privacy-policy Developer
Last updated Aug 16, 2026
Governing language: The Simplified Chinese version is authoritative. This translation is provided for convenience.
Privacy Policy
Effective date: August 8, 2026
摇月 Swaymoon (“we,” “us,” or “our”) takes your privacy seriously. This policy explains how we collect, use, store, share, and protect personal information when providing 摇月 Swaymoon Developer Portal (the “Developer Portal” or “this Service”; the website is develop.swaymoon.com), and the rights you have. By using this Service, you represent that you understand this policy. Where we need additional consent, we will obtain it separately in the relevant context.
The Developer Portal signs in through 摇月 Swaymoon Account. How Swaymoon Account itself processes personal information is described in the Swaymoon Account Privacy Policy. This policy explains only information that the Developer Portal processes additionally or independently.
This policy is prepared in light of applicable requirements, including the Personal Information Protection Law of the People’s Republic of China. Where cross-border processing or users in the United Kingdom or the European Union are involved, we follow the stricter of UK GDPR / GDPR in principle.
1. Information We Process
1.1 Sign-in and sessions (Portal side)
To complete OAuth / OIDC sign-in and maintain your session on the Developer Portal, the Portal may process and store in local session storage:
- Account identifiers, display name, and email associated with Swaymoon Account (provided by Swaymoon Account within the authorized scope at sign-in)
- Session identifiers, access tokens and refresh tokens (stored encrypted), expiry times, and CSRF protection tokens
- Short-lived state during sign-in (such as PKCE-related parameters and the post-sign-in return address)
1.2 Membership and teams
On first successful sign-in, the system may create a default personal team affiliation record for you (including team identifier, display name, team type, member role, and join time), used to attribute application identifiers you create to that team and to support team-isolated user identifiers (pairwise sub). Membership and invitation records are stored on the Developer portal and are not written to Swaymoon Account. When you invite someone to a team, we process the invitee’s notification email, invitation status, and acceptance time. After someone joins, other members may see their display name and (for Admin and Account Holder) notification email.
1.3 Application configuration you submit in the Portal
Information you submit when creating or editing an identifier (such as application name, icon, redirect URI, permission scopes, data-deletion callback address, and privacy policy link) is forwarded by the Portal to the Swaymoon Account side for storage, for OAuth / OIDC client registration and user-authorization display. These configurations serve your application integration and are not end-user personal profiles, but files such as icons may contain image content you upload.
1.4 Content we do not retain long-term on the Portal side
- The plaintext
client_secretof a confidential client is shown to you only once in the creation response; the Portal does not keep it as plaintext that can be viewed again - Consent records, tokens, UserInfo, and the like generated after end users authorize through your application are processed by Swaymoon Account under the Swaymoon Account Privacy Policy and are not separately archived by the Developer Portal
2. Purposes of Processing and Legal Bases
| Purpose | Examples |
|---|---|
| Provide the Developer Portal | Sign-in, sessions, membership display, identifier management |
| Proxy calls to Swaymoon Account developer APIs | Create/update/delete clients, upload icons |
| Safeguard security | CSRF, session validation, abuse-prevention and troubleshooting logs |
| Respond to user deletion requests | When a Swaymoon Account data-deletion callback is received, clean up that account’s local session data on the Portal and similar |
| Perform legal obligations | Respond to regulatory requirements, handle security incidents |
Where consent is required, we will give a clear prompt in the interface or documentation. Processing necessary to perform a contract, to comply with a legal obligation, or to protect vital lawful interests will be carried out in accordance with applicable law.
3. Sharing, Transfer, and Public Disclosure
We do not sell your personal information. We share or disclose it only in the following circumstances:
- Swaymoon Account: information necessary for sign-in and client registration flows between Swaymoon Account and the Developer Portal in accordance with the agreement and the authorized scope.
- Information visible to end users: the application name, icon, privacy policy link, and the like that you register may be shown to end users on the Swaymoon Account consent page or in authorization details.
- Processors: such as cloud infrastructure, who may process data only on our instructions and for purposes necessary to provide the Service, and who assume corresponding confidentiality and security obligations.
- Legal circumstances: pursuant to laws and regulations, litigation, or mandatory requirements of competent government authorities.
- Business combination: in the event of a merger, division, or asset transfer, we will require the successor to remain bound by this policy and, where required, seek your consent again.
4. Cross-Border Processing and Storage
Local data such as Developer Portal sessions and teams, and configuration data related to Swaymoon Account, are processed and stored in Jiangsu, China (or a location consistent with Swaymoon Account infrastructure). We protect data through access control, encryption, minimized transmission, and similar measures.
To provide globally accessible websites and APIs, static content or edge acceleration may be transmitted via overseas content delivery networks; this does not change the storage and processing location of the account and Portal business data described above.
Retention is limited to what is necessary to achieve the purpose: while you continue to use the Developer Portal, we retain session and team information necessary to provide the Service; after a session expires or you sign out, the corresponding session data will become invalid or be deleted. If Swaymoon Account initiates a data-deletion notice for your account, the Portal will clean up local session data and similar as agreed; whether registered OAuth clients are deleted is determined by your operations in the Portal and the rules on the Swaymoon Account side (a deletion notice does not by default automatically clear all identifiers under the team). Except where laws and regulations require retention.
5. Your Rights
Under applicable law, you generally have rights of access, copying, rectification, deletion, withdrawal of consent, export, and the like. For the Developer Portal:
- You may view membership and configurations of identifiers you have created in the Portal
- You may edit identifier fields that are allowed to be modified, or delete identifiers you no longer need
- For Swaymoon Account profile, security settings, export, and account deletion, go to passport.swaymoon.com
- Consequences of deleting a Swaymoon Account are governed by the Swaymoon Account Privacy Policy; local Portal sessions will be cleaned up as part of the deletion process
When you exercise your rights, we may verify your identity. Contact details are below.
6. Cookie and Local Storage
The Developer Portal uses Cookie (such as session Cookie) and necessary security tokens to maintain sign-in and CSRF protection. See the Cookie Policy. If you disable necessary Cookie, you may be unable to sign in or use the Portal.
7. Minors
If you are a minor, please read this policy and use this Service under the guidance of a guardian. We will not knowingly collect personal information of minors without guardian consent. If you become aware of such a situation, please contact us so we can address it.
8. Security Measures
We take technical and organizational measures commensurate with business risk, including encryption in transit, access control for sessions and tokens, key management, and least-privilege authorization. You should also properly safeguard client_secret, servers, and signed-in devices.
9. Policy Updates
We may update this policy and will publish the updated version and effective date on the documentation site. Material changes will be highlighted in a prominent manner. If an update requires consent to be obtained again, we will obtain your consent in the relevant context.
10. Contact Us
For requests or complaints related to personal information protection, email hello@swaymoon.com, or visit docs.swaymoon.com to read Contact Swaymoon and the latest information.