Shwink is built for wedding and event photographers. We take your privacy seriously, especially your health data. This policy explains what we collect, why, and how you stay in control.
1. Who We Are
Shwink is operated by Sensego (Pty) Ltd, based in South Africa. For privacy questions, contact privacy@shwink.app.
2. What We Collect
- Account information: email address, display name, username, and optional bio, location (city/country), years of experience, and profile photo.
- Age confirmation: when you create your account we ask you to confirm that you are at least 13 years old, in line with our Terms of Service. This is a simple yes or no confirmation. We do not collect your date of birth. If you signed up before July 2026 and provided a date of birth, it has been deleted from our servers.
- Health & fitness data: with your explicit permission we read from Apple HealthKit / Google Health Connect during shoot sessions: step count, distance, heart rate (average and peak), flights climbed, active calories. Used only to generate your Shwink Card stats and personal bests. We never sell health data, never use it for advertising, never share it with third parties without your explicit consent.
- Shoot & session data: shoot type, duration, date, mood, photo count, optional venue or couple name. You control what appears on your public Shwink Card.
- Photos & content: behind-the-scenes photos you choose to share and the Shwink Card images we generate. You own this content at all times.
- Social activity: follows, winks (likes), comments, notifications.
- Messages: direct messages (text, images, and voice notes) you send and receive in the app.
- Device & technical data: push notification tokens, app version, device type, crash reports.
- Safety & moderation data: records of reports you file and users you block.
3. How We Use Your Data
To operate the app and provide your Shwink Card; show stats, streaks and personal bests; power the social feed and notifications; improve performance and fix bugs; send product updates / stat summaries you have opted into (section 7); and promote Shwink with screenshots of the app that may show your public content, as set out in section 3 of our Terms of Service. Your health data is never used for this. If we introduce new uses we will update this policy and notify you in the app first.
4. Who We Share Data With
- Firebase / Google: authentication, database hosting (Firestore in Europe), file storage, push notifications, basic product analytics. Processed under a Data Processing Agreement. See policies.google.com/privacy.
- Image moderation (Google Cloud Vision): uploaded photos are automatically scanned by Cloud Vision SafeSearch for adult/violent/graphic content before publishing. Automated; staff don't review unless content is later reported. Cloud Vision does not retain the image.
- Apple HealthKit: health data is never shared with third parties, never used for advertising, never combined with third-party data outside the app.
- Meta (website only, and only if you accept): if you accept the cookie bar on shwink.app, Meta Platforms receives the website data described in section 6. Nothing from your Shwink account, and never health data.
- Other users: your profile, Shwink Cards, and posts you share are visible to other users. You control what is public; venue and couple names can be kept private. Public content may also appear in screenshots we use to promote Shwink, with health stats blurred or cropped out. To opt out, email privacy@shwink.app and we will stop featuring you within 30 days.
- Legal requirements: we may disclose data if required by law or to protect user safety.
- We do not sell your personal data. Period.
5. Your Rights & Controls
Access (view your data in-app), correction (edit profile/shoots), deletion (Settings → Delete Account, permanent and processed immediately; see also shwink.app/delete-account), health-permission revocation (iPhone Settings → Privacy & Security → Health), notification control (device Settings). EEA/UK users also have the right to object to processing, request data portability, and complain to their local data protection authority.
6. Tracking & Analytics
In the app. On iPhone we ask via Apple's App Tracking Transparency prompt before any analytics use the device advertising identifier (IDFA). If you choose "Ask App Not to Track," analytics continue in non-personalised aggregate form without the IDFA. The Shwink app shows no ads and we don't sell data to advertisers. If we ever add ads to the app we'll update this policy and tell you in-app first.
On our website. We advertise Shwink on Instagram and Facebook. To see which of those ads bring people to the App Store and Google Play, shwink.app can use the Meta Pixel, a measurement tool made by Meta Platforms. It stays off until you choose Accept in the cookie bar. If you decline, or never answer, nothing from Meta loads and no Meta cookie is set.
- In your browser: once you accept, the pixel loads from Meta and sets two cookies on shwink.app:
_fbp, which tells Meta this is the same browser as before, and_fbc, set only if you arrived from a link on Facebook or Instagram. Each expires 90 days after it was last set. The pixel tells Meta which page you opened and when you tap an App Store or Google Play button. We have switched off its automatic collection of page text and button clicks. - From our server: when you tap a store button, our server sends that same tap to Meta's Conversions API, so it still counts if an ad blocker stops the browser. It carries your IP address and browser details (Meta uses these to match the tap to an ad), your country as a hashed code, the two cookie values above, which store you picked, and the campaign tags in the link you arrived on. Hashing turns a value into a fixed code that can be compared but not read back. We send no email address, no name and nothing from your Shwink account.
- Campaign tags: if you accept, we keep the campaign tags from the link you arrived on (for example
utm_campaign, and Meta's click ID) in your browser for that visit only, so a store tap can be credited to the right ad. They are cleared when you close the tab or turn tracking off. - Never health data: nothing from Apple Health, Health Connect or your shoot stats is ever sent to Meta, from the website or from the app.
- Where it goes: Meta processes this data on its own servers, which are outside South Africa, including in the United States. Meta uses it to measure and deliver our ads, and also under its own Privacy Policy. We also ask Meta to apply its Limited Data Use setting to visitors in the US states whose privacy laws call for it, which restricts how Meta may use their data.
- Changing your mind: tap Cookie settings at the bottom of any page on shwink.app and choose Turn it off. The pixel stops, we delete the
_fbpand_fbccookies from your browser and nothing more is sent. Clearing your browser's data for shwink.app does the same. For data Meta already has, use the privacy settings in your Facebook or Instagram account, or email privacy@shwink.app and we'll help.
7. Marketing & Email
Occasional emails (weekly stat summaries, monthly Shwink Card, product updates, tips). Opt out anytime via the Unsubscribe link or Settings → Notifications → Email notifications. Transactional emails (verification, password reset, security alerts, content-removal notices) are still sent.
8. Safety, Reporting & Blocking
Report any post, comment, or profile in-app. We aim to review within 24 hours and remove content that violates our Terms. Block any user anytime. Once blocked you won't see their content and they can't see yours or message you. Blocked users are not notified.
9. Data Retention
We keep your data while your account is active. On deletion, your profile, shoots, posts, and health data are permanently deleted from our servers. Deleted photos can stay in our storage provider's recovery backup for up to 7 days before they are gone for good. Reports you have filed may be retained for safety-audit purposes for up to 12 months after deletion. If we remove a post, comment or photo for breaking our Terms, we keep a private copy for up to 90 days as a record of that decision, even if the account is deleted, and then delete it. Some anonymised, aggregated statistics (e.g. total platform steps) may be retained and cannot be linked back to you.
10. Children
Not intended for anyone under 13. At signup you confirm that you are at least 13 years old. We do not collect a date of birth. Report suspected under-13 accounts to privacy@shwink.app and we will remove them.
11. Data Security
Stored on Google Firebase with encryption in transit and at rest. Industry-standard practices. Report vulnerabilities to privacy@shwink.app.
12. Changes to This Policy
We may update this policy and will notify you of significant changes in-app. Continued use means you accept the update.
13. Contact
privacy@shwink.app for privacy; support@shwink.app for everything else. We aim to respond within 24 hours and always within 30 days.