Legal

Privacy Policy

Last updated 7 September 2026. MySwipe is operated by [registered legal entity], [registered postal address].

The short version

MySwipe stores the posts you save and everything it can read out of them, because reading them is the entire product. To do that it sends your saved content to a handful of named third parties, listed below. It does not sell your data, does not show you ads, carries no advertising SDK, and we do not use your saved content to train models.

What we collect

Your account

  • Your email address, and your name if you give one.
  • If you use Sign in with Apple or Sign in with Google, whatever that provider releases to us — normally an email address and a name. If you use a password, we store a hash of it, never the password.
  • Session records, your timezone, and which plan you are on.

Your devices

  • Platform, a push notification token, and when the device was last seen.
  • We do not ask for your location. The coordinates in the app come from place names found in what you saved, not from your phone.

What you save

  • The link exactly as you shared it, and the canonical link we resolve it to.
  • Any image or screenshot you share, and any note you type.
  • When you saved it.

What we fetch on your behalf

When you save a link, MySwipe fetches the post and keeps what it finds. That is the point of the app, and it is the largest category of data we hold about you:

  • The caption or post body, and for an article, the extracted article text.
  • The video transcript, with timings, where the source platform provides one.
  • Text read out of images and video frames by OCR.
  • The thumbnail and any shared images, copied to our own storage so they survive the original expiring.
  • The author name, the posting date, the language and the duration.
  • The raw response from the fetching service, kept so a save can be reprocessed without buying the fetch again.
  • If a saved web page has no cover image, a screenshot of that page taken by a headless browser.

What we derive from it

  • A title, a summary, a content type, tags.
  • Entities: places, tools, people, products and brands mentioned.
  • Coordinates and address details for the places, and the trips they group into.
  • Auto-generated collections, and their names.
  • Numeric embeddings and a keyword index built from all of the above, which is what makes search work.

Operating records

  • A per-item processing log: which stage ran, how long it took, whether it failed, and what the AI call cost.
  • Counters used to enforce rate limits and plan quotas, including a short-lived record of each save you queue and rate-limit rows keyed on IP address and request path.
  • Monthly totals of saves and AI spend.
  • Diagnostic error reports and traces. These carry stack traces, request paths and your account id; they do not carry saved content.

Payment

If you subscribe, we store a Stripe customer id, a subscription id, its status and its renewal date. Card details go to Stripe directly and never reach our servers.

Who else sees it

MySwipe cannot read a post without sending it somewhere. Every service that can see your content, and exactly what it gets:

ServiceWhat it doesWhat it receives
ScrapeCreatorsReads the post you shared and returns its caption, body, media and transcript.The URL you shared. Not your email or account id.
AnthropicGenerates the title, summary, tags, content type and entities; reads on-screen text out of images; names auto-collections; answers "ask my saves".The saved text, transcript and images, and your question when you ask one.
Voyage AITurns saved text and your search queries into the vectors that make search work.The saved text and your search queries.
OpenCageTurns a place name found in a save into coordinates for the map.The place name only — never the surrounding post.
CloudflareObject storage (R2) for thumbnails, shared images and raw provider responses; screenshots a saved web page when it has no cover image; DNS and proxy for this site and the API.Saved media and raw fetch responses, the URL of a page being screenshotted, and request metadata.
NeonHosts the PostgreSQL database.Everything in your account.
HetznerHosts the API and the background workers.Everything in your account passes through, in memory and in transit.
Expo (Expo Application Services)Delivers push notifications and over-the-air app updates.A push token, the notification text — which contains the AI title of the item — and device/app version metadata.
MapboxDraws the map in the Places tab.The map areas your device requests, plus Mapbox SDK telemetry.
Apple, GoogleSign in with Apple and Sign in with Google, if you use them.Your email address and name as released to us by the provider.
StripeTakes payment for a paid plan.Your email and billing details. Card numbers go to Stripe directly and never reach our servers.
SentryError and performance diagnostics.Stack traces, request paths and your account id. Not saved content.

Saving a link also causes an ordinary web request to the site or platform you saved from, made either by us or by the fetching service above. That site sees the request the same way it would see any visit.

We do not sell personal data and we do not share it for advertising. We may disclose data where the law requires it, or to a successor if the business is transferred.

How long we keep it

  • Saves are kept until you delete them. Deleting a save hides it immediately and a scheduled purge removes it and its stored media permanently.
  • Files staged during an upload that never completes are deleted automatically after seven days.
  • Rate-limit and quota records are pruned continuously and are never long-lived.
  • Deleting your account deletes your account record, your saves, and everything stored under your prefix in object storage. Database backups age out on their own within [backup retention window].

Your choices

  • Export. You can export everything in your account as JSON and CSV from Settings.
  • Delete. You can delete a save, or your whole account, from Settings. Both are permanent.
  • Access and correction. Email privacy@myswipe.app and we will answer.
  • Push notifications. Turn them off in iOS settings; nothing else stops working.

Security

Traffic is encrypted in transit. Passwords are hashed. Session tokens are held in the iOS Keychain. Every stored file is filed under the account that owns it, so account deletion is a deletion of that account’s prefixes rather than a search. No system is perfectly secure, and we do not claim otherwise.

Children

MySwipe is not intended for anyone under 13, and we do not knowingly collect their data.

International transfers

The services listed above operate in the United States and the European Union, so your data is processed in both.

Changes

If this policy changes materially we will say so in the app before the change takes effect. The date at the top always reflects the current version.

Contact

privacy@myswipe.app, or [registered legal entity], [registered postal address]. This policy is governed by the law of [country of governing law].