1. Scope and accountability
This policy applies to LemonSnap’s website, accounts, resource downloads, support, quality reports, optional analytics, and paid services. LemonSnap is responsible for personal information under its control and uses the contact address below for privacy questions, access requests, corrections, withdrawals of consent, and complaints.
2. Who the service is for
LemonSnap accounts are intended for teachers, school staff, parents, guardians, and other adults. We do not ask students to create accounts, and the service is not directed to children under 13. Do not send us student names, contact details, health information, education records, or other identifiable student information in a search, report, or support message. If we learn that such information was submitted unnecessarily, we will take reasonable steps to delete or de-identify it.
3. Information we collect
- Account information: email address; a one-way password hash and salt; account role, plan, subscription status, verification and security records; legal-acceptance version and date.
- Usage and resource records: resources downloaded, saved, or recently viewed; export format; month and time; optional grade or subject preference; reports you submit about a resource.
- Free-download and security data: random browser identifiers, necessary cookies, approximate request information, and cryptographic hashes derived from an IP address. LemonSnap does not store the raw IP address in its application database, although hosting and security providers may process it in their operational logs.
- Optional analytics: if you choose “Allow analytics,” page paths, searches, resource views and clicks, referring website host, campaign source, a random first-party identifier, and, when signed in, account ID.
- Billing data: Stripe customer and subscription identifiers, plan and status, and billing period dates. Card numbers and full payment credentials are handled by Stripe and are not stored by LemonSnap.
- Communications: the email address, message, and related context you provide when contacting us or reporting a problem.
4. Why we use information
We use information to verify and secure accounts; deliver previews and downloads; apply free and paid access limits; remember an optional browsing preference; maintain download and saved-resource history; process subscriptions; respond to support and quality reports; prevent fraud, scraping, credential abuse, and attacks; measure catalog use when permission is given; correct and improve resources; comply with law; and establish, exercise, or defend legal rights.
We do not sell or rent personal information. We do not use third-party advertising cookies, build advertising profiles, or use student data for advertising.
5. Consent and choices
Essential cookies and processing are used when reasonably necessary to provide a requested feature, secure the service, or meet legal obligations. Optional analytics remain off until you actively choose “Allow analytics.” Choosing “Use essentials only” is just as easy and does not restrict browsing, previews, downloads, account creation, or subscriptions. Use “Privacy choices” in the footer to change your selection at any time. Withdrawing consent does not affect processing that occurred lawfully before withdrawal or information that must be retained for legal or security reasons.
6. Cookies
- Session cookie: keeps a signed-in account authenticated and is HttpOnly.
- Free-download cookie: remembers the anonymous monthly allowance and is HttpOnly.
- Analytics choice cookie: stores “allow” or “decline” for up to 180 days.
- Optional analytics identifier: created only after analytics permission and used to distinguish visits without using a name.
- Owner exclusion cookie: prevents the site owner’s activity from entering product analytics.
Browser settings can remove cookies. Removing essential cookies may sign you out or reset local functionality; attempting to remove them to evade access controls violates the Terms.
7. Service providers and disclosure
We disclose only the information reasonably needed for a provider to perform its role. Current provider categories include Cloudflare for hosting, network delivery, database infrastructure, and security; Resend for account-verification email; and Stripe for checkout, payments, subscriptions, invoices, and billing support. Providers may process information outside your province or Canada, where it may be subject to local law.
We may also disclose information when required by law, to respond to valid legal process, to protect safety or rights, to investigate abuse, or as part of a business transaction subject to appropriate confidentiality and continued lawful handling. We do not disclose personal information to a school or employer merely because an email domain matches, unless the plan or agreement expressly provides organization administration.
8. Retention
We keep information only as long as reasonably needed for the purposes described here. Verification codes expire after 10 minutes and are periodically deleted. Sessions expire after 30 days and may end sooner. Optional analytics and routine usage records are generally retained for up to 24 months, then deleted or aggregated. Quality reports are generally retained while open and for up to 24 months after resolution. Account, download, subscription, transaction, consent, fraud-prevention, and dispute records may be retained while the account is active and afterward for the period reasonably needed for legal, tax, accounting, security, or enforcement obligations. Backups may persist for a limited rotation period.
9. Safeguards and breaches
Safeguards include encrypted HTTPS transport in production, one-way password hashing with unique salts, HttpOnly and SameSite cookies for sensitive tokens, session expiry, sign-in lockout, rate limits, cross-site request checks, request-size limits, security headers, restricted administrative routes, payment separation through Stripe, and access controls around the production database. No online system is risk-free. If a breach creates a real risk of significant harm, LemonSnap will investigate, keep required records, notify affected people, and report to regulators as required by applicable law.
10. Access, correction, deletion, and complaints
You may request access to personal information LemonSnap holds about you, ask for correction, request account deletion, withdraw optional consent, or ask how a decision was made. We may need to verify your identity. Access may be limited where law requires or permits, including where disclosure would reveal another person’s information or protected confidential information. We will explain a refusal where required. You may also complain to the Office of the Privacy Commissioner of Canada or another regulator with jurisdiction.
11. Changes
We will update the effective date when this policy changes. We will provide prominent notice and seek new consent where a material change introduces a new purpose, new disclosure, or materially different risk that requires consent.
12. Contact
Email privacy requests to Lemon.snap.info@gmail.com with the subject “Privacy request.” Please do not include passwords, payment-card details, or student personal information.