The honest version of how we keep your account and data safe — what we do, and what we don’t (yet).
Your password is stored as a one-way bcrypt hash — we can’t read it, and neither can anyone who might see the database. Sign-ins are rate-limited, magic links are single-use, and you can sign out of any device at any time. Everything runs over HTTPS, and we never see your card details — payments are handled entirely by Mollie.
When you set a password, we store it as a one-way bcrypt hash, never as plain text. That means we can’t see or recover your password — we can only check that the one you type matches. To keep accounts safe we also:
Use a unique password you don’t use anywhere else — or skip passwords entirely and sign in with a magic link, Google, or Apple.
You can sign in with a password, a one-time magic link by email, or your Google or Apple account. Each sign-in creates a session that’s tied to a fresh, random token stored on our server, so we can check it’s really you on every request.
From your security settings you can see where you’re signed in and sign out of any device — or all other devices at once. Sessions expire on their own, and signing out ends them immediately.
Snacknap is served over HTTPS, and we use HSTS so your browser always connects securely. Our servers run on our own hardware in a data center in the Netherlands, inside the EU.
If you support us with a paid option, the payment itself is handled entirely by our payment provider, Mollie. You enter your payment details on Mollie’s secure checkout — they never pass through Snacknap, and we never see or store your card or bank details. We only keep a record of the order (what, when, how much) so we can support you and meet our bookkeeping duties. More in Payments & Refunds.
We don’t offer two-factor authentication (2FA) yet. It’s on our list. Until then, a strong, unique password or a passwordless sign-in method is your best protection.
Found a security issue? Please tell us before sharing it publicly, and give us a reasonable chance to fix it. Email [email protected] (or [email protected]) with the details and how to reproduce it. We’re a small team, but we take these seriously and will get back to you.
If a data breach ever affects your personal data, we’ll act on it and notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and affected users where the law requires.