SwiftCram logo SwiftCram
  • Home
  • Terms
  • Privacy
Legal · GDPR

Privacy Policy

SwiftCram is built for students, and student material is personal. This policy explains exactly what we collect, why we collect it, who processes it on our behalf, how long we keep it, and the rights you can exercise over it at any time.

Last updated: June 2026 GDPR (EU) 2016/679 compliant Data stored in the EU

On this page

  1. Data controller
  2. Data we collect
  3. Legal bases for processing
  4. Files and uploads
  5. Third-party processors
  6. International transfers
  7. Your GDPR rights
  8. How to exercise your rights
  9. Retention periods
  10. Security
  11. Cookies and local storage
  12. Children's privacy
  13. Changes and complaints
1

Data controller

For the purposes of the EU General Data Protection Regulation (GDPR), the data controller responsible for your personal data is:

SwiftCram
Data protection contact: privacy@swiftcram.com
General support: support@swiftcram.com
Registered in Romania, European Union.

Any question about how your data is handled — including requests to access, correct, or erase it — can be sent to the privacy address above.

2

Data we collect

Account data
Full name, email address, hashed password, and your main target subject. Provided by you at sign-up.
Study data
Uploaded materials, generated decks, flashcards, quiz results, homework questions and solutions, and AI Mentor conversations.
Preference data
Your onboarding answers (study goal, bottleneck, preferred learning style) and study toggles such as Deep Work Mode.
Usage data
Streak counts, XP, deck totals, and feature usage counters used to run progress tracking and plan limits.
Billing data
Subscription status, plan, and a RevenueCat customer reference. We never receive or store your card number.

We do not sell your personal data, and we do not use it for advertising or profiling that produces legal effects.

3

Legal bases for processing

Under Article 6 GDPR, we rely on the following legal bases:

  • Contract (Art. 6(1)(b)) — to create your account, generate study material, and deliver the features you subscribed to.
  • Legal obligation (Art. 6(1)(c)) — to retain invoicing and tax records for the statutory period.
  • Legitimate interests (Art. 6(1)(f)) — to keep the platform secure, prevent abuse, and diagnose faults.
  • Consent (Art. 6(1)(a)) — for any optional communication you opt into. You may withdraw consent at any time.
4

Files and uploads

Study materials, documents, images, and PDFs you upload to the Homework Helper or deck generator are transmitted to our AI provider strictly to produce your study response, then stored against your account so you can revisit the result.

Your uploads are not used to train third-party AI models, and are not shared with any party other than the processors listed in section 5.

5

Third-party processors

We use a small number of sub-processors. Each is bound by a Data Processing Agreement under Article 28 GDPR and may only process your data on our documented instructions.

RevenueCat Payments
Processes subscriptions, trials, and billing via RevenueCat Web Billing. Receives your email address and payment details during checkout. RevenueCat and its payment gateway act as independent processors for fraud prevention and regulatory compliance.
Render Hosting
Hosts the SwiftCram application servers and database. Stores your account record, study decks, and uploaded materials at rest. No SwiftCram data is processed by Render for its own purposes.
Google Gemini API AI processing
Generates lessons, flashcards, quizzes, explanations, and homework solutions. Receives the content of the material you submit for the duration of the request. Requests made through the paid API are not used to train Google's models.
Google Sign-In Optional auth
Used only if you choose to sign in with Google. We receive your name, email address, and Google account identifier — never your Google password.
6

International transfers

Some of our processors operate infrastructure outside the European Economic Area. Where personal data is transferred outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses or an applicable adequacy decision, together with supplementary technical measures such as encryption in transit.

7

Your GDPR rights

As a data subject in the EU or UK you hold the following rights over your personal data, free of charge:

Right of access Art. 15
Obtain confirmation of whether we process your data, and receive a copy of it along with details of how it is used.
Right to rectification Art. 16
Have inaccurate or incomplete data corrected. Your name and subject can be edited directly in Settings.
Right to erasure Art. 17
Have your data deleted — the “right to be forgotten”. Deleting your account in Settings → Danger Zone performs this immediately.
Right to data portability Art. 20
Receive your account and study data in a structured, machine-readable format (JSON), and have it transmitted to another controller where technically feasible.
Right to restriction Art. 18
Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
Right to object Art. 21
Object to processing carried out under our legitimate interests.
Right to withdraw consent Art. 7(3)
Withdraw any consent you have given, at any time, without affecting processing already carried out.
8

How to exercise your rights

  • In the app. Edit your profile in Settings, or delete your entire account and all associated data from Settings → Danger Zone.
  • By email. Write to privacy@swiftcram.com stating which right you wish to exercise.

We respond to every request within one month, as required by Article 12 GDPR. If a request is particularly complex we may extend this by a further two months and will tell you why. We may ask you to confirm your identity before acting on a request.

9

Retention periods

  • Account and study data — kept while your account is active, then deleted on account deletion.
  • Uploaded files — retained only as long as needed to serve the generated result back to you.
  • Billing records — retained for the statutory accounting period (up to 10 years) as required by law.
  • Security and error logs — retained for a maximum of 12 months.
10

Security

We apply industry-standard technical and organisational measures under Article 32 GDPR: passwords are hashed with bcrypt and never stored in plain text, all traffic is encrypted in transit over TLS, session tokens expire, and access to production data is limited to the people who need it.

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform you without undue delay.

11

Cookies and local storage

SwiftCram does not use advertising or third-party tracking cookies. We store a small amount of data in your browser's local storage that is strictly necessary to run the app:

  • Your session token, so you stay logged in between visits.
  • A cached copy of your profile, decks, and study preferences for fast offline-tolerant loading.
  • Your onboarding answers, so you are not asked the same setup questions twice.

Clearing your browser storage logs you out and removes this cached copy.

12

Children's privacy

SwiftCram is not directed at children under 16. Where a user is under 16, processing is carried out only with the consent of a parent or legal guardian. If you believe a child has provided us with personal data without that consent, contact privacy@swiftcram.com and we will delete it.

13

Changes and complaints

We will notify you by email or in-app before any material change to this policy takes effect. The “last updated” date at the top of this page always reflects the current version.

If you believe we have handled your personal data unlawfully, you have the right to lodge a complaint with your local supervisory authority. In Romania this is the Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP). We would appreciate the chance to resolve your concern first — please contact us at privacy@swiftcram.com.

SwiftCram
Home Terms Privacy Open app
© 2026 SwiftCram. All rights reserved.