Snailbound

Snailbound

Privacy Policy

Last updated: June 22, 2026. This page is maintained by Snailbound to explain how we handle account, address, and message data.

What we collect

When you create a Snailbound account, we collect your email address and display name. If you sign in with Google OAuth, we also receive basic profile information from your Google account. Subscribers can save multiple mailing addresses with custom labels, and each subscription is mapped to the address selected at checkout. Creators provide club details, tier pricing, and payout information through Stripe Connect. Message threads between users are stored so both creators and subscribers can keep track of conversations. We also keep payment metadata, such as billing dates and plan status, through Stripe.

How we use it

We use your information to run your club or membership: displaying landing pages, processing subscriptions, generating in-memory mailing-label CSV exports for creators, delivering messages, and handling billing through Stripe. We do not use address data for advertising, and we do not build profiles for third-party marketing.

How we protect it

Every Snailbound account is protected by server-side authentication checks, and all database access follows Row Level Security policies with default-deny rules. Addresses and message threads have additional isolation controls so users can only access data that belongs to their own account or clubs. Session cookies are HttpOnly, Secure, and SameSite=Strict. Image uploads are validated and stripped of EXIF metadata. We also apply rate limiting to auth, messaging, and sensitive actions.

What we never do

We do not sell subscriber address data or message contents. Mailing-label CSVs are generated in memory and streamed directly to the creator; they are never persisted on our servers. We do not store full birth years—only month and day when a user chooses to share a birthday.

Subprocessors and integrations

Snailbound uses Lovable Cloud / Supabase for authentication, database, and hosting, and Stripe for payment processing and creator payouts. Google OAuth is offered as a sign-in option. These providers process data only as needed to deliver the service.

Cookies

We use cookies strictly for authentication and session management. You cannot use signed-in features if cookies are disabled.

Retention and deletion

We keep your data for as long as your account is active so you can manage clubs, subscriptions, and addresses. You may request export or deletion of your account data at any time by contacting support. Some billing records may be retained longer where required for tax or financial reporting.

Your rights

You may update or remove your addresses, cancel subscriptions, delete messages, and close your account from the app. For data-export or deletion requests that cannot be handled in-app, contact our support team.

Contact

If you have questions about this policy or want to make a data request, please reach out through the Support page.