KaroSnip
Privacy notice

Your captures stay local until you choose to share.

This notice explains how Cristian Cotovan, trading as Media Makers in the United Kingdom, handles personal data for KaroSnip. Karo's local capture library, OCR, tags, and local analysis do not enter KaroSnip merely because you use the Mac app.

Effective 12 July 2026 · Last updated 13 July 2026

Data controller and contact

The controller is Cristian Cotovan, trading as Media Makers, United Kingdom. Privacy and data-rights requests can be sent to support@karosnip.com. A complete business correspondence address will be added to the Support page before access expands beyond invited testers.

What we process

  • Account data: email address, verified-email status, browser and Karo sessions, and device-authorization state.
  • Sharing data: the image or video you deliberately upload, video poster, title, optional description, dimensions, duration, checksums, storage usage, share state, and approximate aggregate view count.
  • Security data: request IDs, short-lived rate-limit records, coarse request metadata, and hashed client-IP keys. We do not keep per-view IP histories.
  • Safety data: report reason and details, optional reporter email, a one-way hash of the reporting IP, notification state, and reasoned operator actions.
  • Billing data: KaroSnip tier and quota entitlement, Stripe Customer and Subscription identifiers, subscription status, Price identifier, renewal/cancellation timing, and processed webhook event identifiers. Stripe—not KaroSnip—collects and stores payment-card and billing-address details.
  • KaroSnip does not provide public search, galleries, advertising trackers, or user profiling.

Why we process it

  • To provide accounts, unlisted sharing, owner controls, playback, deletion, and support under our contract with you.
  • To secure the service, enforce quotas, prevent abuse, recover from failures, and understand aggregate reliability under our legitimate interests.
  • To receive, investigate, and act on safety or legal reports and comply with applicable legal obligations.

Processors and location

Cloudflare runs the Workers, Queue, D1 database, and private R2 storage. The production D1 database and R2 bucket are configured for Cloudflare's EU jurisdiction and currently operate in Eastern Europe. Resend delivers sign-in and safety-notification email. Stripe provides hosted Checkout, subscription billing, tax calculation, and the customer portal when Karo Pro is enabled. These providers may process limited service data under their own infrastructure and contractual safeguards.

When rich previews are enabled, a chat or social service that receives your bearer link may fetch and cache preview media. That independent cache may remain after you deactivate or delete the KaroSnip share.

Optional YouTube publishing from Karo

If you connect YouTube in the Karo Mac app, Karo uses YouTube API Services to identify the channel you approve and to perform only the publishing actions you review. The app sends the selected video and the title, description, tags, category, audience, visibility, captions, thumbnail, playlist, scheduling, language, licence, distribution, subscriber-notification, and synthetic-media values you explicitly choose directly from your Mac to Google. KaroSnip, Cloudflare, and Media Makers do not receive those video bytes or Google OAuth tokens.

Google access and refresh tokens stay in macOS Keychain. Non-secret upload recovery and history—such as the destination channel/video IDs, approved metadata, resumable URL, byte offset, and local snapshot path—stay in Karo's local application-support storage. Disconnecting YouTube asks Google to revoke access and immediately removes Karo's local credential, YouTube upload recovery, and YouTube result history. You can also revoke Karo from Google Account Connections; Karo deletes the same local data when Google definitively rejects the stored authorization on a later launch. Revocation does not delete videos already uploaded to your channel; manage or delete those in YouTube.

Retention

  • Active and inactive shares remain until the owner permanently deletes them. Deactivation alone does not delete media or free storage.
  • Abandoned upload reservations expire after 24 hours. Scheduled maintenance aborts multipart uploads, removes partial objects, and incrementally reconciles unreferenced R2 objects after a 24-hour safety grace period.
  • Browser and Karo sessions expire after seven days and may renew with use; they can be revoked at any time. Magic links and device codes expire after ten minutes.
  • Safety reports and operator audit records are retained for up to two years unless a legal claim or reporting duty requires longer retention.
  • Operational logs follow the retention available on the Cloudflare plan. Request logs are allow-listed and must not contain magic links, bearer tokens, R2 signatures, or share tokens.
  • Self-service account deletion first locks the account and removes sessions, then a retryable maintenance task removes stored share objects before deleting the identity and share rows. Provider recovery copies may persist only for their bounded backup window before ageing out.
  • Stripe billing-event identifiers and subscription state are kept for replay safety and accounting obligations. Deleting an account first requests cancellation of any Karo Pro subscription so account deletion cannot silently leave recurring billing active.

Your rights

Depending on the circumstances, you may ask for access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. You may complain to the UK Information Commissioner's Office. Contact support@karosnip.com first if you would like us to resolve a concern.