Privacy
Privacy Policy
Last updated: June 30, 2026
This Privacy Policy describes how Swappr (the « Service », « we ») collects, uses, stores and protects your personal data under Regulation (EU) 2016/679 (GDPR). By using the Service, you acknowledge this policy. Cookie details are on the Cookie Information page.
1. Data controller
The data controller is the Publisher of the Service, operating under the trade name Swappr. Full registration details will be published when legally required. Personal data contact: [email protected] — General: [email protected].
2. Data collected
2.1 Account data
On signup we collect:
- Email address (via Clerk or Google OAuth)
- First and last name (if provided via Google OAuth)
- Unique user ID (generated by Clerk)
2.2 Payment data
- Shopify order identifiers (reference, amount, products) — no card numbers
- Crypto wallet address (linking and transaction verification)
- Blockchain transaction hash (USDC/USDT on Ethereum or Solana)
Card payment data is processed exclusively by Shopify and its payment providers. We do not access it.
2.3 Usage and billing data
- Credits consumed, engine types, generation and error history
- Instagram publishing history (Social Manager)
- Generation settings (model, quality, format)
- Public API keys, usage timestamps and quotas
- Affiliate history and referral cookie
2.4 Content and prompts
Prompts, reference images, audio and video files you submit are sent to third-party AI engines to fulfill your requests. Media saved to Library is stored in Supabase Storage (EU hosting). Unsaved outputs may be temporarily hosted by AI providers (~14 days). Swappr Help and AI Assistant exchanges are stored in the database (messages and conversation memory summary).
2.5 Biometric data (optional)
If you use identity verification (AWS Rekognition CompareFaces), face images are sent to AWS to compute a similarity score. This is biometric data processing under GDPR, enabled only by your explicit action.
2.6 Consents and compliance
- Platform terms acceptance (version, date, IP address, user-agent)
- NSFW mode consent (version, date, IP address)
- Uncensored assistant consent (version, date)
2.7 Security and anti-fraud
- IP address at signup and certain events
- Device fingerprint (browser, canvas, WebGL, FingerprintJS components)
- User-Agent
- Cloudflare Turnstile verification result
- Fraud signals, account links, strikes and ban decisions
2.8 Data NOT collected by certain modules
The local file preparation module processes files entirely in your browser: no files are sent to our servers during that processing.
3. Purposes and legal bases
- Contract performance (Art. 6.1.b): account, credits, generations, API, support
- Legal obligation (Art. 6.1.c): consent proof retention, billing records
- Legitimate interest (Art. 6.1.f): security, anti-fraud, product improvement, aggregated analytics
- Consent (Art. 6.1.a): analytics cookies (GA4, PostHog), PostHog session replay, marketing if enabled
We do not sell your data. We do not use it for third-party targeted advertising.
4. Processors and transfers
Main providers:
- Clerk — authentication — United States (SCC)
- Supabase — database and storage — European Union
- Shopify — card payments — Canada / international (SCC)
- Kie.ai — image/video generation, help bot — variable hosting
- ElevenLabs — voice synthesis and cloning — US / EU (SCC)
- Google (Gemini) — assistant, tools, help bot — US / EU (SCC)
- Anthropic / OpenAI — AI assistant — United States (SCC)
- Mammouth.ai — NSFW assistant — per provider
- AWS Rekognition — optional face comparison — per AWS region
- Meta / Instagram — publishing — US / EU (SCC)
- Cloudflare Turnstile — anti-bot — international
- Google Analytics 4 — audience measurement — United States (consent required)
- PostHog — product analytics, session replay — EU (consent required)
- Vercel — hosting, Speed Insights — US / EU
- Alchemy — blockchain verification — no direct personal data
- MoonPay — auxiliary crypto on-ramp — per provider
- Pexels — stock search — queries only
Transfers outside the EU are governed by EU Standard Contractual Clauses or equivalent safeguards where applicable.
5. Profiling and automated decisions
We use anti-fraud scores and signals (IP, device fingerprint, email, wallet) to detect multi-account abuse. This may result in bonus limits, additional verification or account suspension. You may contest a decision via [email protected].
6. Security
- Supabase Row Level Security (RLS) per user
- HTTPS (TLS) on all communications
- Clerk JWT tokens with expiration
- Storage buckets with RLS policies
- Security headers (HSTS, X-Frame-Options, etc.)
- Server-protected credit addition function
7. Retention
- Active account: data kept while account exists
- Temporary media: ~14 days at AI providers
- Payment history: 5 years (accounting obligation)
- Consents: account lifetime + legal retention
- Server logs: up to 30 days
- Help bot / assistant messages: account lifetime or deletion on request
On account deletion request (email to [email protected]), personal data and media are erased within 30 days, except legally required retention.
8. Your rights
You have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent (where processing is consent-based).
Exercise: [email protected] — response within 30 days. You may lodge a complaint with your supervisory authority (in France: CNIL, www.cnil.fr).
9. Cookies and trackers
We use strictly necessary cookies (session, security) and, with your consent, analytics trackers (GA4, PostHog, Vercel Speed Insights). Full details: Cookie Information. You can change your choice anytime via the « Cookies » link in the page footer.
10. Minors
The Service is for people 18 and over. We do not knowingly collect data from minors.
11. Changes
We may modify this policy. The update date appears at the top. For material changes, we may notify you by email or in-app notice.
12. Contact
- Personal data: [email protected]
- General: [email protected]
Swappr — AI Identity Studio — 2026