SwapMatch
LegalLast updated 1 October 2026

Privacy Policy

What SwapMatch collects when you swap things, why we need it, who else ever sees it, and what you can ask us to do with it. It covers the SwapMatch app and this website.

1. Who we are

SwapMatch is a barter app built and run by the SwapMatch Team. We decide what the app collects and why, which makes us responsible for everything described here. Write to support@swapmatch.me — that address reaches the people who build the app, and it is the right place for a support question, a privacy request and a legal notice alike.

We have written this policy to the standard the European GDPR sets, and we apply it to everyone using SwapMatch, wherever they live.

The short version We collect what a swap needs: an account, your listings, the area you swap in, and the chats you have about a swap. We do not sell any of it, we run no advertising on it, and you can take a copy or delete all of it from inside the app.

2. What we collect

  • Your account — what the account you sign in with shares with us — from Google, its email address, name and profile picture; from Apple, an email address and the name you let Apple pass on, and no picture — and the date of birth you enter at sign-up. If you chose Hide My Email, the address we hold is the private relay address Apple made for SwapMatch, never your real one.
  • Your phone number — optional, and empty unless you type one in. Sign-up asks for it on the same screen as your location, and you can add, change or clear it afterwards in Profile → Menu → Edit profile. We hold it as a way to reach you if a dispute or an incident comes up around a swap, including where a public authority makes a lawful request of us; that is the whole of what it is for. We do not verify it, we send no text messages, and no other member is ever shown it. It is in the copy of your data you can download.
  • Your listings — the photos, titles, descriptions and categories of the things you offer. Photos are stripped of their embedded metadata before they are stored, so the capture coordinates a phone writes into a picture never reach us.
  • Where you swap — the place you set as yours. If you tap Use my current location, your device's coordinates are sent to us and stored. They stop there: see below for the only two things anyone else is shown.
  • Swiping and swaps — the items you passed on, the swaps you offered, and how each one ended. This is what makes the deck worth swiping and stops the same item coming back forever.
  • Your achievements — which of the app's achievements you have earned, and when each one turned. That pair is the whole of what is stored: how far along you are towards a coin you have not earned yet is worked out from the listings, swaps and messages already above, each time it is shown, rather than kept as a separate record of you.
  • Chats — the messages, photos and places you send to someone you matched with, kept so the conversation is still there when you open it again.
  • Safety records — reports you make, reports made about you, people you have blocked, and any suspension. What earns one is set out in the Community Guidelines.
  • Your device — app version, platform, operating-system version and language, plus a push token for the phone itself if you switch notifications on.
  • Usage statistics — only if you allow them, and they are described in full in the Data Tracking Policy.

We never ask for an identity document, a payment card or a bank account. There is nothing to pay for in SwapMatch, so there is nothing for us to hold.

3. Why we are allowed to hold it

European data protection law asks for a reason behind every purpose. Ours are these.

  • To run the service — your account, your listings, the deck, your swaps and your chats. Without this data there is no service to give you — it is what the Terms of Use commit us to.
  • To keep the place usable — reports, blocks, suspensions and rate limits, so that fraud, prohibited items and harassment can be acted on. This is our legitimate interest in protecting the people here, and yours in not meeting any of it.
  • To answer you — the support conversation itself, and enough context to make sense of it.
  • Because you said yes — your phone number, your device's precise location, push notifications, and usage statistics. None of it is on until you turn it on or type it in, and each can be turned back off, or cleared, without losing anything else.
  • Because the law requires it — the rare case where we must keep or hand over something. We do not go looking for reasons to.

4. What other members see

Your public profile is your first name with the initial of your surname — Marko Janković appears as Marko J. — your picture, and your town. Your email address, phone number, coordinates, street address, date of birth and swiping history are never shown to another member.

A member can open that profile from one of your listings or from a conversation. Four more things are on it: how many swaps you have settled, as a count and not a list; how long you have been here, as one rounded figure — "14 d", "6 mo.", "2 y" — which gets coarser the longer you stay and is never the date you signed up; your achievements, with when each one turned and how far along you are towards the ones you have not earned; and your things, unless you have turned them off.

There is no rating and no review on SwapMatch: nobody scores you, and nobody writes about you after a swap. The swaps behind that count, the people you swapped with, the items you passed on and when you were last in the app are shown to nobody.

Hiding your things Profile → Menu → Your data → Privacy holds the switch. It takes your collection off your profile and nothing else: your listings stay in the deck, stay matchable and stay visible to you, and a visitor is told your things are hidden rather than shown an empty shelf. The count, the time and the coins stay on the profile either way — and a collector's achievement counts the things behind the switch, so how many you have stays readable even when what they are does not.

Next to someone's item you also see roughly how far away it is — "6 km" — and that number is built so it cannot be turned back into an address. Before any distance is measured we move the owner's position to the nearest point on a two-kilometre grid, and the result is given in whole kilometres, never less than one. Measuring from three different places and comparing the answers is the obvious way to locate somebody that way, and it does not work here: every reading agrees with the same grid point, however many you take.

Everything you write or send inside a chat goes to the person you are chatting with. Treat it the way you would treat a message anywhere else, and share an address or a phone number only when you have decided to.

5. Who else touches it

We keep this list short deliberately. Each of these does one job for us, receives only what that job needs, and may not use it for anything of its own.

  • Hosting — the servers running SwapMatch and its database are in Frankfurt, Germany.
  • Photo storage and delivery — Cloudflare. Your photos are stored in their object storage in a European location, and delivered through their network, which keeps a copy near whoever is looking at one so the app is not fetching every picture from Frankfurt.
  • Google — sign-in only. Google tells us the email address, name and picture on your account; your Google password is never seen by us and never reaches the app.
  • Apple — sign-in only, on iPhone. Apple confirms who you are and tells us an email address — your own, or the relay address if you chose to hide it — and, the first time only, the name you allowed it to share. Your Apple ID password is never seen by us. Apple also gives us a token that stands for SwapMatch's access to your Apple ID; we keep it encrypted and use it for one thing only: withdrawing that access when you delete your account.
  • PostHog — our analytics provider (PostHog) — usage statistics, and only with your consent, on their European cloud in Frankfurt. The Data Tracking Policy is the detail.
  • Push notifications — if you switch them on, the push service that reaches your phone receives the device token and the notification's title. It is why a notification says a message arrived and never what it said.
  • Place names — turning your coordinates into a town name is a lookup against Nominatim, the public search service of OpenStreetMap. It receives the coordinates and nothing else — no name, no account, no device, nothing that says the point belongs to you.
  • Email — the only email we send today is our own reply when you write to us. We do not send notification emails yet; when we do, they will go out through a provider in the EU and this list will name it before the first one is sent.

Your phone also names the place for itself, through the map service built into iOS or Android, so the label appears while you are still on the screen. Beyond that: there is no advertising network in this list, no data broker, and nothing that receives your data in order to sell it on.

A phone number you have given us goes to none of the providers above. It stays on our own servers: no analytics event carries it, no notification carries it, and neither photo delivery nor a place-name lookup has any use for it.

When this changes This list is the current one. If we add a provider that handles member data, it appears here before it starts.

6. Where it is kept

Everything above is stored in the European Union: the servers and the database in Frankfurt, the photos in European object storage, the usage statistics in PostHog's European region. A photo being looked at may also sit for a while in a cache near the person looking at it — that is what a delivery network is for, and it moves a copy, never the original.

Three things reach past it, and only these three. Signing in is a conversation with Google or Apple, whichever you chose. A push notification travels through a push service in the United States — which is exactly why a notification carries a title and never the text of a message. And a place-name lookup goes to OpenStreetMap's public service, run by the OpenStreetMap Foundation in the United Kingdom. The first two run under the transfer terms in those providers' own data-processing agreements; the third is a public map service we send a pair of numbers to, with nothing attached that could say whose they are.

7. How long we keep it

  • Your account and everything on it — for as long as you have an account. Delete it and the data goes with it.
  • Your phone number — for as long as it is on your account. Clear the field and it is gone from that moment; delete the account and it goes with the rest. Removing it changes nothing else — you sign in the same way and keep everything you had.
  • Notifications — the in-app inbox holds about a month, then rolls off on its own.
  • Reports — a report stops counting towards a sanction after about three months, and is deleted with the account it was about.
  • Sign-in sessions — signing out ends the session on that phone immediately. Profile → Menu → Log out of all devices ends every session on every phone at once, this one included — for a phone you have lost, or an account someone else may have got into. A session you leave alone expires by itself.
  • Usage statistics — 84 months, if you allowed them at all; crash and error reports, 14 days. Deleting your account deletes both, and you can ask us to delete them without deleting the account — see the Data Tracking Policy.
  • Backups — we keep two weeks of daily database backups so the service can be brought back after a failure. Each one is deleted as the next fortnight's arrives.
  • Server logs — the ordinary record of requests reaching the service, kept 14 days and then deleted. What our own application writes down is smaller than that sounds: the network you came from rather than your address, and which part of the app you called rather than anything you typed into it — a search you run over your own messages is not in there.

The backups above aside, one thing outlives a deletion by design, and we would rather say so than have you discover it. If an account is suspended and then deleted, we keep an irreversible fingerprint of each sign-in identity it had — Google, Apple or both — not a name, not an email address, nothing that can be read back into a person — so that a suspension cannot be shaken off by deleting the account and signing up again a minute later. A temporary suspension's fingerprint is deleted the day the suspension would have ended; a permanent one's is deleted after two years. Nothing else survives.

8. Deleting your account

Profile → Menu → Edit profile → Delete profile. It happens immediately and it cannot be undone: your profile, listings, photos, swaps, achievements, notifications and chats are erased.

A one-to-one conversation belongs to both people equally, so deleting your account removes the whole thread for the other person too. We cannot leave your half of a conversation standing in someone else's app once you have asked to be gone.

Two things outlast the button, and we would rather name them than let "immediately" mean more than it can. Your account is still in the daily backups until they roll off, at most a fortnight — those exist to bring the service back after a failure and are never opened to look somebody up. And if the account was suspended, the fingerprint described above stays for its own term. Nothing else.

If you had allowed usage statistics, we also ask our analytics provider to delete the events recorded against your account.

If you ever signed in with Apple, we also withdraw SwapMatch's access at Apple, which takes the app off your Apple ID's list of apps using Sign in with Apple. Withdrawing it yourself from your Apple ID settings does not delete your SwapMatch account — only the button above does that.

9. What you can ask of us

  • A copy of your data — Profile → Menu → Your data → Download my data builds one on the spot, in a machine-readable format. It carries your achievements and when each one turned, and it carries your own messages: the other person's messages in a shared thread are their data rather than yours, so they are not in the file.
  • A correction — Profile → Menu → Edit profile changes what you gave us.
  • Deletion — as above — and a suspended account can still be exported and deleted. Falling out with us is not a reason to lose the right to your own data.
  • To take a consent back — the usage-statistics switch is in Profile → Menu → Your data → Privacy, notifications are under Profile → Menu → Notifications, and location access is in your phone's settings. A phone number you gave us is taken back by emptying the field in Profile → Menu → Edit profile, and nothing else about the account changes when you do.
  • To show less — the switch that hides your things from your profile is in Profile → Menu → Your data → Privacy. It is not a consent and nothing is riding on it, so flip it as often as you like — the collection comes back exactly as it was.
  • To object — if you think something we do on the grounds of our legitimate interest should not be done to you, tell us and we will look at it properly.
Where to start Most of it is a tap away in the app. Anything else: support@swapmatch.me. We answer as quickly as we can, and within a month at the outside.

If you live in the European Union or the EEA, you can also complain to the data protection authority of your country. We would rather you told us first, but it is your right and not ours.

10. How it is protected

  • In transit — every connection between the app and our servers is encrypted (HTTPS/TLS). There is no unencrypted path.
  • On your phone — the sign-in token is kept in the device's secure keystore rather than in ordinary app storage.
  • On our side — access to the production systems is limited to the people who run the service.

Chats are not end-to-end encrypted, and we would rather be plain about it than imply more than we do: a conversation can be read when a report or a lawful request makes it necessary. Nobody reads chats for any other reason, and no automated system reads them to profile you or to sell you anything.

No service is immune to going wrong. If something happens that puts your data at real risk, we will tell you and the relevant authority, as the law requires and as we would want to be told ourselves.

11. Adults only

SwapMatch is for people aged 18 and over. The app asks for your date of birth before it asks for anything else, and an account that does not clear that gate is not created. If we find out an account belongs to someone younger, we delete it.

12. Changes to this policy

The date at the top of this page is the version you are reading. When we change something that affects what we do with your data, we will say so here, and we will tell you before the change takes effect rather than after.

13. The language of this policy

This policy is written and published in English, and English is the only version we stand behind. We publish no official translations, and a translation — your own, your browser's, or one we send you as a courtesy — has no legal effect and cannot be relied on against the English text.

The app itself speaks six languages; these documents do not. If English is difficult, ask us for a translation at support@swapmatch.me and we will send one to help you read it. The English version still governs.

14. Contact

Any question about this policy, and any request about your data: support@swapmatch.me. Related reading: the Data Tracking Policy, the Terms of Use and the Community Guidelines.