Snowfairy AI™ Labs Private Limited — Snowfairy AI™ OS Pen Software
Last updated: August 10, 2026 · Governing law: India
This Privacy Policy explains exactly what data OS Pen collects, why, how long it's kept, who sees it, and the rights you have. It covers only OS Pen — other Snowfairy AI™ products (like IntelliRecover) have their own separate privacy policies, since each collects different data for different reasons.
The following data is collected as a condition of using OS Pen, disclosed here and in the in-app License Agreement.
When you create an account: your email address. If you use Google or Microsoft sign-in instead: your display name, email address, and profile photo, as provided by that service. Passwords are managed entirely by Firebase Authentication — we never see or store raw passwords.
Your license key, product tier (Basic, Standard, or Premium), activation date, and device count, if you purchase or activate a license. We keep your license bound to that device using a one-way hashed device identifier, so it stays valid across an app uninstall or reinstall. The same kind of device identifier is used during your 14-day free trial, solely to limit each device and account to one trial. In both cases, we only ever see the hash — never the underlying device information itself, and it can't be reversed to identify your hardware.
A short-lived 6-digit verification code, used only to confirm your email address before a trial can start. It's deleted as soon as you verify successfully, and it stops working automatically after 10 minutes if you don't.
If you buy a license: your order reference, product tier, price, and a payment gateway reference number. If you're in India, payment is processed entirely by Razorpay; outside India, by Paddle.com Market Limited (our Merchant of Record for those purchases). Either way, we never receive or store your full card number, CVV, or bank account details — that's handled entirely by the processor.
If OS Pen terminates unexpectedly, a privacy-minimised crash report is written to a local file on your own device — it is not automatically uploaded to us. These reports never include your screen content, ink strokes, file names, or the contents of any file you have annotated. If you contact support, you can choose to send us that local file to help diagnose the issue; nothing leaves your device unless you decide to share it.
If you use the website chat, we process the messages you submit together with limited context such as the current Snowfairy domain, page path, device category, and a random chat-session identifier. Messages are sent to our AI provider to generate replies. When a conversation ends, a redacted transcript may be delivered through our email provider to Snowfairy's restricted support inbox so our team can understand unresolved issues and improve support. We do not store the transcript itself in Firebase; limited hashed rate-limit, abuse-prevention, and duplicate-delivery records may be stored temporarily. Do not submit passwords, verification codes, payment-card details, license keys, government identifiers, or another person's personal information through chat.
Local-network collaboration. When the user starts or joins Wi-Fi/LAN Collaboration, the application uses the local network to discover or connect participating devices and exchange session information necessary for collaboration. Availability may depend on firewall, router and device settings. Local collaboration content is not automatically uploaded to Snowfairy's servers unless a separately identified online service is explicitly used.
In more detail: Wi-Fi/LAN Collaboration (a complimentary Premium Beta feature, local-network sessions between devices on the same WiFi/LAN) connects participating devices directly over your local network using a plain TCP socket connection — there is no internet connection, no Snowfairy server or cloud relay, and no third-party signaling service involved in setting up or carrying a Wi-Fi/LAN Collaboration session. The host device shares a session room code; a joining device uses it to connect directly to the host over the local network. The drawing/annotation data exchanged between devices during the session is encrypted with a key derived from that room code (AES-256-GCM). As with any local-network feature, connection reliability and how many participants a session can smoothly support depend on your WiFi network's speed and stability — see Terms of Service Section 17 for which tiers include Wi-Fi/LAN Collaboration.
Local screen, camera and microphone processing. When the user explicitly starts Creator Recorder, the application may access the selected screen or display, microphone and optional camera for the purpose of creating a local recording. Recording controls and status are shown to the user. Recordings are saved to a location selected or controlled by the user and are not automatically uploaded to Snowfairy. Operating-system permission and privacy settings apply.
Creator Recorder is a Premium feature for Windows (see Terms of Service for which tiers include it). All recording — screen, camera, and microphone — happens locally on your device; nothing is uploaded to Snowfairy unless you explicitly choose to share the resulting file yourself.
On Android, the optional OCR tool uses Google ML Kit to recognise text. The image or screen content selected for OCR, and the recognised text produced from it, are processed on your device and are not sent to Google by ML Kit. ML Kit may periodically contact Google to receive bug fixes, updated models or hardware-accelerator compatibility information, and may send performance and utilisation metrics. Google processes those limited metrics under its own privacy policy. Snowfairy does not use ML Kit to upload your drawing, screenshot or recognised text content.
We do not sell your personal data, use it for advertising profiling, or share it with data brokers.
Crash reports and support logs are both generated locally on your device only, and OS Pen never uploads either one automatically. A crash report contains application version, Windows OS version, error type, and a truncated stack trace — never file-system paths, your screen content, or file contents. Support logs work the same way: only ever generated on your device, and only ever shared with us if you explicitly choose to send them when contacting support.
When you visit our pricing page, it makes a single request to ipapi.co (a third-party geolocation service) to determine your approximate country, so the correct currency (USD or INR) can be shown. We do not store your IP address in our own databases beyond what's needed to process that single request. If you prefer not to share this, select your region manually on the pricing page, or block outbound requests to ipapi.co in your firewall.
OS Pen shares the same account system (account.snowfairy.ai) used across Snowfairy AI™ Labs products. That portal uses:
We do not use advertising cookies, cross-site tracking, or retargeting pixels on the account portal or the OS Pen desktop application.
| Data | Purpose |
|---|---|
| Email address | License key delivery, trial verification, renewal reminders, and critical security notices |
| License key & tier | Validate your license and enforce which features are unlocked |
| Hashed device identifier | Enforce one trial per device/account; bind an activated license to your device |
| Payment/order data | Process your purchase and provide receipts |
| Crash reports (only if you choose to send one to support) | Diagnose bugs and improve stability |
| Website geolocation | Show correct regional pricing |
| Website chat messages and page context | Generate support replies, route unresolved issues, prevent abuse, and maintain support records |
Account, license, and trial data is stored in Google Firebase (Firestore + Firebase Authentication), hosted on Google Cloud infrastructure. Security measures:
No system can guarantee complete security. In the event of a personal data breach that poses a risk to your rights, we will notify you as required by applicable law.
| Data Type | Retention |
|---|---|
| Account data (email, auth) | Until you request account deletion |
| License records | 7 years (tax & audit compliance) |
| Email verification codes | Deleted immediately on successful verification; otherwise stops working after 10 minutes |
| Trial records | Retained, tied to device and account, solely to enforce the one-trial-per-device-and-account rule |
| Crash reports | Stored locally on your device only, until you delete them yourself — we never receive one unless you send it to support |
| Support correspondence | 3 years from last correspondence |
| Website chat transcript delivered to the support inbox | Treated as support correspondence; retained for up to 3 years from the last correspondence unless earlier deletion is appropriate or longer retention is legally required |
| Chat rate-limit, abuse-prevention, and duplicate-delivery metadata | Short-lived operational records; transcript content is not stored in these Firebase records |
| Website geolocation lookup | Not stored beyond the single request (Section 4) |
| Web session cookie (sf_session) | 1 hour from last activity |
| Service | Purpose | Data Shared | Their Policy |
|---|---|---|---|
| Google Firebase | Authentication, database, hosting, cloud functions | Email, license and trial data | firebase.google.com/support/privacy |
| Google ML Kit (Android OCR) | Optional on-device text recognition; model, compatibility and reliability maintenance | Limited performance and utilisation metrics; selected OCR content and recognised text remain on-device | developers.google.com/ml-kit/terms · policies.google.com/privacy |
| Razorpay | Payment processing (India) | Email, order reference; card details handled independently by Razorpay | razorpay.com/privacy |
| Paddle.com Market Ltd | Payment processing & Merchant of Record (outside India) | Email, order reference; card details handled independently by Paddle | paddle.com/legal/privacy |
| Google / Microsoft (OAuth) | Optional sign-in methods | Display name, email, profile photo — only if you choose to sign in with one of these | policies.google.com · privacy.microsoft.com |
| ipapi.co | IP-based geolocation, pricing page only | Your IP address, one request per page visit | ipapi.co/privacy |
| Groq | Powers the website AI support chat | Chat text and limited page context submitted to generate a reply | groq.com/privacy-policy |
| Resend | Delivers chat digests and support emails | Redacted chat transcript and limited conversation context | resend.com/legal/privacy-policy |
We do not share your data with any other third party, except as required by applicable law.
Wherever you're located, you can ask us to access, correct, or delete your data, or object to a specific use described above. Email support@snowfairy.ai with your registered email address and the right you wish to exercise. We aim to acknowledge within 3 business days and resolve within 30 days (or the applicable statutory deadline). We may verify your identity before acting on your request.
This policy is written with reference to GDPR, UK GDPR, DPDP Act 2023, and CCPA/CPRA concepts as a matter of good practice — this is not a representation that every jurisdictional threshold making a specific law legally mandatory for us has been independently verified.
OS Pen is not directed at children under the age of 18, or the higher age threshold required by local law. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact support@snowfairy.ai immediately and we will delete it without undue delay.
Our data is stored on Google Firebase infrastructure. Where Google or our other service providers transfer personal data across borders, this is done under the contractual safeguards required by applicable law (such as Standard Contractual Clauses, where relevant). See each provider's policy in Section 9 for further detail on their own transfer practices.
We may update this Privacy Policy from time to time. We'll post the updated policy here with a new "Last updated" date and notify you of material changes by email or in-app notification before they take effect. Continued use of OS Pen after the effective date constitutes acceptance of a non-material update; for a materially expanded use of your data, we will seek fresh consent where required by law.
India DPDP Act grievance: If your grievance is not resolved within 30 days, you may escalate it to the Data Protection Board of India.