Security & Data Protection

    Last updated: August 12, 2026 — public summary of our written information security program.

    1. Scope

    This summary covers CrayonSnap's consumer photo-to-coloring-page service, including account data, uploaded photos, generated coloring pages, and billing records. CrayonSnap is operated from the United States and is intended for US customers.

    2. Who is responsible

    CrayonSnap is a small team. A named owner is accountable for security decisions, vendor review, incident response, and periodic review of this program. Security questions go to hello@crayonsnap.com.

    3. Data we hold, and for how long

    • Uploaded photos. Original photos are deleted within 7 days by a nightly, logged job; residual encrypted backup copies are purged within about 30 days. A scheduled job runs nightly and its results are logged so deletions can be verified.
    • Generated coloring pages. Kept in your account so you can reprint them, and deleted when you delete the page or your account.
    • Account and billing data. Email, plan status, and usage counts. Card numbers never touch our servers — Stripe processes payments directly.
    • We do not collect, generate, or store biometric identifiers, faceprints, or facial-recognition data.

    4. Technical safeguards

    • TLS encryption for all traffic in transit; encryption at rest for stored files and database records.
    • Row-level security on every user-facing database table, so one account cannot read another's photos or pages.
    • Private storage buckets — generated files are served through short-lived signed URLs, not public links.
    • Secrets are stored in the hosting platform's encrypted secret store, never in source code.
    • Automated dependency and security scanning, with findings triaged and tracked.

    5. Access controls

    Administrative access is limited to the smallest number of people needed to run the service, protected by unique accounts and multi-factor authentication. Administrative views are used for support and abuse handling, not for browsing customer photos.

    6. Subprocessors

    We use a small set of vendors to run the service: cloud hosting and database/storage, a paid enterprise AI image API for the conversion step, Stripe for payments, and an email provider for transactional mail. Your photos are not used to train AI models — we use a paid, enterprise AI API whose terms contractually prohibit training on submitted content.

    7. Incident response

    If we detect unauthorized access to personal information, we contain the issue, investigate scope, and notify affected users and any required regulators consistent with applicable US state breach notification laws. We keep an internal record of incidents and the remediation taken.

    8. Your controls

    You can delete individual coloring pages at any time from your dashboard, or request full account and data deletion at /delete-my-data. Daycares and schools should also review the Daycare / School Addendum and our printable parent consent form.

    9. Review

    This program is reviewed at least annually and after any significant change to the service, our vendors, or the data we handle. Material changes are reflected in the date at the top of this page.