Privacy Policy
Last updated 11 August 2026
This policy covers the Super Snapshot AI Chrome extension and the report portal at portal.supersnapshotai.com. For everything else — the website, billing, support, and the rest of the AllThingsGHL suite — the AllThingsGHL family privacy policy applies.
The short version
The extension reads your GoHighLevel sub-account and builds a report from it. That reading happens in your browser, using the session you are already signed in with.
Two things leave your machine: a licence check every time you export, and — because Save to my online library is on by default — a copy of the report itself. Credentials are stripped from that copy before it is sent. You can turn the library off in the extension, and you can delete any saved report from the portal at any time.
What the extension reads
When you run an export, the extension reads your GoHighLevel sub-account's configuration through GoHighLevel's own interfaces, in your browser, using your existing login. That is the product: workflows, funnels, pipelines, forms, templates, tags, custom fields and the other asset types listed on the homepage.
It is read-only. It never creates, edits or deletes anything in your GoHighLevel account.
What leaves your machine
1. Licence validation and usage records
Your licence key is stored locally in the browser and sent to our server to check that it is valid. Each completed export also records the product, the extension version, the sub-account id, and your browser's user-agent string. This is how we tell a working licence from a cancelled one and spot a key being shared across unrelated agencies. Exports are not metered or capped.
2. Your report, if the library is on
Save to my online library is enabled by default. While it is on, a copy of the Dashboard report is uploaded to our servers so you can reopen it later from the portal without exporting the account again.
Before that copy is uploaded, the extension removes credentials from it:
- API keys, access tokens, refresh tokens, client secrets and private keys
- Webhook tokens, and secrets embedded in URLs or query strings
- Authorization headers, bearer tokens and cookies
If that removal cannot be completed for any reason, nothing is uploaded.
What is not removed: everything else in the report. A GoHighLevel sub-account routinely contains personal data — names, email addresses and phone numbers inside templates, forms, workflow steps and custom values — and that content is retained in the saved copy, because without it the report is not a report. If your account holds personal data you are not willing to store with us, turn the library off before exporting.
The files you download are not stripped. A backup without its credentials is a broken backup, so your local copies keep them. Look after them accordingly.
3. OpenAI, only if you ask for it
AI workflow analysis is off by default. If you enable it and supply your own OpenAI API key, workflow data is sent to OpenAI under your own account and their terms, and is passed through the same credential-stripping first. We never see your OpenAI key; it is stored locally.
Storage, retention and deletion
- Saved reports are stored against your licence key. Anyone holding that key can read them — treat it like a password.
- Each licence includes 25 MB of library storage. When it is full, new uploads are refused and the report downloads to your computer instead. Nothing is overwritten or evicted to make room.
- Nothing is ever deleted automatically. Reports stay until you delete them, or until the account is closed at your request.
- You can delete any individual report from the portal at any time. To have everything removed, including your licence records, email support.
Who else receives this data
We do not sell your data, and we do not use or transfer it for anything unrelated to running the product. Report storage and licence checks run on our infrastructure hosted with Supabase. OpenAI receives workflow data only when you have enabled AI analysis with your own key.
Your rights
You can access your saved reports at any time through the portal, delete them yourself, and request full erasure by contacting us. Depending on where you live you may also have rights to a copy of your data or to object to its processing; write to us and we will act on it.
Changes
If this policy changes in a way that affects what we store or who sees it, we will update the date at the top and describe the change in the release notes.
Contact
Questions about any of the above: contact AllThingsGHL support.