Security

Security and data handling

How Swoosh protects your files and personal data, feature by feature. This summarises what actually happens to your data; for the full legal detail — lawful bases, international transfers, retention and your rights — see the privacy policy.

1. How your data is handled, by feature

Different features touch your data in very different ways. Here is exactly what happens with each.

PDF tools (compress, merge, split, rotate, convert, combine, HEIC to JPG) run entirely in your browser using WebAssembly. The file never leaves your device and is never uploaded to us — there is no server round-trip to intercept.

Large-file transfer uploads your file over an encrypted connection and stores it encrypted at rest. It is shared only through the link you send, and is deleted automatically when that link expires — 7 days on the free tier, up to 90 days on Pro.

OCR and the AI readers (image to text, handwriting, receipts, tables and other readers) send the image or its text to our AI provider to be read, then return the result to you. It is kept no longer than needed to do the job, and is never used to train any model.

Translate and summarise send the extracted text to the same AI provider to be translated or summarised, then return it. The same rules apply: not trained on, and not kept beyond the task.

2. Encryption

All traffic to and from Swoosh is encrypted in transit with HTTPS (TLS). Transferred and stored files are encrypted at rest. Card details are handled entirely by Stripe, our PCI-DSS-compliant payment processor; we never see or store them.

3. Deletion and expiry

Transfers delete themselves automatically when their link expires: 7 days on the free tier and up to 90 days on Pro. Text handled for OCR, translation and summarisation is not retained beyond the moment it takes to return your result. At the model level, our AI provider deletes API content within about 30 days (or retains nothing on zero-retention endpoints).

4. We never train on your content

We do not use your files, images or extracted text to train any model. Our AI provider's API terms state that content sent through their API is not used to train their models by default. The transfer feature does not send your files to any AI model at all.

5. Processors we use

We rely on a small set of carefully chosen processors, each under written data-processing terms: Cloudflare (hosting, edge delivery, file storage and database), Clerk (accounts and sign-in), Stripe (payments), OpenAI (the models behind OCR, summarisation and translation), Resend (transactional email, such as transfer notifications) and Plausible (cookieless, aggregate analytics). We do not sell your personal data. The privacy policy sets out the lawful basis, international-transfer safeguards and retention period for each.

6. Reporting a security issue

If you believe you have found a security vulnerability, please email [email protected] with the details. We take reports seriously and will respond promptly. Please give us a reasonable chance to investigate and fix an issue before disclosing it publicly.