Last updated: March 2026
Snolly ("we", "us", "our") is a web application that provides AI-powered assistance for ServiceNow development. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our service at snolly-ai.com.
We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), the ePrivacy Directive, and applicable data protection laws.
The data controller responsible for your personal data is:
We have not appointed a Data Protection Officer (DPO) as we are a small-scale operation that does not engage in large-scale processing of special categories of data. For all privacy inquiries, contact support@snolly-ai.com.
Storage: Supabase (encrypted at rest, US region)
Retention: Until account deletion
Storage: Encrypted with AES-256-GCM in your browser's localStorage. Credential tokens (encrypted JWTs) are sent to our backend per-request but never persisted server-side.
Retention: Client-side only, until you remove them or clear browser data.
Important: We never log or permanently store your credentials on our servers.
Storage: PostgreSQL via Supabase
Retention: 90 days (automatically purged)
Note: Analytics events are linked to your user ID (pseudonymized, not anonymous). No message content, ServiceNow data, or conversation history is stored server-side. You can opt out of analytics collection in your Settings page.
Chat messages and conversation history are stored exclusively in your browser's localStorage. They are never sent to or stored on our servers. You can export or delete them at any time from the Settings page.
We use the following sub-processors to deliver our service. Your data may be transferred to and processed in the United States by these providers:
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Authentication, analytics database | Email, user ID, analytics events | US |
| Anthropic | AI model provider (Claude) | Prompts and responses (via your API key) | US |
| OpenAI | AI model provider (optional) | Prompts and responses (via your API key) | US |
| OpenRouter | AI model routing | Prompts and responses (via your API key) | US |
| Vercel | Frontend hosting | IP address, request logs | US |
| Railway | Backend hosting | API requests, application logs | US |
AI Providers Note: When you use Snolly, your prompts are sent to AI providers using your own API key (BYOK model). Snolly acts as an intermediary but does not control these providers' data practices. Review their privacy policies:
We use Google Fonts (Geist family) which are self-hosted via Next.js optimization. No requests are made to Google servers at runtime.
Your data may be transferred to and processed in the United States by our sub-processors listed above. These transfers are protected by:
Under the GDPR, you have the following rights:
To exercise any of these rights, use the self-service options in your Settings page or contact us at support@snolly-ai.com. We will respond within 30 days.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU/EEA member state of your habitual residence, place of work, or where the alleged infringement occurred. A list of supervisory authorities is available at edpb.europa.eu.
Important: When using Snolly, you must not include third-party personal data (names, emails, employee IDs, etc.) in your prompts or queries unless you have a legal basis to process that data. Snolly is a developer tool — if you query ServiceNow records containing personal data, your organization's data protection policies and legal basis apply.
| Data Type | Retention Period | Location |
|---|---|---|
| Account data (email, user ID) | Until account deletion | Supabase (server) |
| API credentials | Until you remove them | Browser localStorage (client) |
| Conversation history | Until you delete it | Browser localStorage (client) |
| Usage analytics | 90 days (auto-purged) | PostgreSQL via Supabase (server) |
| ServiceNow data | Not stored (proxied only) | N/A |
We use a minimal number of cookies for authentication and preferences. No tracking or advertising cookies are used. Non-essential cookies (sidebar preference) are only set after you consent via the cookie banner. For full details, see our Cookie Policy.
Snolly uses AI models to generate responses based on your prompts. These AI-generated outputs are informational and advisory only. No automated decisions with legal or significant effects are made about you. All code execution on your ServiceNow instance requires your explicit approval unless you manually enable skip-confirmations mode.
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top of this page indicates the most recent revision.
If you have any questions about this Privacy Policy or wish to exercise your data protection rights: