Privacy policy
Last updated 1 October 2026
Schwifty is an app for making plans with your friends and their friends. This policy explains what we collect when you use the app and the website schwifty.eu, why, who else handles it, how long we keep it and what you can do about it.
Who we are
Schwifty is run by Miguel Castellano Merino, in Italy, who is the data controller until Schwifty has a company of its own (this policy will say so when it does). For anything about your data, write to support@schwifty.eu, in English, Italian, Spanish or German.
What we collect
When you sign up
- The ID Apple or Google gives us for your account, and the email address they share, if any (Apple may share a private relay address instead of yours).
- Your mobile number, which we check once with a text message. It’s never shown to anyone.
- Your first name and birthday. Your profile shows your age, never your birthday.
You need these, and at least one photo, to use Schwifty. Everything else is up to you.
What you add
- Photos, a headline, a bio, your interests, the languages you speak and your city.
- Plans you post (what, where, when, costs and who can see them), requests to join and their notes, messages in plan chats, and shared costs you add to a plan.
- Friends, friend requests, hosts you follow (nobody else sees who), groups, blocks and reports.
- Your notification settings and language.
From your phone, if you allow it
- Contacts. The app turns the phone numbers in your contacts into hashes on your phone and sends only those. We compare them with the numbers of people on Schwifty, keep the matches and discard the rest straight away. Names and other details never leave your phone.
- Location. Used to show how far away plans are, and to suggest places near you when you post one. It’s sent with those requests and never stored, not even in our logs.
- Notifications. A push token, so we can send notifications to your phone.
On the website, if you ask to join without the app
- A code derived from your mobile number (a keyed hash, never the number itself) and your note to the hosts. When you sign up with that number, your request goes to them; if you don’t, it’s deleted after 30 days.
Automatically
- For each phone you sign in on: whether it’s an iPhone or Android, its model, the app version and when it was last used.
- Your IP address, in our server logs and when you ask for a text code.
- For each text code: the number, when it was sent and the IP address that asked for it.
The app has no analytics or advertising trackers, and the website sets no cookies.
Why we use it
- To run Schwifty for you: your account and profile, plans, requests, chats, friends, groups and notifications. The legal basis is the contract between us (GDPR Article 6(1)(b)).
- To keep Schwifty safe and fair: the one-time phone check, limits on text codes and requests, checking photos, keeping blocks in place when an account is deleted, holding the age limit, handling reports, and keeping server logs. The legal basis is our legitimate interest, and yours, in a community where people are who they say they are (Article 6(1)(f)).
- To find your friends: matching the numbers in your contacts with people on Schwifty, which you can stop by turning off contacts access in your phone’s settings. The legal basis is our legitimate interest in connecting people who know each other (Article 6(1)(f)); we keep only the matches.
- To understand how Schwifty is used: counts the team looks at, such as how many plans were posted or how many people went each week, worked out from the data above. No analytics company is involved, and the counts never single anyone out. The legal basis is our legitimate interest in making Schwifty work better (Article 6(1)(f)).
- To comply with the law (Article 6(1)(c)), for example when an authority sends us a valid order.
Photos are checked automatically when you upload them, for nudity, violence and hate symbols; a photo that fails is refused, and you can try another or write to us. Reports are always looked at by a person.
We don’t sell your data, and there are no ads in Schwifty. If that ever changes, we’ll update this policy and tell you in the app first.
What other people see
- Your profile: your first name, age, photos, headline, bio, interests and languages, how you’re connected and any friends you have in common. People on Schwifty can open it when they come across you, in a plan, a group, a chat or a request. Your number, birthday, friends list and location are never shown.
- Your plans are seen by the people you choose: your friends, their friends too, or a group. Only the people who are in see the exact address; everyone else sees the area.
- When you ask to join a plan, its hosts see your profile, how many plans you’ve joined, how many times you’ve cancelled late, and your note.
- Messages in a plan’s chat are seen by everyone in the plan, including people who join later.
- Shared costs in a plan (what was spent, who paid and who paid whom back) are seen by everyone in the plan.
- On the day of a plan, whether you’re on your way, running late or there, if you say so, is seen by everyone in the plan.
- Your host level, from Regular up, shows on your profile and your plans. Your points, worked out from who came to your plans, are only for you.
- Links you share open a page on schwifty.eu for anyone who has them. It shows your first name and main photo, and for a plan its title, day and time, area, cost and how many are going: never the address, and never who.
Who else handles your data
These companies run parts of Schwifty for us. They handle data only on our instructions, under data processing agreements:
- Amazon Web Services (Amazon Web Services EMEA SARL, Luxembourg): our servers, database and file storage, in Ireland. Through AWS we also send text codes (through phone carriers), check photos (Amazon Rekognition) and search for places (Amazon Location Service, which gets what you search for and the area, never who you are). We have opted out of AWS using any of it to improve its own services. Photos are delivered through Amazon CloudFront, which keeps copies close to where they’re viewed, in Europe and North America.
- Expo (650 Industries, Inc., USA): passes our notifications on to Apple and Google. A notification’s text goes through Expo, so a chat notification includes the message.
- Apple and Google: deliver notifications to your phone. When you sign in with them, they act under their own privacy policies.
- Vercel (Vercel Inc., USA): hosts the website, and sees the IP addresses of its visitors.
- Apple (iCloud Mail): our mailbox, which keeps the emails you send us.
Where data leaves the European Economic Area, it’s protected by the EU-U.S. Data Privacy Framework (Expo and Vercel are certified under it) or by the European Commission’s standard contractual clauses.
We share data with authorities only when the law requires it.
How long we keep it
- Your account and what you add: until you delete it, or your account.
- Text codes: 90 days.
- Notifications we’ve sent: 30 days.
- Requests to join made on the website: until you sign up with that number, 30 days at most.
- Server logs, with IP addresses: 30 days.
- Reports: two years after we’ve handled them. What we decided (what we took down and why) stays as a record, no longer linked to the account once it’s deleted.
- Backups of the database: 14 days, so anything deleted is gone from them too after that.
Deleting your account
You can delete your account in the app, under You. Your profile, photos, friendships, contact matches, groups, Activity and sessions are erased straight away. Upcoming plans you host are called off, and the people in them are told; you leave the plans you joined. Your messages are erased and show as “Message deleted”. Shared costs you added or paid stay, without your name, so the others’ sums still add up. If you no longer have the app, write to support@schwifty.eu and we’ll delete your account for you.
Two things stay, as keyed hashes that only work with a secret key we hold: your phone number and your Apple or Google ID. If you come back, they put blocks back in place, both the ones you made and the ones made against you. If an under-18 birthday was ever entered on the account, that birthday is kept with them, so the age limit holds. Nothing else is kept.
Your rights
You can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, and receive it in a format you can take elsewhere. You can change or delete most of it yourself in the app. For anything else, write to support@schwifty.eu: we’ll ask what we need to know it’s you, and answer within a month.
You can also complain to a data protection authority: in Italy, the Garante per la protezione dei dati personali, or the one where you live or work.
Age
Schwifty is only for people aged 18 and over. Under-18 birthdays are refused, and we delete any account we learn belongs to someone younger.
Security
Data travels encrypted, and the database, its backups and stored photos are encrypted too. Only the people who run Schwifty can reach them. Sign-in tokens are stored only as hashes, and the app keeps yours in your phone’s secure storage.
Changes
If we change this policy in a way that matters, we’ll tell you in the app before the change applies. The date at the top says when it last changed.