Snowline is an independent project by Frey.Support Us
Privacy & Data Transparency

Privacy Policy.

We believe enterprise intelligence should be transparent, secure, and respectful of user data sovereignty.

Last Updated: September 2026

1. Overview & Privacy Commitment

At Snowline, accessible from snowlineapp.xyz, we are committed to safeguarding your privacy and ensuring transparency regarding how your data is handled across our web platform, APIs, Model Context Protocol (MCP) integrations, and associated services.

We adhere to a strict privacy-first standard: we do not sell or monetize personal data, we do not deploy invasive cross-site advertisement trackers, and we only collect information essential to delivering verified business intelligence, executive summaries, and milestone tracking.

2. Information We Collect

To provide continuous intelligence feeds, synchronize your workspace across devices, and manage account entitlements, we collect the following categories of data:

  • Account & Identity Data: Display name, verified email address, and avatar image provided through third-party authentication providers (such as Google Sign-In and X/Twitter OAuth) or direct sign-in.
  • Workspace & Watchlist Data: Saved companies, tracked milestones, custom radar categories, executive summary history, and notification preferences associated with your account.
  • Subscription & Transaction Details: Active tier entitlements (Free, Starter, Pro) and billing reference identifiers handled through secure, PCI-DSS compliant payment processors.
  • Technical & Usage Data: IP address, browser type, device operating system, session timestamps, and interaction logs utilized solely for platform security, rate limiting, and performance diagnostics.

3. Google API Services & User Data Policy Compliance

Snowline facilitates frictionless account creation and login via Google Sign-In. Our use and transfer of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements:

  • We only request basic OAuth profile scopes (openid, email, profile) to verify your identity.
  • We do not request or access private Google Drive documents, Gmail messages, contacts, or calendar data.
  • User data obtained via Google APIs is never sold, shared with advertising brokers, or used to train generalized artificial intelligence models without user consent.

4. How We Use Your Information

We process collected information solely for legitimate operational and business purposes:

  • Delivering, personalizing, and maintaining real-time intelligence feeds and watchlist alerts.
  • Generating AI-assisted executive briefs and milestone summaries based on your tracked entities.
  • Managing account authentication, subscription tier access, and customer support inquiries.
  • Protecting the integrity and security of the platform against fraud, abusive crawling, and DDoS attacks.

5. Data Sharing & Third-Party Processors

We do not sell, rent, or trade your personal information. We may share limited data with trusted infrastructure vendors strictly to execute core services:

  • Cloud & Database Infrastructure: Enterprise cloud providers hosting encrypted application databases and serverless APIs under strict confidentiality agreements.
  • Payment Gateways: Certified PCI-DSS payment processors managing secure recurring subscription billing.
  • Legal Compliance: We may disclose information only if required by a valid legal process, subpoena, or applicable regulation.

6. Security & Data Protection Standards

We implement comprehensive technical and organizational measures to protect your information:

  • End-to-end TLS 1.3 / HTTPS encryption across all web traffic, API transactions, and streaming connections.
  • Encrypted databases with automated backups, strict tenant data isolation, and least-privilege administrative access.
  • Strict Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), and secure token handling.
  • Structured RFC 9457 standard error handling preventing exposure of internal database or server traces.

7. Cookies & Local Storage

Snowline utilizes essential cookies and local storage tokens strictly necessary to maintain your login session, preserve your UI preferences (such as light or dark theme mode), and support security tokens. We do not employ third-party tracking or advertising cookies.

8. Push Notifications & Permissions

Snowline offers real-time milestone alerts via standard Web Push and Service Worker Notification APIs.

Notifications are strictly opt-in. You can grant, modify, or revoke push notification permissions at any time directly through your web browser site settings or in your Snowline Account settings.

9. AI & Developer Integrations (API & MCP)

When utilizing our OpenAPI 3.1 endpoints or Model Context Protocol (MCP) servers:

  • AI queries and executive briefs are generated dynamically and are not utilized to train public foundation models without explicit user consent.
  • API access keys are scoped directly to your authenticated account and monitored for fair usage.

10. Data Retention & Account Deletion

We retain your account information for as long as your account is active or as necessary to provide you the Service.

You have the right to request full permanent erasure of your account and all associated workspace data at any time. Upon receiving a verified request, we promptly purge your personal records from our active databases in accordance with applicable data protection laws.

11. Your Rights & Data Sovereignty

Depending on your jurisdiction (including rights under GDPR, CCPA, and similar data protection laws), you possess the following rights:

  • Access & Portability: View and export your account data and tracked watchlist feeds.
  • Correction: Rectify inaccurate or incomplete profile details at any time.
  • Erasure: Request permanent deletion of your account and stored workspace assets.
  • Consent Revocation: Withdraw previously granted permissions (such as browser notifications) at any time.

12. Children's Privacy

The Service is intended for business professionals, investors, and developers. Snowline does not knowingly collect personal data from individuals under 13 years of age. If you become aware that a child has provided us with personal data, please contact us immediately.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect operational, legal, or regulatory updates. We will notify you of any material changes by revising the “Last Updated” date at the top of this page.

14. Contact & Privacy Inquiries

If you have questions, feedback, or data privacy requests regarding this Privacy Policy, please reach out to us at chainlate@gmail.com or submit an inquiry through our dedicated Contact Page.