Snipe Browser - Privacy Policy
Effective date: 27 July 2026 Last updated: 27 July 2026 Version: 1.0
This Privacy Policy is issued by Snipe Group Limited, a company registered in England and Wales with its registered office in Covent Garden, London, United Kingdom ("Snipe", "we", "us", "our"). For the purposes of the UK General Data Protection Regulation ("UK GDPR"), the EU General Data Protection Regulation (Regulation (EU) 2016/679, "EU GDPR") and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), Snipe Group Limited is the data controller (GDPR) and the business (CCPA) responsible for the processing described in this Policy.
1. Scope of this Policy
This Policy applies to:
- The Snipe Browser application ("the Browser") on all supported platforms:
- Snipe Browser for Windows (Windows 10 and 11, x64);
- Snipe Browser for Linux (including .deb packages for Ubuntu/Debian, RPM packages for openSUSE and compatible distributions, Flatpak bundles, and legacy builds for Ubuntu 16.x "Xenial"-era systems);
- Snipe Browser for Android (package name
org.snipesearch.snipebrowser), whether obtained from Google Play or installed directly as an APK ("sideloaded"); - Snipe Browser for macOS (forthcoming; see Section 11.4).
- The Snipe Browser website at
browser.snipeoffice.organd its subpages ("the Website"), including download pages, installation guides, the browser-detector tool, and support content.
This Policy does not apply to other products and services in the SnipeSearch ecosystem - including SnipeSearch (snipesearch.net, snipesearch.co.uk and related domains), SnipeSocial, SnipePay, SNIPE.PICS, SnipeOffice, TTWrite, or SnipeSearch Adclicks. Those services are governed by their own privacy policies. Where the Browser links to or loads those services (for example when you run a search or sign in to SnipeSocial), the relevant service's own policy applies to what happens on that service.
This Policy also does not apply to third-party websites you visit using the Browser. The Browser is a tool for accessing the web; the sites you visit are independent controllers of any data they collect from you.
2. Our Privacy Philosophy - Summary
Snipe Browser is a de-Googled Chromium browser designed around a simple principle: your browsing data belongs on your device, not on our servers.
In plain terms:
- We do not collect telemetry. The Browser contains no usage analytics, no crash-report uploads, no experimentation frameworks, and no background "phone home" services.
- We do not require an account. There is no sign-up, no login, and no cloud profile needed to use any feature of the Browser.
- Your browsing history, bookmarks, cookies, cache, autofill data, and saved passwords are stored locally on your device only. The built-in Password Manager is local-only; there is no forced cloud sync, and we operate no sync service.
- We do not sell, rent, or share your personal information for money or for cross-context behavioural advertising. We never have.
- Google-specific data services have been removed from the Chromium base, including Google Safe Browsing cloud lookups, Google account sync, Google background telemetry, field trials, and pre-connections to Google services.
The remainder of this Policy describes, in detail, the limited situations in which any data leaves your device at all, and the data we process when you use our Website.
3. Data Processed by the Browser (All Platforms)
3.1 Data stored locally on your device only
The following data is created and stored exclusively on your device. We have no access to it, we cannot see it, and it is never transmitted to Snipe:
- Browsing and download history;
- Bookmarks and reading lists;
- Cookies and site data set by the websites you visit;
- Cache, session storage, local storage, and IndexedDB contents;
- Saved passwords and passkeys in the local Password Manager (
chrome://password-manager), including passwords you import from CSV files exported from other browsers or password managers; - Autofill data (addresses, form entries, and, if you choose to save them, payment card details);
- Site permissions you grant or deny (camera, microphone, location, notifications, etc.);
- Browser settings, themes, search-engine selection, and ad-blocker configuration (filter lists, allowlists, custom rules);
- Installed extensions and their data (desktop; and Android where the experimental extensions feature is enabled);
- Open tabs and session-restore data.
You can inspect, export, or delete this data at any time using the Browser's built-in tools (e.g., Settings → Privacy → Clear browsing data), or remove it entirely by uninstalling the Browser and deleting its profile directory.
Deleting local data: because this data never reaches our servers, deletion is entirely under your control and takes effect immediately and permanently when you clear it. We cannot recover it for you, and we cannot delete it for you, because we never had it.
3.2 Update checks
When you use the "Check for updates" function (available in the new-tab footer and, on some builds, automatically on a new build), the Browser fetches a static version file from our update endpoint over the network.
- The request is a plain fetch of a static file. No identifiers are sent: no user ID, no installation ID, no serial number, no hardware fingerprint, and no browsing data.
- Like any HTTP(S) request on the internet, the request necessarily exposes your IP address and standard connection metadata (user-agent string, timestamp) to the server that hosts the file. We use this information transiently to deliver the response and for short-term server security logging (see Section 5.2); we do not use it to build profiles of update-checkers.
- The Browser compares the fetched version number against your installed version locally, on your device, and shows you the result. Whether you download and install an update is entirely your choice; there are no forced or silent upgrades on any platform.
3.3 Ad-blocker filter list updates
The Browser ships with content blocking built into its core (uBlock Origin integrated on desktop builds; Adblock Plus-compatible blocking on Android) and subscribes to filter lists such as EasyList, BadBlock Lite, 1Hosts, and regional lists, some of which are fetched from third-party list maintainers (for example cromite.org on Android).
- Filter list updates are plain fetches of static text files, refreshed automatically on the same cadence as the upstream maintainers publish them. No identifiers are sent beyond the unavoidable IP address and standard request headers received by the server hosting the list.
- Filter list servers operated by third parties (e.g., list maintainers) are independent of Snipe; their receipt of your IP address in serving a static file is an inherent property of how the internet works, not a data-sharing arrangement.
- Certain first-party ecosystem domains (SnipeSearch, SnipeSocial, SnipePay, SNIPE.PICS, SnipeOffice, and the contextual listings inside SnipeSearch Adclicks) are allowlisted by default so the Browser does not block its own ecosystem's services. You can modify or remove these allowlist entries in the blocker settings at any time.
3.4 Search
- The Browser's default search engine is SnipeSearch. When you type a query into the address bar or the new-tab search box and submit it, that query (and your IP address) is sent to SnipeSearch to return results. SnipeSearch's own privacy policy governs that processing.
- During setup (and at any time afterwards in Settings) you may choose Google or Microsoft Bing instead, or configure any other search engine. If you do, your queries are sent to that provider under their privacy policy, not ours.
- The Browser does not send keystroke-by-keystroke "search suggestions" telemetry to Snipe. Any suggestion behaviour depends on the search provider you select and can be disabled in Settings.
3.5 Web content you request
When you browse, the Browser connects directly from your device to the websites you choose to visit and to any resources those pages embed. Those sites receive your IP address, user-agent, and whatever data you provide them. This is inherent to web browsing and is outside our control; we are not a party to those connections, we do not proxy them, and we do not observe them.
3.6 Fingerprinting mitigations
Websites can attempt to identify you by combining device characteristics (language, time zone, screen resolution, pixel ratio, CPU thread count, available memory, installed fonts, and similar values). Snipe includes fingerprinting mitigations - for example, font fingerprinting mitigation is enabled by default on Android (Developer options). These features reduce, but cannot completely eliminate, fingerprinting by third-party websites. They involve no data collection by Snipe.
3.7 What the Browser does NOT do
For the avoidance of doubt, the Browser does not:
- Transmit browsing history, URLs visited, page contents, search history (other than to your chosen search engine as described in 3.4), bookmarks, passwords, autofill data, downloads, or settings to Snipe or to anyone else;
- Contain any analytics SDK, advertising SDK, attribution SDK, or crash-reporting SDK;
- Perform cloud-based Safe Browsing lookups against Google or any other provider (this Google service is removed in the de-Googling process);
- Operate or connect to any cloud sync service;
- Use AI features that transmit data off-device ("no AI features phoning home");
- Create or use any advertising identifier, and does not read the Android Advertising ID (AAID) or any equivalent platform advertising identifier;
- Require, request, or support the creation of a Snipe account.
4. Data Processed by the Website
The Website (browser.snipeoffice.org) is an ordinary informational website: download links, installation guides, FAQs, screenshots, and a client-side browser-detector tool. When you visit it, the following processing occurs.
4.1 Server logs
Our web host receives standard request data - IP address, requested URL, referrer, user-agent, timestamp - as with any website. This is used for delivering the site, security, abuse prevention, and debugging, and is retained only for the short period described in Section 7.
4.2 Third-party analytics on the Website
The Website currently uses two third-party visitor-measurement services. These run on the Website only. They are not present in, and have no connection to, the Browser application on any platform.
| Service | Provider | What it receives | Purpose |
|---|---|---|---|
Rommie Analytics (rommie.net) |
Rommie Analytics | IP address, user-agent, page viewed, referrer, approximate (coarse, IP-derived) location, timestamp | Aggregate visit counting and traffic statistics for the Website |
Statcounter (statcounter.com) |
StatCounter | IP address, user-agent, page viewed, referrer, approximate (coarse, IP-derived) location, timestamp; may set a cookie or use similar technology to distinguish returning visitors | Aggregate visit counting and traffic statistics for the Website |
These providers act as our processors/service providers for basic audience measurement. We use the resulting statistics in aggregate form (visit counts, popular pages, referrer sources). We do not use them to identify individual visitors, and we do not combine Website analytics with any Browser data (we have no Browser data to combine them with).
Consent (EEA/UK visitors): where these tools store or access information on your device (e.g., a Statcounter cookie) in a way that requires consent under the UK Privacy and Electronic Communications Regulations (PECR) or the EU ePrivacy Directive, the Website will request your consent via a consent banner before such storage or access occurs, and you may withdraw consent at any time via the banner's settings link. Declining consent does not affect your ability to use the Website or download the Browser.
4.3 Embedded third-party resources on the Website
- Google Fonts: some Website pages load web fonts from
fonts.googleapis.com/fonts.gstatic.com. Your browser's request for the font files exposes your IP address and user-agent to Google. Google states that Fonts requests are not used for advertising profiles. If you prefer, the Browser's built-in blocker can be configured to block these requests, and we are evaluating self-hosting fonts to eliminate this call entirely. - Archive.org download links: some legacy installers are hosted on the Internet Archive (
archive.org). Downloading from those links is a direct connection between you and the Internet Archive, governed by its own privacy policy. - Browser-detector tool: the "what browser am I" style detector on the Website runs in your own browser using client-side JavaScript. Detected values (browser, OS, screen, locale, hardware characteristics) are displayed to you on the page. Where the tool performs an IP lookup to display your public IP or coarse location back to you, that lookup is made to the relevant lookup endpoint for display purposes only; we do not store the result.
4.4 Contacting us
If you email us or contact us through the Website, we process the contact details and message content you provide in order to respond. See Sections 6 and 7.
5. Categories of Personal Data, Purposes, and Legal Bases (GDPR)
Under UK/EU GDPR, we must identify a legal basis for each processing purpose. Because the Browser is engineered not to collect data, the list is short.
| # | Data category | Source | Purpose | Legal basis (Art. 6 GDPR) |
|---|---|---|---|---|
| 1 | IP address and standard request metadata (user-agent, timestamp, requested resource) received when the Browser fetches the update version file | Your device (automatic, only when an update check runs) | Delivering the requested file; short-term security logging; abuse and attack prevention | Legitimate interests (Art. 6(1)(f)) - operating and securing our update infrastructure |
| 2 | IP address and standard request metadata received when the Browser fetches filter lists from Snipe-operated endpoints | Your device (automatic, periodic) | Delivering the requested static file; security logging | Legitimate interests (Art. 6(1)(f)) |
| 3 | IP address, request metadata, pages viewed on the Website (server logs) | Your browser when visiting the Website | Serving the Website; security; debugging | Legitimate interests (Art. 6(1)(f)) |
| 4 | Website analytics data via Rommie Analytics and Statcounter (IP, user-agent, page, referrer, coarse location; Statcounter cookie where consented) | Your browser when visiting the Website | Aggregate audience measurement | Consent (Art. 6(1)(a)) where cookies/device storage are used; otherwise legitimate interests (Art. 6(1)(f)) in minimal audience measurement |
| 5 | Contact details and correspondence you send us (name, email address, message content) | You | Responding to enquiries, support requests, data-subject-rights requests | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) for rights requests |
| 6 | Records needed to comply with law (e.g., rights-request logs) | Generated by us | Demonstrating compliance | Legal obligation (Art. 6(1)(c)) |
Balancing test note (legitimate interests): in each case relying on Art. 6(1)(f), the processing is limited to data unavoidably transmitted by internet protocols, retained briefly, used for no secondary purpose, and never used for profiling or marketing. We consider the impact on your rights and freedoms to be minimal.
No special category data. We do not seek or knowingly process special category data (Art. 9 GDPR) or criminal offence data (Art. 10 GDPR).
No automated decision-making. We carry out no automated decision-making or profiling producing legal or similarly significant effects (Art. 22 GDPR).
5.1 Data minimisation by design
The Browser is our primary data-protection measure. Consistent with data protection by design and by default (Art. 25 GDPR), features that would require server-side processing of user data (telemetry, sync, cloud Safe Browsing, cloud AI) have been removed or are not implemented.
5.2 Server security logs
Our update and download infrastructure keeps standard short-lived access logs (IP, timestamp, resource, response code) strictly for security, capacity, and abuse prevention. Logs are not enriched, not linked to any identity, and are deleted or irreversibly anonymised on the schedule in Section 7.
6. Data Sharing and Recipients
We do not sell personal data. We do not share personal data for cross-context behavioural advertising. We share personal data only with:
- Infrastructure providers (processors): hosting providers that serve the Website, update files, and filter lists on our behalf, under contracts imposing GDPR Art. 28 obligations.
- Website analytics providers: Rommie Analytics and StatCounter, as described in Section 4.2, acting on our documented instructions for audience measurement only.
- Third parties you direct us to interact with: e.g., the search engine you choose (SnipeSearch, Google, or Bing), filter-list maintainers whose lists your Browser fetches, and the Internet Archive if you download from an archive.org link. These parties act as independent controllers of what they receive.
- Authorities and legal recipients: where required by law, court order, or to establish, exercise, or defend legal claims - noting that, because we hold essentially no user data, there is very little we could produce in response to any such demand.
- Corporate transactions: if Snipe Group Limited is involved in a merger, acquisition, or asset sale, the limited data described in this Policy may transfer to the successor entity, which will remain bound by this Policy or one materially as protective.
We have no data brokers, no advertising partners, and no "data monetisation" arrangements of any kind.
7. Data Retention
| Data | Retention period |
|---|---|
| Browser data stored on your device (history, passwords, bookmarks, settings, etc.) | Under your exclusive control; retained until you delete it or uninstall the Browser. We never hold it. |
| Update/filter-list request logs (IP + metadata) | Maximum 30 days, then deleted or irreversibly anonymised |
| Website server logs | Maximum 30 days, then deleted or irreversibly anonymised |
| Website analytics data held by Rommie Analytics / Statcounter | Per those providers' retention schedules for our account; we configure the shortest practical retention offered and review annually |
| Correspondence and support emails | Up to 24 months after the matter is closed, then deleted unless a longer period is required for legal claims |
| Data-subject / consumer rights request records | 24 months (CCPA requirement) and up to 6 years where needed under UK limitation periods |
8. International Transfers
Snipe Group Limited is established in the United Kingdom. Data we process is processed primarily in the UK/EEA.
- Statcounter is established in Ireland (EEA); transfers from the UK to the EEA are covered by the UK's adequacy arrangements for the EEA.
- Where any provider (including Rommie Analytics, Google Fonts infrastructure, or hosting/CDN nodes) processes data outside the UK/EEA - including in the United States - we rely on: (a) an adequacy decision/adequacy regulations (including, for the US, the EU-US Data Privacy Framework and UK-US Data Bridge where the recipient is certified); or (b) the UK International Data Transfer Agreement / Addendum or EU Standard Contractual Clauses, with supplementary measures where appropriate.
You may request a copy of the relevant transfer safeguards via the contact details in Section 15.
9. Your Rights under UK/EU GDPR
If you are in the UK or the EEA (and, in practice, we extend these rights to all users worldwide), you have the right to:
- Access (Art. 15): obtain confirmation of whether we process your personal data and a copy of it;
- Rectification (Art. 16): have inaccurate data corrected;
- Erasure / "right to be forgotten" (Art. 17): have your data deleted;
- Restriction of processing (Art. 18);
- Data portability (Art. 20): receive data you provided in a structured, commonly used, machine-readable format;
- Object (Art. 21): object to processing based on legitimate interests; we will stop unless we demonstrate compelling legitimate grounds;
- Withdraw consent (Art. 7(3)): at any time, where processing is based on consent (e.g., Website analytics cookies), without affecting prior processing;
- Not be subject to solely automated decisions with legal or similarly significant effects (Art. 22) - we make none;
- Complain to a supervisory authority: in the UK, the Information Commissioner's Office (ICO) - ico.org.uk, +44 303 123 1113; in the EEA, your local data protection authority.
An honest practical note: because the Browser sends us no identifiable data, in most cases we hold nothing that we could link to you. If you submit an access or erasure request, our truthful answer regarding Browser usage will normally be that we hold no personal data about your use of the Browser. Rights requests are most meaningful for Website analytics data and correspondence. We will never ask you to create an account or provide additional identifying data solely to exercise rights, and we respond within one month (extendable by two further months for complex requests, with notice). Exercising your rights is free of charge.
To exercise any right, contact us at privacy@snipeoffice.org.
10. California Privacy Rights (CCPA/CPRA) and Other US State Laws
This section applies to California residents and serves as our Notice at Collection. Residents of other US states with comprehensive privacy laws (e.g., Virginia, Colorado, Connecticut, Utah, Texas, Oregon) have similar rights, which we honour on the same terms.
10.1 Categories of personal information collected (last 12 months)
Using the categories in Cal. Civ. Code §1798.140:
| CCPA category | Collected? | Examples | Source | Purpose | Disclosed to |
|---|---|---|---|---|---|
| A. Identifiers | Yes (limited) | IP address (update checks, Website visits); email address if you contact us | You / your device | Service delivery, security, correspondence | Hosting and analytics service providers |
| B. Customer records (Cal. Civ. Code §1798.80) | Yes (limited) | Name and email if you contact us | You | Correspondence | Hosting provider (email) |
| C. Protected classifications | No | - | - | - | - |
| D. Commercial information | No | - | - | - | - |
| E. Biometric information | No | - | - | - | - |
| F. Internet or network activity | Yes (Website only) | Pages viewed on our Website, referrer, user-agent | Your browser on our Website | Aggregate audience measurement | Rommie Analytics, Statcounter (service providers) |
| G. Geolocation data | Coarse only | Approximate location derived from IP by analytics on the Website | Your browser on our Website | Aggregate audience measurement | Analytics service providers |
| H. Sensory data | No | - | - | - | - |
| I. Professional/employment information | No | - | - | - | - |
| J. Education information | No | - | - | - | - |
| K. Inferences | No | - | - | - | - |
| L. Sensitive personal information | No | - | - | - | - |
The Browser application itself collects none of these categories other than the transient IP address inherent in update and filter-list fetches (Category A, used only for service delivery and security).
10.2 Sale and sharing
- We do not sell personal information and have not done so in the preceding 12 months.
- We do not share personal information for cross-context behavioural advertising and have not done so in the preceding 12 months.
- We have no actual knowledge of selling or sharing personal information of consumers under 16 years of age.
- Because we neither sell nor share, we do not offer a "Do Not Sell or Share" link; there is nothing to opt out of. We nevertheless honour the Global Privacy Control (GPC) signal on the Website as an opt-out of any non-essential analytics where technically applicable.
- We do not use or disclose sensitive personal information for purposes requiring a "Limit the Use of My Sensitive Personal Information" right.
10.3 Your CCPA rights
California residents may exercise the rights to know/access, delete, correct, portability, opt out of sale/sharing (not applicable, as above), limit use of sensitive PI (not applicable), and non-discrimination for exercising rights. Submit requests to privacy@snipeoffice.org with the subject "CCPA Request". We will verify your request using the information you provide in it; because we hold minimal data, verification is usually limited to confirming control of the relevant email address or IP context. You may use an authorised agent; we may require proof of authorisation. We respond within 45 days, extendable once by a further 45 days with notice. We do not charge for requests and will not discriminate against you for making one.
10.4 Retention and minimisation (CPRA)
Retention periods are stated in Section 7 and reflect the CPRA principle that personal information is kept no longer than reasonably necessary for the disclosed purposes.
11. Platform-Specific Disclosures
The Browser's privacy behaviour is deliberately identical across platforms - no telemetry, no accounts, local-only data - but each operating system has its own mechanics worth spelling out.
11.1 Android (org.snipesearch.snipebrowser)
Distribution channels. Snipe for Android requires Android 10 or later and is available (a) on Google Play and (b) as a direct APK download (arm64) from our Website. This Policy applies identically to both. If you sideload the APK, Android will ask you to grant your download source the "Install unknown apps" permission; that is an Android system permission governing installation, not a data permission used by Snipe.
Google Play Data Safety declaration. Our Play Data Safety form declares, accurately:
- Data collected: none. The app transmits no user or device data to the developer for collection purposes. (Update checks and filter-list fetches transmit no identifiers; the transient IP address inherent in any network request is not retained beyond short-term security logs and is not used to identify users, consistent with Play's definition of "collection".)
- Data shared: none.
- Search queries you submit are sent to the search engine you select (SnipeSearch by default; Google or Bing if you choose them) as a user-initiated action - this is your direct interaction with that provider, and their privacy policy applies.
- Data encrypted in transit: all Snipe-operated endpoints are served over HTTPS.
- Data deletion: all app data is stored locally; you can delete it at any time via Android Settings → Apps → Snipe → Storage → Clear data, via the in-app Clear browsing data controls, or by uninstalling the app. Because no data is collected by us, there is no server-side data to request deletion of, and no account to delete - accordingly, no in-app account-deletion flow is required or present.
Android permissions requested. The app requests only permissions required for user-visible browser functionality, and each is used solely on-device or at your direction:
- Internet / network state - loading web pages, update checks, filter-list updates;
- Camera / Microphone (runtime, optional) - only when a website you visit requests them (e.g., video calls) and only after you grant permission per-site;
- Location (runtime, optional) - only when a website requests geolocation and you approve; the Browser itself never collects your location;
- Storage / media access via system pickers - downloads and file uploads you initiate;
- Notifications (runtime, optional) - only for websites you explicitly allow.
You can revoke any runtime permission at any time in Android settings without losing core functionality.
Advertising ID. The app does not request, read, or transmit the Android Advertising ID, and contains no advertising or analytics SDKs. Our Play declaration reflects this.
WebView vs full browser. Snipe for Android is a full Chromium-based browser (147.x track), not a WebView wrapper; its network behaviour is as described in Section 3.
Experimental extensions. If you enable the experimental Extensions feature (Developer options; relaunch required), extensions you choose to install may process browsing data according to their own privacy policies. Review extensions before installing them.
Fingerprinting mitigation. Font fingerprinting mitigation is on by default in Developer options on Android.
Families/children. The app is a general-audience web browser, is not directed at children, and does not participate in Google Play's "Designed for Families" programme. See Section 12.
11.2 Windows (Windows 10 & 11)
- The installer and the installed browser transmit no identifiers; installation requires no account and no registration.
- All profile data (history, passwords, bookmarks, settings) is stored under your Windows user profile directory and is removed if you delete the profile folder; uninstalling via Windows Apps & features offers deletion of browsing data.
- There is no background updater service that reports to us; updates occur only through the manual/visible "Check for updates" mechanism described in Section 3.2 (static file fetch, no identifiers, no forced upgrades).
- No Windows telemetry integrations, no error-reporting uploads, and no Microsoft Store account linkage are used by the Browser.
11.3 Linux (Ubuntu/Debian .deb, openSUSE RPM, Flatpak, legacy Xenial builds)
- Package installation via
apt,zypper,dpkg,rpm, orflatpakinvolves your distribution's or Flathub-style tooling; any password prompts (sudo) are handled entirely by your operating system - Snipe never sees or transmits system credentials. - The Flatpak bundle declares its sandbox permissions visibly at install time (
org.snipeoffice.SnipeBrowser); it requests only what is needed to run a browser (network, display, user-selected file access via portals). - Legacy builds for Ubuntu 16.x-era systems behave identically with respect to privacy: zero telemetry, local-only data, manual updates. Note that running an end-of-life operating system carries its own OS-level security risks outside our control; the Browser's own security architecture and web stack are current-generation Chromium.
- Downloads hosted on
archive.orgfor legacy installers are served by the Internet Archive under its own privacy policy (Section 4.3). - Profile data lives in your home directory (e.g.,
~/.config/) and is deletable by you at any time.
11.4 macOS (forthcoming)
Snipe Browser for macOS is in development. When released, it will follow this same Policy in full: no telemetry, no accounts, no sync service, local-only profile data (stored in your macOS user Library), the same static-file update checks with no identifiers, and the same filter-list behaviour. If distribution occurs via direct download, standard Apple notarisation checks performed by macOS itself (Gatekeeper/notarisation ticket lookups to Apple) are an operating-system function governed by Apple's privacy policy, not data collection by Snipe. If the app is later offered on the Mac App Store, we will complete Apple's App Privacy "nutrition label" consistently with this Policy ("Data Not Collected") and update this Section with any store-specific details before launch.
12. Children's Privacy
The Browser and the Website are general-audience products and are not directed at children under 13 (or the higher age of digital consent applicable in your country, up to 16 in parts of the EEA). We do not knowingly collect personal information from children - and, structurally, the Browser collects no personal information from anyone. If you believe a child has provided us personal information (for example by emailing us), contact us at privacy@snipeoffice.org and we will delete it promptly. Parents and guardians remain responsible for supervising children's web browsing; the Browser's content blocker is an ad/tracker blocker, not a parental-control or content-filtering product.
13. Security
- All Snipe-operated endpoints (Website, update files, Snipe-hosted filter lists) are served over HTTPS/TLS.
- The Browser inherits the current-generation Chromium security architecture, including its multi-process sandbox model and site isolation, with regular rebases against upstream security releases.
- Because Safe Browsing cloud lookups are removed for privacy reasons, the Browser does not query URL-reputation services; protection comes from the sandbox, the built-in content blocker (which blocks many malicious ad/tracking domains via filter lists), and your own judgement. We disclose this trade-off plainly rather than pretending otherwise.
- Locally stored passwords are protected using the platform's standard credential-storage mechanisms (e.g., OS keychain/credential vault integration where available).
- Internally, access to server logs is restricted to personnel who need it, and we maintain proportionate technical and organisational measures (Art. 32 GDPR) for the minimal data we do hold.
- Breach notification: in the unlikely event of a personal data breach affecting you, we will notify the ICO within 72 hours where required and inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
No system is perfectly secure; however, our core mitigation is architectural - data that is never collected cannot be breached on our servers.
14. Changes to this Policy
We may update this Policy from time to time - for example when the macOS version launches, if we change analytics providers on the Website, or to reflect legal developments. When we do:
- The "Last updated" date at the top will change, and a changelog will be maintained below;
- Material changes (any change that expands data collection, adds recipients, or reduces your rights) will be announced prominently on the Website and, for the Android app, reflected in an updated Google Play Data Safety declaration before the change takes effect;
- We will never apply material changes retroactively, and we will never introduce telemetry, data sale, or ad-tech data sharing under cover of a policy update without clear prior notice.
Changelog
- v1.0 - 27 July 2026: Initial publication. Covers Windows, Linux (including legacy builds), Android (Play + APK), the Website, and forward-looking provisions for macOS.
15. Contact Us
Data Controller / Business:
Snipe Group Limited
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
Company No. 17158391
Privacy enquiries and rights requests: privacy@snipeoffice.org
UK supervisory authority: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom - ico.org.uk - +44 303 123 1113. You may lodge a complaint with the ICO (or your local EEA authority) at any time, though we would welcome the chance to address your concern first.
EU / EEA users: For the purposes of Art. 27 EU GDPR, please contact Snipe Group Limited at the registered address and privacy email above. We will update this section if an EU representative is appointed.
This Policy is written in English. If it is translated, the English version prevails in case of conflict.