SwipeSwipe

Privacy Policy

Last revised on September 15, 2026

How SwipeSwipe, operated by SellerForge LLC, collects, uses and protects your data — and what you can demand about it.

1. Who is responsible

SellerForge LLC is the controller of the data processed in SwipeSwipe. For any request related to this policy, use the support page.

2. What we collect

Account data: the email you sign in with. Your password is stored encrypted by our authentication provider and is not readable by us.

Content you create: saved carousels, your text, the covers you pick and your Brand Kit (colours, fonts, logo, and the profile handle and website you enter).

AI requests: the topic you write and the commands you send to the assistant. They are tied to your account to show your history and to meter usage.

Service usage: number of generations, which AI provider and model were used, and how much text was produced. We use this to enforce plan limits and understand cost.

Payment: plan, subscription status and transaction identifier. We never receive or store card numbers — Mercado Pago or Stripe process the payment.

Affiliate programme, only for participants: payout name, payout method and payout key (a PIX key or Stripe identifier), plus a record of who referred whom. The PIX key is sensitive data and exists only to pay your commission.

Affiliate programme application, only for applicants: full name, WhatsApp number (with country code), country, state or region, city, age, the profiles you provide (Instagram, TikTok and/or YouTube) and, if you choose to submit one, a screenshot of your profile. We use this only to review your application and, if approved, to contact you about the programme — including over the WhatsApp number you gave us, to add you to the affiliate group.

Sign-in with Google or Apple: we receive from the provider the e-mail and the name you authorize on its screen. Nothing else from your account there reaches us.

Purchases in the iOS app: Apple charges you. Through RevenueCat we receive the plan, the transaction identifier, the amount and the currency — never the card.

Technical data: IP address, browser type and approximate country, collected automatically on each visit.

3. Cookies

We use few cookies. The essential ones need no permission. The only advertising cookie — the Meta Pixel — is set only if you accept it in the bar shown on your first visit:

  • login session — keeps you signed in; expires when you sign out;
  • language — remembers whether you chose Portuguese, English or Spanish;
  • currency — stores which currency to show prices in, for 180 days;
  • affiliate referral — records who referred you, for 90 days;
  • cover donation — remembers whether you already answered the invitation to contribute a cover;
  • consent — stores your answer to the cookie bar, for one year;
  • Meta Pixel (_fbp, _fbc) — only after you accept; links your visit to the Facebook or Instagram ad that brought you here.

Cloudflare also sets its own cookies when protecting the signup form against bots.

To change your mind about the Pixel, clear this site's cookies in your browser: the bar asks again.

4. Why we process it

To perform the contract: create your account, generate and store your carousels, charge the subscription.

To comply with legal obligations: retention of tax and access records required by law.

For legitimate interests: keeping the service secure, preventing fraud and abuse, and understanding in aggregate how the product is used.

Based on your consent, when you opt into something specific — joining the affiliate programme, for example.

5. Who we share with

We do not sell your data. We share it only with the companies needed to run the service:

  • Supabase — authentication and database;
  • Hetzner — servers the application runs on;
  • Cloudflare — content delivery and bot protection;
  • Google (Gemini) — script and image generation;
  • Groq — text generation, only when the primary provider fails;
  • OpenAI — cover image generation, only when you ask for it;
  • Mercado Pago — payments in Brazilian reais;
  • Stripe — payments in US dollars and affiliate commission payouts;
  • Apple and RevenueCat — subscriptions bought in the iOS app;
  • Resend — delivery of the service's e-mails (sign-in code, account notices);
  • Kiwify — when you buy a pack through its checkout, it sends us your e-mail and the order so we can unlock what you bought;
  • Meta (Facebook and Instagram) — ad measurement. With your acceptance in the cookie bar, the Pixel runs in your browser and, at signup and checkout, we send your irreversibly hashed e-mail, IP and browser. Without acceptance, none of that is sent. For purchases we send only a hashed internal identifier and the amount — no e-mail, no IP — to count conversions in aggregate.

6. What the AI receives

Worth spelling out, because many people do not expect it: the topic you write and the text you ask the AI to rewrite are sent to the AI providers listed above so they can produce the response.

Do not send them information you would not want leaving your machine — other people's personal data, trade secrets or credentials.

We do not use your content to train our own models.

7. International transfers

The database and the files you upload are stored in Brazil (São Paulo). The application servers and most providers above are located in the United States and Europe. By using the service, your data is processed in those countries, under the contractual safeguards each supplier offers.

8. How long we keep it

Account data and carousels: for as long as your account exists.

Billing records: for the period tax law requires, even after the account is deleted.

Backups: we take a daily copy of the database and files, kept for 30 days on our own server with restricted access. Deleted data disappears from the copies within 30 days.

Affiliate programme application: if approved, the data becomes part of your affiliate record, above. If declined or not yet decided, we keep it for up to 12 months — including the profile screenshot, if you sent one — and then delete it.

When you delete your account from the account page, we erase your carousels, your Brand Kit and your profile data. Whatever the law obliges us to keep remains only for that purpose.

9. Your rights

At any time you may request:

  • confirmation that we process your data, and access to it;
  • correction of incomplete or outdated data;
  • erasure, subject to what the law requires us to keep;
  • portability of your data;
  • information about who we share it with;
  • withdrawal of consent, where consent was the basis for processing.

These rights are granted by the GDPR in the European Union and by the LGPD in Brazil. To exercise them, use the support page. We answer within 15 days.

If our answer does not satisfy you, you may complain to the data protection authority in your country.

10. Security

Traffic is encrypted over HTTPS, passwords are stored hashed by the authentication provider, and database access is restricted to the service itself. The servers only accept traffic coming through Cloudflare, administrative access is key-based, and backups are tested.

No system is immune. If an incident occurs that poses a material risk to your data, we will notify you and the competent authority as the law requires.

11. Minors

The service is not intended for anyone under 13 and we do not knowingly collect data from that age group. If we identify such an account, it will be deleted.

12. Changes to this policy

When this policy changes materially, we will announce it on the site or by email before the new version takes effect. The revision date at the top indicates the version in force.

Terms of UsePrivacySupport