Privacy Policy

Last updated: September 2026

The short version

Swoop's free tier classifies your tabs entirely on your device — tab data never leaves your browser unless you choose to spend one of the 10 one-time AI credits a free account includes. (Optional sign-in adds account-status calls: sign-in state, usage counters, referral status — never your tabs.) Paid tiers and spent credits send tab metadata — the title, the domain, and the page address with everything after the ? or # removed — to our backend for AI classification. On paid plans this happens automatically as you browse, which is what keeps your groups current without you having to ask. It's processed in memory and discarded: never stored by us, never sold, and never used to train AI models. We never send page content or screenshots, and we never read your browser history. Because we strip the query string and fragment on your device first, a token carried in one — a password reset, a magic link, an OAuth callback — is removed before the request is sent. Two honest limits: a token built into the page path can't be removed without breaking classification, and a page's own title is sent as it wrote it. (The one place a full address is sent is the feedback form, where you see the exact URL and choose whether to attach it — see below.)

Free tier — what we collect

Nothing about your tabs, unless you spend an AI credit. Free-tier classification runs entirely on your device — no account required, no tracking. Everything — your tab classifications, corrections, and settings — stays in chrome.storage.local. If you choose to sign in while on the free tier (for referrals, for the 10 one-time AI credits a free account includes, or before upgrading), your browser makes account calls — sign-in state, usage counters, and referral status — and your tab titles and URLs still never leave your device unless you choose to spend an AI credit. Spending one sends that Organize run's tab titles and URLs for classification, on exactly the same terms as a paid tier: processed in memory and discarded — never stored by us, never sold, and never used to train AI models.

Pro & Premium — what we collect

When you sign in and subscribe to a paid tier, we collect the minimum data needed to deliver AI features and manage your account:

  • Email address — for authentication via Supabase Auth (Google OAuth or magic link)
  • Anonymous device ID — a randomly generated UUID stored in your extension, used to link usage to your account
  • Tab metadata — title, URL, and domain of tabs sent to our backend for AI classification. Processed in-flight, then discarded — never stored (see "What we can see" below). Never page content, never screenshots, never embeddings computed on your device.
  • Usage counts — a timestamped count of your AI calls, for rate limiting your plan
  • Subscription data — Stripe customer ID, subscription status, plan tier, renewal date

What we can see

Even on paid tiers, our servers can see surprisingly little. AI requests are processed in memory and discarded — no tab title, URL, or content is ever written to our database. What we can see:

  • Usage counts — which feature you called and on what day, for rate limiting. Never what was in the request.
  • Account & subscription info — email, plan tier, and Stripe subscription status
  • What you explicitly send us — if you submit feedback, we store the message you typed (and the page URL it was sent from, so we can reproduce bugs)

How Swoop learns

When you drag a tab to a different group or correct a category, Swoop remembers — right on your device. Corrections live in your browser's local storage and personalize classification locally. They are not sent to our servers, and we never train AI models on your browsing.

Coming soon: community corrections. We're building an optional way to share corrections — anonymized and stripped of any identifiers — so everyone's defaults get better. It will be strictly opt-out: you can turn it off anytime in Settings, and nothing is collected until the feature launches. The consent toggle already ships in the extension today, so your choice is honored from day one.

On-device AI on Firefox

Swoop's on-device classifier runs locally on both Chrome and Firefox — the same model, the same categories, the same results. It is slower on Firefox, because Firefox extensions can't use multiple CPU threads for it, so sorting a large window takes longer there. On the free tier nothing leaves your device on either browser unless you choose to spend an AI credit; on paid plans the cloud tier behaves the same on both, as described above.

What we DON'T collect

  • Page content — we never read, save, or transmit what's on the pages you visit
  • Browsing history — the extension has no history permission
  • Cookies, form data, passwords, or anything you type into websites
  • Screenshots, DOM snapshots, or any content rendered by the page
  • Personal files, downloads, or anything outside your open tabs

How we use it

  • To classify your tabs into categories (Development, Shopping, etc.) and topic groups (e.g. "React hooks tutorials")
  • To enforce rate limits on your plan
  • To process payments through Stripe and keep your subscription active
  • To improve classification accuracy for everyone — anonymized community corrections, coming later. Nothing is collected until it launches, and you can opt out anytime in the extension's Settings (see "How Swoop learns" above)

Third-party services

We rely on a small set of trusted providers:

  • Supabase — database, authentication, and Edge Functions. Stores your account and subscription data. Hosted in the United States (Amazon Web Services, us-east-1) — see "Where your data is processed" below.
  • Stripe — payment processing. PCI-compliant. We never see your card details.
  • Anthropic — AI classification (Claude). We send tab metadata only. Anthropic does not train on API inputs and automatically deletes API data within 30 days at most (retained longer only if flagged by their safety systems).
  • Voyage AI — embeddings for topic detection. Receives tab titles and domains only (no full URLs), not identifiable to you. Our organization has opted out of Voyage's data training, so your data is deleted immediately after processing and never used to train their models.
  • Resend — email delivery for waitlist updates and magic link sign-in.
  • Vercel — hosts swooptabs.com. Analytics are anonymous and aggregated.

Where your data is processed

Swoop is run from Slovakia, but every provider above is established outside the EEA, so your personal data is transferred out of it. Under EU law each such transfer needs a safeguard. Here is the one each provider relies on — we checked every certification below against the official list at dataprivacyframework.gov on 2 September 2026.

  • Supabase (Supabase Pte. Ltd., Singapore), hosting your data on Amazon Web Services in the United States. No Supabase entity appears on the Data Privacy Framework list, so this transfer relies on the European Commission's Standard Contractual Clauses (Decision 2021/914, controller-to-processor), incorporated into Supabase's Data Processing Addendum, with the UK Addendum where applicable.
  • Anthropic — not certified under the Data Privacy Framework; transfers rely on the Standard Contractual Clauses incorporated into Anthropic's Data Processing Addendum.
  • Voyage AI (Voyage AI Innovations, Inc., a MongoDB company). Listed as a covered entity under MongoDB, Inc.'s active EU–US Data Privacy Framework certification for non-HR data; its Data Processing Addendum separately applies the Standard Contractual Clauses to transfers the Framework does not cover. Voyage does not publish a fixed processing region, so processing may also take place elsewhere.
  • Stripe — we contract with Stripe Payments Europe, Limited (Ireland). Onward transfers to Stripe, LLC in the United States rely on Stripe, LLC's active Data Privacy Framework certification, with the Standard Contractual Clauses as the fallback in Stripe's Data Transfers Addendum. For fraud prevention, anti-money-laundering and its own legal duties Stripe acts as an independent controller under its own privacy policy, not as our processor.
  • Resend (Plus Five Five, Inc., United States) — listed on the Data Privacy Framework for non-HR data; its Data Processing Addendum applies the Standard Contractual Clauses to any transfer an adequacy decision does not cover.
  • Vercel (Vercel Inc., United States) — an active participant in the EU–US Data Privacy Framework, its UK Extension and the Swiss–US Data Privacy Framework. Vercel runs a global edge network, so this data may also be processed in other countries.

You can ask us for a copy of these safeguards at hello@swooptabs.com.

Your rights (GDPR)

If you're in the EU or UK, you have the right to access, export, correct, or delete your data at any time. Email us at hello@swooptabs.com and we'll respond within one month, and in practice within a few days.

You can also delete your account yourself, without asking us. Open Swoop's Settings, scroll to Danger zone and choose Delete account (the account menu in the popup links straight there). You will be shown exactly what is deleted and asked to type a confirmation. It is immediate and permanent: your account, subscription records, custom categories, corrections, usage history, referral records, any feedback you sent and any waitlist entry are erased from our live systems, and your payment details are deleted at our payment provider. If you have an active subscription it is cancelled at the same time.

Data retention

  • Account data: retained until you delete your account
  • Tab metadata: never stored by Swoop — processed in memory, then discarded. Our AI providers don't keep it either: Anthropic auto-deletes API data within 30 days at most, and Voyage AI deletes it immediately after processing
  • Usage logs: each entry holds only a feature name and date — never tab data — and is retained until you delete your account
  • After account deletion: removed from our live systems immediately. Encrypted database backups are kept up to 7 days for disaster recovery and are then overwritten — data in a backup is never used for anything else. Our payment provider, Stripe, keeps invoice and transaction records where accounting and tax law requires it, and tab titles and addresses already sent to our AI providers are held only for the retention periods listed above

Cookies

swooptabs.com uses only essential cookies for Supabase Auth sessions. No tracking cookies, no advertising cookies, no cross-site tracking. The Chrome extension uses no cookies at all — it stores data in chrome.storage.local.

Changes to this policy

We'll update this policy if we add new data collection or third-party services. Material changes will be announced by email to account holders and in the extension popup at least 30 days before they take effect.

Contact

Privacy questions? Reach out at hello@swooptabs.com. See also our Terms of Service.