Legal
Privacy Policy
Last updated: October 4, 2026
This Privacy Policy explains how Arche Labs Ltd (“we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use GetSwapped at www.getswapped.app (the “Service”). It also explains the choices and rights you have. Because the Service works with photos of people’s faces, we have written a dedicated section on how we handle face images (Section 4).
1. Who we are
The controller responsible for your personal information is Arche Labs Ltd, Apostolou Louka 14, 8577 Tala, Cyprus. You can reach us about privacy matters at getswapped.com@gmail.com.
2. Information we collect
Information you give us
- Account information: your name, email address, password or sign-in credentials (if you sign in with a third-party provider, we receive basic profile information from it), and your account preferences.
- Payment information: payments are processed by Stripe. Stripe collects your card or other payment details directly; we never receive or store your full card number. We receive limited billing information from Stripe, such as your name, billing country, the last four digits and expiry date of your card, and your subscription and transaction history.
- Uploaded content: the photos and videos you upload to create swaps (“Inputs”), which may include images of your face or of people who have given you permission.
- Generated content: the images and videos the Service creates for you (“Outputs”) and the settings or templates you chose.
- Communications: messages you send to our support team, abuse reports, and any information you include in them.
Information collected automatically
- Usage and log data: IP address, browser and device type, operating system, pages visited, actions taken in the app (such as generations started, completed, or failed), credit usage, timestamps, and error logs.
- Cookies and similar technologies: see Section 10.
3. How we use your information
- to create and manage your account and authenticate you;
- to provide the Service, including processing your Inputs to generate the Outputs you request, and storing your Outputs so you can access them;
- to process payments, manage subscriptions and credits, and prevent payment fraud;
- to keep the Service safe, including detecting and preventing abuse, enforcing our Terms of Service and Acceptable Use Policy, and responding to reports of misuse;
- to provide customer support and send service messages such as receipts, security alerts, and changes to our terms;
- to understand how the Service is used in aggregate and improve its performance and reliability; and
- to comply with legal obligations and respond to lawful requests.
We send marketing emails only where permitted by law, and you can unsubscribe at any time using the link in each email.
4. Face images and biometric information
We know face images are sensitive, so we apply strict limits to how they are handled:
- Limited purposes. Face images in your Inputs are processed only to generate the Outputs you ask for and to run the safety checks needed to enforce our Acceptable Use Policy (for example, blocking content that appears to depict a minor). Authorized staff review content only when it is flagged or reported for abuse.
- No identification. To create a swap, our AI provider analyzes the face in your photo. This can involve measuring facial features (facial geometry). We use this only to render your Output. We never use it to identify or verify who someone is, we never build a database of faces, and we do not keep it after the generation finishes.
- Never sold. We do not sell, lease, trade, or otherwise profit from face images or any biometric information.
- Not used for training. We do not use your Inputs or Outputs to train or fine-tune AI models, and we do not provide them to anyone else for that purpose.
- Short retention. Any facial geometry or other intermediate data derived from a face during generation is used transiently to produce the Output and is not retained after generation completes. Uploaded source photos and videos are automatically deleted within 30 days (see Section 8).
- Consent at upload. Before you upload a face, we ask you to confirm that it is your own face or that you have the explicit consent of the person depicted. If it is your face, you consent at upload to the processing described in this section for the purpose of generating your Output. If it is someone else’s face, you must obtain that person’s explicit, informed consent to this processing before uploading.
This section is intended to serve as our written policy on biometric information for the purposes of laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas and Washington biometric privacy laws, and similar laws. To the extent any data we process is considered a biometric identifier or biometric information, it is destroyed when the initial purpose for collecting it (generating your Output) has been satisfied and in all cases within 30 days, unless we are legally required to retain it longer. Before any face is processed, we get a written release through a checkbox at upload. It states the purpose (generating your Output), that the image is shared with our AI provider Higgsfield AI for that purpose only, and the retention period.
5. Legal bases for processing (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases under the GDPR and UK GDPR:
- Performance of a contract — to provide the Service, generate Outputs, manage your account and subscription, and provide support.
- Explicit consent — for processing face images in your Inputs. If the face is yours, you give this consent at upload, and you can withdraw it by deleting the upload. If it is someone else’s face, we process it only because that person has given explicit consent, which you must get before uploading and show us on request. We delete the content if that consent is missing or withdrawn. Consent also covers non-essential cookies and, where required, marketing emails. You can withdraw consent at any time without affecting processing that has already taken place.
- Legitimate interests — to secure and improve the Service, prevent fraud and abuse, and enforce our terms, where those interests are not overridden by your rights.
- Legal obligation — to keep tax and accounting records and respond to lawful requests from authorities.
6. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share personal information only with the following categories of recipients:
- Stripe — payment processing, subscription billing, and fraud prevention. Stripe acts as an independent controller for some processing, such as fraud prevention and regulatory compliance, under the Stripe Privacy Policy.
- Higgsfield AI — AI generation. Your Inputs are transmitted to this provider to generate Outputs on our behalf.
- Vercel — website and application hosting and content delivery.
- Email, storage, and analytics providers — to send transactional emails, store files, and measure aggregate usage of the Service.
- Legal and safety — law enforcement, regulators, or other parties when required by law or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of our users, the public, or Arche Labs Ltd, including reporting child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC).
- Business transfers — a successor in a merger, acquisition, or sale of assets, subject to this Privacy Policy.
Except where stated above, our service providers act as processors on our behalf under written agreements that limit their use of your data to providing services to us and require appropriate security. A current list of sub-processors is available on request from getswapped.com@gmail.com.
7. International data transfers
We and our service providers may process your information in the United States and other countries whose data protection laws may differ from those where you live. When we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), or on an adequacy decision such as the EU-U.S. Data Privacy Framework where the recipient is certified.
8. Data retention
- Uploaded source photos and videos: automatically deleted within 30 days of upload, including copies held by our AI provider, or sooner if you delete them.
- Generated Outputs: kept in your account until you delete them or close your account.
- Account information: kept while your account is active. You can request deletion of your account at any time by emailing getswapped.com@gmail.com; we will delete your account, Inputs, and Outputs within 30 days of verifying the request.
- Billing records: kept as long as required by tax and accounting laws (typically up to 10 years).
- Logs and security records: kept for a limited period, generally no longer than 12 months, unless needed to investigate abuse or comply with law.
We may retain information longer where needed to resolve disputes, enforce our terms, or comply with a legal obligation, including preserving evidence of suspected illegal content for law enforcement. Deleted data may persist in encrypted backups for a short period before being overwritten.
9. Your privacy rights
Rights for everyone
Wherever you live, you can ask us to access or update your account information, delete your Inputs and Outputs, and ask us to delete your account.
EEA, UK, and Swiss residents
You have the right to access your personal data, to rectify inaccurate data, to erase your data, to restrict or object to our processing (including processing based on legitimate interests), to data portability, and to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority.
California and other U.S. state residents
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and similar U.S. state laws, you have the right to know what personal information we collect, use, and disclose; to access and receive a portable copy of it; to correct it; to delete it; and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined in these laws, and we use sensitive personal information (such as face images) only to provide the Service you request. We will not discriminate against you for exercising your rights. You may use an authorized agent to submit a request on your behalf.
How to exercise your rights
Email getswapped.com@gmail.com from the address associated with your account. We may need to verify your identity before acting on your request. We respond within 30 days (or 45 days where permitted by U.S. state law), and we will let you know if we need more time.
10. Cookies and analytics
We use essential cookies that are necessary to run the Service, such as keeping you signed in, remembering your preferences, securing your session, and completing checkout. We also use basic analytics to understand aggregate usage, such as which pages are visited and whether features work correctly. We do not use advertising cookies or allow third-party ad networks to track you on the Service. Where required by law, we ask for your consent before setting non-essential cookies. You can control cookies through your browser settings, although blocking essential cookies may prevent the Service from working.
11. Children
The Service is not intended for anyone under 18. We do not knowingly collect personal information from anyone under 18, and our Acceptable Use Policy prohibits uploading images of minors. If you believe a minor has provided us with personal information or that images of a minor have been uploaded, please contact getswapped.com@gmail.com and we will delete it promptly.
12. Security
We use administrative, technical, and organizational measures designed to protect your information, including encryption in transit (TLS), encryption at rest provided by our infrastructure providers, access controls that limit who can access user content, and logging and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service before they take effect. The “Last updated” date at the top of this page shows when it was last revised.
14. Contact us
If you have any questions about this Privacy Policy or how we handle your information, contact us at getswapped.com@gmail.com or by mail at Arche Labs Ltd, Apostolou Louka 14, 8577 Tala, Cyprus.