Privacy policy
Last updated 20 August 2026 · Alan Wizemann, LLC · hello@swiftstats.co
Two kinds of data
There is data about you, our customer, and data your apps send us about their own usage. They are handled differently and stored separately.
Data about you
Your email address, so we can sign you in and contact you about the service. When paid tiers launch, payment details will be held by Stripe, not by us. Sign-in rate-limit records store an HMAC of your address and IP rather than either value in the clear, so the table holds nothing readable.
Data your apps send
Event names, counts, timestamps, flat properties you choose, a session id, a salted hash install id, app version, OS version, device model and locale. No IP addresses are retained with events. No advertising identifiers are collected at all. Nothing links one app to another. If your app calls identify(), the value you pass is hashed on the device before it is sent, so we never hold it in the clear. See the privacy and data handling page for the full list, including what the schema forbids outright.
This website
No cookies, no analytics scripts, no third-party embeds on the marketing site. It stores one thing on your device — your light/dark theme choice, in localStorage — and that never leaves the browser. The app sets one session cookie after you sign in, which is strictly necessary to keep you signed in. If you use the contact form, it collects the name, email address and message you type and mails them to hello@swiftstats.co so we can reply; the form also holds your IP address in memory for about ten minutes to rate-limit submissions, and it is never written to storage.
Where it lives, and who else touches it
The site, the app and the ingest API run on Cloudflare Workers; your data is in a Cloudflare D1 database, and sign-in email goes out through Cloudflare. When paid tiers launch, payments will run through Stripe, which will hold your card details rather than us. Cloudflare and Stripe are our only subprocessors; nobody else is sent your data.
How long
Raw events for 90 days — the default window and the shortest we run. Daily rollups indefinitely, unless you delete the app, which deletes both. Account records until you ask us to delete the account, after which they go within 30 days.
Your requests
Email hello@swiftstats.co to see, correct, export or delete what we hold about you. One caveat worth stating plainly: because install ids are salted hashes and we hold no personal identifiers, we cannot locate one of your app's end users on request — there is nothing in our data that points at a person.
Children
The service is for app developers and is not directed at children.
Changes to this policy
Material changes will be announced by email and dated at the top of this page. Questions about anything here: hello@swiftstats.co.