Privacy Policy

Last updated Aug 16, 2026

Privacy Policy

Effective date: 16 August 2026

Swaymoon (“we”) respects your privacy. This Policy explains how we collect, use, store, share, and protect personal information when we provide Swaymoon Report a Problem (the “Portal” or “Service”, at reportaproblem.swaymoon.com), and the rights you have. Using the Service means you understand this Policy. Where we need a separate consent, we will ask for it in that flow.

The Portal signs you in with Swaymoon Account. How the Account itself handles personal information is in the Swaymoon Account Privacy Policy. This Policy covers only information the Report a Problem Portal handles in addition or on its own.

This Policy is written to meet the Personal Information Protection Law of the People’s Republic of China and similar rules. For cross-border or UK/EU users we follow the stricter of UK GDPR / GDPR where it applies.

1. Information we process

1.1 Sign-in and session

To complete OAuth / OIDC sign-in and keep you signed in, the Portal may process and store:

  • Account identifier (sub), username, and display name
  • Email (from the Account within the granted scopes, or the contact address you enter on a report)
  • Account language preference (if you grant locale)
  • Session id, access and refresh tokens (stored encrypted), expiry, and a CSRF token
  • Short-lived login state (PKCE values, return URL)

1.2 Reports you submit

  • Intent (report a problem / report abuse or a security issue) and product
  • Subject, description, follow-up notes, and public admin replies
  • Attachment original name, type, size, and file bytes (zip or jpeg / png / gif / webp; 10MB each; up to 3 at submit, 3 per message, 12 per report)
  • Status and timestamps

Internal admin notes are for handling only. They are not shown to you and do not trigger mail to you.

1.3 Information created while you use the Portal

  • Source IP, IP version, and which edge you hit (Hangzhou or Virginia), used for the footer “where you are” line and for security
  • Access and error logs needed for security and troubleshooting, kept as small as practical

1.4 What we do not ask for

We do not ask for sensitive personal information that is unrelated to handling a report. Do not put passwords, codes, passkeys, or client_secret in text or files. Notification mail does not attach your files; it only includes a link.

PurposeExamples
Provide the PortalSign-in, session, submit and view reports
Handle and replyReview, correspondence, progress mail
SecurityCSRF, session checks, file-type checks, abuse prevention, troubleshooting
Legal dutiesRegulatory requests, security incidents

Information required to submit a report (including email and description) is necessary to provide the Service. For sign-in, openid, preferred_username, and email are required scopes; locale is optional.

3. Sharing, transfer, and disclosure

We do not sell your personal information. We share or disclose it only when:

  1. Swaymoon Account: identifiers and granted claims flow between Account and the Portal as needed to sign you in.
  2. Processors: infrastructure and the mail provider that delivers notices to you and to our handling mailbox, only on our instructions and only as needed.
  3. Handlers: the smallest set of people who need access to work the report.
  4. Law: where statutes, litigation, or a competent authority require it.

Attachments stay on local disk for this Service. They are not uploaded to object storage and are not sent as mail attachments.

4. Location and retention

Reports, sessions, and attachments are processed in Jiangsu, China on local storage. We use access control, token encryption, and minimized transfer.

To make the site reachable worldwide, your browser may first connect to an edge in Hangzhou or Virginia, then reach the processing host over an encrypted tunnel. Edges do not keep report bodies or attachments. Static acceleration or mail delivery may send contact details over overseas paths; that does not change where report data is stored.

As a result, some limited personal information (for example connection data at an edge, and contact details needed to deliver mail) may be processed outside mainland China. We direct our processors under this Privacy Policy and only as needed to provide the Service.

We keep data only as long as needed for the purpose. While a report is open we keep what handling requires. After you delete your Swaymoon Account, Portal sessions for that account are cleared. Later deletion or anonymization of reports and files follows minimization and the law. Audit and security logs may be kept for a shorter or, where required, longer period.

5. Your rights

Under applicable law you typically have rights to access, correct, delete, withdraw consent, and export. For this Portal:

  • After sign-in, My Reports shows what you submitted and public replies
  • You can add notes or attachments on a report
  • You can manage authorization, export, and deletion in Swaymoon Account → Privacy
  • We may verify your identity before acting on a request

You may also use this Portal or hello@swaymoon.com for privacy requests.

6. Cookies and local storage

The Portal uses a REPORTAPROBLEM_SID session cookie (SameSite=Lax; Secure) to keep you signed in. Language preference may use the site-wide swaymoon_locale cookie. You can control cookies in the browser; turning them off may block sign-in or language persistence.

7. Children

If you are a minor, read this Policy and use the Service with a guardian. We do not knowingly collect a minor’s personal information without guardian consent. Contact us if you believe that has happened.

8. Security

We use technical and organizational measures matched to the risk, including transport encryption, encrypted tokens, magic-byte checks on files, access control, and least privilege. Do not put secrets in reports, and keep your account and devices safe.

9. Updates

We may update this Policy and publish the new version and effective date in Docs. Material changes will be highlighted. If we need a new consent, we will ask for it in the relevant flow.

10. Contact

For privacy requests or complaints, use Report a Problem or email hello@swaymoon.com. See also Contact Swaymoon.