Privacy Policy
Last updated: August 13, 2026
Summary
Swirlz ("we", "us") is a journaling and documentation tool built for people navigating divorce and high-conflict co-parenting. We are designed around a deliberate principle: your documentation records live in your own Google Drive, not on our servers. We hold the minimum account information necessary to know who you are and where in your Drive your records are kept, plus the specific server-side features listed below; each stored only if you use that feature.
What we store on our servers
On our backend (Supabase), we store a small profile record per user containing only:
- Your email address (from Google sign-in)
- Google Drive file/folder IDs that point to the resources Swirlz created in your own Drive (folders, sheets, docs, the markdown journal file)
- Account timestamps (created, updated)
- Optional self-described "situation tags" you choose for the support resources feature; kept in a table only your own sign-in can read; they are not accessible from our admin tooling
- If you use the email forwarding feature ("Important life info"): the emails you choose to forward; sender, subject and body; and the summaries generated from them, stored until you delete them. Only mail you deliberately forward to your private address is ever received; we never connect to your inbox. Links you import into School info yourself work the same way: the page's text and its summary are stored like a forwarded email, until you delete them.
- If you use the Grades feature in School info: the class, grade and open-assignment snapshots a computer you control pushes to your private grades address (class names, averages, assignment titles, dates, scores and Google Classroom links). We never sign into your school portal or Google Classroom and never hold those passwords; the newest thirty checks per student are kept and older ones are deleted automatically.
- Your Google refresh token. This is what keeps you signed in: Google's access expires every hour, and without a stored refresh token you would have to re-approve Swirlz's access that often. It grants exactly the access you already approved (files Swirlz created in your Drive) and nothing more. Remove Swirlz at your Google Account permissions and it stops working immediately.
- If you use the board calendar link: a copy of your routines (names, who they're for, schedule and step titles) so the board can show them. Stars and completions are not copied. Replacing the link doesn't remove this copy; deleting the routines in the app does, on your next visit to Routines.
- If you share a to-do project by link: a copy of that project only; task names, due dates, whether each is done, and any reward amount you put on a task with its offered/owed/paid state; so the page can be shown to someone who has no Swirlz account. Nothing else from those tasks is copied, and no other project is. Turning the link off deletes the copy immediately. We never store a Google credential to do this; when someone ticks something off, it is written to your Drive by your own browser the next time you open Swirlz.
- If you share a recipe by link: a copy of that recipe only; its text, picture, and details; so the page can be shown to someone who has no Swirlz account. Sharing again after an edit updates the copy; turning the link off deletes it immediately.
- If you connect Craft.do note syncing: the connection URL Craft issues for your space (which embeds its own access credential) and your folder mapping.
- A basic activity record: which kind of action you took and when - for example "created a to-do" or "opened Coparenting"; used to understand how the app is being used. This records the kind of action and its time only. It never includes what you wrote, the category you chose, or any other detail of the entry.
We do not store the content of your journal entries, your co-parenting event records, your photos, your audio recordings, or transcripts on our servers. All of that lives in your Google Drive. The only user content on our servers is what the two optional features above describe: forwarded email and imported links with their summaries, and a Craft connection if you add one.
What lives in your Google Drive
When you sign in, Swirlz creates its own folder in your Drive containing subfolders for To-do's, Notes, and Coparenting. Each subfolder holds Sheets, a Doc, a Markdown file, and a Media folder. You own these files. If you stop using Swirlz, you can keep them, export them, or delete them. We never copy them off your Drive.
Third-party services we send your data to
When you record a voice memo or write a journal entry, Swirlz may transmit that content to the following services to provide the features you used:
- Google: for Drive, Sheets, and Docs storage. Subject to Google's privacy policy.
- OpenAI: for audio transcription (Whisper). Audio bytes you record are sent to OpenAI to convert speech to text. Subject to OpenAI's API data usage policies.
- AssemblyAI: for call recording transcription. If you use the call recording feature, the audio you record is sent to AssemblyAI to be converted to a transcript with speaker labels, and live captions during a call stream your microphone audio there as well. The finished transcript is held by AssemblyAI only until it has been written to your own Google Drive; we then delete it from AssemblyAI immediately, and AssemblyAI removes uploaded audio after transcription completes. We never store the audio or the transcript on our servers. Subject to AssemblyAI's privacy policy.
- Anthropic: for AI tag suggestion, summarization, event structuring, and Ask. Text you've written or had transcribed is sent to Anthropic; for Ask, your browser picks the records that match your question and only those are sent. Search runs entirely on your device and sends nothing. Subject to Anthropic's commercial terms.
- Twilio SendGrid: receives email you forward to your private forwarding address and delivers it to us. Subject to Twilio's privacy policy.
- Jina: some school newsletters are only a link, and some of those pages are built in the browser so we can't read them directly. In that case we send the link on its own to Jina, which opens the page and returns its text so we can summarise it. Only the link is sent; never your email, your name, or who sent it. Subject to Jina's privacy policy.
- Craft.do: only if you connect it: notes in categories you map are sent to your own Craft space. Subject to Craft's privacy policy.
- Supabase: for authentication and the small profile record described above. Subject to Supabase's privacy policy.
- Vercel: for application hosting. Standard server logs may include IP addresses and request paths.
Swirlz does not sell your data to anyone, and does not use your content for advertising or analytics profiling.
Cookies and authentication
We use authentication cookies (managed by Supabase) so you stay signed in between visits. We use one localStorage flag to remember you've entered the access code on this device. We do not use advertising or analytics cookies.
Your rights
You can delete your account and all server-side data by emailing us (contact below). To delete the records in your Drive, delete the Swirl App folder in Google Drive; that's the canonical store. To revoke Swirlz's access to your Drive, visit your Google Account permissions and remove Swirlz.
Children's privacy
Swirlz is intended for adults navigating personal legal documentation. It is not directed to children under 13 and we do not knowingly collect data from them.
Changes
We may update this policy. The date at the top reflects the most recent change. Material changes will be surfaced in the app the next time you sign in.
Contact
Questions or deletion requests: accounts@bmhprod.com.