Privacy Policy
Last updated 11 September 2026
This Privacy Policy explains how SKOTY (“swity”, “we”, “us”) collects and uses personal data when you use the swity app and the pages we host at swity.app. We are the data controller for that processing.
1. Who we are
- App author: SKOTY Tomasz Szykulski
- Aleje Jerozolimskie 109 lok. 70, 02-011 Warsaw, Poland
- NIP 5223382461 · REGON 545562954
- Privacy contact: privacy@swity.app
2. What we collect
- Account data: when you create an account with an email address we collect the name and email address you give us, and a password, which we store only as a hash and never in readable form. When you sign in with Apple instead we receive your name and email address (Apple may provide a private relay address). You choose a public handle, and we derive an approximate country from your device or App Store region. You may add optional profile details (role, location, bio, links, avatar).
- Your email preferences: which kinds of email you have switched off, the language you use the app in, and — if you gave it — the moment you agreed to hear about what is new. Withdrawing that agreement removes the record of it.
- Interest list: if you leave your email address on our website to hear when swity opens up, we keep that address for that purpose only. It is deleted once we have written to you about access, or sooner if you ask.
- Content you publish: the photos, text and project details you upload. Published pages are public and can be viewed by anyone with the link.
- Usage & analytics: scans and views of your pages, coarse country derived from IP (not stored as a full IP), a rotating non-identifying visitor hash used only to de-duplicate counts, and basic technical logs.
- How the app is used: a small, fixed set of signals from the app itself, such as how far you got in first-time setup, when the plans screen was opened and which screen led there, and when publishing failed (with a short reason such as “network”, never your content or file names). We use these to fix what is confusing or broken. They are tied to your account, kept for six months, never shared, and are not used to build a profile of you or to follow you anywhere else.
- Website analytics: for the pages we run ourselves, we count visits using Vercel Web Analytics: which page was opened, where the visit came from, an approximate country, and the type of device. It is measured at our host’s edge and is cookieless – no cookie, no data stored on your device, and no identifier that could follow you to another website. We cannot tell who you are from it.
- Safety & moderation data: reports you submit or that concern your content, and the outcome of any review.
- Subscription status: which plan you are on, when it renews or lapses, and an identifier that ties a purchase to your account. Apple is the seller for anything bought inside the app, so it takes the payment and we never receive or store card numbers.
- Notification tokens: if you turn on notifications, the token Apple issues so we can send them to your device. It identifies the install, not you, and it stops working when you turn notifications off.
- Audio: if you add a voice note or an audio clip to a page, the recording itself, exactly as with a photograph.
- Crash and diagnostic data: when the app fails, what it was doing and where. We use it to fix the fault and nothing else.
- Support messages: what you write to us, and the bug reports you send from inside the app, including the diagnostic detail attached to them.
3. Why we use it, and our legal basis
- To provide the service and your account: performance of a contract (Art. 6(1)(b) GDPR).
- To keep the service secure, measure usage, and moderate content: our legitimate interests (Art. 6(1)(f)).
- To handle illegal content and respond to lawful requests: legal obligation (Art. 6(1)(c)).
- For anything optional we ask you to opt into: your consent (Art. 6(1)(a)), which you can withdraw at any time.
4. Who we share it with
We do not sell your data. We use service providers (processors) who process data on our behalf under contract:
- Supabase: Database, accounts and sign-in (EU).
- Cloudflare: Photo and audio storage, and CSAM scanning (EU / global edge).
- Vercel: Hosting for swity.app, and cookieless website analytics (EU / global edge).
- Anthropic: Automated safety review of uploads before publishing (United States).
- Resend: Sending account and service emails (United States).
- RevenueCat: Keeping track of subscriptions bought through the App Store (United States).
- Apple: sign-in, at your choice, and payment for anything bought inside the app.
Automated review. Before anything is published we send the photos and text to Anthropic’s Claude to check them against our guidelines. This is automated, and it can hide a project pending a human check. You can ask a person to review that decision from inside the app. Anthropic keeps a copy for up to 30 days and may access it for safety and security purposes.
Your published pages are public by design. Some providers operate outside the EEA; where they do, transfers rely on an adequacy decision or the EU Standard Contractual Clauses.
5. How long we keep it
- Account and content data: for as long as your account is active.
- When you delete a project or your account, we delete the associated data; residual copies may persist briefly in encrypted backups before rotating out.
- Where the law requires it (for example, evidence of illegal content, or accounting records), we retain the minimum necessary for the required period.
6. Your rights
Under the GDPR you can request access to, correction, deletion, restriction or portability of your data, and object to certain processing. You can delete your account in the app at any time. To exercise a right, contact privacy@swity.app. You may also lodge a complaint with the President of the Personal Data Protection Office (UODO), Poland.
7. Children
swity is not intended for anyone under 16. We do not knowingly collect data from children under that age.
8. Security
We use encryption in transit, access controls and reputable infrastructure providers. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.
9. Cookies
swity does not use cookies for advertising or tracking, and we do not share anything with ad networks. Our website sets no cookies at all, and our analytics are cookieless, which is why you are not asked to accept anything. The only thing stored on your device is the sign-in session inside the app.
10. Changes
We may update this policy; we will change the “last updated” date above and, for material changes, tell you in the app.
11. Contact
Questions about this policy or your data: privacy@swity.app.