Skip to content
SwapThisFace.com
Face swapPricingJournal
Sign in with GoogleOpen studio
Sign inOpen studio
On this page
  1. Who we are
  2. Information we collect
  3. How we use information
  4. Photos and face processing
  5. Service providers and disclosures
  6. Storage and retention
  7. Cookies and external content
  8. Security and access
  9. Your choices and requests
  10. Children’s information
  11. International processing
  12. Policy updates
SWAPTHISFACE.COM · CODEFLOW SOLUTIONS

Privacy policy

Last updated: 27 September 2026 · Staging edition

This policy explains how information is handled when you visit SwapThisFace.com, sign in, upload photos, create previews, or contact us. It covers the people using the service and people depicted in uploaded photos.

The short version: photos are stored privately to provide your requested result. Original uploads expire after 24 hours. Account results are available for 30 days; guest results for 24 hours. Download anything you want to keep.

Current service: this is a staging environment. Google sign-in and photo storage are connected. Payments and an external face-swap provider are not yet live. Mock previews use the target photo and do not perform a real face swap. We will update this policy before enabling external face processing or paid access.

1. Who we are

SwapThisFace.com is operated by Codeflow Solutions (“we”, “us”, or “our”). Codeflow Solutions decides how the service uses personal information. For support, privacy questions, or requests concerning your photos, email [email protected].

Our operating country and business contact address are being finalized and will be published before public launch. This staging policy does not claim registration in any particular jurisdiction.

2. Information we collect

  • Account information: when you choose Google sign-in, we receive account identifiers and basic profile information such as your name, email address, and profile image if supplied. Authentication records link your Google identity to your account. We do not receive your Google password.
  • Photos and jobs: your source face photo, target photo, generated preview or result, upload time, file type, dimensions, size, ownership identifiers, job status, and processing errors. Images can contain personal information about anyone pictured.
  • Trial and credit records: a guest-session identifier, trial availability, queued jobs, credit reservations and deductions, and links between guest creations and an account when you sign in.
  • Billing information, when enabled: Stripe customer, subscription, checkout and payment references, plan and payment status, billing dates, and credit purchase records. Stripe will collect payment details through its payment interfaces; our application is not designed to store full payment card numbers.
  • Technical and support information: request and error logs, network and browser information handled by our hosting providers, security/rate-limit signals, and information you include in emails or reports. Please avoid sending passwords, payment card details, or unnecessary sensitive photos in support messages.

3. How we use information

We use account and photo information to authenticate you, store your uploads, run the requested job, display and deliver results, associate creations with your account, and respond to support requests. Trial, billing, and credit records help enforce usage limits, prevent duplicate charges or credit deductions, reconcile payments, and manage subscriptions.

Technical information helps us diagnose failures, maintain security, prevent automated abuse, and enforce our terms. Where applicable, we also preserve records needed to comply with legal obligations or handle disputes.

Where data-protection law requires a legal basis, providing requested account and service functions may rely on performance of our agreement with you; proportionate security and abuse prevention may rely on legitimate interests; legally required records rely on legal obligations. Where consent is required, we must obtain it before the relevant processing, and you may withdraw it for future processing. We will confirm any additional consent and legal-basis requirements for face processing before the external provider is enabled.

4. Photos and face processing

Upload only photos you are entitled to use and have permission to process, including permission from other people shown. Do not upload identity documents or images containing unrelated sensitive information. If someone uploaded your image without permission, contact us with enough information to locate the image or account; we will investigate without asking you to make the disputed image public.

The current mock processor creates a labeled preview from the target image. The application does not currently use face recognition to establish a person’s identity or use your uploaded photos to train its own models. A future face-swap provider may extract facial features to create a result. Its identity, processing purposes, retention, training practices, and any biometric-data implications must be reviewed and disclosed before that integration goes live.

Uploads and results are not automatically posted in a public gallery or blog. If you download and share a result elsewhere, that copy is outside our storage and deletion controls.

5. Service providers and disclosures

We use providers to operate the service. They receive information relevant to their role, subject to their service arrangements and, where applicable, their own privacy notices:

  • Railway: application and background-worker hosting, including requests, operational logs, and data processed by the application.
  • Neon/PostgreSQL: structured account, authentication, job, usage, credit, and subscription records.
  • Cloudflare R2: private image-file storage. Public blog media, if published, are separate from private customer uploads.
  • Google: identity verification and sign-in. Google also supplies website fonts; see section 7.
  • Stripe, when activated: checkout, recurring payments, billing portal, and transaction reconciliation.
  • Face-swap provider: not yet connected. We will identify the provider before sending photos to it.
  • Email services: support correspondence sent to our Gmail contact address is handled by Google’s email service.

We do not currently sell personal information or run targeted advertising using your uploads. We may disclose information when legally required, to investigate misuse, or to protect people and the service. If the business is transferred, any transfer of personal information must remain subject to applicable law and appropriate notice.

6. Storage and retention

The application currently uses the following expiry rules. Expired files become unavailable through the app; background cleanup removes the underlying objects. Cleanup may be delayed by outages or retries, so expiry is not a promise that every physical copy disappears at that exact moment.

Source and target uploads · 24 hours
Expiry starts when the file is uploaded, including files that never produce a completed job.
Guest results · 24 hours
Expiry starts when the result is saved. A guest cookie is needed to access your guest creation.
Account results · 30 days
Expiry starts when the result is saved. Claiming an eligible guest result by signing in extends its retention to at least 30 days from the claim.
Deleted photos
A deletion request removes app access and queues physical file removal. Copies you already downloaded or shared are unaffected.
Account, usage, billing, and support records
Photo expiry does not erase these records. The current staging build has no automatic retention schedule for all non-photo records. Account-deletion requests require a manual review of remaining records and any legal or dispute-related reason to keep them. A documented retention schedule, including provider backups and logs, must be finalized before public launch.

7. Cookies and external content

Essential authentication cookies maintain sign-in and protect authentication flows. The fs_guest cookie identifies your guest session and trial and is configured for 30 days. Clearing it can prevent access to guest results; it does not delete the stored photos or grant permission to bypass trial limits. Cookie and server-session expiry can differ.

We do not currently include advertising or optional analytics cookies in the application. Blocking essential cookies may prevent sign-in, guest access, or job ownership checks.

Some pages load Google Fonts and illustrative photos from Unsplash. Your browser contacts those services to display that content, which can disclose your IP address and technical request information to them. These illustrative photos are separate from your uploads. External links and services have their own privacy practices.

8. Security and access

We use authenticated ownership checks for private assets, private storage, limited-duration access mechanisms where needed, and access controls for administration. Administrators and service providers may access information when needed to operate, support, or secure the service; “private” does not mean nobody operating the service can ever access it.

No online service can guarantee absolute security. Protect your Google account, use a device you trust, and sign out of shared devices. Report suspected unauthorized access to [email protected]. We will assess security incidents and make notifications where required by applicable law.

9. Your choices and privacy requests

You can download or delete available results in your account history. To request account deletion, use account settings. The current workflow disables account access, ends sessions, cancels pending jobs, and schedules photo removal; it does not instantly erase every account, audit, or financial record.

An active subscription must have ended before the self-service deletion request can complete. Canceling future renewal may leave the subscription active until its paid period ends. Contact us if you need a privacy request handled while a subscription remains active; the app’s billing check does not remove your legal rights.

Depending on the laws that apply to you, you may have rights to access, correct, erase, restrict, object to processing, receive a portable copy, or withdraw consent. Email [email protected] with your request and account email. We may ask for proportionate information to verify your identity or authority. We will explain any lawful limitation and respond within the time required by applicable law. You may also complain to your competent data-protection authority where that right applies.

10. Children’s information

The service is not directed at children. Do not use it if you are below the minimum age for an online account or valid consent under the laws that apply to you. Where permission from a parent or guardian is legally required, that permission is necessary. Contact us if you believe a child’s information has been submitted without appropriate authorization so we can investigate and address it.

11. International processing

Our providers may process information in countries other than the country where you live. The final deployment regions, subprocessors, and any required transfer safeguards are being confirmed before public launch. This staging notice does not represent that all information stays in one country. We will publish the applicable transfer information and provide details of relevant safeguards on request where required.

12. Changes to this policy

We will update the date above when this policy changes. Material changes, including the activation of a face-processing provider or new uses of photos, will be explained before they take effect and any legally required consent will be requested. The current policy remains available from the website footer.

Questions? Contact Codeflow Solutions at [email protected].

Privacy policy · Terms & conditions · Account settings

SwapThisFace.com

A new perspective, one photo at a time.

Create a swapPricingJournalPrivacy policyTerms & conditions
© 2026 Codeflow Solutions · SwapThisFace.comContact support