our servers:

    • Your saved fact collections
    • Display and category preferences

    This data is fully controlled by you and remains on your device.

    3.2 Information you voluntarily submit

    We only receive personal data if you actively provide it.

    a) Contact Form Submissions

    If you contact us, we may process:

    • Name (optional)
    • Email address (required for a reply)
    • Subject
    • Message content

    b) Content Reporting

    If you report a fact, we may process:

    • Fact ID
    • Report reason
    • Email address (optional, for follow-up)

    3.3 Technical and security data

    To ensure stability and security, we collect:

    • Anonymized IP addresses
    • Server logs (error logs, request timestamps)
    • Aggregated, non-identifiable page-view analytics

    This information does not identify you personally.

    3.4 We do NOT collect

    • Account registrations
    • Passwords
    • Advertising identifiers
    • Cross-site tracking data
    • Sensitive personal data (as defined in GDPR Article 9)

    4. How We Use Your Information

    We use the limited data we collect strictly for:

    • Responding to contact form inquiries
    • Following up on content reports
    • Ensuring platform stability and performance
    • Detecting fraud, abuse, or security threats
    • Meeting legal obligations

    We never sell, rent, or share personal data with advertisers or data brokers.

    5. Legal Basis for Processing (GDPR)

    We process personal data based on:

    • Art. 6(1)(a) – Consent (when you provide your email to contact us)
    • Art. 6(1)(b) – Contract (responding to your inquiries)
    • Art. 6(1)(f) – Legitimate interest (security, optimization, debugging)
    • Art. 6(1)(c) – Legal obligations when applicable

    6. Analytics (Google Analytics 4)

    SnapFacts uses Google Analytics 4 (GA4) for aggregate traffic analysis to understand how visitors use our site and to improve the user experience.

    What GA4 collects

    • Page views and session data
    • General device and browser information
    • Geographic region (country-level)
    • Referral source

    Privacy protections we apply

    • IP anonymization: IP addresses are anonymized
    • No personal data: We do not collect names, emails, or identifiers through analytics
    • No user tracking: We do not use User IDs or cross-site tracking
    • No advertising: Google Signals and ad personalization are disabled
    • No remarketing: We do not build audience profiles
    • No input tracking: Calculator inputs and form values are never tracked

    GA4 data is used solely for aggregate, anonymized traffic statistics and is never used to identify individual users.

    7. Third-Party Service Providers

    SnapFacts uses a small number of GDPR-compliant services:

    Google Analytics 4

    Used for anonymized, aggregate traffic analysis. Configured with IP anonymization and no ad personalization.

    Supabase

    Used for database hosting (facts only) and serverless functions. Hosted on AWS infrastructure with EU data-storage options.

    Resend

    Used only to send contact-form emails. No marketing, profiling, or tracking.

    Lovable

    Hosting for the frontend React application.

    None of these services have access to your localStorage data.

    8. Local Storage

    We use localStorage to store your collections and preferences on your device. This data is not shared with us or third parties and remains entirely under your control.

    Privacy-first approach: SnapFacts uses only anonymized, aggregate analytics. We do not use behavioral monitoring, session recordings, heatmaps, or cross-site tracking tools.

    9. International Data Transfers

    If personal data is processed outside the EU/EEA (e.g., via AWS, Google, or Resend), we rely on:

    • EU Standard Contractual Clauses (SCCs)
    • Data Processing Agreements (DPAs)
    • Additional technical and organizational safeguards

    This ensures lawful and secure international transfers under GDPR.

    10. Your Rights

    Depending on your location, you may have:

    GDPR/UK GDPR rights

    • Right of access
    • Right to rectification
    • Right to erasure
    • Right to restrict processing
    • Right to data portability
    • Right to object

    CCPA/CPRA rights (California)

    • Right to know what data is collected
    • Right to deletion
    • Right to correct inaccurate data
    • Right to opt out of data sale (we do not sell data)
    • Right to non-discrimination

    How to exercise your rights

    Email: snapfacts.eu@gmail.com

    Note: Most of your data (collections, preferences) is stored locally in your browser. You may delete it at any time by clearing localStorage.

    11. Data Retention

    • LocalStorage data: remains until you manually delete it
    • Contact form messages: up to 2 years
    • Content reports: up to 12 months
    • Security logs: up to 90 days

    After these periods, data is securely deleted.

    12. Data Security

    We apply industry-standard safeguards, including:

    • TLS/SSL encryption
    • Access-controlled administrative dashboards
    • IP anonymization
    • Rate-limiting and security monitoring
    • Strict internal access controls

    No system can guarantee 100% security, but we follow best practices.

    13. Children's Privacy

    SnapFacts is a general-audience website.

    We do not knowingly collect personal data from children under 16 (or lower age as defined by local laws). If you believe a child has submitted their data, contact us immediately.

    14. Changes to This Policy

    We may update this Privacy Policy from time to time. The "Last updated" date at the top will always indicate the latest version.

    Continued use of SnapFacts.eu means you accept any changes.

    15. Supervisory Authority Contact (GDPR)

    If you are in the EU/EEA and believe your data has been misused, you may contact:

    Datatilsynet (Norwegian Data Protection Authority)

    Website: https://www.datatilsynet.no

    16. Contact Us

    For any privacy-related questions or requests:

    SnapFacts

    Attn: Helge Andresen

    Oslo, Norway

    Email: snapfacts.eu@gmail.com