Privacy policy
Last updated: 24 September 2026
Swapness is a small bartering app running as an invite-only beta in the New York City area. This page lists the personal data the app actually holds today, why it holds it, who else sees it, and how long it stays. It is written from the database and the storage that are running, and it describes the same app as our Amsterdam service, swapness.nl, with its own servers in the United States. If anything here is unclear, ask us.
Who is responsible
Swapness is built and run by one person, based in the Netherlands. That person decides what data is collected and why. For any question, request or complaint about this page, write to privacy@swapness.com. Full company and postal details are published here before the app opens beyond the invite-only beta.
What we collect
Account details
Your email address, a username, a display name, and optionally an avatar and a short bio. If you set a password, it is stored by our authentication service as a hash, so it stays unreadable to us. Sign-in by magic link works without a password.
Approximate location
Your town or borough and ZIP code, plus a coarse point derived from them, used to show items nearby and to tell others roughly how far away an item is. Your street address stays with you: the app has no shipping and never asks for one. A precise meeting point is something you share yourself, in chat, with one person.
Listings, photos and alerts
The photos, titles and descriptions of the items you list, and the wishes and alerts you save to be told when something matching shows up. Photos of published items are visible to other members and are served from a public storage bucket, so anyone holding the link can open one.
Messages, and photos you send in chat
The messages you exchange with other members after a match, and the photos you send in chat. Those photos live in a private bucket and are served through short-lived signed links, so they stay inside the conversation. Chat video is switched off during the beta.
Automatic checks on messages
Every message you send is automatically checked before it is delivered. The check runs in two steps: a list of terms held in our own database, and, only for the cases that list marks as doubtful, a language model that reads the message text and returns a verdict. A message can be refused, and you are told so and can rewrite it. The verdict is used for that message alone. It produces no automated decision about your account: suspending an account is a decision a person takes, after reading.
That model runs at OVHcloud, in France. The text of a flagged message is sent there to be judged and the verdict comes straight back. OVHcloud states that it does not store these requests and never uses them to train models.
Handover photos
When you complete a swap, each side photographs the item they receive, two to five photos each. They are the record of what actually changed hands, so they are kept as evidence if the other side later disputes the swap. They live in a private bucket, readable by the two people in that swap. A photo taken at a meeting point can show a doorway, a street or a living room: take the picture of the object, framed as tightly as you can.
Swipes, wishes and category affinities
Every swipe you make is stored: which item you liked or passed, and which of your items you offered for it. From those swipes the app builds a score per category, so the feed can lead with the kind of thing you keep saying yes to, and a graph of who would give what for what, which is what finds matches. This history is yours alone and is shown to no other member.
Waiting list
The landing page has a waiting list, and it takes your email address and optionally your ZIP code before you have any account at all. We use both to decide who to invite next: a spot given to somebody too far from New York is a spot burned. Each submission also stores a salted one-way hash of the IP address it came from, for one hour, to cap how many entries a single source can push. Your address stays on that list until you are invited or until you ask us to remove it.
Reports and moderation records
If you report a member or an item, we store your report, what you wrote in it, and the name and reference of what you reported, so the case can be read and acted on. Every action taken afterwards is recorded too: what was decided, by whom, and why. A member who is reported is not told who reported them.
Notifications
The events the app raises for you (a match, a message, a swap step) are stored so your notification list can be rebuilt. If you turn on push notifications, your browser gives us a push endpoint, its keys and the user-agent of that browser, which together identify one device. You can withdraw that at any time in your browser or in the app.
IP address, device and sessions
Each time you sign in, our authentication service records the session: your IP address, the user-agent of your browser, and the times it was created and last used. It is what lets you stay signed in, and what lets us end a session that is no longer yours. Requests to the app also pass through our hosting and database providers, whose own access logs hold your IP address, a rough city and region derived from it, your internet provider and a browser signature. Those logs are theirs, kept under their own retention, and we cannot shorten them.
AI estimation
When you list an item, its photos are analysed to suggest a category, a title, a description and an indicative value in US dollars. They are sent for that to OVHcloud, in France, which states that it does not store these requests and never uses them to train models. The copy sent for analysis is kept nowhere, and your photos are not used to train third-party AI models. We keep a small counter of these calls per person and per hour, to cap what a single account can spend.
Product analytics
Inside our own database, and nowhere else, the app counts which screens you open. A row holds a date, the name of one screen, your account, and a number. The screen name comes from a fixed list that the database refuses to add to: it is a name such as “feed” or “messages”, never a web address, so nothing records which listing you looked at or which conversation you opened. There is one row per screen per person per day, not one per tap. We keep that detail for 90 days, then keep only a running total that carries no account.
The same database also counts when you hit one of the beta limits, and stores your name against it once if you raise your hand for Swapness Plus. None of that reaches a third party, and none of it is used to profile you or to decide anything about your account.
Counting visits to the pages themselves
We use Vercel Web Analytics to count page views across the site, the landing page included. It sets no cookie and stores nothing on your device. Per view, it records the time, the page, where you came from, an approximate location from your IP address, your device type, and your browser and operating system. Vercel identifies a visitor by a hash computed from the request rather than by an identifier that follows you, and drops it again after a short window, which Vercel publishes in its own privacy documentation.
The page address is cut down before it leaves your browser. Every address is reduced first to the shape of the screen: a conversation becomes “messages” and a member page becomes “member”, never the conversation or the person. Anything after a question mark or a hash sign is dropped whole. So a visit never records which conversation you opened, whose profile you looked at, or what you typed into search.
Which parts of the landing page people use
Since 24 September 2026 the landing page also uses Microsoft Clarity. It runs on the landing page only, never on a screen you reach once you are signed in. It tells us which parts of the page people read, how far down they scroll and what they tap, so we can fix the page instead of guessing at it.
It runs without cookies: we have turned cookies off in its settings. Nothing is written to or read from your device by Clarity, so two visits cannot be joined together, and neither can two pages of the same visit. What reaches Microsoft is one visit to the landing page at a time: the page, the time, what you scrolled and tapped, an approximate location from your IP address, and your device, browser and operating system. Clarity may keep that single visit as a recording of the page so we can see how it was read. What you type into a form field is masked before it leaves your browser.
We also tell Clarity when someone sees, starts or submits the request form for beta access, or receives an error, together with the page variant, the language, the kind of screen and the campaign codes in the link you followed. These events never include an email address, a ZIP code, anything you typed or an advertising click ID.
It is on the landing page only, and that is a deliberate limit. A tool of this kind records the page it is placed on, so on a conversation it would record the conversation. It is therefore fenced in twice: it is installed on that one page, and the browser is instructed to refuse it everywhere else, so a mistake on our side is blocked rather than quietly obeyed. Clarity is measurement of our own page, not advertising, and it is not used to show you ads.
Optional advertising measurement with Meta and TikTok
Our landing page can use Meta Pixel and TikTok Pixel to measure visits and requests for beta access, and to improve our Facebook, Instagram and TikTok ads. Their scripts start only when you choose “Accept” in “Advertising choices”. Before you accept, we load no advertising script and send no event to either provider. Choosing “Decline” or continuing without choosing keeps it off, and you can request beta access either way. They never run on a screen you reach once you are signed in.
If your browser sends a Global Privacy Control signal, we treat it as a refusal: no advertising script loads, even if you click, and the panel tells you so.
After you accept, we send a page-view event and an event when our server acknowledges a request for beta access. An acknowledgement can also cover a repeated request or one limited to prevent spam, so it does not tell either provider whether a new address joined the waiting list.
The providers receive your IP address, browser and device information, the landing-page address and its advertising attribution information, and cookies they can access. Meta cookies may include _fbp and _fbc. TikTok cookies may include _ttp, ttclid and cookies beginning with ttcsid. Each provider may link this information with data it already holds, including a Facebook, Instagram or TikTok account. We do not add your email address, ZIP code, account identifier or form contents to these events, and we do not enable automatic matching of form details. Depending on its pixel settings, TikTok can also collect page metadata, button clicks, scrolling and page-performance information, also only after you accept.
We remember your choice in this browser, and ask again when it expires or you clear it. You can withdraw it with “Advertising choices” in the landing-page footer, or open your advertising choices. Withdrawal stops our future events and removes the advertising cookies and pixel storage that this site can access. It does not erase what either provider has already received, or cookies on their own domains.
Meta explains its own uses and retention in its Privacy Policy and Cookies Policy. TikTok explains its own in its Privacy Policy and describes its advertising cookies in its TikTok Pixel cookie information.
Why we use it
- To run the service: your account, listings, swipes, matches, messages and handover photos exist so the app can do what you signed up for.
- To keep the platform safe: the automatic checks on messages, reports and moderation records, session records, and the caps that stop one account or one source from flooding the service.
- To know whether the app works: the screen counters and page-view counts tell us which screens people reach and where they stop. We count screens, not people, and no decision is taken about an account from them.
- Because you asked: the waiting list, push notifications, and the optional Meta and TikTok advertising measurement. You can stop any of them at any time.
How long we keep it
Each line below has a mechanism behind it, running on our servers. Where there is no mechanism yet, the line says so instead of naming a comfortable number.
- Account, listings, wishes, swipes and messages: for as long as your account exists.
- Sign-in sessions, with their IP address and user-agent: a session ends after 14 days without use, and after 60 days in every case. An hourly job deletes the ended sessions, and the IP address goes with them.
- Reports and moderation records: deleted 24 months after they are filed, by a job that runs every night, so repeated abuse can be recognised in between.
- Screen counters: the rows that carry your account are deleted 90 days after the day they count, by a job that runs every night. Before it removes them, the same job writes a running total for that day, which carries no account and stays.
- Photos of listings: deleted from storage when you withdraw or delete the listing.
- Photos left over from a draft: a photo uploaded during a draft that is never published is picked up by a daily job after 72 hours. That job does not delete yet: it only writes the list of files it would delete, so we can read those lists before we switch the deletion on. Ask us and we delete yours in the meantime.
- Photos you send in chat: kept as long as the conversation. A photo uploaded but never sent is picked up by the same daily job after 24 hours, and the same holds: the job writes the list and deletes nothing for now. Ask us and we delete yours in the meantime.
- Handover photos: kept as long as the swap record they prove. There is no automatic deletion for them today. Ask us and we delete yours.
- Waiting list: your address stays until you are invited or you ask for it to be removed. The hashed IP of a submission is dropped when its one-hour window closes.
- Provider access logs: kept by our hosting and database providers under their own retention. We hold no log archive of our own beyond what is described above.
- If you ask us to delete your account: your files are listed first, then removed from storage, and the account itself goes last. What belongs to somebody else stays without your name on it: a report filed against you, and the swap record of the person you swapped with. A swap you have already agreed to holds the request until it is finished or cancelled, so nobody vanishes in the middle of a handover.
Who we share it with
We do not sell your personal data for money. The Meta and TikTok advertising measurement described above is the only sharing for advertising, it runs only if you accept it, and you can stop it at any time. Other members only see what the app shows them: your public profile, your published items, your approximate distance, the messages you send them, and the handover photos of a swap you are part of. The following providers process data for us, for the purposes described here.
- Supabase: database, file storage and authentication, hosted in the United States (Virginia). This is where accounts, listings, messages, photos and session records live.
- Vercel: hosting of the web app, run in the United States (Washington, D.C. area), and the counting of page views described above. Requests pass through it, so its access logs hold your IP address.
- OVHcloud: the AI model that reads the photos of an item being listed and judges the messages flagged as doubtful, run in France. It receives those photos and the text of those messages, and states that it keeps neither and uses neither to train models.
- Resend: delivery of the emails the app sends you (invitation, sign-in link, password reset), from the United States. It sees your email address and the content of those emails.
- Microsoft Clarity: which parts of the landing page people use, as described above. It sees only that page, never a screen you reach once you are signed in.
- Meta: optional advertising measurement on the landing page, after you accept it, under its Business Tools Terms and Privacy Policy.
- TikTok: optional advertising measurement on the landing page, after you accept it, under its Business Products (Data) Terms and Privacy Policy.
Your data is therefore stored in the United States, and the photos and flagged messages described above are processed in France. We also hand data to an authority when the law requires it, and we say so here if it ever becomes routine.
Your choices and rights
Wherever you live, you can ask us to access, correct, export or delete your personal data. Access and export are served by the app itself: it assembles a copy of your account, listings, messages, swipes and swap records, and you can delete your account yourself from your settings. For anything else, email privacy@swapness.com. We answer within 45 days, and tell you if we need more time and why.
If we turn down a request, you can ask us to look at it again by replying to our answer with the word “appeal”. We answer an appeal within 60 days and explain the result. If you are still not satisfied, you can contact the Attorney General of your state. We do not treat you differently for using any of these rights.
Swapness is not meant for children, and we do not knowingly collect personal data from anyone under 13. If you believe a child has given us their data, write to us and we delete it.
Do Not Track and Global Privacy Control
We honour Global Privacy Control: when your browser sends it, the Meta and TikTok advertising measurement stays off, whatever you click. Do Not Track has no agreed meaning and we do not act on it, but nothing advertising-related runs on Swapness until you accept it anyway.
How we protect it
Traffic to Swapness is encrypted. Every table of the database carries access rules that limit each member to what the app is meant to show them, private photos are served through links that expire, passwords are stored as hashes, and sign-in sessions end on their own as described above. No system is perfectly safe: if a security incident ever exposes your personal data, we tell you without unreasonable delay, as the law of your state requires.
Changes to this page
This page changes when the app changes, and before, when the change concerns your data. The date at the top says when it last changed. When a change matters, for example a new provider or a new use of your data, we also tell you by email or in the app before it applies.
Reporting content
Anyone can flag content they believe is illegal or against our rules. The route we can stand behind is the “Report” option on any item or profile: it files a case, and while a case is open the system raises an alert to us every hour until someone has read it. Every action taken on a report is recorded, and you can ask what happened to yours by writing to privacy@swapness.com. We give no fixed handling time yet, because the beta is run by one person and a promise we cannot hold is worth less than this sentence. See also our Terms of use.