Back

Privacy notice

Last updated 6 September 2026

This notice describes what Snoopios does with personal data today. Every sentence describes code that exists. A solicitor reviews it before launch; until then it is a draft that is nonetheless true.

Who we are

Snoopios is a product of Archema Labs, a company in the United Kingdom and the controller for the data described here. Archema Labs is registered with the Information Commissioner's Office.

Accounts

When you create an account we hold your email address, the name you give, and a password hash kept by our authentication provider. We use them to sign you in, to send the emails the product needs (confirmation, a check that starts failing, a document access decision), and for nothing else. There is no marketing list.

Projects and connections

The tokens you connect are encrypted before they reach our database with a key that is not stored there, are used only to read configuration from the provider, and are deleted the moment you remove the connection. Each check stores the raw response it read as evidence, kept for the number of months your plan states and then deleted by a nightly job. Documents you attach to a control as your own evidence are stored in a private bucket for your organisation, reviewed by a fixed checklist and never by a model, kept for the life of the account, and included in your export. Evidence can contain identifiers from your own systems; it is never shared with anyone but the members of your organisation. If you confirm a statement about your organisation on a control, we record your name, the time and the words you confirmed, and show them to the members of your organisation. If you ask for written feedback on a document you attached, its text and the review lines are sent once to an AI language model provider, which returns the suggestions; nothing is sent unless you ask, and the feature stays switched off until that provider's agreement, retention and region are recorded in this notice.

Visitors to a trust page

If you request documents from a customer's trust page we hold the name, work email and company you give, the time you accepted the confidentiality undertaking, a keyed hash of your IP address for abuse limits, the decision, and a record of each download. The customer whose page it is sees this register; that customer, not Snoopios, decides your request. Requests are kept for 24 months and then deleted.

Who else is involved

Data is held in a Supabase project in London. The application runs on Vercel and is served through Cloudflare, which see the ordinary technical data any web server sees, such as your IP address, to deliver pages and defend against abuse. Email is sent through Resend. No advertising or analytics scripts run anywhere on the site, so there is no consent banner.

Cookies

The application sets the cookies that keep you signed in and nothing else. The marketing pages set none.

Your rights

From Settings you can download everything your account participates in as one file, and you can delete the account: a 30-day grace period you can cancel, then removal of the organisation, its projects, connections, evidence and your sign-in. You can also ask us anything about your data by email; we answer within one month. If you are unhappy with our answer you can complain to us first, and then to the Information Commissioner's Office.

Questions and requests: privacy@snoopios.com