Privacy Policy
Last updated Aug 16, 2026
Privacy Policy
Effective date: 16 August 2026
Swaymoon (“we”) respects your privacy. This Policy explains how we collect, use, store, share, and protect personal information when we provide Swaymoon Report a Problem (the “Portal” or “Service”, at reportaproblem.swaymoon.com), and the rights you have. Using the Service means you understand this Policy. Where we need a separate consent, we will ask for it in that flow.
The Portal signs you in with Swaymoon Account. How the Account itself handles personal information is in the Swaymoon Account Privacy Policy. This Policy covers only information the Report a Problem Portal handles in addition or on its own.
This Policy is written to meet the Personal Information Protection Law of the People’s Republic of China and similar rules. For cross-border or UK/EU users we follow the stricter of UK GDPR / GDPR where it applies.
1. Information we process
1.1 Sign-in and session
To complete OAuth / OIDC sign-in and keep you signed in, the Portal may process and store:
- Account identifier (
sub), username, and display name - Email (from the Account within the granted scopes, or the contact address you enter on a report)
- Account language preference (if you grant
locale) - Session id, access and refresh tokens (stored encrypted), expiry, and a CSRF token
- Short-lived login state (PKCE values, return URL)
1.2 Reports you submit
- Intent (report a problem / report abuse or a security issue) and product
- Subject, description, follow-up notes, and public admin replies
- Attachment original name, type, size, and file bytes (zip or jpeg / png / gif / webp; 10MB each; up to 3 at submit, 3 per message, 12 per report)
- Status and timestamps
Internal admin notes are for handling only. They are not shown to you and do not trigger mail to you.
1.3 Information created while you use the Portal
- Source IP, IP version, and which edge you hit (Hangzhou or Virginia), used for the footer “where you are” line and for security
- Access and error logs needed for security and troubleshooting, kept as small as practical
1.4 What we do not ask for
We do not ask for sensitive personal information that is unrelated to handling a report. Do not put passwords, codes, passkeys, or client_secret in text or files. Notification mail does not attach your files; it only includes a link.
2. Purposes and legal bases
| Purpose | Examples |
|---|---|
| Provide the Portal | Sign-in, session, submit and view reports |
| Handle and reply | Review, correspondence, progress mail |
| Security | CSRF, session checks, file-type checks, abuse prevention, troubleshooting |
| Legal duties | Regulatory requests, security incidents |
Information required to submit a report (including email and description) is necessary to provide the Service. For sign-in, openid, preferred_username, and email are required scopes; locale is optional.
3. Sharing, transfer, and disclosure
We do not sell your personal information. We share or disclose it only when:
- Swaymoon Account: identifiers and granted claims flow between Account and the Portal as needed to sign you in.
- Processors: infrastructure and the mail provider that delivers notices to you and to our handling mailbox, only on our instructions and only as needed.
- Handlers: the smallest set of people who need access to work the report.
- Law: where statutes, litigation, or a competent authority require it.
Attachments stay on local disk for this Service. They are not uploaded to object storage and are not sent as mail attachments.
4. Location and retention
Reports, sessions, and attachments are processed in Jiangsu, China on local storage. We use access control, token encryption, and minimized transfer.
To make the site reachable worldwide, your browser may first connect to an edge in Hangzhou or Virginia, then reach the processing host over an encrypted tunnel. Edges do not keep report bodies or attachments. Static acceleration or mail delivery may send contact details over overseas paths; that does not change where report data is stored.
As a result, some limited personal information (for example connection data at an edge, and contact details needed to deliver mail) may be processed outside mainland China. We direct our processors under this Privacy Policy and only as needed to provide the Service.
We keep data only as long as needed for the purpose. While a report is open we keep what handling requires. After you delete your Swaymoon Account, Portal sessions for that account are cleared. Later deletion or anonymization of reports and files follows minimization and the law. Audit and security logs may be kept for a shorter or, where required, longer period.
5. Your rights
Under applicable law you typically have rights to access, correct, delete, withdraw consent, and export. For this Portal:
- After sign-in, My Reports shows what you submitted and public replies
- You can add notes or attachments on a report
- You can manage authorization, export, and deletion in Swaymoon Account → Privacy
- We may verify your identity before acting on a request
You may also use this Portal or hello@swaymoon.com for privacy requests.
6. Cookies and local storage
The Portal uses a REPORTAPROBLEM_SID session cookie (SameSite=Lax; Secure) to keep you signed in. Language preference may use the site-wide swaymoon_locale cookie. You can control cookies in the browser; turning them off may block sign-in or language persistence.
7. Children
If you are a minor, read this Policy and use the Service with a guardian. We do not knowingly collect a minor’s personal information without guardian consent. Contact us if you believe that has happened.
8. Security
We use technical and organizational measures matched to the risk, including transport encryption, encrypted tokens, magic-byte checks on files, access control, and least privilege. Do not put secrets in reports, and keep your account and devices safe.
9. Updates
We may update this Policy and publish the new version and effective date in Docs. Material changes will be highlighted. If we need a new consent, we will ask for it in the relevant flow.
10. Contact
For privacy requests or complaints, use Report a Problem or email hello@swaymoon.com. See also Contact Swaymoon.