SWIPEFILE.DESIGN
Privacy Policy
How Swipefile handles browser boards, shared links, submissions, exports, and optional analytics.
Effective and last updated: September 8, 2026Who is responsible
Neil Busque operates Swipefile at swipefile.design. For questions or requests about personal information, email busqueneil@gmail.com with “Swipefile privacy” in the subject. This policy covers Swipefile, not the independent websites and AI tools linked from the library.
What works today
The public library does not currently offer user accounts or cloud synchronization. You can browse, swipe, and save boards without signing in. Administrator sign-in is used to manage submissions and the library; it is separate from the planned public account feature.
Boards, swipe progress, and preferences
Board names, saved reference identifiers, and board timestamps are stored in your browser’s local storage. The current swipe session and recent browse state use session storage. Your theme and analytics choice are also stored on your device. Local boards are not automatically uploaded or synchronized. Clearing browser data, using a different browser, or losing access to your device can make them unavailable.
Use the board controls to remove a board or reference. Use Back up boards to download a copy before clearing browser data. Downloaded backups are files under your control; Swipefile cannot recover a local-only board for you.
Shared links and PDF exports
A shared board link encodes its board name and reference list. When someone opens that link, the snapshot reaches our server so the page can be displayed. Anyone with the link can read and redistribute it. Links may also appear in browser history, messages, or hosting request logs. They are not password-protected or revocable links. Editing or deleting the original local board does not change a previously shared snapshot or someone else’s copy.
When you request a PDF, our server processes the board name and selected references. We cache the generated PDF in private server storage to reuse it for equivalent requests. A cached PDF can contain the board name, reference list, and public board link. Private storage does not make an already shared link confidential. Contact us with the relevant link to request removal of a cached export; a later request for the same valid snapshot can generate it again. Do not put confidential or sensitive information in a shared board name.
Reference submissions and messages
The submission form collects the source URL, reference type, and any reference name or description you provide. A reference name means the title of the resource, not your personal name. Submissions are held for review and may become public if approved. Do not include personal information or private access tokens in them.
If you email us, we receive your email address, message, and attachments. We use those details to respond and handle the request. Please send only what is needed.
Service and security information
Our hosting and infrastructure providers process request information such as IP address, requested URL, time, browser information, and errors to deliver and secure the service. Submission protection uses a keyed hash of the network address to limit repeated requests. Administrator authentication uses session cookies and account records. These operational uses are separate from optional audience analytics.
Optional analytics
If you choose Allow analytics, we use Sonar, our own analytics app, for aggregate public-page visits and successful board creation, reference saves, and prompt copying. Data can include the public page path, referring site hostname, time, device/browser category, and country. Outcome events include only a page category and a broad referral category.
We remove query strings and fragments from analytics page URLs. We do not send board names, saved reference lists, search text, prompt text, or personal shared-board tokens in analytics events. Analytics are excluded from personal shared-board, submission, admin, and API routes. We do not enable session replay, advertising pixels, cross-site advertising profiles, or analytics cookies. Sonar creates a site-specific, daily-changing visitor hash from request information to count visits. This is a pseudonymous measurement, not an account identity. Swipefile does not send a persistent visitor ID, advertising click IDs, or campaign query parameters, and does not store an analytics identifier in your browser.
You can decline without losing functionality, or withdraw permission using Analytics preferences in the footer. Do Not Track and Global Privacy Control keep optional analytics off. See Cookies & Analytics.
Why we use information
We use information to provide requested features, review submissions, respond to messages, protect the service, handle rights and content requests, and—if you allow it—understand aggregate usage. Where a data-protection law requires a legal basis, these purposes rely on providing the service you request, our legitimate interests in operating and securing it, applicable legal obligations, or your consent for optional analytics. You may withdraw that consent at any time; this does not undo processing that already occurred.
We do not sell personal information or share it for cross-context behavioral advertising. Swipefile does not send your project prompt to an AI model. If you copy it into an external AI tool, that provider’s terms and privacy policy apply.
Providers, disclosure, and international processing
Vercel provides hosting and delivery for Swipefile and Sonar. Supabase provides the submission database, administrator authentication, private PDF-cache storage, and Sonar’s analytics database. Sonar is operated by Neil Busque at analytics.neilb.app. Email services process messages you send to the contact address. These providers handle information needed for their services under their applicable terms. See Vercel’s privacy notice and Supabase’s privacy notice.
Providers may process information in the United States and other countries where they operate. Protections and legal rights can differ by country. Contact us if you need information about a particular transfer or the safeguards applicable to your request. We may disclose information when required by law, to protect rights and safety, or to investigate abuse. Approved library content and intentionally shared snapshots are public as described above.
How long information remains
Local storage remains until you remove it or your browser clears it; session storage generally lasts for the browser tab’s session. Approved references remain available while they belong in the library. Submission records and related moderation history are retained as needed to review content, handle duplicates, and resolve disputes. Cached PDFs remain until removed or replaced; there is currently no automatic expiry for that cache. Contact correspondence is retained as needed to resolve your request and keep necessary records.
Infrastructure logs have provider-controlled retention. Sonar event records remain in its analytics database until removed; Swipefile does not currently promise an automatic event-expiry period. We do not promise an expiry period that the current service does not enforce. When handling deletion requests, we consider legal retention requirements and any copies or backups outside our immediate control. We will explain material limits relevant to your request.
Your choices and privacy rights
Depending on your location and the law that applies, you may have rights to access, correct, delete, receive a portable copy of, restrict, or object to the processing of personal information, and to withdraw consent. You may also be entitled to appeal a decision or complain to your local data-protection authority. Email the contact above to exercise a right or ask about a decision; we will respond within the period required by applicable law and explain any applicable exception.
We may ask for enough information to verify the request and locate relevant records, but please do not send identity documents unless a secure, necessary verification process has been agreed. We cannot retrieve local-only browser data remotely or reliably identify a person in aggregate analytics. Removing our copy cannot remove files or links independently held by other people. We will not penalize you for exercising applicable privacy rights.
Children and security
Swipefile is intended for people aged 16 and older and is not directed to children. If you believe a child has submitted personal information, contact us so we can investigate and remove it where appropriate. We use access controls and provider security features, but no service or transmission is completely secure. Avoid sensitive personal data in boards, prompts, submissions, and support messages.
Planned accounts and cloud saves
Account sign-in and cloud saving are planned, not active public features. Before launch, we will explain the account details collected, authentication providers, cloud-stored boards and swipe history, visibility defaults, retention, and export/deletion controls. This policy does not claim those controls exist today. Existing local boards will not be described as cloud-backed until synchronization is actually available.
Updates
We will revise this page when our practices change and update the effective date. Material account or data-use changes will be explained in the relevant product flow before they take effect. Where consent is required for a new optional use, we will ask for it.