Swage Privacy Policy (public beta)

Draft, not a legal opinion. Written from the review in

docs/legal/LEGAL-SCAN-2026-09-28.md, without a lawyer. The owner

decided 02.10.2026 not to bring in a lawyer (docs/DECISIONS.md,

"юрист не привлекается"). The open points below are decided by the

orchestrator instead: docs/legal/DECISIONS-LEGAL-2026-10-02.md.

Effective from: [OWNER: publication date].

Left blank for the owner

data.

02.10.2026).

LEGAL-SCAN section 4.2, "lawyer only": whether a representative is

needed and who it would be.

(docs/HOSTING-OPTIONS-2026-09-28.md).

back to a file spool (src/smartetl/mail.py:26-29). A real

provider (Resend or another, docs/DECISIONS.md "mail, DNS, Resend:

later") has not been chosen.

now shows a news list instead of a subscription form

(docs/landing/index.html, section #news). A newsletter signup is

planned but not live, so this row describes a future feature.

(Umami) only runs once these build variables are set

(O2, scripts/build-landing.sh). Until then there is no analytics

script at all.

1. Who processes the data

Operator: [OWNER: full name], sole proprietor (osek) registered in Israel, No. [OWNER: registration number], [OWNER: registered address]. Contact

for data questions: ask@useswage.com.

2. What data, why, for how long, on what legal basis

DataPurposeRetentionLegal basis (GDPR)
The uploaded file and its contentRun the conversion job the user asked forDeleted as soon as processing no longer needs it. The result no later than the job's retention period (default 24 hours, src/smartetl/store.py:1167, ttl_hours)performance of a request made by the user (GDPR art. 6(1)(b))
E-mail address, if given to be notified a job is doneSend one e-mail when the job finishesStored with the job, deleted on the same schedule as the job. Never reaches the output and is never written to the intake log beyond the fact that a send happened (src/smartetl/mail.py:20-24)consent when the address is given, otherwise performance of the request (GDPR art. 6(1)(a) or (b))
E-mail address left for the project newsletter (planned, the page currently shows a news list with no signup form, docs/landing/index.html)Send news and updates about the serviceUntil unsubscribed or consent withdrawn. A working unsubscribe link in every e-mailconsent (GDPR art. 6(1)(a))
Text and optional contact in a "Send for review" report / "something's wrong" complaintStudy why reading the file failed30 days (src/smartetl/feedback.py:36, KEEP_DAYS), then deletedconsent (an explicit user action)
Messages in the on-site chatReply to the user30 days (src/smartetl/chat.py:53), then deletedconsent
A file kept beyond the normal schedule, for studying a failureUnderstand why a conversion failedUntil the study is done, then deleted, and only with the user's separate, explicit permission for that one file (docs/handoff/L1-dev.md)explicit, separate consent for each such case
Anonymised statistics (job count, formats, object counts, verification outcome)Understand load and quality. Not linked to any file or userNot tied to the source data, no separate time limitlegitimate interest in operating the service
swage_ask cookieAvoid asking for a review on the same job more than once per 30 days. Holds no e-mail, job number, or name (src/smartetl/reviewrequest.py:12-23)Until the cookie expires (long-lived: the 30-day rule inside it is what actually limits repetition, src/smartetl/reviewrequest.py:68-69)legitimate interest / strictly necessary function
Admin login session cookieTell a signed-in administrator apart from an ordinary visitor. Does not affect regular usersFor the session's durationlegitimate interest of the operator

What is not collected: the service does not process payment: the

donate button, when configured, links to a third-party address

(src/smartetl/jobpage.py:192-207). There are no accounts or

passwords (docs/landing/PRODUCT-BRIEF.md, "Status").

3. What the service does NOT do with your data

requested.

anywhere, we only look at it, then delete it, never pass it to

anyone, and derived files too are deleted", docs/DECISIONS.md,

2026-09-10. Restated 2026-09-24: "we never store the data itself

anywhere... the final data only exists in your own copy").

and only once they are confirmed by statistics across many files.

The user's own data never becomes part of a rule (owner: "we don't

take their data, we take rules, and only if they're confirmed by

statistics", docs/DECISIONS.md, 2026-09-23).

separate permission and deleted once the study is done.

4. Data transfers

surveyed in docs/HOSTING-OPTIONS-2026-09-28.md, no decision yet).

processors (hosting, mail).

5. Cookies

Checked against the code on 2026-10-01 (src/smartetl/web.py,

webpage.py, simple.py, jobpage.py, intake.py, admin.py,

l10n.py, reviewrequest.py, via a grep for Set-Cookie/cookie):

account, Hobby plan, EU region (script

https://cloud.umami.is/script.js, website id

cdc2b8d0-d8d7-4503-88fd-c45d25f947b2, live since 2026-10-02). It sets

no cookies and stores no IP addresses. Data is processed by Umami

Software, the service provider, in the EU region. It will also be

used on the working stand (app.useswage.com) later, with job URLs

anonymised to /job/:id and downloads not tracked.

docs/legal/PRIVACY-ru.md: it uses Yandex.Metrica behind a consent

banner, which EN visitors do not see.

a last-shown date, limits how often a review is asked for

(src/smartetl/reviewrequest.py).

administrator, does not affect ordinary users

(src/smartetl/admin.py).

(docs/legal/DECISIONS-LEGAL-2026-10-02.md, point 1) -- it carries no

personal data, is never used for tracking or advertising, and serves

one narrow technical purpose (not asking for a review on the same

job more than once per 30 days), closer to the "remembers a

dismissed message" / interface-customisation category that common

regulator guidance treats as not requiring a banner.

6. Your rights

You may:

immediately. Stopping an address being given on your next job

withdraws consent for the completion e-mail. Unsubscribing from

the newsletter works through a link in every e-mail, once that

feature is live.

with a supervisory authority.

Because the service keeps no accounts, most of these rights are

already met automatically by the retention schedule: job data is

deleted once its period ends, without anyone having to ask. For a

request outside that schedule (for example, deleting a letter still

sitting in the mail spool), contact ask@useswage.com.

7. GDPR specifics

under GDPR by art. 3(2) regardless of the beta being free

(LEGAL-SCAN, section 4.2).

separate, unticked checkbox, a working unsubscribe link in every

e-mail, no bundling with any other consent or with these terms.

02.10.2026 not to claim the "occasional processing" exemption under

art. 27(2)(a): the service processes EU users' data as an ongoing

part of a regularly offered service, not occasionally, so the

exemption is unlikely to apply (docs/legal/DECISIONS-LEGAL-2026-10-02.md,

point 4). Appointing a representative is an administrative step for

the owner, not resolved as of publication.

files contain third-party personal data, the operator will sign a

separate, reasonable data-processing agreement. Until then the

general terms of this policy and of docs/legal/TERMS-en.md apply

(decided 02.10.2026, docs/legal/DECISIONS-LEGAL-2026-10-02.md,

point 2).

see docs/legal/PRIVACY-ru.md and docs/legal/RKN-CHECKLIST.md.

8. Changes to this policy

This policy may be updated as the service develops. The date of the

last change is shown at the top.

9. Contact

For data questions: ask@useswage.com.

Review status

The owner decided 02.10.2026 not to have this document reviewed by a

lawyer (docs/DECISIONS.md, "юрист не привлекается". The original

recommendation was in docs/legal/podpiska-152fz-2026-10-02.md,

"Дополнительно"). The open legal points that were waiting on a lawyer

are now decided by the orchestrator:

docs/legal/DECISIONS-LEGAL-2026-10-02.md. This remains a draft, not a

legal opinion. The owner answers any regulator inquiry himself as it

comes up.

← back to the beta page