Legal
Privacy Policy
Effective August 26, 2026
Swaymark never sells Health data, never uses it for advertising or marketing, and never writes data to Apple Health. You choose which Apple Health categories the app may read and where approved data is sent.
Scope
This policy explains how the Swaymark iOS app and its built-in Swaymark connection handle information. A destination you add yourself is operated under that destination's own privacy policy and security practices.
Information the app processes
Apple Health data you approve
Depending on the permissions you select, Swaymark may read health and fitness information such as sleep and sleep stages, activity, steps, energy, workouts and workout routes, heart and respiratory measurements, body measurements, mindfulness, and nutrition. Swaymark requests read-only access and does not access clinical health records.
Destination and delivery information
The app stores the destination names and URLs you add, the credentials needed to authenticate with those destinations, your selected data categories, delivery settings, and recent delivery status. Secrets and device tokens are stored in the iOS Keychain. Non-secret preferences and recent delivery diagnostics are stored locally on your device.
Swaymark connection
If you choose the built-in Swaymark destination, the app exchanges a one-time pairing code for a device credential and sends the approved health summaries to Swaymark at swaymark.app. Swaymark may store health and fitness data, workout route location, a device identifier, the device name you provide, and app check-ins so the service can show your history, trends, and requested features. This information is linked to the account that created the pairing code.
Connected work services
If you connect RescueTime, Swaymark receives completed-day aggregates for Focus Work, Other Work, distracting time, total recorded time, and Productivity Pulse. It does not request or store the names of apps, websites, documents, or individual activities. The RescueTime API key is encrypted server-side, is never returned to your browser after saving, and can be removed without deleting previously imported daily aggregates.
Weather and calendar context
If you enable Weather, your browser obtains a location only after you press the setup button. Swaymark rounds its latitude and longitude to two decimal places before sending or storing them, stores the label and time zone you provide, and sends the rounded location to Apple WeatherKit. Swaymark stores daily condition aggregates such as temperature, cloud cover, humidity, precipitation, wind, daylight, and condition—not a continuous location trail.
If you connect Google Calendar, you choose one or more calendars to include. Swaymark requests read-only access to your calendar list and events. Calendar identifiers, calendar labels, and OAuth tokens are encrypted server-side. Event timing, type, attendee presence, and conference presence may be processed temporarily to calculate daily event, meeting, scheduled-focus, all-day, and after-hours totals. Swaymark does not store event titles, descriptions, attendee names or email addresses, meeting links, locations, or individual event identifiers.
Custom destinations
If you add a custom HTTPS endpoint, Swaymark sends the categories you selected directly from your device to that endpoint. The Swaymark developer does not receive a copy merely because you use a custom endpoint. You are responsible for confirming that the endpoint is yours or that you have permission to send data to it.
Website analytics
Swaymark uses Google Analytics and PostHog to process limited website and product usage information, including pages visited, selected signup and onboarding actions, device and browser details, the referring page, and approximate location. Swaymark uses this information to understand and improve the site and product. Google and PostHog act as Swaymark's processors for this information.
Analytics loads automatically when you use swaymark.app. It does not receive Apple Health data, mood or journal notes, form contents, email addresses, or URL query parameters and fragments. Product events may use a pseudonymous internal account identifier so Swaymark can measure whether onboarding steps were completed, but that identifier is not an email address or name. Session replay is disabled.
Subscription billing
If you start a paid Swaymark subscription, Stripe processes checkout, payment details, invoices, and subscription management under Stripe's privacy terms. Swaymark stores the Stripe customer, subscription, and price identifiers, billing interval, subscription status, trial and renewal dates, and cancellation state needed to provide access. Swaymark does not receive or store your complete payment-card number.
How information is used
Information is processed only to:
- read the Apple Health categories you explicitly approve;
- format and deliver data to enabled destinations;
- show sync history, delivery status, and actionable errors;
- maintain reliable retries and background delivery when iOS permits it;
- provide Swaymark features when you connect Swaymark;
- import the daily work aggregates you request from connected services;
- start, manage, and verify subscription access through Stripe;
- measure website use, signup, onboarding, and integration adoption; and
- protect the service from abuse and troubleshoot support requests.
Health data is not used for advertising, marketing, profiling, credit decisions, or data brokerage. The app contains no third-party advertising SDK. Swaymark does not use Google Analytics for advertising and does not track you across other companies' apps or websites.
Sharing and disclosures
Swaymark sends information only to destinations you enable. Apple receives a rounded location when Weather is connected, and Google provides the selected calendar information needed to create daily schedule totals. Stripe receives the account and transaction information needed to process a subscription, but does not receive Apple Health data, mood notes, or your private Swaymark timeline from Swaymark. Information may also be disclosed when required by law, to protect users or the service from fraud or harm, or to infrastructure providers that process Swaymark data solely to operate the service. Health and fitness data is not sold or shared with data brokers, advertisers, or marketing platforms.
Storage, security, and retention
Swaymark uses encrypted HTTPS transport for supported network destinations and requires custom endpoints to use HTTPS. Destination credentials are stored in the iOS Keychain. Delivery preferences and diagnostics remain on the device until you remove a destination or delete the app.
Swaymark retains paired health summaries until you delete the associated data or account, subject to limited backups and records that must be kept for security or legal reasons. No method of storage or transmission can be guaranteed completely secure, so connect only destinations you trust.
Your choices and controls
- Choose individual Health categories in Apple's authorization sheet.
- Review or revoke Health access in the Health app or iOS Settings.
- Disable or delete any destination in Swaymark.
- Disconnect RescueTime or revoke its API key from your RescueTime account.
- Disconnect Weather to stop new condition samples while retaining saved daily aggregates.
- Choose which Google calendars are included, disconnect Calendar, or revoke Swaymark access from your Google Account.
- Unpair Swaymark to remove the device credential from the phone.
- Delete Swaymark data from the service or contact support for help.
- Delete the iOS app to remove its local preferences and Keychain entries.
Children
Swaymark is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided information through Swaymark, contact us so it can be reviewed and removed.
International processing
Swaymark infrastructure may process information in the United States. Custom destinations process information wherever their operators specify. By enabling a destination, you direct Swaymark to transmit the selected information to it.
Changes to this policy
This policy may be updated as Swaymark changes. The effective date above will be revised, and material changes will be communicated in the app or on this page when appropriate.
Contact
Questions, privacy requests, and deletion requests can be sent to michaelrode44@gmail.com. Please do not email Health data, passwords, webhook secrets, or pairing codes.