Privacy & Data Trust
This policy explains what data Snipset collects, where it is stored, when it leaves your device, and how long we keep it. Every fact below reflects how the product actually behaves.
Effective: September 2026
analytics or crash-report SDKs bundled with the apps
of snippet content stored on your device by default
raw blog analytics kept before anonymization
maximum retention for opt-in crash reports
Who This Policy Covers
PT BCB Academy Indonesia (we, us, our) publishes Snipset for desktop, Android, and this website.
This policy describes how we handle data across the Snipset desktop application, the Snipset Android application, this website and blog, and the company servers that power licensing, support, updates, and crash analysis.
It is written against UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (Indonesia's PDP Law) for users in Indonesia. If you use Snipset in the European Economic Area, the same practices apply, and we handle GDPR access, erasure, and portability requests through the contact at the end of this page.
The short version: your snippet content lives on your devices, not on our servers. The servers hold a small set of operational records (licenses, support tickets, QA reports, blog analytics, and opt-in crash reports) described below with exact retention periods.
Where Every Kind of Data Lives
One table for the whole product family. If a row says your device, that data never touches our servers.
| Data | Where it lives | Leaves your device | Retention or control |
|---|---|---|---|
| Snippets, groups, settings | Local SQLite database on your device | No | Local backup and in-app delete |
| Clipboard history | Local SQLite database (on by default) | No, unless you share an item | Sensitive-content filter, retention caps, and an off switch |
| Keystroke buffer | Memory only, for trigger matching | No | Discarded the moment it is processed |
| Activity journal (optional) | Encrypted database on your device | No | Delete-all control in the app |
| AI prompts and embeddings | Local Ollama on your device | No by default | Local models; web grounding off by default |
| License key and machine ID | Company license registry | Yes, at activation | Kept for the license lifetime; email erased on request |
| Support messages | Company ticket database | Yes, when you submit | Deleted after 730 days |
| QA reports | Company QA database | Yes, when you submit | Drafts 90 days, submitted 365 days |
| Blog views | Company blog analytics | Yes, when you read | Raw data anonymized after 30 days |
| Crash reports (optional) | Company database and storage | Yes, only if you opt in | Deleted after 90 days |
| Site cookies and preferences | Your browser | No | 30 days to 1 year, clearable anytime |
| Android app data | Local database on your phone | No, except license checks and updates | In-app controls and OS permissions |
What Stays on Your Computer
The desktop application is local-first. No account, no cloud sync, no analytics SDKs.
Local storage
Snippets, groups, settings, clipboard history, chat history, and embeddings live in a local SQLite database on your machine. The optional activity journal lives in a separate encrypted database, and secrets such as vault payloads use your operating system's credential store. Local backups are plain files on your disk, so treat copies you move to cloud drives the way you would treat any sensitive file.
Clipboard and keyboard
Clipboard history is on by default and stores what you copy, including the source application. A sensitive-content filter rejects passwords, keys, and tokens before they are written, per-application exclusions are honored, and retention caps prune old entries. The global keyboard hook exists only to match snippet triggers: keystrokes are evaluated in memory and discarded immediately, never logged or stored, and password fields are suppressed by default.
Local AI
Text generation and semantic embeddings run against your own local Ollama daemon, so prompts and vectors stay on your hardware. We operate no cloud AI service. Web-search grounding is off by default; when you enable it, only your query is sent to the provider you choose.
What Leaves the Device, and When
The apps have no scheduled telemetry. Below is the complete list of network calls the product makes.
Routine calls (licensing and updates)
- License activation sends the license key and a hashed machine ID, one time.
- A device check runs only to recover a license after a reinstall.
- The updater fetches the signed manifest at launch and every 4 hours; it can be turned off in Settings.
- The Android app verifies the license code during onboarding and checks the update manifest.
Only with your permission or action
- Crash reports: only if you opt in, carrying the device ID and a sanitized stack trace.
- Telegram and Todoist: only if you link an account, only the items you choose.
- AI web-search grounding: only your query, only if you enable it.
- Pomodoro music player: only your search query to the company proxy.
- LAN sync: only between your devices on the local network, off by default.
- Inspect variables: only URLs you embed in a snippet, fetched when the snippet runs.
What Stays on Your Phone
The Android app mirrors the desktop model: a local database, no analytics SDKs.
Snippets, clipboard entries, preferences, and usage history live in a local on-device database. Text expansion works through the Android Accessibility service, which reads only the currently focused editable field to detect triggers; it does not intercept hardware key events.
The app contacts our servers in exactly two situations: it sends your license code once during onboarding to verify it, and it checks the signed update manifest to offer new releases. The microphone permission is declared for future voice features; no recording code path ships in the current app, so nothing is recorded.
Browsing, Cookies, and Forms
The marketing site collects as little as a static site can while still answering support requests.
Analytics
Analytics and conversion measurement on this site (Cloudflare Web Analytics, Google Analytics 4, and Meta Pixel) run only after you choose Accept All in the cookie banner. Until you grant consent, no analytics or marketing scripts load. Choosing Essential Only ensures no tracking scripts or advertising cookies are loaded.
Cookies and browser storage
We set three first-party cookies: language preference (30 days) and your cookie and analytics choices (1 year). Your theme lives in local storage, marketing attribution parameters live in session storage for the active visit only, and the QA self-assessment tool keeps its session token in your browser. Clearing cookies resets every choice.
Forms
The contact form collects your name, email, and message so we can reply; a copy is forwarded to our inbox through our email provider. The support flow verifies your license code first and then stores your ticket. Live-demo registration collects your name, email, and phone number and forwards them to our automation; it is not stored in our database. The download gate collects only your license code. There is no newsletter and no marketing use of form data.
The Small Set of Records We Hold
Only operational records reach us, only through the flows listed above.
License registry
When you activate, we store your license key, the owner name and email supplied at purchase, and one hashed machine identifier per activated computer. The identifier is derived from a one-way hash, so raw hardware details never reach us. These records support license recovery after a reinstall and stay for the life of the license; owner email and name are erased on a verified data-subject request.
Support tickets
Tickets contain whatever you write, plus an optional name and email. Contact-form submissions are also forwarded to our inbox by email. Tickets are deleted automatically after 730 days.
QA reports
Tester reports contain the identity you type (name, role, email, phone), your checklist answers, and your browser user agent. Drafts are deleted after 90 days and submitted reports after 365 days.
Blog analytics
Each blog view records the article, timestamp, and technical request details. Raw addresses and user agents are anonymized after 30 days, keeping only aggregate counts and dates.
Crash reports
Crash reports exist only if you opt in inside the app. Each report carries a random device identifier, app and OS version, and a sanitized message with a stack trace. Reports and any stored full traces are deleted after 90 days.
What we never log
Our servers do not log request bodies. Short-lived rate-limit records keyed by address expire within about a minute and are never used for profiling.
External Services We Use
No third party stores your snippet content. The services below handle site delivery, licensing, support, and optional integrations.
| Service | Role | Data it receives | |
|---|---|---|---|
| Cloudflare | Site hosting, Workers, database, bot protection, site analytics | Platform request logs, captcha responses, aggregate site visits | |
| GitHub | Release and update-manifest hosting | Installer downloads by visitors | |
| Gmail | License code, contact notification, and ticket/QA receipt email | License owner, reporter, or contact name, email, and message content | |
| n8n | Live-demo registration automation | Live-demo name, email, and number | |
| Telegram | Optional desktop app integration | Only messages you choose to share | |
| Todoist | Optional task sync integration | Only tasks you sync | |
| Web search providers | Optional AI grounding (DuckDuckGo, Tavily, Brave, SearXNG) | Only your search query | |
| Google Fonts | Desktop app interface font | Standard font request when the app opens |
Telegram, Todoist, and web-search integrations stay off unless you enable them and supply your own keys or tokens.
Your Rights Over Your Data
Under Indonesia's UU No. 27 of 2022 on Personal Data Protection, you can request access, correction, and deletion of your personal data. Users in the European Economic Area receive the same handling for GDPR access, erasure, and portability requests through the contact below.
Request a copy or deletion
Email us from the address you used for the license, ticket, or QA report. We export your license, ticket, and QA records, then delete or anonymize your personal data.
On-device controls
Clipboard history can be turned off and capped, the activity journal has a delete-all button, backups are local files you own, and auto-updates and crash reporting can be switched off in Settings.
Site cookies
The cookie banner only stores your choice. Site analytics never runs until you pick Accept All, and you can clear cookies anytime to reset the choice.
How Long Each Record Lives
The same numbers our servers enforce automatically.
| Record | Rule |
|---|---|
| Support tickets | Deleted after 730 days |
| Submitted QA reports | Deleted after 365 days |
| QA drafts | Deleted after 90 days |
| Crash reports and stored traces | Deleted after 90 days |
| Blog analytics (raw address data) | Anonymized after 30 days |
| License records | Kept for the license lifetime; personal details erased on request |
Children's Privacy
Snipset is not directed at children under 13, and we do not knowingly collect their personal information.
Changes to This Policy
Material changes are posted on this page with a new effective date before they take effect.
Privacy Questions and Requests
For access, correction, deletion, or any privacy question, reach us directly.
- Email: iwan@snipset.belajarcarabelajar.com
- WhatsApp: +62 821-2926-7114
Related reading: Security & Trust Center
Straight Answers
The questions buyers, IT reviewers, and privacy-conscious teams ask us most.