Privacy Policy

Last updated: 9 October 2026.

GeoSwirl is operated by Sumit Pundir, India. Privacy and data requests: support@geoswirl.com.

Accounts and technical information

Firebase Authentication processes your email, credentials, verification status and account identifier. Our application records do not store your plaintext password. Google App Check/reCAPTCHA Enterprise, Google Cloud and Cloudflare process technical information, including network and browser information, to authenticate requests, protect the service and deliver the website. These services are not anonymous.

Projects, media and rendering

Draft projects and imported media are stored in browser IndexedDB, scoped by account in the app. Local project changes do not by themselves upload media for rendering. Authentication, map data and security-related requests may also occur during use.

When you request Preview or Export, required media, story settings and selected map coordinates are sent to our Google Cloud rendering service. Preview may use a smaller video proxy; export uses required original media within supported limits. Preview media is request-scoped and cleanup is attempted after rendering. Local previews and drafts have separate retention from server files.

Purpose and providers

We process information to provide your requested service, manage access and usage, respond to support/data requests, and protect against misuse. Relevant providers include Google/Firebase/Google Cloud and Cloudflare; support email is hosted by Spaceship/Spacemail. Provider processing may occur outside your country. Their applicable privacy notices also describe their processing: Google, Cloudflare and Spaceship.

Retention

Browser drafts remain until removed or local storage is cleared. We cannot remotely remove copies on other devices or files exported outside the app. The private production web export bucket schedules objects under exports/ for deletion once they are seven days old, with soft-delete disabled. Deletion is asynchronous and may complete later than seven days.

The production Google Cloud default operational log bucket retains logs for 30 days. Other provider-managed records can follow different rules. Account information remains while the account exists. Minimal account-deletion identifiers used to prevent old tokens from restoring access currently have no automatic expiry; contact us to request review. These settings were checked on 9 October 2026 and are not a claim that every record is deleted within seven days.

Payments are not currently enabled

Live checkout is disabled. At paid launch, Paddle is intended to act as merchant of record, handling card details and buyer billing records. The planned integration sends your verified email to Paddle and keeps subscription identifiers, payment status and usage records for entitlement, cancellation and reconciliation. Live financial-record retention must be finalized before accepting payments; we do not currently offer a production paid subscription. Paddle’s privacy notice is available at paddle.com/legal/privacy.

Your requests and security

Contact support@geoswirl.com for access, correction, deletion or other privacy requests. We may need to verify account ownership. Rights and complaints to a relevant authority depend on applicable law; we do not assume every jurisdiction has identical rules. For account deletion, contact support; local copies, legally necessary records and provider records may require separate handling. Do not send passwords or card numbers.

Service requests use HTTPS and account-scoped access controls. No system can guarantee absolute security. Protect shared devices: signing out alone does not erase browser drafts. This policy may be updated as the service changes; material changes will be communicated as appropriate.