Privacy Policy
Last updated 20 August 2026 · Snapback is a product of RA1 Labs
This Privacy Policy explains how RA1 Labs Pty Ltd (ABN 44 688 244 484) ("RA1 Labs", "we", "us"), operator of Snapback, collects, uses, and protects personal information. Snapback is a product of RA1 Labs. We are committed to handling personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and, where applicable, other data-protection laws such as the GDPR.
1. Information we collect
Account information: name, email address, organisation, and authentication details when you create an account or sign in (including via third-party OAuth providers).
Billing information: subscription plan and payment status. Card details are handled by our payment processor, Stripe, and are not stored on our servers.
Trace data (Customer Data): execution traces you submit for analysis. Traces may inadvertently contain personal information; the Service applies automated redaction to remove common personal data and secrets before storage, but you should avoid submitting unnecessary personal information.
Usage and device information: log data, IP address, and interactions with the Service, used for security, operation, and improvement.
2. How we use information
To provide, operate, secure, and improve the Service; to produce diagnostic verdicts; to process payments; to communicate with you about your account and the Service; to comply with legal obligations; and to maintain aggregated, de-identified diagnostic patterns that do not identify you or your end users.
We always send essential account, security, and billing messages. We only send non-essential messages (such as product news, offers, or partner promotions) if you opt in, and you can opt out at any time from your account settings or via the unsubscribe link in those emails.
3. Redaction and data minimisation
The Service is designed to minimise the personal information it retains. Automated redaction removes common categories of personal data and secrets (such as emails, card numbers, phone numbers, and API keys) from traces. You control the redaction mode per source. No automated redaction is perfect; you remain responsible for what you submit.
4. Disclosure and sub-processors
We do not sell your personal information. We share information with the service providers ("sub-processors") that help us operate the Service, under confidentiality and data-protection obligations, and with authorities where legally required or to protect our rights and users.
Our current sub-processors are: Stripe (payment processing); Hetzner (cloud hosting and storage, Singapore); OpenRouter and the applicable large language model provider it routes to (automated diagnosis of submitted traces); Resend (transactional email); Slack and Telegram (optional verdict delivery, where you enable them); and our error-monitoring provider. We may update this list as the Service evolves and will post material changes here.
5. How traces are processed
When you submit a trace, we first analyse it against our own pattern library to identify known failure classes. Where the library does not fully resolve the diagnosis, the redacted trace is sent to a third-party large language model — which may include open or open-weight language models — accessed via OpenRouter, to complete the automated analysis. This means that, for those traces, your submitted content passes through OpenRouter and the selected model provider, and each of those parties' own data-handling and retention terms apply to that processing in addition to this policy.
We apply automated redaction to remove common personal data and secrets BEFORE a trace leaves our systems for model analysis, to minimise what is exposed at that step. We do not use your trace content to train models. No automated redaction is perfect, so you should avoid submitting unnecessary personal or sensitive information in traces.
6. International transfers
We host and process data with Hetzner in Singapore, and the automated model analysis described above may involve processing in other countries depending on the model provider. Where we transfer personal information overseas, we take reasonable steps to ensure it is handled consistently with this policy and applicable Australian Privacy Principles.
7. Retention
We retain personal information for as long as necessary to provide the Service and for legitimate business or legal purposes. You can request deletion of your account and associated personal information by contacting [email protected].
When you delete your account, we soft-delete it immediately (access and data ingestion stop at once) and retain the data for a 60-day recovery window in case the deletion was accidental. After 60 days, your organization and all associated data — traces, verdicts, sources, usage, and account records — are permanently and irreversibly purged from our systems.
8. Data breach notification
We maintain measures to detect and respond to data breaches. If an eligible data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Because parts of the Service rely on sub-processors, a breach affecting a sub-processor that involves your data will be assessed and, where required, notified in the same way.
9. Security
We implement reasonable technical and organisational measures to protect personal information against loss, misuse, and unauthorised access. No method of transmission or storage is completely secure.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict the processing of your personal information, and to lodge a complaint with a supervisory authority (such as the Office of the Australian Information Commissioner). To exercise these rights, contact [email protected].
11. Automated processing
The Service uses automated processing to analyse the traces you submit and produce diagnostic verdicts (for example, identifying a likely failure class, the step where a failure occurred, and a suggested fix). These verdicts are automated assessments of software and AI-agent behaviour; they are not decisions that produce legal or similarly significant effects about individual people. You remain responsible for how you act on a verdict. If you have questions about how the automated analysis works, contact [email protected].
12. Children
The Service is intended for users aged 18 and older. We do not knowingly collect personal information from children.
13. Changes and contact
We may update this policy and will post changes with a revised effective date. For privacy questions or requests, contact [email protected].