Security
Effective: June 7, 2026
This page explains how SnapMind™ AI protects your information, how we handle security incidents, and how to report a security issue. It applies to our website (usesnapmind.com), mobile application, and any related services. For details on what data we collect and how we use it, see our Privacy Policy. For details on the AI Coach safety protocols, see our AI Safety page.
1. How We Protect Your Data
- Encryption in transit. All traffic between you and the Service is protected with industry-standard TLS encryption. We do not accept unencrypted connections to our application or APIs.
- Encryption at rest. All customer data stored in our databases and backups is encrypted at rest using AES-256 or stronger.
- Hashed and salted passwords. We never store passwords in plaintext. Passwords are hashed using modern, salted hashing algorithms. We cannot retrieve a forgotten password and will never email one to you.
- US-based infrastructure. Customer data is stored and processed on infrastructure located in the United States.
- Regular backups. Production data is backed up automatically. Backups are encrypted and access-controlled.
2. Trusted Infrastructure
We rely on a small number of vetted, industry-trusted providers to host our application and process customer data. Each provider is selected on the basis of its security posture, compliance certifications, and incident-response track record. Our core infrastructure includes:
- Netlify for application hosting and content delivery.
- Supabase for our database, authentication, and storage layer.
- Stripe for payment processing. SnapMind never sees or stores full payment card numbers. Stripe handles the entire payment flow under PCI-DSS Level 1 compliance.
- Anthropic for the large language model behind the AI Coach.
- Google Workspace for internal email, productivity, and document collaboration.
3. Access Controls
- Multi-factor authentication is required on all administrator accounts and on all accounts with access to production systems or customer data.
- Principle of least privilege. Team members are granted only the access required to do their job. Access is reviewed periodically and revoked promptly when a team member's role changes or they leave the company.
- Audited admin actions. Administrative actions on customer data are logged for review.
4. AI Coach Privacy
Conversations with the SnapMind AI Coach are used to deliver personalized coaching to the athlete. They are never sold to third parties, never used for advertising, and never shared with external organizations outside of the limited purposes described in our Privacy Policy.
The AI Coach is built with specific safety protocols around crisis topics, including a structured response and escalation path described in detail on our AI Safety page.
5. Protecting Minor Athletes
A meaningful portion of SnapMind users are under 18. We treat their data with heightened care:
- Parent consent before account creation. Athletes under 18 cannot create an account without verified parent or guardian consent. Our consent flow captures the parent's email, agreement, and a timestamp.
- Parent dashboard. Parents and guardians have ongoing visibility into their athlete's activity through a dedicated portal. They can review activity, manage privacy settings, download their athlete's data, and request account deletion.
- Data minimization. We collect only what we need to deliver the product. We do not collect government-issued identifiers, social security numbers, or financial information from minor users.
- No sale of minor data, ever. We do not sell the personal information of any user, and we never share, lease, or rent the personal information of any user under 18 for marketing purposes.
6. Reporting a Security Issue
If you believe you have found a security vulnerability in any SnapMind product or service, we want to hear about it. We treat security researchers as partners, not adversaries.
How to report: Email a detailed description to security@usesnapmind.com. Include steps to reproduce, the affected URL or component, and the impact you observed.
- We acknowledge every legitimate report within 48 hours.
- We work with the reporter on a coordinated disclosure timeline before any public discussion.
- We do not currently operate a paid bug bounty program. We do publicly credit researchers who responsibly disclose valid issues (if they wish).
- We will not pursue legal action against researchers who follow this policy and act in good faith.
Please do not attempt to access other users' accounts or data, run automated scanners against our production systems without coordinating with us first, or test for vulnerabilities in a way that could impact our users.
7. Incident Notification
If a security incident does affect your personal information, we will notify you in the manner and on the timeline required by the applicable state and federal laws that protect you. For users in Florida (our home state) and in other states with strong notification requirements, that typically means notice within 30 days of the determination that your data was affected, delivered to the email address on file. Where the affected user is a minor, we additionally notify the parent or guardian whose email we have on file from the consent flow.
We maintain a written Incident Response Plan that governs how we detect, contain, investigate, notify, remediate, and document any security incident. The plan is reviewed annually and after any material change to our systems or vendor relationships.
8. Compliance
SnapMind operates in compliance with the privacy and data-protection laws that apply to our business, including:
- Florida Information Protection Act (FIPA)
- California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA)
- Texas Securing Children Online through Parental Empowerment Act (SCOPE Act)
- California Senate Bill 243 (Companion Chatbot Law)
- California Automatic Renewal Law (ARL)
- Children's Online Privacy Protection Act (COPPA) for any users under 13
- State data-breach notification laws in all 50 states
We monitor regulatory changes that affect our users and update our practices accordingly.
9. Contact Us
SnapMind AI, LLC · Florida limited liability company · Operating in the United States