Introduction and scope
This privacy policy explains how Swatted collects, uses, stores, shares, and protects personal information when you use the Swatted.how website, the Swatted dashboard, and the Swatted Discord bot and server (together, “the service”). It also explains the choices you have and the rights you can exercise.
We wrote this policy to be read, not skimmed past. It describes what the service actually does today, in plain terms, rather than listing everything a service like ours could in theory do. Where something depends on how you use the service, we say so. Where we keep something for a fixed period, we give the period. Where there is no fixed period yet, we say that too.
This policy applies to:
- visitors to the public pages of Swatted.how;
- people who create a Swatted account, verify it through Discord, and use the dashboard;
- members of the Swatted Discord server who interact with the Swatted bot;
- anyone who submits a removal request or contacts us about their information.
This policy does not cover the privacy practices of Discord or any other third-party service, even when you reach it through a link on Swatted. Those services have their own policies, and we encourage you to read them. It also does not replace our Terms of service or our Acceptable use policy, which set out the rules for using Swatted. Read together, those documents describe how the service works and what we expect from each other.
When we say “Swatted”, “we”, “us”, or “our”, we mean the operator of the service described in the next section. When we say “you”, we mean the person using the service or whose information we process. “Personal information” means information that identifies you or could reasonably be linked to you.
Who we are
Swatted is operated by the owner of Swatted.how, who decides why and how the personal information described in this policy is processed. In the language of data protection law, the operator is the controller of that information.
Swatted is a private, account-based exposure lookup service. Signed-in users can search by username, email address, phone number, or IP address, see matching records with sensitive fields masked, and spend reveal credits to see a full record. Every account must be linked to a verified Discord identity, and access depends on staying a member of the Swatted Discord server.
We do not currently offer an email address for privacy matters. The way to reach us is through Discord: join the Swatted Discord server, then send a direct message to the owner. The Contact section at the end of this policy explains exactly how, and the Contact page has the current details.
Search records and your account data
Swatted handles two very different kinds of data, and it helps to keep them apart when reading this policy.
Search records
The first kind is the searchable dataset: the records that come back when you run a search. These records are compiled from data sets we assemble, and they vary in age, accuracy and completeness. A record may be out of date, incomplete, or wrong, so it should be treated as a lead to verify rather than proof about anyone. Each record carries a source label that is shown to you before you reveal it, so you can see where a record says it comes from. Some fields in a record, such as a password or an IP address, stay masked until you spend a credit to reveal them.
If you come across a record that appears to describe you, you can ask us to review and remove it. See Removal requests for how that works.
Your account and usage data
The second kind is the information we hold about you as a user of the service: your account details, your linked Discord identity, what you search for and reveal, the credits you spend, the devices you sign in from, and the security records we keep to protect your account and the service. This is real personal information, and it is what the rest of this policy is mainly about.
These two kinds of data are stored separately. Searching for something does not add you to the searchable dataset, and your account information is never returned as a search result to other users.
Information you give us
Most of the personal information we hold comes directly from you, when you create an account, use the dashboard, or contact us.
When you create an account
- Email address. Used to identify your account and to sign in. We store it in lowercase so that the same address cannot be registered twice with different capitalization.
- Password. You choose a password of at least 8 characters. We never store the password itself. We store only an Argon2id hash of it, which lets us check a password you enter without being able to read it back.
When you verify your account
After sign-up we show you a single-use verification code that begins with swatted.how_. You enter that code into the Swatted bot in our Discord server. This links your Swatted account to your Discord account. We describe what we receive from Discord in Information from Discord.
When you use the service
- Search queries. The text you search for, the type of search (username, email, phone, or IP), and a normalized version of the query used to match records.
- Reveals. Which records you choose to reveal, and the search that led to each reveal.
- Recovery codes. If you generate recovery codes, we show you ten codes once and keep only keyed hashes of them, so we can check a code without storing it in readable form.
- Account actions. Choices you make on your account page, such as revoking a session, revoking a trusted device, exporting your data, or deleting your account.
When you contact us or make a request
- Removal requests. The record you are asking about (if you give one), your reason, any explanation you add, and any contact details you choose to provide.
- Messages. What you send us when you contact the owner on Discord, and any information you share to help us handle your request.
We ask you not to send us more than a request needs. In particular, never send us your password or your recovery codes. We will never ask you for them.
Payment information
Paid plans are shown on our pricing page but are not active in this version of the service, and there is no checkout. We do not collect payment card details or billing addresses. If that changes, we will update this policy before paid plans go live.
Device and connection data
Like most online services, Swatted receives some technical information automatically whenever your browser talks to our servers. We use a narrow set of it, for the purposes described in this policy, mainly keeping accounts secure and preventing abuse.
The device and connection data we collect includes:
- the type of browser and operating system you use, kept as a short summary such as “Chrome on macOS” rather than your full browser signature;
- your IP address, together with approximate location and network details derived from it, such as country, region, network provider, and whether the connection appears to come from a hosting provider, VPN, proxy, or mobile network;
- the date and time of sign-ups, sign-ins, searches, reveals, and other account events;
- session identifiers that keep you signed in, and trusted-device identifiers for devices you approve;
- how you signed in (with a password, through Discord, or after a login approval) and when a session was last used.
We collect this information when you sign up, sign in with a password or with Discord, complete a login approval, set up recovery codes, run a search, or reveal a record. Staff actions in the admin tools are recorded the same way.
The approximate location and network details are worked out on our own systems in the current version of the service. They are approximate by design: at most a city-level estimate, and sometimes only a country. We do not collect precise location, and the site does not ask your browser for location access.
We do not use device fingerprinting. Trusted devices are recognized by a random secret stored in a cookie on that device, not by building a profile of your hardware or browser.
Our hosting and network providers may also process connection data, such as request details, as part of delivering and protecting the service. See How we share information.
Information from Discord
Discord is central to how Swatted works. Every account must be linked to a Discord identity, and the Swatted bot runs in our Discord server. This section explains what we receive from Discord and what we do with it.
When you verify
When you submit your verification code to the Swatted bot, we receive and store your permanent Discord user ID, your Discord username, your display name, and a reference to your avatar image. We record when the identity was verified and when it was last seen. The Discord user ID is what we rely on to identify you. We never rely on your username or display name for that, because those can change.
When you sign in with Discord
If you choose to sign in with Discord, Discord asks you to approve a request for the basic “identify” permission. We use it only to read your Discord user ID and match it to your linked Swatted account. We do not request access to your email address through Discord, your servers, your friends, or your messages, and we do not keep the access token Discord issues for the sign-in.
Server membership
The Swatted bot can see who joins and leaves the Swatted Discord server. We use this to keep access in line with membership: if a verified user leaves the server, their account is suspended and their sessions are signed out. If they rejoin and nothing else prevents it, access is restored and the verified role is added again. The bot also manages roles in our server, such as the verified role, and applies moderation actions in the server that match actions taken on the website.
Messages from the bot
The bot may send you direct messages on Discord, for example:
- a confirmation when your account is verified;
- a login approval request, with Approve and Deny buttons, when someone signs in from a new device;
- updates on the status of a removal request you submitted.
If your direct messages are closed, those messages may not reach you. We do not read your other Discord messages.
Bot commands
Some features are available through bot commands in the server. For example, /usage shows your current limits, and /removal lets you open a removal request. When you use a command, we process your Discord user ID and what you enter, to carry out the command. Replies to these commands are visible only to you.
Discord processes your information under its own privacy policy. We have no control over how Discord handles data on its platform.
Cookies, sessions and similar technologies
Swatted uses a small number of cookies. All of them are strictly necessary for the service to work or to keep it secure. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies, so there is nothing to opt into or out of for those purposes.
The cookies Swatted sets are:
- Session cookie (
sw_session). Keeps you signed in. It holds a random token, and we store only a keyed hash of that token on our side. It lasts up to 30 days, unless you sign out or the session is revoked sooner. - Trusted-device cookie (
sw_trust). Set after you approve a sign-in from a new device through Discord, so that the same device does not need approval every time. It lasts about 30 days and can be revoked from your account page. - Pending sign-in cookie (
sw_pending_login). Links your browser to a login approval that is waiting for your decision on Discord, so only the browser that started the sign-in can finish it. It lasts up to 10 minutes and is cleared once used. - Discord sign-in cookie (
sw_oauth_state). Protects the “Sign in with Discord” flow against forged requests. It lasts up to 10 minutes.
All of these cookies are marked HttpOnly, which means scripts running in the page cannot read them. They use the SameSite=Lax setting, which limits when they are sent with requests from other sites. In production they are only sent over encrypted connections.
The network provider that sits in front of the site may set its own short-lived cookies that are strictly necessary to protect the service from automated abuse. These are not used for advertising.
Browser storage
The public site and the dashboard do not use your browser’s local storage to track you. The only item Swatted keeps in local storage is a display preference in the staff admin tools.
Managing cookies
You can clear or block cookies in your browser settings. Because the cookies above are needed for signing in and for account security, blocking them will stop you from signing in or from completing a login approval.
How we use information
We use the information described above for these purposes:
- To provide the service. Creating and running your account, signing you in, verifying your Discord identity, running your searches, showing matches, revealing records you choose, keeping your history, and showing you your usage and remaining credits.
- To enforce plan limits. Counting your searches and reveals against the daily and weekly limits of your plan.
- To keep accounts secure. Recognizing trusted devices, asking for Discord approval when a sign-in comes from a new device, letting you see and revoke your sessions and devices, and supporting account recovery.
- To prevent and investigate abuse. Applying rate limits, detecting patterns such as many accounts created from the same network, investigating misuse of the service, and enforcing our Terms of service and Acceptable use policy, including through suspensions and bans.
- To keep access tied to membership. Checking that verified users remain members of the Swatted Discord server, and keeping roles in the server in step with account status.
- To handle your requests. Responding to messages, processing removal requests, providing data exports, and carrying out account deletion.
- To communicate with you. Sending the service messages described in Information from Discord.
- To meet legal obligations. Keeping records we are required to keep, and responding to lawful requests.
- To maintain and improve the service. Fixing problems and understanding, at an aggregate level, how the service is used, for example the total number of searches in a day, using the data we already hold.
We do not use your information for advertising, we do not build marketing profiles, and we do not sell or rent your information to anyone.
Legal bases for processing
Where applicable data protection law requires a legal basis for processing personal information, we rely on the following.
- Performance of a contract. Most of what we do is needed to provide the service you signed up for under our Terms of service: your account, sign-in, Discord verification, searches, reveals, limits, history, exports, and deletion.
- Legitimate interests. We process some information because we, our users, and the public have a legitimate interest in a service that is secure and not misused. This covers device and connection data, security and audit records, rate limiting, abuse investigation, moderation, and keeping records after an account is deleted so that bans cannot be dodged by starting over. We balance these interests against your rights, and we limit what we collect and how long we keep it for that reason.
- Legal obligation. We may process or keep information where the law requires it, for example to respond to a valid legal request or to keep records of how we handled a rights request.
- Consent. Where applicable law requires your consent for a particular use, we will ask for it first, and you can withdraw it at any time. We do not currently rely on consent for any cookie, because every cookie we set is strictly necessary.
Where we rely on legitimate interests, you can object to the processing. See Your rights.
Searches, reveals and history
Searches and reveals are the core of Swatted, so we want to be specific about what happens to them.
What we record for each search
Each time you run a search, we record the text you searched for, a normalized version of it, the search type, the number of results, and the time. We also keep a security record of the search with the search type, result count, and page, tied to a keyed reference for the network it came from.
What we record for each reveal
Each time you reveal a record, we record which record it was, the search it came from, the time, and a request identifier that stops the same reveal from being charged twice. When a reveal uses a credit, we add an entry to your credit history.
Where you can see this
Your search history and your revealed records are shown to you in the dashboard, so you can find past results again without searching or paying twice. The same information is included in your data export.
Why history cannot be edited
You cannot delete individual searches or reveals. This history is part of how we keep the service safe: it lets us enforce limits, investigate misuse, and respond when a lookup service like ours is used against someone. Keeping an accurate record of who searched for what is one of the strongest protections we have against abuse. We explain how long we keep it in Retention.
Who can see your searches
Other users cannot see your searches or reveals. Authorized administrators can view search and reveal activity, including through staff tools on the website and in our Discord server, to operate the service, support users, and investigate abuse. Access to those tools is restricted to staff accounts and checked on the server for every request.
Security and abuse prevention
A service that can look up usernames, emails, phone numbers, and network addresses has to take misuse seriously. Much of the information we process exists to keep your account safe and to stop the service from being used to harm anyone.
Protecting your account
- New-device approval. When you sign in with a password from a device that is not trusted, we send a login approval request to your Discord account. The sign-in only completes if you approve it, and the request expires after 5 minutes.
- Sessions and trusted devices. Your account page lists your active sessions and trusted devices, with a browser and operating system summary and when each was last used, so you can spot anything unfamiliar and revoke it.
- Recovery codes. If you lose access to Discord, recovery codes together with your password let you prove that the account is yours. Each code works once.
- Consistent sign-in responses. Sign-in takes a similar amount of time whether or not an email address is registered, which makes it harder to find out who has an account.
Protecting the service
- Rate limits. We limit how often sign-ins, sign-ups, searches, and reveals can be attempted in short periods of time.
- Security and audit records. We log security-relevant events, such as sign-ups, sign-ins, denied logins, Discord linking and unlinking, recovery code use, searches, reveals, account deletion, and moderation actions. These records never contain passwords, session tokens, or recovery codes.
- Correlation for investigations. When we investigate abuse, authorized administrators can see which accounts and Discord identities have used the same network within the retention period. This is how we find people who create several accounts to get around limits or bans.
- Moderation. Administrators can temporarily disable or permanently ban accounts that break our rules, and each action is recorded along with any reason given. Those actions are applied in our Discord server as well.
If you think your account has been restricted by mistake, you can appeal. The appeals page explains how.
Automated decisions and limits
Some decisions in the service are made automatically, by rules applied the same way to everyone. None of them use profiling to predict anything about you personally.
- Plan limits. On the Free plan you can run 20 searches per day and reveal 3 records per day, up to 9 per week. Days reset at midnight UTC and weeks reset on Monday at midnight UTC. When you reach a limit, further searches or reveals are refused until the next reset.
- Short-term rate limits. Bursts of activity are limited over short windows. For example, sign-in attempts are limited per email address and network over five minutes, and sign-ups are limited per network over an hour. When a limit is reached, you are asked to wait and try again.
- Login approval. A password sign-in from a device without a valid trusted-device cookie triggers a Discord approval request.
- Membership. Leaving the Swatted Discord server automatically suspends access and signs out your sessions. Rejoining restores access unless another restriction applies.
- Expiry of temporary restrictions. A temporary disable ends automatically when its period is over.
Bans and temporary disables are decided by people, not by an automated system. If you disagree with any decision that affects your access, you can contact us and ask for a person to review it.
How we share information
We share personal information only as described here. We do not sell it, we do not rent it, and we do not share it with advertisers or data brokers.
Service providers
We use a small number of providers to run the service. They process information on our behalf and only to provide their services to us.
- Hosting and infrastructure. Our hosting and infrastructure providers run the servers, database, and caching systems that store and process the information described in this policy.
- Network and security. Traffic to Swatted.how passes through Cloudflare, which delivers the site and helps protect it from attacks and automated abuse. To do that, Cloudflare processes connection data for the requests you make.
Discord
Discord is not our service provider in the usual sense, but the service depends on it. To verify your account, send you approval requests and notifications, and keep server roles and moderation in step with your account, we exchange information with Discord through its platform. This includes your Discord user ID, the roles we assign in our server, moderation actions such as bans and timeouts, and the content of the messages the bot sends you. A login approval message tells you which browser and operating system the sign-in came from.
Legal and safety reasons
We may disclose information if we believe in good faith that it is necessary to comply with the law or a valid legal process, to protect the safety of any person, to prevent or respond to fraud, abuse, or security problems, or to protect the rights and property of Swatted and our users. Where the law allows, we will try to tell you about a request for your information before we disclose it.
Changes to the service
If Swatted is ever transferred to a new operator, the information we hold may be transferred as part of that change. The new operator would have to keep using it in line with this policy, or tell you about any changes first.
With your direction
We will share information in other ways when you ask us to. Your data export, for example, is a copy of your information given to you to use as you wish.
International transfers
The service is available on the internet and depends on providers that operate around the world. Your information may be stored and processed in countries other than the one where you live, including by our hosting and infrastructure providers, by Cloudflare, and by Discord. Those countries may have data protection rules that differ from the rules where you live.
Where applicable data protection law requires it, we take steps intended to make sure that information transferred across borders keeps an appropriate level of protection, such as relying on the safeguards our providers offer for international transfers. You can ask us for more information about the safeguards that apply to your information by contacting us.
Retention
We keep personal information only for as long as we need it for the purposes in this policy. Some information expires on a fixed schedule. Some is kept for as long as your account exists. Some security records are kept after an account is deleted, because deleting them would make it easy to evade bans and hard to investigate abuse. The table below sets out what we keep and for how long.
| Information | How long we keep it |
|---|---|
| Account data (email address, password hash, account status, recovery code hashes) | For as long as your account exists. When you delete your account, your email address and password hash are replaced immediately. See Account deletion. |
| Discord identity (user ID, username, display name, avatar reference) | For as long as your Discord account is linked. The identity record is removed when you delete your account or when your Discord account is unlinked. Your Discord user ID can remain in security and audit records, as described below. |
| Search and reveal history, and credit history | For as long as your account exists, and after deletion for security and abuse prevention. There is no fixed automatic deletion period in the current version of the service. |
| Device and connection data | Records of the IP addresses we observe are set to expire 180 days after they are collected and are then deleted by a scheduled cleanup job. Browser and operating system summaries, keyed references, and approximate network details can remain attached to the session, device, and security records they belong to. |
| Sessions and trusted devices | Sessions stop working after 30 days, and trusted devices after about 30 days, or sooner if revoked. A record that the session or device existed is kept as part of your security history. |
| Short-lived security tokens and counters | Verification codes expire after 15 minutes, login approval requests after 5 minutes, and sign-in flow cookies after 10 minutes. Rate limit counters expire within one hour at most. |
| Security and audit logs, and moderation records | Kept for as long as they are needed for security, abuse investigation, and legal purposes, including after an account is deleted. They are not deleted on a fixed schedule in the current version of the service. |
| Removal requests | Kept after the request is resolved, so that we have a record of what was asked for and what we did. There is no fixed automatic deletion period in the current version of the service. |
| Deleted accounts | The account is kept in a deleted state, without your email address, password, or Discord link, so that the remaining history and security records stay consistent. It cannot be signed into again. |
Where no fixed period applies, we still aim to keep information no longer than we need it, and we plan to set fixed periods as the service matures. When we do, we will update this table. We may keep information for longer where the law requires it, or where it is needed to establish, exercise, or defend legal claims.
How we protect information
We use technical and organizational measures designed to protect personal information against loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These include:
- Password hashing. Passwords are hashed with Argon2id, a modern algorithm designed to make stolen hashes expensive to crack. We never store or log your password in plain text.
- Encryption at rest. Sensitive technical identifiers are encrypted at rest at the application level with AES-256-GCM. The encryption keys are kept outside the database.
- Keyed hashing. Session tokens, trusted-device tokens, verification codes, and recovery codes are stored only as keyed hashes (HMAC-SHA256), so the values that grant access are never kept in readable form. Where we need to recognize the same technical identifier again for security purposes, we use a keyed hash of it instead of the identifier itself.
- Short-lived, single-use tokens. Verification codes, login approvals, and recovery codes can each be used only once, and the first two expire within minutes.
- Secure cookies. Our cookies are HttpOnly and SameSite=Lax, and in production they are sent only over encrypted connections.
- Access controls. Administrative tools are available only to staff accounts. Every administrative and account request is authorized on the server, never on the strength of something your browser sends. Staff access to decrypted technical identifiers is limited to security and abuse investigations.
- Browser protections. The site sends security headers that stop it from being embedded in other sites and that limit what information is passed on when you follow a link.
- Logging discipline. Security records are designed never to contain passwords, session tokens, or recovery codes.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident that affects your personal information, we will take steps to contain it, and we will notify you and the relevant authorities where applicable law requires it.
You can help protect your account by using a strong, unique password, keeping your Discord account secure, saving your recovery codes somewhere safe, and denying any login approval request you did not start. For more practical steps, see Protect yourself.
Your rights
Depending on where you live, applicable data protection law may give you some or all of the following rights over your personal information. We aim to honor these requests for all users, wherever they are, as far as we reasonably can.
- Access. You can ask whether we process your personal information and for a copy of it, along with information about how we use it.
- Export and portability. You can receive your information in a structured, commonly used, machine-readable format. Your account page has a self-service export for this.
- Correction. You can ask us to correct information that is inaccurate or incomplete.
- Deletion. You can delete your account yourself, and you can ask us to delete other personal information. Some information may be kept where we have a valid reason, as explained in Account deletion.
- Restriction. You can ask us to limit how we use your information, for example while we check a correction you asked for.
- Objection. You can object to processing that we base on legitimate interests. We will stop unless we have compelling legitimate grounds that override your interests, or we need the information for legal claims.
- Withdrawing consent. Where we rely on your consent, you can withdraw it at any time. This does not affect processing that took place before.
- Complaint. You have the right to complain to your local supervisory authority for data protection. We would appreciate the chance to address your concern first, but you do not have to contact us before going to an authority.
Some rights have limits. For example, we may keep security and audit records after you ask for deletion where we need them to prevent abuse or meet legal obligations, and we will not share information in a way that would reveal personal information about someone else. If we cannot fully meet a request, we will tell you why.
We will not treat you differently or penalize you for exercising any of these rights.
How to exercise your rights
Self-service tools
Several rights can be exercised directly from your account page, without waiting for us:
- Export my data downloads a JSON file with your profile, your linked Discord identity, your usage, your search history, your reveal history, your credit history, your sessions, your trusted devices, and your removal requests.
- Revoke next to any session or trusted device signs it out or removes its trusted status straight away.
- Delete my account deletes your account after you type a confirmation. See Account deletion.
The export is available while your account is active. If your account is suspended, disabled, or banned, or you need information the export does not include, contact us and we will help.
Requests to us
For any other request, contact the owner as described in Contact. Tell us which right you want to exercise and what it concerns. To protect your account, we need to confirm that the request comes from the account holder. Usually we do that by checking that you are messaging us from the Discord account linked to your Swatted account. If that is not possible, we may ask for other information that proves the account is yours, but we will never ask for your password or recovery codes.
We will respond within the time required by applicable law, which is usually one month. If a request is complex, or we receive many requests, it may take longer, and we will tell you if so. Requests are free unless they are clearly unfounded or excessive.
You can also make a request on someone else’s behalf where the law allows it, for example as a parent or an authorized representative. We may ask for proof of that authority.
Account deletion and what remains
You can delete your account at any time from the Your data section of your account page. You will be asked to type DELETE to confirm. Deletion cannot be undone.
What happens straight away
- Your account is marked as deleted and can no longer be signed into.
- Your email address is replaced with a placeholder, so it no longer appears in our account records.
- Your password hash is replaced with a random value.
- The link between your Swatted account and your Discord account is removed.
- All of your sessions are signed out.
- In the Swatted Discord server, the bot removes your verified role and removes you from the server.
Because your email address is released, you could sign up again with it later. A new account would start from scratch and would still need Discord verification.
What remains
Some records are kept after deletion, linked to the deleted account rather than to your email address. They are kept to prevent abuse, for example to stop someone from deleting an account to escape a ban, and to meet legal obligations. They include:
- your search and reveal history, and your credit history;
- security and audit records, and any moderation records, some of which include your Discord user ID;
- records of past sessions and trusted devices;
- removal requests you submitted;
- device and connection data, which follows the schedule in the Retention table.
If you want to know what remains after deleting your account, or you believe something should not have been kept, contact us. Before you delete your account, you may want to download your data export, because it will not be available afterwards.
Removal requests
If you find information in Swatted that appears to describe you, you can ask us to review it and remove it. If a record seems to match you, we want to hear about it.
How to submit a request
- On the website. Signed-in users can use the removal request form. You can include the record’s ID, your reason, an explanation, and optional contact details.
- On Discord. In the Swatted Discord server, use the
/removalcommand. It opens a short form for your reason and an optional explanation. We record your Discord user ID as the contact for the request.
If you do not have an account and cannot use either option, contact the owner as described in Contact.
What happens next
Each request gets a reference number, such as REM-000123. Staff review it, update its status, and may add internal notes. If you have a linked Discord account, the bot will send you a direct message when the status changes.
Removal requests are handled privately. They are never posted publicly, and only staff who handle requests can see them. We use the information in a request only to process it and to keep a record of how it was handled. Please include only what we need to find the information and understand your request.
Children
Swatted is not intended for children and is not directed at them. To use the service you need a Discord account, and you must be old enough under applicable law to agree to our Terms of service and to consent to the processing described in this policy.
We do not knowingly collect personal information from children. If you believe a child has created an account or given us personal information, contact us. If we learn that we hold a child’s personal information in breach of applicable law, we will close the account and delete that information, except where we need to keep a limited record to prevent the account from being recreated.
Third-party services and links
Swatted links to services we do not operate, most importantly Discord. Search records may also show a source label or a link to where a record says it comes from. When you follow a link to another site or use another service, that site or service handles your information under its own privacy policy, not this one.
We are not responsible for the privacy practices of third parties. We encourage you to read the privacy policies of any service you use through a link on Swatted, starting with Discord’s.
The Swatted site does not load third-party analytics or advertising scripts, and it does not embed social media trackers.
Changes to this policy
We will update this policy when the service changes or when we learn of a better way to explain something. The date at the top of the page shows when it was last updated.
If we make a material change, such as collecting a new kind of information, using information for a new purpose, sharing it with a new kind of recipient, or shortening your rights, we will give notice before the change takes effect. We will do that on this page and, where appropriate, through the service or our Discord server. Where applicable law requires your consent to a change, we will ask for it.
This version of the policy is a product draft. It will be reviewed by a qualified legal professional before the service launches publicly, and it may change as a result.
Contact
For questions about this policy, to exercise your rights, or to raise a concern about how we handle your information, contact the owner of Swatted on Discord. We do not currently offer an email address for these requests.
- Join the Swatted Discord server. The Contact page has the current invite and details.
- Send a direct message to the owner, Discord user ID
1318214074198265997. You can open their profile at discord.com/users/1318214074198265997.
Discord only lets you send a direct message once you share a server with that person, so you will need to join the Swatted server first. Please do not send passwords or recovery codes. Staff will never ask for them, and will not message you first asking for credentials.
If you are not satisfied with our response, you can complain to your local supervisory authority for data protection.