SwipePhotos logoSwipePhotos
작동 방식무료 도구리뷰요금제제휴 프로그램
앱 받기
← Back to SwipePhotos

Privacy Policy. In plain English.

Last updated · July 21, 2026

The short version: the SwipePhotos iPhone and Mac apps never upload your photos anywhere. Everything the app sees — thumbnails, burst detection, your keep/delete decisions — stays on your device. This page tells you what the website at swipephotos.com does with its visitors, and how the apps talk to Apple.

1. Controller (Art. 13(1)(a) GDPR)

Dr. Jan Philip Wahle
Siedlungsweg 24, 37124 Rosdorf, Germany
Email: [email protected]

A Data Protection Officer is not required under Art. 37 GDPR and Section 38 BDSG. Questions are routed to the contact email above.

2. Overview of data processing

Processing of personal data is limited to what is needed to run the website, provide the app, and respond to you when you write in. We do not sell data. For each activity below we name the purpose, the legal basis, and how long data is kept.

3. The SwipePhotos iOS and Mac apps

Photos never leave your device. The apps use Apple's PhotoKit framework to read the library you grant access to. Burst detection and similarity grouping run with on-device machine learning. Keep and delete decisions are written back to the Apple Photos library, so deletions follow Apple's usual “Recently Deleted” recovery window.

What the app never does: upload your photos, send image pixels to our servers, or share anything with advertisers. We literally could not look at your photos if we wanted to — we have no server that receives them.

Crash and diagnostic data: if you opt in to share diagnostics with app developers in your iOS or macOS privacy settings, Apple may forward anonymised crash reports to us through App Store Connect. We use these only to fix bugs. You can opt out at any time in Settings → Privacy & Security → Analytics & Improvements.

Purchases and subscriptions: billing is handled by Apple through the App Store. RevenueCat processes a random app user ID, product, subscription status, transaction identifiers, country, price, estimated tax, and Apple commission so the app can restore access, measure revenue, and calculate affiliate commission. We do not receive your card details, Apple ID, name, address, or photo content. See Apple's privacy policy for details.

Product analytics and attribution: Firebase Analytics, PostHog, and AppsFlyer process a random install ID, device and app information, campaign and deep-link values, and events such as onboarding completion, paywall views, and purchases. When you arrive through an approved creator link, a partner code and random click ID are carried through AppsFlyer and attached to the RevenueCat customer before purchase. This lets us credit the creator on later subscription renewals without identifying you to the creator. Photo pixels, filenames, and photo metadata are never included in analytics or attribution events.

Referral backend: Supabase stores the random app user ID, affiliate attribution, and commission ledger. It does not store the referred customer’s name, email, Apple ID, or payment details. The legal bases are contract performance for purchase access (Art. 6(1)(b) GDPR) and our legitimate interests in product improvement, fraud prevention, accurate partner accounting, and measuring acquisition (Art. 6(1)(f) GDPR). Store and accounting records are retained for the applicable statutory period. IP, browser, and referrer metadata on affiliate clicks is anonymised after 24 months unless needed for a dispute; the random click ID may remain attached to accounting records.

Legal basis: Art. 6(1)(b) GDPR (performance of the app contract) for running the app; Art. 6(1)(f) GDPR (legitimate interest in fixing crashes) for diagnostics.

4. Hosting and server log files

This website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). Every request to the site produces a temporary log entry containing:

  • IP address (truncated)
  • Request date and time
  • URL requested and HTTP method
  • HTTP status code and response size
  • Browser type, version, and operating system
  • Referrer URL (if your browser sends one)

Purpose: keeping the site online, preventing abuse, and investigating bugs. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure service). Retention: log entries are deleted after 14 days unless we need them to investigate a security incident. Vercel acts as our processor under Art. 28 GDPR.

5. Cookies and local storage

We use first-party entries for consent, locale, dismissed interface preferences, affiliate attribution, and restricted partner sessions.cookie-consent records whether you accepted or rejected optional analytics and attribution storage and is strictly necessary to honour that choice under Section 25(2) No. 2 TDDDG.

Analytics cookies and the 60-day sp_aff affiliate cookie are only set after you click “Accept all”. Full details, including how to clear stored choices, are in our Cookie Policy.

6. Analytics (optional, consent-based)

If you opt in, we load Google Analytics 4, provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics collects:

  • Pages you visit and actions you take
  • Approximate location (derived from a truncated IP)
  • Device, browser, and operating system
  • Referrer URL and session duration

We have IP anonymisation enabled and a data-processing agreement in place under Art. 28 GDPR. Data retention in Google Analytics is set to 14 months.

Legal basis: Section 25(1) TDDDG and Art. 6(1)(a) GDPR (your consent). You can withdraw consent at any time by clearing the cookie-consent entry in your browser storage, or by using Google's opt-out browser add-on.

Transfer to third countries: transfers to Google LLC in the United States are covered by the EU–US Data Privacy Framework adequacy decision (C(2023) 4745).

7. Affiliate applications and partner accounts

If you apply to the affiliate program, we process your name, business name, contact and PayPal emails, website and channels, audience and promotion description, postal address, country, tax ID if supplied, terms acceptance, sign-in tokens, payout records, and program metrics. We use this information to review the application, administer the agreement, prevent abuse, send monthly account reports, and meet tax and accounting obligations. The legal bases are Art. 6(1)(b), Art. 6(1)(c), and Art. 6(1)(f) GDPR. Amazon Web Services provides transactional email delivery through Amazon SES, and PayPal processes payouts. Rejected applications are normally deleted after 12 months; contract and payout records are retained for statutory accounting periods.

8. Contact by email

When you email us at [email protected], we process your email address, your name (if you provide one), and the content of your message to answer you. Legal basis: Art. 6(1)(b) GDPR (pre-contractual or support) or Art. 6(1)(f) GDPR (legitimate interest in responding to correspondence). Retention: we keep the thread until the matter is resolved, then delete it unless we are required by law to retain it (e.g. for accounting).

9. Your rights under the GDPR

You can reach us about any of these rights at [email protected]:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)
  • Right to withdraw consent (Art. 7(3))

10. Right to lodge a complaint

You may file a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. Our competent authority is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
Phone: +49 511 120-4500
Email: [email protected]
Web: lfd.niedersachsen.de

11. Data security

We use industry-standard measures to protect data: TLS-encrypted connections (HTTPS) for everything in transit, access controls on our infrastructure, and routine security updates. No system is perfectly secure, but we treat your data like it was our own — which is why the app is designed to never send your photos in the first place.

12. Automated decision-making

The apps use on-device machine learning to group similar photos or bursts. These suggestions are not automated decisions in the sense of Art. 22 GDPR — every keep/delete choice is made by you, tapping on your own device.

13. Changes to this policy

We update this policy when the law, our tools, or our practices change. The current version is always available at this URL. Material changes are noted at the top by updating the date.

SupportImprintPrivacy PolicyCookie PolicyTerms of Service
SwipePhotos
무료 도구가이드Affiliate programAffiliate dashboard지원[email protected]
© 2026 SwipePhotos, inc. · 독일에서 정성껏 만들었어요.
법적 고지개인정보쿠키약관