Privacy policy
What we keep, and what we never see.
Last updated 23 August 2026
The short version
Snagbox is a shared space between a developer and the people testing their app, so it has accounts and it stores what you post. It does not run analytics, show ads, or track you across other apps or sites. Your App Store Connect key is never sent to us. You can delete your account, and everything you own with it, from inside the app.
Who we are
Snagbox is made by Matthew Dickerson, an independent developer in the United Kingdom. Questions about this policy go to support@snagbox.app.
What the app stores
Your account
You sign in with Apple. We receive an identifier for your Apple ID and, if you allow it, your name and email address. Apple’s “Hide My Email” relay is fully supported. Your email is used to sign you in and to contact you about your account; it is not shown to other members. What other members see is the display name you choose and the avatar you set.
What you post
Bug reports, ideas, questions, comments, answers, chat messages, votes, verification verdicts and screenshots you attach are stored so that the other members of the space can see them. A bug report also records the device model, operating system version and app build it was filed from, because that is what makes it useful to the developer.
Screenshots are shrunk and re-encoded on your device before upload, which removes the metadata a photo carries, including location.
Your devices
To attach device details to reports, the app keeps a list of the devices you have signed in from: model, a friendly name and OS version. To send notifications, it stores a push token per device and the device’s name so you can tell them apart in Settings. Notification preferences and read positions (which boards and channels you have seen) are stored so badges are right on every device.
Spaces
A space holds the app’s name, bundle identifier and App Store Connect app identifier, its artwork and links, its invite codes, its members and their roles, builds mirrored from App Store Connect (version, build number, What to Test, upload date), and any PDF resources the developer attaches.
What never leaves your device
Your App Store Connect API key. It is stored in your device’s Keychain and synced between your own devices by iCloud Keychain. Your device calls Apple’s App Store Connect API directly to read your app’s builds and TestFlight details, and writes only the build list into the space. The key is never transmitted to Snagbox’s servers and cannot be read by other members, by us, or by anyone else.
Where it is stored
Snagbox’s backend is hosted by Supabase, Inc., which provides the database, file storage and sign-in service. Data is stored encrypted at rest and in transit. Access to each row is governed by row-level security: members of a space can read that space and nothing else, and only staff can change what staff can change.
Push notifications are delivered by Apple Push Notification service. A notification carries only the title and text you see and a reference to what it is about.
Who else is involved
- Apple — Sign in with Apple, push notifications, the App Store Connect API (called from your device), and TestFlight.
- Supabase — hosting for the database, storage and sign-in, acting on our instructions.
Nobody else receives your data. We do not sell it, share it for advertising, or use it to train anything.
How long we keep it
Until you delete it. Removing a post or message removes it. Leaving a space removes your membership. Deleting your account removes your profile, memberships, devices, push tokens, preferences and every space you own, including all of its content. Reports, comments and messages you wrote in other people’s spaces stay, attributed to “Deleted user”, so the thread still makes sense to the people in it.
Deleting your account is in Settings inside the app. It asks you to sign in with Apple again first, so a phone left unlocked cannot do it on its own.
Your rights
You can see and change your profile in Settings, export what you have posted by asking us, and delete everything as described above. If you are in the UK or EU you have the rights the UK GDPR and GDPR give you, including to access, correct and erase your data and to complain to your supervisory authority. Email support@snagbox.app for anything you cannot do in the app.
Children
Snagbox is a tool for software testing and is not directed at children under 13. We do not knowingly collect data from them.
This website
snagbox.app is a static site served by Cloudflare Pages. It sets no cookies and runs no analytics. Cloudflare may keep short-lived request logs (such as IP addresses) to operate and protect the service, under its own privacy policy. Fonts, images and video are served from this site, not from third parties.
Changes
If this policy changes in a way that matters, the date above moves and the app will ask you to accept the new version.