Your AI buddy. Your rules.
Snappy is built to be powerful and private. Here's what we do to protect you - and how you can get the most out of it while keeping your data safe. No jargon, just the facts.
What we do to protect you
These aren't promises - they're deployed, running systems.
Isolated container per customer
Every Snappy runs in its own dedicated container - completely isolated from all other customers. Your conversations, memory, connected tools, and data never share resources with anyone else. It's your instance, period.
13-hook guardrails plugin
Every message in and out of your Snappy passes through 13 security hooks: a risk gate that blocks dangerous tool calls, injection detection that catches prompt manipulation attempts, crisis detection that surfaces emergency resources, rate limiting that prevents abuse, a token budget that prevents runaway costs, an outbound content filter that automatically redacts Social Security numbers, credit card numbers, and passport numbers before any message is sent, professional disclaimers on legal, medical, and financial content, and a compliance audit trail on every interaction.
Crisis detection and support
If your agent detects language suggesting self-harm or harm to others, it immediately prepends crisis resources - including the 988 Suicide & Crisis Lifeline and Crisis Text Line - to its response. The SnappyClaw team is also notified immediately so we can check on you. Your agent is not a substitute for professional help, but it will never ignore a cry for help.
Automatic professional disclaimers
When your agent's response touches on legal, medical, or financial topics, a disclaimer is automatically appended reminding you that this is AI-generated information, not professional advice. This happens in code - your agent can't skip it, and you'll always know when to seek a qualified professional.
Your agent asks before acting
Your agent is built to confirm before taking actions that can't be undone - sending emails, posting to social media, modifying external systems, or anything that leaves your workspace. Internal work like research, drafting, organizing files, and searching the web happens freely. External actions that affect other people get a confirmation first.
Tamper-proof security settings
Your agent can't disable its own safety controls - even if someone asks it to. An independent watchdog process monitors security settings and restores them instantly if anything is changed. The guardrails work in code, not in prompts, so they can't be talked around or social-engineered.
Abuse protection
Built-in rate limiting prevents anyone from overwhelming your agent - no more than 10 messages per minute or 100 per hour from any sender. This protects against spam, bot-to-bot loops, and denial-of-service attempts. Your agent stays responsive for you, not for bad actors.
Complete audit trail
Every conversation, every tool call, every action - logged and auditable. Your agent pushes health checks and compliance data to our monitoring systems every few minutes. If your agent ever does something unexpected, you have a complete, tamper-evident record of exactly what happened and why.
Encrypted secrets management
Your LLM API key, connected tool tokens, and channel credentials are stored as encrypted secrets - not in environment variables, not in config files. They're injected at runtime only and can be rotated without restarting your agent. Even if someone gained access to the container filesystem, your credentials aren't there.
BYOLLM - your AI provider, your rules
SnappyClaw uses a Bring Your Own LLM model. Your conversations go directly from your container to your chosen AI provider using your own API key. We never see, log, or store your AI traffic. Important: your AI provider's privacy policy governs how they handle your data - we recommend reviewing it. We have no control over third-party providers.
Built-in usage limits
Every plan includes daily and monthly usage caps that prevent unexpected costs. Your agent tracks its own token spend in real time and pauses gracefully when limits are reached - no surprise bills, no runaway API charges. Upgrade anytime if you need more capacity.
Utah AI Act compliance - built in
SnappyClaw is designed to meet Utah's AI compliance requirements: conversation audit trails, active guardrails, AI disclosure on every interaction, TOS acceptance with age verification, and clear accountability for automated actions. We're not checking boxes - these are the same protections we'd want for ourselves.
What you can do to stay safe
Simple, practical habits that make your Snappy even more secure.
Your Snappy is YOUR Snappy
Every Snappy runs in its own isolated environment. Your conversations, your connected apps, your data - none of it is shared with other users. Ever. Think of Snappy like your personal phone - you wouldn't hand it to a stranger.
💡 Best practices
- Don't share your SnappyClaw login with anyone
- Don't let someone else message Snappy from your account
- If you think someone accessed your account, change your password immediately
One channel, one you, one Snappy
Snappy is designed for 1-on-1 conversations with you. Whether you're on Telegram, SMS, or web chat - it's always a private conversation between you and your assistant. That's not a limitation, it's the point.
💡 Best practices
- Don't add Snappy to group chats with other people
- If you use multiple channels, Snappy remembers context across all of them
- Your conversation on Telegram is just as private as your conversation on the web
What Snappy knows stays with Snappy
Snappy remembers things to be more helpful - your preferences, your schedule, your work context. That memory is encrypted, isolated, and never used to train AI models. We never read your conversations. Period.
💡 Best practices
- Snappy's memory makes it better over time - that's a feature, not a risk
- You can ask Snappy to forget something specific anytime
- When you delete your account, all memory is permanently erased
Connected tools = connected trust
When you connect Gmail, Google Calendar, or other tools to Snappy, you're giving it permission to act on your behalf. That's powerful - and it means you should treat those connections like giving someone a key to your house.
💡 Best practices
- Only connect tools you actually want Snappy to use
- Review your connected integrations regularly in your dashboard
- You can disconnect any tool instantly - Snappy loses access immediately
- Snappy will never connect to a service without your explicit permission
Smart sharing
Snappy is incredibly helpful with personal and business tasks. But like any assistant, use common sense about what you share. Snappy doesn't need your social security number to schedule a meeting.
💡 Best practices
- Share what's useful - your schedule, preferences, work context, goals
- Avoid sharing passwords, SSNs, credit card numbers, or government IDs
- If Snappy needs to handle payments, it goes through Stripe - never share card details in chat
- Business data is fine - Snappy is great with reports, emails, and research
You're always in control
You can pause, disconnect, or delete at any time. No hoops, no retention tricks, no guilt trips. Your data, your call.
💡 Best practices
- Pause Snappy anytime - it'll be right where you left off when you come back
- Disconnect individual tools without affecting your account
- Delete your account and all data with one request - we wipe everything within 30 days
- Export your data anytime from your dashboard
The quick version
Simple do's and don'ts for getting the best out of Snappy.
Do this
- ✓Tell Snappy your preferences so it gets better over time
- ✓Use it for email, calendar, research, social media, and business tasks
- ✓Connect tools you use daily for maximum productivity
- ✓Ask Snappy to remind you, follow up, and stay on top of things
- ✓Treat it like a trusted assistant - the more context, the better it helps
Avoid this
- ✗Share your login credentials with others
- ✗Paste passwords, SSNs, or credit card numbers in chat
- ✗Add Snappy to group chats with other people
- ✗Rely on Snappy for medical, legal, or financial advice without verification
- ✗Ignore connected tool permissions - review them periodically
Built from experience
These aren't just guidelines we wrote in a conference room. We use SnappyClaw every day to run our own business - email, calendar, social media, research, the works. Every best practice on this page comes from real experience. We built Snappy to be the assistant we wanted, and we hold it to the same standard we expect for ourselves.
Ready to meet Snappy?
Private, powerful, and built for people who actually get stuff done.