Skip to content
SnapTablePortuguês

Privacy policy

Last updated: 5 October 2026

This policy explains in plain language what personal data the SnapTable iPhone app and this website process, why, for how long, and what rights you have. It follows the EU General Data Protection Regulation (GDPR). The Portuguese version is the primary one.

1. Who is responsible for your data

The data controller is the publisher of SnapTable, holder of the Apple Developer account that publishes the app and established in Spain. The controller’s full identity can be requested through the contact email and is disclosed to supervisory authorities when they ask for it. For any privacy question write to snaptable@alvarorgz.com.

2. What we collect, why, and on what legal basis

We only process the data the app needs to work. You need an account to use SnapTable. The data below is linked to your account.

DataPurposeLegal basis (GDPR)
Account: email address, internal account ID, creation date, university (derived from the email domain) and verification of the email with a 6-digit code.Create the account, sign you in and make sure only authorised people get in.Performance of a contract (Art. 6(1)(b)).
Profile: first name, optional profile photo, accent colour and preferences (reminders and lead time, offers, outside the eurozone, live updates).Personalise the app and show you to your friends.Performance of a contract. Profile photo: consent (Art. 6(1)(a)), which you can withdraw by removing the photo.
“About you” answers (all optional): level of study, country, how you heard about SnapTable and gender. You can skip this step.Understand who uses SnapTable and improve it, in aggregate analysis only.Consent. You can change or delete these answers at any time.
Timetable: subjects, room, class type, day, start and end time, colour, “needs review” flag, classes skipped or changed on a date, calendar events (title, room, date, time), days off and term dates.Show your week, Home Screen widgets and class reminders.Performance of a contract.
Timetable photo (camera or photo library) and the scan result (extracted classes, status, number of classes found, duration, usage metrics and any errors).Turn the photo into classes, apply the daily scan limit and detect failures.Performance of a contract; legitimate interest (Art. 6(1)(f)) for the usage limit and failure detection.
Student card (optional): photos of the front and back, name, number and expiry date.Keep your digital card, show it in the app and in the “Student ID” widget.Consent, given when you add the card. You can delete it at any time in the app.
Friends: friend requests (sent, received, accepted), sharing settings (“Free time only” or “Full schedule”, “Pause sharing”, same-class alert) and the email of people you invite.Show shared free time and manage connections between friends.Performance of a contract.
Meetups: place, date and time, note and invitees’ replies.Invite friends to meet.Performance of a contract.
Meetup chat: the messages you write (text, date and time) and the date you last read each chat.Let the participants of a meetup talk to each other.Performance of a contract.
Blocks and reports: the people and emails you block; and, if you report someone, the reason, the text you write (up to 500 characters), the reported person and, where relevant, the meetup and a copy of the reported message.Protect users, prevent unwanted contact and review abuse reports.Legitimate interest in the safety of users and the service (Art. 6(1)(f)); performance of a contract.
Notifications: the in-app feed (type, name of the sender, place, time, read/unread) and, if you accept push notifications, your device token.Let you know about friend requests, invitations and replies.Performance of a contract; consent for push notifications (the system permission you grant on your iPhone).
Technical security data from authentication: IP address, device/browser type and session data. The session token is kept in the iPhone Keychain.Keep you signed in, prevent abuse and protect the account.Legitimate interest (security) and performance of a contract.

Cafeteria menu (@novasbe.pt accounts): the app shows the Nova SBE cafeteria menu. It is public information that our server copies from the cafeteria operator’s website (Mon Bistrot) into our database, once per working day. We send no data about you to that operator, and the menu is only visible to @novasbe.pt accounts.

On your iPhone: the app keeps a copy of your data (timetable, friends, friend photo thumbnails, card, preferences and theme) in an area shared with the widgets (App Group). Widgets read that copy without network access. Class reminders are local notifications scheduled on the iPhone itself: their content (subject name, time, room) never leaves the device.

iPhone permissions: the camera (only to scan the timetable and the student card and for the profile photo) and notifications. Photos from the library are chosen through the system picker, which only hands over the images you select. We do not use location, contacts, microphone or Face ID.

3. What we do not do

4. Who we share data with

RecipientRoleData
Supabase (Supabase Inc.)Processor: database, authentication, file storage and server functions. The project is hosted in the EU (Ireland, eu-west-1).All account data described in section 2, including profile and card photos (in private storage).
IONOS (SMTP mail server, EU)Processor: sends the 6-digit sign-in code to your email, and invitation emails when someone invites an address that has no account yet.Your email address and the code; for invitations, the invitee’s email and the inviter’s name and email.
Vision AI provider (third party)Processor: reads the timetable photo and returns the classes as text. Only used when you scan a timetable (see section 5).The timetable photo you choose to send.
Apple (Apple Push Notification service)Delivers push notifications if you enable them. Apple also acts as an independent controller for your Apple account and App Store data.Device token and notification text (for example, “X wants to share schedules with you”).
Vercel (website hosting)Processor: hosts this website. It generates technical access logs (for example, IP address).Technical data of website visitors.
Your friends on SnapTableOther users you accepted or who accepted you (see section 6).Name, email, photo and schedule, depending on your sharing setting. Participants of a meetup also see that meetup’s chat messages.

With Supabase, Vercel and IONOS their respective data processing agreements (DPAs) apply. We may also disclose data to authorities when the law requires it.

5. Timetable and card scanning

Timetable. When you scan a timetable, the photo (reduced to 1600 pixels wide) is sent to a server function of ours, which forwards it to the AI service described above and returns the classes to the app. This scan is not done on your iPhone. We do not store the photo in our systems, but we keep a record of the result (raw extracted text, status, counts and metrics) linked to your account, to limit usage (maximum 10 scans in 24 hours) and fix failures. The photo is processed by a third-party vision AI provider, which stores it for 3 days and then deletes it. That provider may process data outside the EU, including in the United States.

Student card. Cropping, straightening and reading the card are done on your iPhone (Apple’s Vision and Core Image frameworks). Only if you add the card, the images and details (name, number, expiry) are stored in your account, in private storage only you can access.

6. What other users can see

7. International transfers

The database and files are in the EU (Ireland). Some processors are companies based outside the European Economic Area (for example Supabase Inc., Vercel, Apple and the AI service provider). Where this involves a transfer of personal data, it relies on a European Commission adequacy decision (for example the EU-US Data Privacy Framework) or standard contractual clauses.

8. How long we keep data

9. Your rights

You have the right of access, rectification, erasure, restriction, objection and portability, and to withdraw consent at any time (without affecting earlier processing). You can correct your name, photo, timetable and preferences in the app itself, and delete your account in Profile › “Delete account” (see Delete account and data). To exercise any right, write to snaptable@alvarorgz.com from your account email. We reply within one month at most.

10. Complaints

If you think we are mishandling your data, you can complain to a supervisory authority. In Portugal, the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt. As the controller lives in Spain, you can also go to the Agencia Española de Protección de Datos (AEPD), www.aepd.es. The lead supervisory authority is the AEPD, since the controller lives in Spain.

11. Website waitlist (beta)

In the “Notify me” form on this website we only ask for your email address. We use it only to tell you when SnapTable is available and, where relevant, to invite you to the beta. The legal basis is your consent. The email is stored in a Supabase database (EU, Ireland) with the sign-up date, and only we can access it. To leave the list, write to the contact email with the address you signed up with and we delete it. We keep the email for 12 months at most from sign-up, or until you ask for removal, whichever comes first.

For what the website uses in your browser (cookies, local storage, external services), see the Cookies page.

12. Security

Connections use HTTPS. All tables have row-level security (RLS) so each person only reaches their own data; friends’ schedules can only be read through functions that respect your sharing setting; profile and card photos are kept in private storage; and third-party service keys live only on the server, never in the app. No system is completely secure: if a data breach affecting you occurs, we will notify you and the competent authority as the law requires.

13. Minors

SnapTable is meant for university students. It must not be used by anyone under 13, the age of digital consent in Portugal. If we find an account of someone below that age, we delete it.

14. Changes to this policy

We may update this policy (for example if the app starts processing new data). The date at the top shows the latest version and, for relevant changes, we will tell you in the app or by email before they take effect.

15. Contact

SnapTable publisher · snaptable@alvarorgz.com.