Privacy policy
Last updated: 11 August 2026
This explains what AppSwappers stores about you, why, and who else gets to see it. It describes what the software actually does — not a generic template.
1. Who is responsible
The controller for data processing on this website and in the app under the General Data Protection Regulation (GDPR) is:
2. The short version
- We store what we need to run an exchange between developers: your account, your app listings, and the tests you took part in.
- We do not use analytics, advertising pixels, or tracking cookies. That is why you do not see a cookie banner here.
- We never sell your data and we never pass it on for advertising.
- Screenshots you upload as proof are checked by an AI service. That is the one place where your data leaves the EU — details in section 6.
- Other users never see your email address.
3. Data you give us
When you create an account we store your name, your email address and your password. The password is only ever stored as a cryptographic hash — we cannot read it, and neither can anyone who gets hold of the database. Optionally you may add a profile picture.
If you signed up through an invitation, we store the invite code you used and who invited you, so the referral bonus can be credited to the right account.
Legal basis: Art. 6 (1) (b) GDPR — this data is required to provide the service you signed up for.
4. Data we collect automatically
When you are signed in, we store your session together with the IP address and the browser identification (user agent) it was created from. This lets you stay logged in, and it lets us recognise stolen sessions and abusive accounts.
Our web server keeps standard access logs (IP address, time, requested address, status code) for a short period for security and troubleshooting.
Legal basis: Art. 6 (1) (b) and (f) GDPR — providing the service, and our legitimate interest in operating it securely and keeping abuse out of an exchange that only works on trust.
5. Content you create in the app
- App listings: the Google Play link, package name, title, developer name, icon and category of the apps you list.
- Tests: which app you tested and when, the proof screenshot of your install, your star rating, your written feedback, and the screenshot of the review you left.
- Points: your balance and the history of how it changed.
- Messages: direct messages you send to other users. Deleting a conversation hides it for you — the other person keeps their copy.
- Support tickets: the subject and message you send us, and our answer.
- Moderation: if an administrator adjusts points or restricts an account, that action is logged with a reason.
We also store a fingerprint (hash) of every uploaded screenshot. That is how the same screenshot cannot be submitted twice for different apps.
Legal basis: Art. 6 (1) (b) GDPR.
6. The AI check on your screenshots
When you upload a screenshot as proof of an install or of a review you left, it is converted to a compressed image and passed to a specialised provider in the United States for an automated check by an AI model. The model is given one narrow task: decide whether the picture really shows what it is supposed to show.
- Do not put anything in the screenshot that you do not want to leave the EU. Crop out notifications, private messages and anything unrelated.
- The AI cannot award points, change your balance or touch the database. It only returns a yes or no; the server decides what follows.
- The answer it gave is stored with your test session, so the app owner can see on what basis a proof was accepted or rejected.
- If the service cannot be reached, the check fails closed — nothing is approved automatically.
Transfer to a third country: the United States does not have an adequacy decision covering every recipient. The transfer is based on the standard contractual clauses under Art. 46 (2) (c) GDPR.
Legal basis: Art. 6 (1) (b) GDPR — verified proof is the core of the exchange. Without a check, points could be earned without ever installing anything, and the whole system would be worthless to everyone using it honestly.
7. Who else processes data for us
We work with a small number of specialised providers. They act only on our instructions and under data processing agreements. These are the categories, and what each one gets to see:
- Hosting, in Germany — the server the app and this website run on. Your account, your listings and your tests are stored here, inside the EU.
- Backup storage, in Germany — encrypted daily copies, so nothing is lost if a disk fails.
- Email delivery, in the EU — sends address confirmations, password resets and notifications. Receives your email address and the content of that message.
- Automated image checking, in the United States — the screenshot check described in section 6. This is the only recipient outside the EU.
Beyond these, we pass your data on only if we are legally required to do so. We do not sell it and we do not share it for advertising.
Want to know exactly which companies these are? Just ask. You have a right to that information under Art. 15 GDPR and we will name them for you — we simply do not list every supplier on a public page.
8. Cookies
We set exactly one kind of cookie: the one that keeps you signed in. Without it, the app cannot tell one request from another and you would be logged out on every click. There are no analytics cookies, no advertising cookies and no third-party cookies.
Because we only use strictly necessary cookies, no consent banner is required (§ 25 (2) no. 2 TDDDG). We consider that a feature.
9. What other users can see about you
Your public profile shows your display name, when you joined, and the apps you have listed. Developers whose apps you tested additionally see your feedback, your rating and your proof screenshot.
Your email address is never shown to anyone else. It is not merely hidden in the interface — the public profile query does not read it from the database at all. The only place you see your own address is your own settings page.
10. How long we keep things
- Proof screenshots: deleted from the server after 14 days. The record of the test stays — the developer keeps seeing who tested, the rating and the written feedback, just not the image.
- App listings: expire 30 days after they were listed.
- Closed support tickets: deleted 90 days after they were closed.
- Account data, tests, points and messages: for as long as your account exists.
- Backups: encrypted copies may still contain deleted data for a limited period until they are rotated out.
When you delete your account, the data belonging to it is deleted with it. Where information has to be kept because the law requires it, it is blocked from further use instead.
11. Your rights
You can, at any time and free of charge:
- ask what data we hold about you (Art. 15 GDPR),
- have incorrect data corrected (Art. 16 GDPR),
- have your data deleted (Art. 17 GDPR),
- have processing restricted (Art. 18 GDPR),
- receive your data in a portable format (Art. 20 GDPR),
- object to processing based on our legitimate interest (Art. 21 GDPR),
- withdraw a consent you gave, with effect for the future.
One email to bennto23@gmail.com is enough. You do not need to give a reason.
12. Complaints
If you think we are handling your data wrongly, you can complain to a data protection authority. The one responsible for us is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98, 24103 Kiel, Germany
We would appreciate the chance to sort it out directly first — but you are under no obligation to ask us before going to them.
13. Changes to this policy
If we change how the app processes data, we update this page and move the date at the top. If a change materially affects you, we tell you in the app rather than quietly editing this text.
See also our legal notice and terms of service.