PRIVACY
What we store and where it goes
StorageSnap is operated by LeanAI Studio, a one-person studio. This page says what happens to data, in the order it happens. Last updated 11 August 2026.
Running a free snapshot
When you type a facility name into the tool, that text is sent to our server, which asks the Google Places API for the listing, for the storage facilities near it, and for the reviews Google publishes. Our server then fetches the facility's own public website once and reads four things off the page.
We do not ask for your email to do this and we do not store the snapshot against you. What we do store is the Google response itself, keyed by the Google place id and kept for thirty days, so that reloading a snapshot does not make us pay Google to fetch the same public listing again. That cache contains public listing data about a business. It contains nothing about you.
If you create a workspace
Signing in with your email address means we store, on our servers:
- your email address, so you can sign back in;
- the facilities you have saved and their snapshot history;
- a session record, so that signing out on one device actually revokes that session rather than just clearing a cookie;
- if you subscribe, your billing status. Stripe holds the payment details and we never see or store a card number.
Your workspace is private to your account. Every read and write is scoped to your user id in the code itself, not by a filter someone has to remember to add.
Everyone we send data to
- Google (Places API): the facility name you type, and the coordinates of the listing it resolves to, so we can ask for nearby facilities and reviews.
- The facility’s own website: a single HTTP GET from our server, identifying itself as StorageSnapBot. No login, no crawl, no form submission.
- Vercel: hosting, privacy-friendly page analytics, and the file storage holding any personalised video we made for you. Vercel Analytics does not use cookies and does not identify individuals.
- Google (Analytics): which pages were viewed on this site, and the ordinary things a page view carries: an approximate location from your IP, your browser and device, and the page you came from. Only after analytics is on for you. It sets its own cookies, and it is a different Google service from the Places API above.
- MongoDB Atlas: the database holding accounts, saved facilities and the Places cache.
- Stripe: checkout, subscriptions and the billing portal. Only reached when you start a subscription.
- Resend: sends the sign-in link. Only reached when you ask for one.
- Anthropic: drafts review responses for subscribers. It receives the facility name and the text of the review being answered, both of which are already public on Google.
We do not sell data, we run no advertising pixels, and we do not share your email with anyone other than the processors above.
Cookies
Three functional ones, always: a session cookie once you sign in, a short-lived entitlement cookie that records that your subscription is live, and a consent record when you answer the banner. Google Analytics then sets its own, once analytics is on for you and never before. There is no advertising cookie on this site.
Visitors in the EU and EEA are asked before any analytics tag loads, and nothing is collected until they answer. Visitors elsewhere have analytics granted on page load and see no banner. All three tags we could load sit behind whichever of those two answers applies to you: Google Analytics, Vercel's page analytics, and session analytics if it is ever switched on. So is the watch-depth count on a personalised video, described below, which is our own code rather than a tag and is gated by the same answer through the same check. The control below turns all of them off in this browser at any time.
If we sent you a personalised video
Some operators get a short narrated walkthrough of their own snapshot, at a link of the form /v/ followed by a random id. The voice is synthesised. The video is assembled automatically from the same snapshot data as the page it walks through, and nobody watched anything about you to make it.
The file is stored on Vercel at an unlisted public URL. That means it is not listed anywhere and the address is unguessable, but it is not password-protected either: anyone you forward the link to can watch it, and so could anyone who obtained the address some other way. We serve it from this domain rather than handing out the storage address, so the link you were sent is the only one that exists in the wild, and we can take the video down by deleting it.
While you watch, we count five things and only five: that the video started, that it passed a quarter, a half, three quarters, and that it finished. Those are tallies on the video. There is no cookie, no IP address, no device record and no per-viewing log, so we can tell you how far the video was watched and we cannot tell you who was watching. If you declined analytics, or you are in the EU or EEA and have not answered the banner, none of those five counts is sent at all.
Deleting everything
There is a button in your workspace labelled "delete my account and all my data". It is immediate, it is irreversible, and it needs no email to us. It removes your account, your saved facilities and their history, and your sessions.
It does not cancel a Stripe subscription, because that is your billing relationship rather than ours to end quietly. Cancel that from the billing page in the workspace, also one click.
Anything else, write to dario@leanaistudio.com, which reaches a person.
Data about businesses that are not you
A snapshot names nearby facilities and quotes reviews that Google publishes about the subject facility. All of it is public listing data, retrieved through Google's own API and displayed to the operator it concerns. We do not scrape Google Maps pages, we do not collect reviewer profiles, and the pre-built snapshot pages we send to operators are marked no-index so they do not surface in search next to that business's own listing.