Privacy Policy

Get Started

plans

plans

Privacy policy

SwipeReply takes your privacy seriously, so we formatted this for you in a way that you can understand it easily.

Last updated: January 23rd 2026

1. Introduction

We are committed to protecting your personal data and ensuring transparency about how we process it. This Privacy Policy explains how we collect, use, store, and disclose personal data when you use our website and web application (“Site” / “Service”).
It applies to all users (“Users”) located in Germany and the European Union.

We process personal data strictly in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection laws.

2. Data Controller

Julia Petersen

Pappelallee 64

10437 Berlin
Email: hi@swipereply.com

3. Categories of Data We Collect

3.1 Personal Identification Information

We may collect the following personal data when Users voluntarily provide it:
• Name
• Email address
• Postal address
• Phone number
• Payment details via Stripe (we never safe payment details ourselves)
• Account information (if you create an account)

Users may visit the Site without identifying themselves. Personal data is only collected when you voluntarily submit it.

3.2 Automatically Collected Data (Technical + Usage Data)

When accessing our Site, we automatically collect non-personal and technical data including:
• Browser type and version
• Device type
• Operating system
• IP address (short-term, for security/logging)
• Referrer URL
• Usage logs (e.g., timestamps, actions, interactions)

This data is collected for security, performance, analytics, and service operation.

3.3 Cookies and Similar Technologies

We may use cookies to improve user experience, enable core functionality, and store preferences.
Users can disable cookies in their browser settings. Some parts of the Site may not function correctly without cookies.

4. Third-Party Services and Data Processors

To operate and improve our Service, we integrate the following processors/tools. These providers may process personal data on our behalf under GDPR-compliant Data Processing Agreements (DPAs).

4.1 Bolt Native

Used for hosting or delivering the frontend/mobile/web runtime.
Data processed may include device data, usage logs, and technical identifiers necessary to render the Service.

4.2 n8n Automation Platform

Used for workflow automation (e.g., sending emails, routing requests, operational logic).
Personal data may pass through n8n nodes strictly for automation of the Service.

4.3 OpenAI API

Used for AI-powered features within the application.
Data you submit to AI features may be transmitted to OpenAI for processing.
OpenAI processes data under GDPR and does not use submitted data to train models unless explicitly agreed.

Details: https://openai.com/policies/privacy-policy

4.4 Google Gemini API (Google AI Studio / Vertex AI)

Used for AI functionality similar to OpenAI.
Data may be transmitted to Google for inference.
Google processes data according to EU data protection standards and under applicable DPAs.

Details: https://policies.google.com/privacy

We do not fine-tune AI models using your data unless you explicitly permit it.

4.5 Payment Providers

Payment information is collected and processed exclusively by certified external payment processors (e.g., Stripe, PayPal).
We do not store full credit card numbers on our servers.

5. Purpose and Legal Basis of Processing

We process personal data only for the purposes permitted under GDPR.

5.1 To Provide the Service (Art. 6(1)(b) GDPR)

• User account management
• Processing purchases and subscriptions
• Delivering features (including AI-based functions)

5.2 To Communicate With Users (Art. 6(1)(b) and 6(1)(f))

• Transactional emails and important service notifications
• Responding to requests, support inquiries, and feedback

5.3 To Improve and Secure the Service (Art. 6(1)(f))

• Error detection
• Security monitoring
• Performance optimization
• Analytics in aggregated, non-identifiable form

5.4 Based on Consent (Art. 6(1)(a))

• Newsletter
• Marketing communication
• Optional cookies
You can withdraw consent at any time.

6. Data Storage and Security

We implement industry-standard technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration, or destruction.

Data is stored on secure servers within the European Union or in countries with adequate data protection under GDPR-compliant safeguards.

7. Data Sharing

We do not sell or rent personal data.
We may share data only in these cases:
• With service providers under strict GDPR-compliant agreements
• If legally required (e.g., court order in Germany)
• In case of business restructuring (e.g., merger), with adequate safeguards

Aggregated, anonymized data may be shared for analytics or business purposes.

8. International Data Transfers

If personal data is transferred outside the EU/EEA (e.g., to the United States for OpenAI or Google services), this is done exclusively based on:
• EU Standard Contractual Clauses (SCCs)
• Adequacy decisions
• Additional security measures

9. Retention of Data

We keep personal data only for as long as necessary to fulfill the purposes described in this policy or as required by German law (e.g., tax or accounting obligations).

10. Your Rights Under GDPR

Users located in Germany and the EU have the following rights:
• Right of access (Art. 15 GDPR)
• Right to rectification (Art. 16)
• Right to erasure (“right to be forgotten”) (Art. 17)
• Right to restriction of processing (Art. 18)
• Right to data portability (Art. 20)
• Right to object (Art. 21)
• Right to withdraw consent at any time (Art. 7)

To exercise these rights, contact us at: [Contact Email]

11. Automated Decision-Making and AI Use

Our Service includes AI-powered functionality from OpenAI and Gemini.

We do not use your data for fully automated decision-making that has legal or significant effects under Art. 22 GDPR.

AI outputs are generated dynamically and may depend on the text or data you input into the system.

12. Children’s Privacy

The Service is not intended for children under 16.
We do not knowingly collect data from children. If you believe such data was collected, contact us for deletion.

13. Changes to this Privacy Policy

We may update this Privacy Policy to comply with legal requirements or service changes.
The updated version will be published on this page, and the “Last updated” date will be revised.

Users are advised to review this policy periodically.