SNIB, LEGAL
Privacy Policy
Last updated: 15 August 2026
Snib is built for the things people can least afford to forget: bills, medical appointments, renewals, subscriptions. That means it handles information about your money and your health. This policy says exactly what is collected, where it goes, and what never leaves your phone, because a vague privacy policy reads as evasive and you are trusting us with things that matter.
This document covers the Snib iOS app. The policy for the techmoose.com.au website is a separate document.
The short version
Everything you save lives on your phone first, and the app works fully without an account. Photos you scan never leave your device; only the text read out of them can travel, and only when needed. If you sign in, your backup is stored in Sydney, Australia. There are no ads, no tracking, and nothing is sold or shared for marketing. You can export everything, and delete everything, from inside the app.
Who we are
Snib is made by TechMoose, a registered Australian business name (ABN 96 392 476 538) held by Md Sowan Khan. Registered address: 2C Welman St, Launceston TAS 7250, Australia. Contact: admin@techmoose.com.au.
What we collect
Captures. The things you tell the app: typed notes, transcriptions of voice notes, and text read from photos of documents. Because of what this app is for, captures often contain sensitive things: appointment details, medication names, amounts owed, account names. Every capture is treated as sensitive.
Commitments and reminders. The structured records the app builds from your captures: titles, dates, amounts, who they involve, and the reminder schedule.
Email address. Only if you choose to sign in with Apple, and only to identify your backup account. Apple lets you hide your real address; the relay address works fine and we never see the real one.
That is the whole list. We do not collect your contacts, your location, your advertising identifier, or analytics profiles of your behaviour.
What never leaves your phone
Photos. When you scan a bill, an appointment card or a prescription, the image is read on your device using Apple's on-device text recognition. The photo itself is never uploaded, not to us and not to anyone. Only the extracted text travels, and only as described below.
Voice recordings. Voice notes are transcribed on your device wherever the hardware supports it. On devices that do not support on-device recognition, Apple's speech service may process the audio under Apple's own privacy terms. We never receive or store the audio on our servers.
Your reminder schedule. Notifications are scheduled locally on your phone. A reminder fires whether or not our servers exist that day.
Where your data lives
On your device. A local database on your phone is the primary copy of everything. If you never sign in, it is the only copy.
Our servers, if you sign in. Backup and multi-device sync are stored with Supabase in the Sydney, Australia region (AWS ap-southeast-2). Access is restricted by row-level security so your rows are readable only by your authenticated account, and data is encrypted in transit.
Cloud parsing, plainly
The app first tries to understand your capture on your device. When a capture is too messy or ambiguous for the on-device model, the text of the capture, along with your time zone and the current time, which are needed to resolve dates like “next Friday”, is sent to our server, which passes it to OpenAI's API to be parsed into structured commitments. What is sent is the text and nothing else: no photos, no audio, no email address, no name attached to the content. Your captures are not used to train models.
If you are offline, or the cloud service is unavailable, the app falls back to on-device parsing. Capture never depends on the cloud.
Crash reports
When the app crashes it sends a diagnostic report to Sentry, our error monitoring provider, so the fault can be found and fixed. Without this a crash on somebody's phone is invisible: they do not file a report, they delete the app, and nothing gets fixed.
A crash report contains where in the code the failure happened, the app version, the iOS version and the device model. What it never contains is enforced in code and covered by tests, not merely promised: no user identifier, no IP address, no screenshot, no view hierarchy, and no capture content. Every diagnostic message is stripped of quoted text and of numbers that could be amounts before it leaves your device. Crash reporting is disabled entirely in development builds.
What we never do
No advertising and no ad networks. No tracking across apps or websites, and no tracking domains. No selling, renting or sharing of your data for marketing. No reading your data for any purpose other than operating the service.
Your controls
Export. Settings, then Privacy, then Export my data gives you a complete machine-readable copy of every capture, commitment, link and reminder we hold, as a JSON file you can keep anywhere.
Delete. Settings, then Backup, then Delete account and all data permanently removes your account and every record from our servers and from the device. This is immediate and cannot be undone. If you never signed in, deleting the app deletes the only copy of your data.
Sign out. Stops backup. Your data stays on your phone.
Retention
We keep your backed-up data for as long as your account exists, because keeping your history is the product. Delete your account and it is removed from our servers. Short-lived server logs needed to operate the service are retained briefly and are not used to build profiles.
Security
Sign-in tokens are stored in the iOS Keychain. Server access is gated by row-level security tied to your account. Data is encrypted in transit. No system is perfectly secure, and we will notify affected users of any breach as required by law.
Your rights
In Australia we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may access, correct, export or delete your information. The app's export and delete functions exist so you can do this yourself, instantly, without emailing anyone.
If you are in the United Kingdom or the European Economic Area, the export function is your right to data portability and the delete function is your right to erasure. You also have the rights of access, rectification and objection, and the right to complain to your local supervisory authority. In Australia you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Anything you cannot do in the app, ask us: we will respond within 30 days.
Children
Snib is not directed at children under 13 and we do not knowingly collect their information. The App Store age rating reflects this.
Changes
If this policy changes in any way that matters, we will say so in the app before the change takes effect, in plain language, not just by updating a date at the top of this page.
Contact
Questions, requests and complaints: admin@techmoose.com.au, or by post to TechMoose, 2C Welman St, Launceston TAS 7250, Australia.