Privacy Policy

Last updated Aug 18, 2026

Privacy Policy

Effective date: 18 August 2026

This Policy explains how Swaymoon handles personal information when providing Survey (survey.swaymoon.com). Anonymous fills do not require sign-in. If you sign in, Account processing is described in the Account Privacy Policy.

1. Information we process

  • Sign-in (only if you sign in): Account sub, username, display name, email in scope, locale, encrypted session tokens, CSRF tokens.
  • Responses: answers, a schema snapshot, optional password check (plaintext password is never returned on public APIs). Named surveys bind an Account; anonymous surveys do not.
  • Anti-abuse: fill cookie SURVEY_FILL, CSRF, source IP, User-Agent, channel; captcha verify parameters if enabled.
  • Location: search keywords or coordinates you choose are sent by our server to Amap Web REST. The page does not contain a map key.

Do not put passwords, codes, passkeys, or client_secret in answers or files.

2. Purposes

Provide the Service, aggregates and export, security (CSRF, captcha, limits), and legal obligations. We do not sell personal information. Responses and files are stored in Jiangsu, China. Closing an Account deletes named responses via the deletion webhook; anonymous responses are not bound to an Account and are not auto-deleted on Account closure.

Questions: Report a Problem or hello@swaymoon.com.