Privacy Policy

Last updated 1 Oct 2026

This explains what SwingAlerts holds about you, why, who else can see it, and how to get it back or get rid of it. It describes the system that is actually running — if you find a claim here that the product contradicts, that is a bug and we want to hear about it at alerts@swingalerts.app.

Who is responsible

SwingAlerts, of C/ Can Guidet 5, 17310, Lloret de Mar, Spain, is the controller of the personal data described here. Write to alerts@swingalerts.app about anything on this page.

What we collect

Four things, and nothing else.

Your identity. Signing up and signing in are handled by Clerk, our authentication provider. Clerk holds your email address and your sign-in credentials. We never see your password. What SwingAlerts itself stores is an opaque account identifier issued by Clerk, a cached copy of your email address so we know where to send your alerts and notices about your account, and whether your account is an administrator.

Your membership. Whether your account is Free or Paid. If you have paid, we also store the identifiers Stripe gave your customer record and your subscription, when your current paid period ends, and whether you have cancelled. We never see or store your card or other payment details: you pay on Stripe’s own checkout page, and those details stay with Stripe and Link.

What you build. The rules you write: a name, a ticker, a candle size, and the conditions themselves. Rules are content you author, so whatever you type into one — including the name — is stored as you wrote it.

What your rules produce. Every time a rule fires we store the event: which rule, which ticker, which candle size, the moment it fired, and how long your conditions had held. Deleting a rule deletes its alert history with it.

Your delivery settings sit alongside these: which channels you accept, the Telegram chat you linked if you use Telegram, any quiet hours, and a minimum gap between alerts. Quiet hours are stored together with the time zone your browser reported, because a window like 22:00–07:00 means nothing without one.

What we do not collect

SwingAlerts runs no analytics. There is no Google Analytics, no PostHog, no Segment, no Meta pixel, no session recorder and no advertising tag anywhere in the site — not on the landing page, not on the guide, and not inside the app. Nobody is paying us for a profile of you and we are not building one.

We do not ask for your name, your phone number, your address, your date of birth or any identity document, and we never hold your payment details. We are not a broker: we hold no account of yours at any venue, we see none of your positions, and we never learn whether you acted on an alert.

Why we hold it

Your identity, your membership, your rules, your alert history and your delivery settings are held to perform the contract between us — they are the service. Without them there is nothing to evaluate and nowhere to send the result.

A short record of administrative actions (see below) is held on the basis of our legitimate interest in being able to account for what was done to an account and by whom.

We do not rely on consent for any of this, which also means there is no consent banner to click past.

Who else touches it

SwingAlerts is a small service built on other people’s infrastructure. These are every third party that can hold your data, and what each one holds:

  • Clerk — authentication. Holds your email address and sign-in credentials, and is where your account actually lives.
  • Fly.io — hosting. Runs the application and the database, so the rules, alert history and settings described above physically sit there.
  • Upstash — the Redis instance holding each rule’s live evaluation state. Keyed by rule, not by person, but linkable back to you through the rule.
  • Our email provider — delivery. Sees your email address and the contents of each alert and account notice we send you.
  • Telegram — delivery, only if you link a chat. Sees the chat we send to and the contents of each alert we send you there.
  • Stripe — payments, only if you upgrade to Paid. Holds your customer record (your email address and your SwingAlerts account identifier, so a payment can be matched to your account), your subscription, and the payment details you enter at checkout. It is told nothing about your rules or alerts.
  • Link — the merchant of record for Paid, only if you upgrade. Link, Stripe’s payment service, sells you the subscription: it takes the payment, works out and collects any tax due, and issues your receipts, under its own privacy policy.

What never leaves

Our market-data provider is the one supplier we send nothing about you to. SwingAlerts subscribes to a list of tickers assembled from every active rule across the whole service, with no author attached — the engine does not know whose rule it is evaluating, by design. The data provider therefore cannot tell that you exist, let alone what you are watching.

We do not sell your data, we do not share it for anyone else’s marketing, and we do not disclose it to anyone beyond the providers above except where the law requires it.

How long we keep it

Your rules and your alert history stay until you delete them. Deleting a rule deletes every alert it ever fired, immediately and permanently — there is no archive and no recycle bin, so export anything you want to keep first.

Closing your account first cancels any Paid subscription, then removes your Clerk account, then your alert history, then your rules, then your account row. What is left with us afterwards is the administrative record described next.

If you have paid, Stripe and Link keep their own records of your payments and receipts after your account is closed, for as long as tax and accounting law require them to.

The record that outlives deletion

When an administrator acts on something that is not theirs — deleting a rule, silently disabling one, or deleting an account — we write one line recording that it happened: when, which administrator, which account or rule, and how much was removed. That line is never deleted, including when the account it names is deleted. A deletion nobody recorded is indistinguishable from a deletion that never happened, which is exactly the situation this exists to prevent.

It holds a name, an email address and a count. It never holds the contents of a rule or of an alert, so it cannot become a shadow copy of what you deleted. Nothing you do yourself to your own rules is recorded this way.

This is the one thing on this page that survives a request for erasure, and we would rather tell you that than quietly make an exception later.

Your rights

If you are in the UK or the EU, the GDPR gives you the right to get a copy of what we hold, to have it corrected, to have it deleted, to take it elsewhere in a portable form, to object to our processing it, and to restrict that processing while a dispute is open. These rights apply wherever you are, because running two standards would mean building the weaker one.

Write to alerts@swingalerts.app and we will answer within one month. You can delete your rules and their history yourself at any time from inside the app.

If you think we have handled this badly you can complain to your national data protection authority. We would rather you told us first, but that is your choice, not a precondition.

Cookies

The only cookies SwingAlerts sets are the ones Clerk needs to keep you signed in. There are no advertising cookies and no analytics cookies, which is why there is no cookie banner. Clearing them signs you out; nothing else about your account changes.

Stripe’s checkout and billing pages are on Stripe’s own site, and set Stripe’s own cookies while you are there.

Where your data sits

Our providers operate internationally, so your data may be processed outside the country you are in, including in the United States. Where that happens the transfer runs on the safeguards in our agreements with each provider.

Security, honestly stated

Traffic runs over HTTPS. Your session token is verified on every request, and each rule carries its author as a database column that no request of yours can rewrite, so one account cannot read or edit another account’s rules. Administrators can read and delete, but cannot rewrite the body of a rule they did not author — changing what someone else’s alerts mean while leaving their name on them is not something the software will do.

No service can promise it will never be breached, and we are not going to. If one happens and it puts you at risk, we will tell you.

Changes

This policy was last changed on 1 Oct 2026. If we change it in a way that materially affects you, we will email you rather than quietly bumping the date.