Privacy Policy
Last updated July 22, 2026
About this policy
Shiesty is an application operated by Swayy Labs LLC. This policy explains what we collect, why we use it, when it is visible to other people, which service providers process it, and how long we keep it. Shiesty is initially offered only in the United States and is intended for people age 18 or older.
We do not sell personal information, use it for cross-context behavioral advertising, or use Apple's advertising identifier (IDFA). Shiesty does not track you across apps or websites owned by other companies.
Information we collect
- Account and profile: email, display name, handle, bio, optional user-entered location, preferences, authentication records, and account status.
- Vault and activity: catalog and custom items, quantities, values, purchase prices, user-reported MSRP, notes, photos, maintenance, builds, range sessions, disposals, serial numbers, NFA status and dates, and trust names.
- Social content: public profiles, posts, images, comments, likes, follows, blocks, reports, and build or vault fields you choose to share publicly.
- Subscriptions: StoreKit product, entitlement, transaction, environment, and expiration information. Swayy Labs never receives your payment-card number or payment-card credentials.
- Technical and diagnostic data: IP and request logs, security events, account-associated APNs device tokens, and crash diagnostics.
- Analytics: search queries, result taps, and product interactions associated with a stable pseudonymous user hash.
- Support: messages and attachments you send to support@shiesty.io.
Serial numbers, NFA information, and trust names are received by our API so your private vault can synchronize across signed-in devices. Sensitive fields are protected with application-level authenticated encryption before database storage. They are not public, are excluded from analytics and social moderation, and are accessible only through your authenticated account and tightly controlled operational access.
Information that stays on your device
Face ID templates, live barcode-camera frames, device search recents, and Photo Library content you do not select are processed locally and are not collected by Swayy Labs. Apple controls Face ID authentication and does not provide the biometric template to us.
How we use information
- Provide accounts, synchronization, portfolios, builds, social features, subscriptions, support, and requested notifications.
- Calculate user-requested inventory views and preserve purchase, maintenance, and range history.
- Protect accounts, prevent abuse, investigate reports, enforce our Community Guidelines, and maintain service reliability.
- Understand searches and product interactions, improve catalog coverage, diagnose failures, and measure feature usefulness.
- Comply with law, respond to valid legal process, and establish or defend legal claims.
Public content and your choices
Your email, private vault, serial numbers, NFA data, trust information, private notes, and private financial values are not shown to other users. A handle, display name, bio, profile location, avatar, post, comment, or public build may be visible when you use the social features. Vault or build fields become public only when you explicitly share them. You can remove content, make eligible content private, block users, or report content in the app.
Safety screening and human review
Content intended for public or social display may be screened by deterministic Shiesty rules and OpenAI's moderation API before publication. Only that intended-public text and those intended-public images are sent for safety screening. Private vault photos, serial numbers, NFA data, trust information, private notes, purchase prices, and private values are never sent to OpenAI for moderation.
Clear violations may be blocked. Uncertain submissions are held privately for human review and are not visible to other users while pending. A rejected submission may be appealed within 30 days. OpenAI states that API abuse-monitoring data may be retained for up to 30 days by default; Swayy Labs keeps API data-sharing and model-training opt-ins disabled.
Service providers
We disclose only the information reasonably needed for these providers to perform their services:
- Railway — application and database hosting, networking, and operational logs.
- Vercel — public website and authenticated admin-dashboard hosting, networking, and operational logs.
- Cloudflare R2 — storage and delivery of user-selected and catalog media.
- Apple — App Store distribution, StoreKit subscriptions, APNs push delivery, and device capabilities you choose to use.
- Resend — transactional account, security, support, and policy-update email.
- Sentry — scrubbed crash and reliability diagnostics.
- OpenAI — safety screening of intended-public text and images.
Providers process data under their own security and retention controls and our instructions. We may also disclose information when required by law or to protect users, the public, Swayy Labs, or the integrity of the service.
Retention and deletion
- Active account records remain until you edit or delete them, unless a shorter period below applies.
- Account deletion removes active database records immediately and attempts immediate media deletion. Orphaned copies and backups are cleared within 30 days.
- Minimal Apple subscription recovery identifiers are retained until 90 days after the later of account deletion or subscription expiration, without your Shiesty user ID, email, or vault data.
- IP and security request logs are retained for 30 days.
- Raw linked search events and taps are retained for 90 days.
- Anonymous search aggregates may be retained for 13 months. They contain no user hash and omit groups with fewer than five distinct users.
- Pending or rejected moderation payloads and media remain available for a 30-day appeal period, then are deleted. Minimal moderation decisions and resolved reports are retained for 90 days.
- Sentry crash diagnostics are configured for 30-day retention.
We may preserve narrowly limited records longer when required by law, needed to resolve an active dispute, or necessary to prevent repeated abuse. Where deletion from an active system is immediate but backup rotation takes time, the data is isolated from ordinary use.
Security
We use transport encryption, access controls, password hashing, encrypted storage for designated sensitive fields, audit logs, rate limits, diagnostic redaction, and account deletion controls. No security system is perfect, so do not store information you do not want associated with your Shiesty account. Contact us promptly if you believe your account or data has been compromised.
Your U.S. privacy rights
Depending on your state, you may have rights to access, correct, obtain, or delete personal information; appeal a denied request; and receive equal service without discrimination for exercising a privacy right. You may use in-app controls or email support@shiesty.io. We may need to verify your identity before completing a request. If we deny an appeal, we will explain any additional regulator-contact right available under applicable state law.
Age and availability
Shiesty is for adults age 18 and older and is initially available only in the United States. We do not knowingly collect personal information from anyone under 18. Contact us if you believe an underage person has created an account.
Policy updates
We may update this policy as the service or law changes. We will change the date above and, for material changes, provide an in-app notice and email existing account holders. A policy notice is informational and does not prevent access to core account features.
Contact
For privacy requests, moderation appeals, or questions, email support@shiesty.io. Shiesty is operated by Swayy Labs LLC in the United States.