Privacy · last updated 2026-09-29
Privacy policy.
SnapHook is built so that there is very little to have a policy about. There is no account system, no tracking, and no storage layer. This page describes exactly what touches the service and for how long.
The short version
- No accounts. No email address, name, password or third-party login is ever collected.
- No cookies. The service sets none. No local storage, no session storage, no fingerprinting.
- No analytics and no third-party scripts. Every stylesheet, script and font reference is same-origin. Nothing is fetched from a CDN, so no third party observes your visit.
- No disk storage. Captured requests exist in the server process's memory and nowhere else. There is no database, no object store and no payload log.
- Automatic purge. A session and all of its captures are destroyed 2 hours after its last activity, and immediately on service restart.
What is held, and for how long
When you generate a session, the service creates an in-memory record containing a random slug, a creation timestamp and an activity timestamp. When a request arrives at your ingestion endpoint, the service retains the following in memory only:
- the HTTP method, path, query string and protocol version
- the request headers as sent
- the request body, up to 256 KB
- the network address the request came from
- the time of arrival and the captured size
This data is visible to anyone who knows the session slug, which is why the slug is unguessable and why you should not share it. It is discarded when any of the following happens, whichever comes first:
- you clear the session history from the inspector or via
DELETE /api/{slug}/requests - the capture is pushed out by newer ones (each session keeps its 30 most recent requests, and at most 2 MB)
- the session goes 2 hours without a request and without a connected inspector
- the service process restarts, which erases everything
No copy survives any of those events. There are no backups of session data, because there is nothing to back up.
Server logs
The service writes operational logs only: start-up and shutdown lines, and stack traces if it encounters a bug. Request payloads, headers, paths and session slugs are not written to logs. A reverse proxy or hosting provider operated in front of this service may keep its own access logs containing IP addresses and request lines, which is outside the control of the application.
Sensitive data
Please do not send real credentials, access tokens, payment details or personal data to a SnapHook endpoint. The service is a debugging tool on a public network: anyone holding your session URL can read what was sent to it. Use test-mode keys and synthetic payloads. This is stated plainly rather than buried, because the retention guarantee protects you from us keeping your data — it does not protect you from someone who has your link.
Children
SnapHook is a developer tool with no user profiles and is not directed at children. No age information is collected because no personal information is collected.
Your rights
Because the service holds no identifiers tied to a person, there is no account to access, export or delete. If you want a session gone before it expires, clear it from the inspector or call DELETE /api/{slug}/requests; closing the tab and waiting 2 hours has the same effect.
Changes
If this policy changes, the date at the top of the page changes with it. Material changes will not be applied retroactively to data already purged, since purged data cannot be recovered.
Contact
Questions about this policy, or a report of abuse of the service, can be raised through the project's public repository. The terms of use describe what the service may not be used for.