Privacy Policy
This Privacy Policy explains which personal data we, my105 GmbH, Vulkanplatz 7, 8048 Zurich, process when operating SwypeCast. It follows the Swiss Federal Act on Data Protection (FADP). Where persons in the EU or EEA are concerned, we additionally observe the General Data Protection Regulation (GDPR).
Controller and contact for privacy matters: my105 GmbH, Vulkanplatz 7, 8048 Zurich, support@swypecast.com. We have not appointed a data protection advisor or data protection officer; please send any request to this address.
1. Who this policy concerns
- Customers and their team members who use the SwypeCast Studio.
- Viewers who watch stories in the Player, react to them, comment or take part in votes, polls and questions, including stories embedded on third-party websites.
- Visitors of the website swypecast.com and the Help Center, including the waitlist, registration, contact form and support.
2. Customers as controllers, SwypeCast as processor
Stories are published by our customers, usually under their own subdomain (e.g. name.swypecast.com). For personal data processed through their stories, the respective customer is the controller. This includes in particular the usage events, reactions, comments, answers to questions and votes of their viewers as well as the data of their advertisers. SwypeCast processes this data as a processor on the customer's instructions. You will find the customer's legal notice and privacy information in the story under "Legal". Requests about this data are best sent directly to the customer; we forward requests that reach us to the customer.
We are the controller ourselves for the data of customer accounts, the website, the Help Center, support and billing.
3. Which data we process
Studio (customers and team members)
- Account data: email address, name, profile picture (optional), password (hash only), chosen language, role and permissions in the organisation, sign-in methods (email and password, Google or Apple).
- Organisation data: name of the organisation, subdomain, profile (description, logo, links), settings for Player, moderation and advertising, the organisation's legal texts, details of advertisers (name, contact person, email, address, notes).
- Subscription data: plan, term, payment status, number of seats, usage (views, storage, video minutes) and AI credits. Payment details such as card data are collected by Stripe only; we store only the identifiers of the customer and the subscription at Stripe.
- Content: uploaded videos, audio, images and fonts, compositions created in the editor, texts, campaigns and creatives, source information on material used, and confirmations that the rights to uploaded audio are held (with person and time).
- AI generation: prompts, the prompt sent to the provider, settings, results, cost in credits, ratings and feedback (section 5).
- Log data: time of sign-ins, technical error reports, actions of the platform team in the audit log (including the IP address of the acting staff member) and platform support access to customer accounts.
Mobile app (iOS and Android)
The SwypeCast app for iPhone, iPad and Android is the studio on the go, for customers and team members; it does not contain a player for viewers. In addition to the studio data, we process there:
- Sign-in: the same account data as in the studio, plus Sign in with Apple. The session is stored in the device keychain. There is no registration in the app.
- Recordings and imports: photos and videos you record in the app, choose from the library or share from another app stay in the app's storage on your device until they are uploaded (also without a network) and are then handled like content in the studio. The app uses the camera, microphone and photos only when you start a recording or a selection; you grant the permission to the operating system.
- Notifications (optional): if you allow notifications, we store the device token, the platform, the language and your choice of what to be informed about, together with your account and your organisation. Delivery runs through Expo's push service and from there through Apple or Google. A notification contains the title of the story and an excerpt of the comment. The token is deleted when you sign out; you can switch notifications off at any time in the app or in the device settings.
- The app sends no advertising or tracking identifiers and contains no advertising SDKs. We do not collect crash reports from the app through a third-party service.
Player (viewers)
- A random session identifier in a cookie (sc_session) to control reactions, votes, comment limits and ad frequency. It contains neither a name nor an email address.
- Usage events: which story and clip was watched, swiped, shared or completed and when; whether an ad was visible, skipped or clicked; clicks on profile links, music information and store links.
- Technical details: device type (phone, tablet, desktop), operating system, country (derived from the IP address; we do not store the IP address itself in this process) and the domain of the referring page (without path).
- Comments with the freely chosen display name ("Guest" if none is given), answers to open questions, reactions, votes in votes, polls and barometers, each linked to the session identifier.
- If the customer's AI moderation is active, every comment is classified automatically before publication (section 5). The classification decides whether a comment appears immediately, goes to the customer's queue or is hidden; the customer can change any classification in moderation.
- Voluntary contact details: anyone who writes a comment or answers an open question may afterwards leave an email address in order to receive a reply. It is voluntary; sending works without it. We store the address, the time and the wording of the consent, show it to the customer in the Studio and use it only for the answer to that one piece of feedback. Advertising needs a separate consent.
- Prize draws: if a customer runs a prize draw in a story, we collect on its behalf the details its form asks for (depending on the draw: name, email address, mobile number, address and date of birth), the session identifier, the time, the terms of entry and the wording of the consent, plus, where offered, the separate consent to a newsletter. The customer, as the organiser, is the controller of this data.
- Only if diagnostics are explicitly switched on via the address: technical playback logs with session identifier and browser identifier (user agent).
Website, waitlist, registration and Help Center
- Waitlist: email address, optionally name, organisation and intended use, language of the website.
- Registration: first and last name, email address, name of the organisation, subdomain, password (as a hash), invite code and language. When registering with Google we receive name and email address from Google.
- Contact form: name, organisation (optional), email address, message, plan of interest.
- Support: requests, messages and attachments, linked to account, organisation and plan.
- Help Center: ratings of articles ("Was this helpful?") with an optional comment, linked to a random identifier.
For registration, waitlist, contact form, support and unlocking password-protected stories, we use IP addresses only briefly in memory to limit abuse; we do not store them in these processes.
4. What we use the data for
- Providing the service: account, Studio, Editor, publishing and delivering stories, embeds, feeds and QR codes, delivering the customer's advertising.
- Billing: subscriptions, seats and credit packs via Stripe, checking plan limits.
- Security: protection against abuse, rate limits, access control, error analysis.
- Statistics for customers: reach, watch time, interactions, voting results and ad performance of their stories.
- Communication: invitations, confirmations, password and sign-in links, notices about the trial and usage, moderation notifications, replies to support requests.
- Moderation and checks: pre-screening of comments at the customer's request and checking of AI prompts (section 5).
Legal bases under the GDPR, where applicable: performance of a contract and pre-contractual measures (account, registration, subscription, support), legitimate interests (security, statistics, development, answering requests), consent (waitlist) and legal obligations (accounting). Viewer data in customer stories is processed on behalf of the customer, who is responsible for the legal basis.
5. AI features
- Comment moderation (only if the customer has enabled it): the story title, display name and comment text are sent to Anthropic. The session identifier is not transmitted.
- Prompt check: before an image, video or audio track is generated, Anthropic checks the prompt for prohibited content. If the prompt is rejected, nothing is generated.
- Image and video: the prompt (extended by the style and, for "Brand", by the organisation's colours, typeface, description and name) and, where applicable, a source image from the organisation's library are sent to Google (Gemini API, Veo and Gemini Image models). Google's results carry an invisible watermark (SynthID).
- Audio: prompt and length are sent to ElevenLabs. Only instrumental music without vocals is generated.
- Help Center: we have drafts of help articles pre-written internally by Anthropic; no customer data is transmitted in the process.
We store results in the organisation's library. In the Player, AI-generated clips are labelled "AI-generated". When generating, customers can indicate whether they would release a result for a future shared archive. We store this choice but currently do not pass results or prompts on to other organisations. Prompts should nevertheless not contain personal data.
An organisation's feedback on results is included as a hint in that organisation's next prompts. We do not train any AI models ourselves with customer data.
6. Cookies and local storage
Cookies:
- sc_session: random session identifier in the Player (strictly necessary, 12 months).
- sc_name: last display name chosen for comments (12 months, only after a comment with a name).
- sc_access_…: unlock of a password-protected story (strictly necessary, 12 hours).
- Supabase auth cookies (sb-…): sign-in to the Studio (strictly necessary).
- sc_ui: remembered settings of the Studio interface (strictly necessary).
- sc_lang: chosen language of the website (strictly necessary, 12 months).
- sc_help: random identifier for article ratings in the Help Center if no sc_session exists (12 months).
- sc_impersonate: only for the platform team during a logged access to a customer account (30 minutes at most).
Local browser storage (localStorage, sessionStorage):
- Theme of the Studio (light or dark).
- sc_cookie_ok: cookie notice in a story has been seen.
- sc_sound: sound on or off during the session.
- sc_react_recent and sc_react_order: recently used reactions and the order of the quick reactions.
- sc_row_seen: stories already opened in an embedded story row (for the "new" ring).
- sc_oauth_intent and sc_signup_params: temporary storage during sign-in or registration with Google.
- sc_diag: only if playback diagnostics have been switched on.
We use no third-party tracking or advertising cookies and no personalised advertising. Advertising in the Player is selected based on the story and the customer's campaigns, not on the person; the session identifier only serves to cap frequency.
7. Service providers and third parties
We work with the following providers who process data on our behalf or on behalf of our customers:
- Supabase (database, authentication, file storage, real-time updates in the Player): data centre in London, United Kingdom; Supabase Inc., USA.
- Vercel (application hosting and delivery via a worldwide network): server functions in Frankfurt, Germany; Vercel Inc., USA.
- Mux (processing, storage and delivery of videos, thumbnails; optionally Mux Data for measuring playback quality, without cookies): Mux Inc., USA. When a video plays, the browser fetches the files directly from Mux.
- Mailgun (email delivery, including sign-in and confirmation emails): Sinch Mailgun, servers in the USA.
- Expo (push service of the mobile app: receives device tokens and the message text and passes them on to Apple or Google): Expo (650 Industries Inc.), USA.
- Stripe (payment processing, invoices, customer portal, tax calculation): Stripe, Ireland and USA. Stripe processes payment data partly as an independent controller.
- Sentry (error reports, without session recording and without cookies or user identifiers): Functional Software Inc., USA.
- Anthropic (comment moderation, checking of AI prompts, drafts of help articles): Anthropic PBC, USA.
- Google (generation of images and videos via the Gemini API): Google, USA.
- ElevenLabs (generation of audio tracks): ElevenLabs, USA.
- Mapbox (place search in the editor; only the search term is transmitted, server-side): Mapbox Inc., USA.
- Pixabay (search for stock images and videos in the editor): we send search terms server-side; the browser loads the thumbnails in the search grid directly from Pixabay (Pixabay GmbH, Germany). Material that is chosen is copied into the organisation's library.
Other providers whose content the browser loads directly and who receive the IP address in the process:
- Google sign-in: anyone who signs in or registers with Google is redirected to Google; Google's privacy policy applies in addition.
- Apple (iTunes): if a clip contains a song from iTunes, the Player streams the preview, the cover and, where applicable, the video preview directly from Apple servers (USA). The song search in the Studio runs server-side via the iTunes Search API.
- Links to third parties (e.g. Apple Music, Google Maps for a place, customers' websites and social media profiles, incompetech.com): data only flows once you open the link.
Music from the music library (Kevin MacLeod, incompetech.com) is delivered from our own storage; no data flows to the author. Fonts from Google Fonts (for the Player, the font picker and the Editor) are loaded through our own servers; the browser does not connect to Google for them, and Google receives no visitor data.
8. Transfers abroad
Our data is mainly located in the United Kingdom and the EU; according to the Swiss Federal Council and the European Commission, these countries ensure adequate data protection. Several providers (section 7) are based in the USA or process data there. For these transfers we rely on the recipient's certification under the Swiss-U.S. or EU-U.S. Data Privacy Framework, where available, and otherwise on the standard contractual clauses of the European Commission recognised by the FDPIC.
9. Data security
Transfers are TLS-encrypted. Passwords are stored as hashes only. Access to data is restricted to the respective organisation through roles and row-level permissions. Access of the platform team to customer accounts is time-limited, logged and requires two-factor authentication. Support attachments are kept in non-public storage.
10. Retention and deletion
- We store account data and content for as long as the organisation exists. When a paid subscription ends, the organisation continues on the Free plan.
- If an organisation is deleted, its data is permanently removed after 30 days. If a person deletes their account, the account is removed immediately.
- Usage events in the Player are deleted after 13 months; aggregated statistics remain without personal reference.
- Voluntary contact details under comments and answers, and entries in prize draws, are deleted automatically after twelve months. The customer may delete single entries earlier at any time; only administrators of its organisation may do so.
- Search results from Pixabay, iTunes and Mapbox are cached for 24 hours at most.
- Comments and reactions in the example stories on swypecast.com are deleted after 24 hours.
- Statutory retention obligations, for instance for accounting records, remain reserved.
11. Your rights
You have the right to access, rectification, erasure, restriction of processing and data portability, and the right to object to processing or withdraw consent. You can request that a classification by the AI moderation be reviewed by a human; the customer in whose story the comment appears is responsible for this. To exercise your rights, contact support@swypecast.com. Data subjects in the EU may also contact a supervisory authority; in Switzerland the Federal Data Protection and Information Commissioner (FDPIC) is responsible.
12. Changes
We update this policy when the service or the legal situation changes. The version published on this page applies.
Last updated: 6 October 2026
