Privacy notice
What information the hosted service uses, where it goes, and how to ask about your personal data.
Effective 9 October 2026.
1. Who is responsible
Petamatic Limited provides the hosted DataTug service at datatug.app and the DataTug website at datatug.io. We are registered in Ireland under company number 492141, with registered address 38 Abbeylock, Corbally, Limerick, Ireland, V94 C9XA. VAT number: IE9774367T.
For privacy questions and rights requests, email privacy@sneat.co. For product or billing support, email support@sneat.co. The Terms of service cover subscriptions and cancellation.
We are the controller of personal data used to manage our customer relationships, operate accounts, bill for the service and protect it. If your organisation supplies personal data in a shared project, its own responsibilities and our role for that content depend on the purposes of processing and the applicable service arrangement. Contact us to establish those arrangements before using the service for organisational personal data.
2. Information the service handles
- Identity and account: shared Sneat platform account identifiers, sign-in-provider identifiers, email address, display name and available profile information. Google Firebase Authentication supplies the signed-in identity used by DataTug; a linked sign-in provider can supply profile information.
- Projects and sharing: Space identifiers and membership, repository owner/name and folder/branch addresses, project metadata, saved queries and operation records needed to authorise and complete your requested actions. Query text, filenames and metadata can contain personal data you or another project member supply.
- GitHub connection: the authorisation you grant, your GitHub actor identifier and username, repository/installation permissions and encrypted OAuth access and refresh credentials used by the backend. GitHub provides repository contents and metadata for the operations you request.
- Billing: Stripe customer, checkout, invoice, subscription and payment-event references; account/subscription status; amount, currency, period and discount; and information needed for support, refunds and reconciliation. Payment details entered in Stripe Checkout are handled by Stripe.
- Technical and support information: requests, IP addresses and related hosting/network information, browser and application details, error reports, operational logs and information you send when contacting us. These can include account or request identifiers and page URLs.
We receive information from you, your sign-in provider, GitHub, Stripe and other authorised members of a shared project or Space. Which information is involved depends on the feature you use. Connecting a database or repository does not mean that every record is copied to our hosted storage: requests and results follow the connection and execution path you choose.
3. Purposes and legal bases
We use account and connection information to authenticate you, apply access permissions, carry out requested project operations and provide purchased access. For personal data necessary to provide the service to you, the legal basis is performance of our contract with you or steps you request before entering it.
We process billing and financial records to collect payments, manage subscriptions, reconcile transactions and meet applicable accounting and tax obligations. The bases are performance of the service contract and compliance with applicable legal obligations.
We use necessary operational diagnostics, support records and limited payment notifications for our legitimate interests in keeping the service secure, identifying and resolving failures, preventing misuse and disputes, and supporting customers. For information about other people in a shared project, the relevant basis depends on their relationship to the account holder and the processing arrangement; the uploader must have authority to provide it.
Account and authorisation information is needed to use signed-in or connected features; billing information is needed for a paid subscription. If you do not provide it, those features cannot work. Ordinary reading of the public website does not require a paid account. We do not rely on acceptance of the Terms as consent to optional analytics.
4. Storage, sharing and service providers
Cloudflare serves the public website and app. Google Cloud and Firebase provide hosted backend infrastructure, authentication and Firestore storage for account, Space, shared-project and billing-operation records. The same identity can be used by other Sneat platform products; account identity being shared does not make every project publicly visible.
GitHub holds GitHub-backed project files and receives API operations you request. Supported saves can create commits under the authorised integration. Repository visibility and GitHub permissions determine access there, alongside DataTug's Space and service checks. You can review and revoke an app authorisation in GitHub settings.
Stripe handles checkout and payment processing. Our backend receives payment and subscription events and retains the references needed to reconcile access and deal with refunds or disputes. Stripe also processes information for its own payment, security and legal purposes under its Privacy policy.
Sentry receives operational error reports used to diagnose failures. Depending on an error, reports can contain stack traces, application/browser information, request or page URLs and diagnostic breadcrumbs. DataTug browser error reports are sent to our Sentry organization with EU data storage. EU storage does not mean that every provider operation or transfer remains within the EU.
Telegram carries payment/subscription notices to the operator channel for customer support and transaction follow-up. Notices can include the product, plan, billing period, amount and currency, discount and regular price, payment or subscription status, customer references, a resolved buyer display name, and a verified linked Telegram username. They can also include the buyer's country, transaction time, checkout IP address, and payment, provider-account and invoice references. Collapsing message details does not restrict their access: channel members and Telegram receive those fields. These notices are separate from sharing your project with collaborators.
People with the permissions you grant can access shared project content. Provider personnel and authorised operators may have access needed to deliver, secure or support the service. Information may also be disclosed where required by law or necessary to establish or defend legal claims.
5. Own-key AI
The current own-key AI feature stores the provider settings, including the API key, in this browser's local storage. Requests go directly from your browser to the endpoint you choose and include your prompt and the query/session context assembled by the feature, such as previous queries and result metadata. The provider receives that information and processes it under its own terms.
Do not use this feature for information you are not authorised to send to that provider. Review its storage, retention and model-training terms yourself: this notice does not promise that a third-party AI provider never uses inputs for training. Remove the provider from DataTug or clear the relevant browser storage to remove that local configuration; revoke a compromised key with its provider. Clearing browser storage does not delete a provider's records or revoke its key.
6. Browser storage, analytics and diagnostics
The app uses browser storage to maintain sign-in and local settings and, where selected, locally stored project/query data and own-key AI settings. A demo hand-off can use tab session storage to preserve its question across reloads. Clearing that storage can sign you out or remove those local settings and data.
Optional browser Google Analytics, Firebase Analytics and PostHog capture/session recording are disabled in the DataTug app for launch. This does not disable Firebase Authentication, Stripe's payment functionality, hosting/security logs or Sentry error diagnostics.
This notice covers the DataTug website and browser app, including the operator payment notices described above. It does not cover conversations or commands sent to a Telegram bot.
7. Retention and removal
Subscription cancellation ends or limits paid access as described in the Terms; it does not automatically delete a shared project, the shared Sneat platform identity, repository history or provider records. Local browser data remains until removed through the relevant feature or browser controls. GitHub content and commit history remain subject to repository administration and GitHub's retention arrangements.
We keep account and connection records while they are needed for your account or a connected feature, and shared-project records while needed by its authorised members. Billing and payment-operation records are kept for reconciliation, refunds, disputes and applicable accounting/tax duties. Support and diagnostic records are kept while needed to resolve the issue, investigate misuse or establish or defend a legal claim. When you request erasure, we consider whether particular records must be kept under an applicable legal obligation or another lawful exception; ending Pro alone is not a deletion request.
Email privacy@sneat.co to request access, correction or erasure, or to ask what information we hold about you. We assess and respond to requests manually. We may ask you to verify your identity and identify the relevant account or shared Space. We explain the outcome, including any action taken, further steps needed, and any applicable lawful reason for keeping particular information. Removing a shared identity can affect other Sneat platform products. We do not promise automatic expiry-based deletion or immediate erasure of every backup, GitHub commit or third-party copy.
8. International processing
Our service providers may process information outside Ireland and the European Economic Area. In particular, Google's Firebase privacy documentation states that Firebase Authentication processes data in the United States. Selecting an EU backend or storage location does not remove that authentication processing or all other provider transfers.
Firebase's published terms include data-processing terms, and Google Cloud's processing addendum provides for applicable transfer safeguards; Google LLC describes its EU–US Data Privacy Framework certification. Cloudflare's standard subscription terms incorporate its processing addendum and applicable standard contractual clauses. Stripe's transfer addendum provides for the Data Privacy Framework and standard contractual clauses according to the transfer involved.
GitHub describes international processing and its use of standard contractual clauses and the Data Privacy Framework. Telegram describes group companies outside the EEA and contractual safeguards for those group transfers. These provider statements do not mean that every DataTug record remains in the EU or that every provider acts only on our instructions. Contact privacy@sneat.co for information about safeguards relevant to your data.
9. Your rights and complaints
Where applicable, you can request access to your personal data, correction, erasure, restriction of processing or portability, and object to processing based on legitimate interests. If a processing activity relies on consent, you can withdraw that consent without affecting earlier lawful processing. These rights are subject to the conditions and exceptions in applicable law; they do not guarantee a universal product export or immediate deletion of every shared record.
Send requests to privacy@sneat.co. You can also complain to the Irish Data Protection Commission or the supervisory authority available to you under applicable law.
10. Changes to this notice
We will update this notice when service processing materially changes and identify the current version here. A new optional feature that changes what information is sent should be reviewed before you enable it. This notice covers our hosted service; self-hosted software and independently selected external services have their own operational arrangements.
