Privacy Policy
Last updated 3 October 2026
This policy explains what personal data Swipework collects, why we collect it, who processes it and what choices you have. Swipework is run by Md Shafiur Rahman, a sole proprietor in Bangladesh, who is responsible for your data (“we”, “us”). If you have questions, email shorol2k14@gmail.com.
In short
- We collect what we need to run your account, make your carousels and bill you.
- We don't sell your data, show ads or use advertising or analytics cookies.
- Your briefs go to AI providers only to generate your results. We don't use them to train AI.
- You can delete your account, and the data in it, at any time.
1. What we collect
- Account: your email address and your password. The password is stored only as a secure hash by our sign-in provider. If you use Google sign-in, we also get your name, email and profile picture from Google. We also store your profile settings: display name, avatar, country, app and content languages, and whether you want product emails.
- Your content: briefs, brand kits (name, handle, colours, logo and description), carousels (customer analysis, hooks, slides, captions and design choices), images you upload and images we generate for you.
- Credits and usage: your credit balance and its history. We also keep a record of each AI generation: the type of job, the model used, token counts, cost, credits charged, time taken and whether it worked. These records don't include your content.
- Purchases: when Paddle processes a purchase, it tells us your plan, its status, its renewal date and a reference for the payment. Paddle collects your payment details, and we never receive your full card number.
- Technical data: our hosting providers log IP addresses, browser details and request times so they can run and secure the service. When our security check is switched on, Cloudflare Turnstile checks that sign-ups come from a person.
- Browser storage: Swipework keeps your sign-in session in your browser's local storage. We don't use advertising or analytics cookies.
2. How we use it
| Purpose | Legal basis (where the law asks for one) |
|---|---|
| Run your account, save your work, generate content and create exports | Performing our contract with you |
| Track credits, apply plan limits, and handle purchases and refunds | Contract, and legal duties to keep records |
| Prevent fraud and abuse, and enforce rate limits | Our legitimate interest in keeping Swipework safe |
| Answer your messages and support requests | Contract, and our legitimate interests |
| Send sign-in links and messages about your account | Contract |
| Send product news, only if you opt in | Your consent, which you can withdraw at any time |
| Set prices and improve Swipework using overall usage and cost figures, not your content | Our legitimate interests |
3. How AI processes your content
When you run an AI action, we send what that job needs to OpenRouter, an AI gateway. That might be your brief, brand details, the analysis and slides you're working on, or, for an image, the slide's visual idea. OpenRouter passes it to the model provider: Anthropic (Claude) for text and Google (Gemini) for images. They process it to return your result. We set our text requests to use only providers that don't collect prompt data, and we never use your content to train AI models.
Please don't put sensitive personal data, such as health details, ID numbers or financial account details, into your briefs.
4. Who processes your data
We use these service providers to run Swipework. Each one gets only what it needs for its job.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, sign-in and file storage | South Korea (Seoul) |
| Vercel | Hosts the website | United States and a global network |
| OpenRouter | Routes AI requests to model providers | United States |
| Anthropic | Writes analyses, slides and captions | United States |
| Generates images (Gemini), runs Google sign-in if you use it, and serves web fonts | Global | |
| Paddle | Our Merchant of Record: checkout, payment, tax, invoices and refunds | United Kingdom and United States |
| Cloudflare | Security check (Turnstile) and delivery of code libraries (cdnjs) | Global |
| jsDelivr | Delivers code libraries | Global |
Paddle is responsible for the payment data it collects. Its privacy policy explains how it handles that data.
We don't sell personal data. We share data in only three other cases: when the law requires it, when it's needed to protect someone's rights or safety, and with a buyer if Swipework is ever sold. We'd tell you before a sale.
5. International transfers
Your data is stored in South Korea. It's also processed in the United States and in the other countries where our providers operate. Where data protection law requires it, we rely on the safeguards our providers offer, such as standard contractual clauses.
6. How long we keep it
- We keep your account and content until you delete them or your account.
- Deleting your account immediately removes your account, profile, carousels, brand kits, uploaded and generated images, and credits. We keep the records of AI generations for cost accounting, with the link to you removed. Database backups may hold copies for a limited time until they expire.
- Paddle keeps its transaction records for as long as tax law requires.
- Hosting providers keep server logs for short periods.
7. Your rights
Depending on where you live, including the EU and UK, you may have the right to:
- access a copy of your data;
- correct it;
- delete it;
- export it;
- object to or restrict how we use it;
- withdraw your consent.
You can do most of this yourself in Swipework. You can edit your profile, delete carousels and brand kits, or delete your account. For anything else, email us. We'll reply within 30 days, and we may need to confirm your identity first. You can also complain to your local data protection authority.
8. Children
Swipework is for people aged 18 and over. We don't knowingly collect data from children. If you think a child has given us data, email us and we'll delete it.
9. Security
We protect your data in four ways:
- Every connection uses HTTPS.
- Row-level security lets each account read only its own data.
- Files sit in private storage behind short-lived links.
- All AI and payment keys stay on our servers.
No system is perfectly secure. If a breach affects your data, we'll tell you as the law requires.
10. Changes to this policy
When we update this policy, we'll post the new version here and change the date at the top. We'll email you about significant changes.
11. Contact
Md Shafiur Rahman, trading as Swipework, Bangladesh. Email shorol2k14@gmail.com.