SwiftTool
Privacy policy
What SwiftTool collects, why it is used, where it is processed and the choices available to you.
Scope and controller
This policy applies to swifttool.org, the SwiftTool web application, the SwiftTool Telegram bot and the private cloud endpoint when they process information for the same SwiftTool account and services. SwiftTool Studio determines the purposes and means of the website and web application processing described here.
Privacy questions and rights requests can be submitted through the support form. Signed-in users can also start data export and deletion actions from Profile.
Information we process
The information depends on how you use SwiftTool. We limit collection to information needed to provide, secure, support and improve the requested service.
- Account data: name, email, locale, timezone, password hash and account status.
- Connected identity data: verified Google subject and email, or verified Telegram ID, username and profile fields supplied in the signed payload.
- Project and media data: project names, source references, uploaded source files, processing instructions, outputs and job status.
- Subscription and usage data: plan, expiry, transfer and processing counters, without exposing the raw serialized VIP record to the browser.
- Support data: contact details, category, subject, message and support history.
- Security and device data: IP address, user agent, device label, session times, login attempts, audit and security events.
- Consent and preference data: selected cookie categories, language, theme, accessibility and tool preferences.
Why we use information
We use account, project and media information to perform the service you request; security information to protect users and infrastructure; support information to answer requests; and optional analytics only after consent to understand aggregate product use.
Depending on the context, processing is based on performance of the service agreement, legitimate interests in operating and securing SwiftTool, consent for optional categories, or compliance with applicable obligations.
Telegram bot and Mini App
When you use the Telegram bot, Telegram supplies identifiers and message or file context needed to handle the interaction. SwiftTool may process URLs, uploaded media, requested options, output and usage counters. Telegram processes its own platform data under its policies.
Mini App identity is linked only after validation of Telegram’s signed authentication data. Entering a numeric ID without verification does not link an account or grant a subscription.
Processors and processing locations
The current production deployment uses infrastructure processing locations in Germany (Frankfurt) and France (Paris). A particular request may use one location according to service availability, storage role and processing workload.
Google processes OAuth authentication when you choose Google sign-in. Telegram processes bot, Login and Mini App platform interactions. Service providers receive only the data needed for their role and are subject to contractual and technical controls appropriate to that role.
Retention
Account information is kept while the account is active. An authenticated deletion request starts a 30-day grace period. Project source, temporary and output files follow the retention displayed by the applicable tool and can be removed earlier when the project is deleted.
Self-service export archives expire after 24 hours. Expired authentication artifacts are removed after 7 days, rate-limit events after 30 days, login attempts after 90 days, expired or revoked session records after 90 days, sent email queue content after 30 days, and consented first-party analytics after no more than 13 months.
Security and audit records are kept for the period needed to investigate abuse, protect accounts and demonstrate administrative actions. Support records are retained while a request is active and for a reasonable follow-up period. Consent history is retained to record the choice that applied at a given time.
Backups expire according to the documented rotation schedule. Deletion from active systems can therefore precede final expiry from encrypted backups, where access remains restricted and restoration procedures reapply deletion queues.
Your choices and rights
Depending on applicable law, you may request access, a machine-readable copy, correction, deletion, restriction or objection, and may withdraw optional consent without affecting earlier lawful processing. SwiftTool may need to verify identity before acting on a request.
The profile provides direct export, active-session control and account deletion. Cookie choices can be reopened from the footer. Other requests can be submitted through Support using the Privacy category.
Security and incident response
SwiftTool uses transport encryption, hashed passwords, hashed session tokens, role-based administrative access, rate limits, audit records and restricted service wrappers. No internet service can promise absolute security, so controls are reviewed and incidents are investigated according to severity.
Children and policy updates
SwiftTool is not directed to children who cannot lawfully consent to an online service in their jurisdiction. Material policy changes are dated on this page and, when appropriate, communicated in the application before they take effect.