1. Who We Are
Snap Entry is operated by Onishi Studios. This policy explains how we collect, use, and protect your data when you install Snap Entry from the Ring Appstore and connect your Ring account.
2. Data We Collect
- Ring account identifier — A unique ID issued by Ring, used as your identity within Snap Entry. Each user’s data is isolated from every other user’s.
- Email address — Retrieved from your Ring profile at sign-in and used for billing-related emails. Not shared with third parties for advertising.
- OAuth tokens — Access and refresh tokens used to retrieve device data on your behalf. Stored in our database; refreshed automatically.
- Device metadata — Names, types, and status of your Ring devices, fetched from the Ring Partner API.
- Webhook events — Door sensor and related event notifications forwarded by Ring, persisted as a per-user activity log.
- Snapshot images — When a door sensor triggers, Snap Entry requests a still image from the associated Ring camera via the Ring Partner API. That image is stored in Cloudflare R2 (see Section 4 for data processors) and linked to the corresponding door event record. No video or audio streams are stored.
- Sensor ↔ camera pairings — Mappings you create in the dashboard linking a contact sensor to its companion camera.
- Subscription & billing records — Whether your account is on the Free or Premium tier, your Stripe customer ID, and your current subscription period. Payment card details are handled exclusively by Stripe and are never stored on our servers.
- Session cookies — A signed session cookie (httpOnly, secure, sameSite: lax, 30-day rolling expiry) is set after sign-in. Used solely to identify your dashboard requests; not used for tracking.
3. How We Use Your Data
- To display your Ring device activity to you in the Snap Entry dashboard. Other users never see your data, and you never see theirs.
- To proxy your authorized requests to the Ring Partner API.
- To process and manage your Premium subscription through Stripe.
- We do not sell, rent, or share your data with third parties for advertising.
- We do not use Ring data to train AI or machine learning models.
- We do not perform facial recognition or license-plate recognition.
- We do not store or retransmit Ring video or audio streams.
4. Data Processors & Sub-processors
We rely on the following third-party services to operate Snap Entry. Each acts as a data processor under our instructions:
- Cloudflare R2 — Object storage for snapshot images. Images are stored in a private bucket and only accessible via short-lived signed URLs generated at request time.
- Stripe — Payment processing for Premium subscriptions. Stripe receives your email address and processes payment details directly. We store only your Stripe customer ID and subscription status. Stripe’s privacy policy is available at stripe.com/privacy.
5. Data Retention & Deletion
Free accounts: Door event records (including snapshot images) are retained for 30 days and then automatically deleted by a daily sweep.
Premium accounts: Door event records and snapshot images are retained for the duration of your active subscription. Once your subscription ends (cancelled or lapsed), the 30-day retention window resumes and events older than 30 days are swept on the next daily run.
If you unlink Snap Entry from your Ring account (via the Ring app or the Ring Appstore), your access tokens are deleted immediately, your dashboard is signed out, and your remaining data (sensor pairings, event history, snapshots) is held in a 30-day grace period so you can re-install without losing your setup. After 30 days, all of your data is hard-deleted automatically.
You can also delete your account immediately at any time using the Delete my account button in the dashboard footer. This disconnects the integration on Ring’s side, removes all your data (including all stored snapshots) from our systems, and signs you out — no waiting period.
6. Security
All traffic is transmitted over HTTPS. Session cookies are signed and httpOnly. Snapshot images are stored in a private Cloudflare R2 bucket and only served via short-lived presigned URLs. Each user’s data is isolated by their account ID; every database query and Ring API call is scoped to the requesting user’s session. Access to production infrastructure is restricted to authorized personnel. Onishi Studios personnel may access your data only when necessary to investigate a reported issue, respond to a data access request, or maintain service security. Such access is limited to the minimum data required and is logged.
7. Your Rights (DSAR)
You may request access to, correction of, or deletion of your personal data at any time. The fastest paths:
- Delete: use the Delete my account button in the dashboard footer for immediate deletion of all data including snapshots.
- Access or correction: email dev@onishistudios.com with your request. We will respond within 30 days.
- Already unlinked: if you have already removed the Snap Entry integration from Ring and need expedited deletion before the 30-day automatic sweep, email us with the Ring account email address used at install.
8. Changes to This Policy
We may update this policy. Material changes will be communicated via in-app notice. Continued use after changes constitutes acceptance.