SWOOPEN·← Back

Privacy Policy

Effective: June 15, 2026

Swoopen ("we", "us", "our") is an AI video-generation service. This Privacy Policy explains what personal information we collect, how we use and share it, and the rights you have over it. By creating an account or using the app, you agree to the practices described here. If you do not agree, do not use Swoopen.

1. Scope and applicability

This policy covers personal information processed by Swoopen through our mobile apps (iOS, Android), our web app, and our API. It does not apply to third-party services we link to (e.g., Apple App Store, Google Play, Stripe), each of which has its own privacy policy. Where local law (GDPR in the EU/EEA, UK GDPR, CCPA/CPRA in California, LGPD in Brazil, APPI in Japan) grants you stronger rights than this policy describes, those laws apply.

2. Children and minors

Swoopen is not directed to children under 13 (or under 16 in jurisdictions that require it, such as the EU). We do not knowingly collect personal information from such users. If we learn that a user is under the relevant minimum age, we will terminate the account and delete associated data. Parents or guardians who believe their child has created an account should email [email protected] for immediate removal.

3. Information we collect

Account data: email address, Apple/Google account identifier, display name, password hash (when using email login). Device data: device model, operating system version, language, time zone, IP address, app version, anonymous device fingerprint. Content data: photos and prompts you upload, videos we generate for you, captions and metadata, drafts. Transaction data: subscription tier, in-app purchase receipts, billing currency, country of purchase (we do not store your full card number — that lives with Apple/Google/Stripe). Usage data: which features you use, generation success/failure rates, crash reports, performance traces. We do not collect your contacts, precise location, microphone audio, health data, or biometric identifiers.

4. How we collect it

Directly from you when you sign up, generate content, subscribe, or contact support. Automatically when you use the app (analytics SDKs, crash reporters). From third parties: Apple Sign In / Google Sign In return a stable user identifier and (with your consent) your email; the App Store / Play Store / Stripe return purchase confirmations and subscription status. We do not buy or rent personal data from data brokers.

5. How we use your information

(a) Provide the service — generate your videos, deliver them to your device, and store them for re-download. (b) Operate your account — authentication, password reset, plan changes, customer support. (c) Process payments and prevent fraud — verify receipts, detect abuse, manage refunds. (d) Improve the product — aggregate analytics on which features work, debug crashes, A/B test improvements. (e) Communicate with you — receipts, security notices, mandatory service updates; marketing only with your opt-in consent and always with an unsubscribe link. (f) Comply with law — respond to subpoenas, court orders, and lawful regulator requests. We do not use your prompts, reference images, or generated videos to train AI models — yours or ours.

6. Sharing and disclosure

We share personal information only with: (i) the upstream AI provider (Google Veo / Vertex) for the duration of a single generation request — they process and return the result and do not retain it for training; (ii) infrastructure providers under written contracts (cloud hosting, object storage, CDN, push-notification, email delivery, analytics, crash reporting) acting solely on our instructions; (iii) payment processors (Apple, Google, Stripe) when you subscribe; (iv) law enforcement, regulators, or other parties when required by valid legal process or to protect the safety of users or the public. We do not sell your personal information to advertisers or data brokers, and we do not engage in cross-context behavioral advertising. Under California's CCPA, you have the right to opt out of "sale" or "sharing" — even though we do neither, you can confirm by emailing [email protected].

7. International data transfers

Swoopen stores data in the United States and the European Union. If you are outside those regions, your data will be transferred to and processed in countries whose data-protection laws may differ from yours. For transfers from the EU/EEA or UK, we rely on Standard Contractual Clauses (Module 2) with all sub-processors and conduct transfer impact assessments. For transfers from other jurisdictions, we apply equivalent protections.

8. Data retention

Account profile: retained while your account is active. Upon your deletion request, all personally identifiable fields (email, phone, display name, handle) are immediately anonymized and the account is marked deleted — this is permanent and cannot be reversed. Generated videos, images, and uploaded photos: retained while your account is active; immediately removed from our storage and content delivery network at the moment of deletion. Authentication tokens: maximum 30 days. Payment receipts and tax records: up to 7 years (legal requirement) — these contain transaction IDs and amounts only, no personal information. Crash logs and analytics: up to 90 days, then aggregated and de-identified. Backups containing deleted data are rotated out within 90 days. We do not retain personal data beyond what is required by law or operationally necessary.

9. Your rights and choices

Depending on where you live, you have some or all of the following rights: access (request a copy of your data), rectification (correct inaccurate data), erasure (delete your account and data), restriction (limit how we process your data), portability (receive your data in a machine-readable format), objection (object to certain processing including marketing), withdrawal of consent (where processing is based on consent), and the right not to be subject to automated decision-making with legal effect. Exercise any right by emailing [email protected] from the email on your account; we respond within 30 days. If you are in the EU/EEA or UK, you may also lodge a complaint with your local data-protection authority. We will not retaliate against you for exercising your rights.

10. Data security

We protect your data with industry-standard measures: encryption in transit (TLS 1.2+) and at rest (AES-256 for stored media), private storage buckets accessed only via short-lived signed URLs, hashed passwords (Argon2id), least-privilege access for engineers with audit logging, automatic security patching, and regular penetration testing. No system is perfectly secure; if a breach affects you, we will notify you within 72 hours where required by law.

11. Cookies and tracking

Our web app uses strictly-necessary cookies for sign-in and session management, and minimal first-party analytics. We do not set advertising cookies, and we do not allow third parties to set tracking cookies through our pages. The mobile apps do not use IDFA / GAID for advertising; we honor App Tracking Transparency on iOS.

12. Changes and contact

We may update this policy to reflect new features, legal requirements, or operational changes. Material changes will be announced in-app at least 14 days before they take effect; continuing to use Swoopen after that date constitutes acceptance. For privacy questions, data-rights requests, or to reach our Data Protection Officer, email [email protected]. We respond within 5 business days for general inquiries and within statutory timelines for formal rights requests.