Privacy Policy

Last updated: January 2026

Your Privacy Rights

GDPR Compliant
Swiss FADP Compliant
No AI Training
Right to Erasure
Data Portability

1. Introduction

Snipara ("we", "our", or "us") is committed to protecting your privacy in accordance with the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR), and other applicable data protection laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our context optimization service.

This policy applies to Snipara services including our web application, API, and MCP endpoints.

2. Data Controller

The data controller responsible for your personal data is:

STARBOX GROUP GMBH

CHE-326.317.262

Chemin du Pré-Guillot 9

1288 Aire-la-Ville

Switzerland

3. Information We Collect

Account Information

When you create an account, we collect:

  • Email address (required for account creation and communication)
  • Name (if provided voluntarily)
  • Profile picture (only if using OAuth authentication via GitHub/Google)

Usage Data

We automatically collect:

  • Query logs - Tool used, timestamps, token counts (NOT the actual query content)
  • API usage statistics - Request counts, rate limit data
  • Error logs - For debugging and service improvement
  • Device information - Browser type, operating system (for security monitoring)

Documentation Content

When you upload documentation to Snipara, we store and process this content solely to provide our context optimization service. This content remains your intellectual property.

What We Do NOT Collect

  • We do NOT read or analyze the semantic meaning of your documentation
  • We do NOT track your behavior across third-party websites
  • We do NOT use advertising trackers or analytics that profile users
  • We do NOT collect data from your LLM provider or your LLM conversations

5. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve our context optimization service
  • Process your queries and return optimized context to your LLM
  • Send you service-related notifications (account, billing, security)
  • Monitor usage for billing purposes and enforce plan limits
  • Respond to your inquiries and support requests
  • Ensure the security and integrity of our platform
  • Comply with legal obligations

6. AI Training - Our Commitment

Your Data is NEVER Used for AI Training

We make the following legally binding commitments:

We will NEVER use your documentation, queries, or any data to train, fine-tune, or improve AI/ML models
We will NEVER share your data with third parties for AI training purposes
We will NEVER aggregate user data for model training or research
Your embeddings and indexes are isolated per project—never mixed with other users' data
Snipara employees will NEVER access your content except for technical support with your explicit written permission

Why this matters: Unlike many AI services, Snipara is a context optimization service—not an AI provider. We don't run LLM inference. Your data flows through our indexing system and is returned to your chosen LLM. We have no incentive or mechanism to use your data for training purposes.

7. Data Storage & Security

Your data is stored securely in data centers located in the European Union and Switzerland.

Security Measures

Encryption in Transit

All data transmitted via HTTPS/TLS 1.3

Encryption at Rest

Database storage encrypted with AES-256

Hashed API Keys

We never store raw API keys

Regular Audits

Security audits and penetration testing

8. Data Sharing & Third Parties

We do NOT sell your personal information. We never have and never will.

We may share data with the following categories of recipients, all bound by Data Processing Agreements (DPAs):

Service ProviderPurposeData Safeguards
Stripe (USA)Payment processingStandard Contractual Clauses (SCCs)
Resend (USA)Transactional email deliveryStandard Contractual Clauses (SCCs)
Vercel (USA/EU)Hosting infrastructureEU data residency option
Neon (EU)Database hostingEU data centers, DPA
GitHub/GoogleOAuth authentication (optional)Only if you choose these login methods

We may also disclose data to legal authorities when required by Swiss or applicable law, or to protect our legal rights and enforce our Terms of Service.

9. International Data Transfers

When we transfer personal data outside of Switzerland or the European Economic Area (EEA), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable (e.g., Switzerland, UK)
  • Supplementary measures including encryption and access controls

You may request a copy of the safeguards in place by contacting privacy@starbox-group.com.

10. Your Rights Under GDPR and Swiss FADP

Your Data Protection Rights

AccessObtain confirmation of whether we process your data and receive a copy
RectificationCorrect inaccurate or incomplete personal data
ErasureRequest deletion of your personal data ("right to be forgotten")
PortabilityReceive your data in a structured, machine-readable format (JSON/CSV)
RestrictionRestrict processing in certain circumstances
ObjectObject to processing based on legitimate interests
WithdrawWithdraw consent at any time where processing is based on consent

To exercise any of these rights: Contact us at privacy@starbox-group.com. We will respond within 30 days (or 72 hours for urgent requests). You will not be charged a fee for exercising your rights in most cases.

11. Data Retention & Deletion

We retain your data for as long as your account is active or as needed to provide services.

Upon Account Deletion or Request

  • Personal data is permanently deleted within 30 days
  • All documentation content, embeddings, and indexes are purged
  • API keys are immediately revoked
  • Anonymized usage statistics may be retained for analytics
  • Legal/tax records retained as required by Swiss law (typically 10 years)

To delete your account: Go to Dashboard → Settings → Delete Account, or email privacy@starbox-group.com with the subject "Account Deletion Request".

12. Cookies and Similar Technologies

We use only essential cookies for authentication and session management. We do NOT use tracking cookies for advertising or cross-site tracking purposes.

Cookie TypePurposeDuration
Session cookiesRequired for authentication and securitySession
Authentication tokenKeeps you logged in securely30 days
Preference cookiesRemember your settings (theme, language)1 year

We do NOT use Google Analytics, Facebook Pixel, or any third-party tracking scripts.

13. Children's Privacy

Our service is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will delete it within 72 hours.

If you believe a child has provided us with personal data, please contact privacy@starbox-group.com immediately.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Email notification to your registered email address
  • Prominent notice on our service dashboard
  • At least 30 days before the changes take effect

Your continued use of the service after the effective date constitutes acceptance of the updated policy.

15. Supervisory Authority

If you believe that our processing of your personal data violates data protection laws, you have the right to lodge a complaint with a supervisory authority.

In Switzerland

Federal Data Protection and Information Commissioner (FDPIC)

Feldeggweg 1

CH-3003 Berne

Switzerland

www.edoeb.admin.ch

In the EU

For EU residents, you may contact your local data protection authority. A list of EU DPAs can be found at edpb.europa.eu.

16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights:

Data Protection Contact

We aim to respond to all privacy-related requests within 30 days.

Questions about your privacy? Contact privacy@starbox-group.com

View Terms of Service →