Back to Login

Privacy Policy

Last updated: September 19, 2026

This policy explains what information Swentel collects when you use the service, how we use it, and the choices you have. Swentel is operated by Aswani Dammalapati (“we”, “us”), who is responsible for your information and can be reached at the contact address in section 13.

1. Information we collect

  • Account information: your phone number (used to sign you in), your display name, and a profile photo or email address if one is associated with your account.
  • Messages and conversations: the people in each conversation, message timestamps, read status, reactions, and the message text. Message text is encrypted on your device before it is stored (see section 5).
  • Photos: photos you send in chats (encrypted on your device before upload; we strip location and other metadata) and the profile picture you choose to upload.
  • Presence: whether you are online and when you were last seen, so others in your conversations can see it.
  • Blocking: the list of users you have blocked.
  • Encryption keys: your public key and an encrypted copy of your private key, used to protect your messages and let you access them from more than one device.
  • Technical data: basic request data such as IP address and browser type, which our hosting and authentication providers process to deliver and secure the service.

We collect this information directly from you and from your use of the service.

2. How we use it and why

We use this information to verify your identity, deliver messages, show who is in a conversation and whether they are online, prevent abuse and fraud, keep the service secure, and comply with the law. We do not sell or share your personal information for advertising, and we do not show advertising.

Where the law requires a legal basis (for example in the European Economic Area and the UK), we rely on:

  • Contract: to provide the service you asked for, such as signing you in and delivering messages.
  • Legitimate interests: to keep the service secure and prevent abuse.
  • Legal obligation: to respond to valid legal process.
  • Consent: where we ask for it, which you can withdraw at any time by deleting your account.

3. What other users can see

Other signed-in users can find you by name or email and can see your display name and profile picture, so choose a picture you are comfortable sharing. People in a conversation with you can see your messages in that conversation, your online status, and when you have read their messages. Your phone number is not shown to other users.

4. Sharing and service providers

We do not sell your data. We rely on trusted providers who process data on our behalf:

  • Google Firebase: authentication, SMS verification codes, database and file storage.
  • Google reCAPTCHA: protects sign-in from automated abuse.
  • Vercel: website hosting.
  • Cloudflare: domain registration and DNS.

Your data may be processed in the United States and other countries where these providers operate. Where data leaves the EEA or UK, we rely on the safeguards our providers offer, such as Standard Contractual Clauses or the EU-US Data Privacy Framework. We may also disclose information when required by law, as described in our Terms of Service.

5. How messages are protected

Message text and photos are encrypted on your device before they are sent, and all traffic uses HTTPS. Profile pictures are not encrypted, because other users need to see them. Stored data is also encrypted at rest by our infrastructure providers.

Swentel does not currently provide end-to-end encryption in the strict sense. To let you use your account on any device, the key that protects your encryption keys is derived from your account rather than from a secret only you hold. This means that someone with administrative access to our database could technically decrypt message content. We do not read your messages, and access to production data is restricted, but you should not rely on Swentel for information that must remain secret from the service operator.

If we become aware of a security incident that affects your personal information, we will notify you and the relevant authorities as required by law.

6. Cookies and local storage

We use one strictly necessary cookie to remember that you are signed in, and your browser's local storage to keep your encryption key and small interface preferences. We do not use advertising, analytics or cross-site tracking cookies, and we do not respond to “Do Not Track” signals because we do not track you across sites.

7. Retention and deletion

We keep your information for as long as your account exists. You can delete your account at any time from Settings → Delete account, after confirming with a code sent to your phone. Deleting your account permanently removes your profile, profile pictures, sign-in, encryption keys, presence record and every message and photo you sent, removes you from all conversations, and deletes conversations where you were the only member.

The following may remain after deletion:

  • Messages and photos that other people sent to you, which stay in their conversations.
  • Anonymous technical references to your former account ID, such as read receipts, reactions, or being listed as a group's creator. These no longer identify you once your account is gone.
  • Copies held by our providers in backups and security logs for a limited period, and SMS delivery records kept by phone carriers and Google according to their own policies.
  • Information we must keep to comply with the law or to resolve disputes.

8. Your rights

Wherever you live, you can:

  • Download a copy of your data: Settings → Download my data.
  • Delete your account and data: Settings → Delete account.
  • Correct your name: Settings → Edit profile.
  • Ask us to access, correct, restrict or stop processing your information, or ask about anything else in this policy, by emailing us at the address in section 13.

We will respond within 30 days (45 days for California requests, extendable as the law allows). We may need to verify your identity first. If you are in the EEA or UK and are unhappy with our response, you can complain to your local data protection authority.

9. Additional information for U.S. residents

In the past 12 months we collected the following categories of personal information described in the California Consumer Privacy Act (and similar state laws): identifiers (phone number, display name, account ID, IP address), internet activity related to using the service (presence and read status), and the contents of messages you send within the service. We collect them for the purposes in section 2, from you directly, and disclose them only to the service providers in section 4.

We do not sell or share personal information for cross-context behavioral advertising, and we use message contents only to provide the service. You have the right to know, access, delete and correct your personal information, and to not be discriminated against for exercising these rights. To use them, use the in-app tools in section 8 or email us. An authorized agent may make a request for you with your written permission.

10. Children

Swentel is not for anyone under 16. If we learn that we have collected information from a child under 16, we will delete it.

11. Legal requests

We may disclose information if required by law or to respond to valid legal process, as described in our Terms of Service.

12. Changes

We may update this policy from time to time. The “Last updated” date above shows the latest version, and we will notify you of significant changes where appropriate.

13. Contact

Questions, requests or complaints? Email Aswani Dammalapati at support@swentel.com.

See also our Terms of Service.