ChatSwap is operated by Based LLC, a Texas limited liability company. References to “ChatSwap”, “we”, “us”, or “our” in this Privacy Policy refer to Based LLC. Contact us at info@chatswap.ai.
We collect what we need to make matches and let buyers and sellers find each other: your email, the listings and wants you post, and messages you send to counterparties. Listing and want text is sent to OpenAI (for embeddings) and Anthropic (for the matching agent). Your email is hidden from other users until both of you accept a deal. We don't sell your data. The formal version is below.
§ 1. What we collect
- Account info. Your email address (verified via Supabase Auth) and the username you choose.
- User Content. Listings, wants, photos, and direct messages you send to counterparties, plus any accept/pass actions you take on deal proposals.
- Embeddings.A 1,536-dimensional vector generated from each listing/want's text, used for semantic matching.
- Operational data. IP addresses, user agent strings, timestamps, error logs — used for security, abuse prevention, and debugging. Standard server-log data.
- Auth cookies. A Supabase-managed session cookie that keeps you logged in across requests. No third-party advertising or analytics cookies.
§ 2. How we use it
- Matching. When you post a listing or want, we use its embedding and structured fields (price, location) to surface candidate matches.
- Communication. Direct messages you send to a counterparty are stored and shown to that counterparty in their thread on the same deal.
- Account security. Detecting abuse, spam, fraud, and unauthorized access.
- Service improvement. Aggregate usage data, error rates, and product analytics. We do not train AI models on your private content.
- Legal compliance. Responding to lawful requests from authorities and enforcing our Terms of Service.
§ 3. Third parties we share with
We use a small number of third-party services to operate the Service. We share only what each needs to do its job:
- Supabase (database + auth + storage). Stores your account, listings, wants, deals, messages, embeddings, and uploaded photos.
- OpenAI(embeddings only). The text of each listing and want title + description is sent to OpenAI's text-embedding-3-small endpoint to generate a vector for semantic matching. Per OpenAI's API terms in effect at the time of writing, API content is not used to train their models.
- Anthropic(LLM for the chat intake agent and the match validation step). Your chat-intake messages, draft listings, and sometimes counterparty content are included in prompts to Claude. Per Anthropic's API terms, API content is not used to train their models.
- Vercel (hosting). Standard server-log data is processed for delivery of the Service.
- Federated ChatSwap instances. If you post a listing here, its public fields (title, description, price, location, photos, sourceUrl) may be replicated to approved instances of the federation network for cross-instance discovery. Your email, walk-away price, and direct messages are never federated.
§ 4. What other users see
Your username is visible to anyone you have a deal with, and to anyone who clicks a listing you posted while signed in. Your emailis hidden from counterparties until both parties accept a deal — at which point it's revealed so you can coordinate the exchange. Your walk-away price is never revealed to anyone. Your direct messages are visible only to you and the counterparty on that deal.
§ 5. Cookies
We use a single Supabase-managed auth-session cookie. We do not use third-party advertising cookies, behavioral tracking cookies, or marketing analytics cookies. You can clear cookies at any time from your browser; doing so will sign you out.
§ 6. Data retention
We keep your account and User Content while your account is active. When you delete an item via the Service, the row and any uploaded photos are removed from our database and storage bucket. Federated copies on other instances may persist independently per their own retention policies. When you delete your account entirely, we remove your User Content within 30 days. Server logs containing IP addresses are rotated within 90 days.
§ 7. Security
Data is encrypted in transit (TLS) and at rest (provider defaults at Supabase and Vercel). Auth tokens are stored in HTTP-only cookies. We follow standard practices for managing service-account credentials. No system is perfectly secure; if you become aware of a vulnerability please email info@chatswap.ai.
§ 8. International transfers
Our infrastructure is hosted in the United States. By using the Service from outside the U.S., you consent to your data being transferred to and processed in the U.S.
§ 9. Your rights (general)
Depending on your jurisdiction (e.g., EU/UK GDPR, California CCPA/CPRA, Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA), you may have rights to access, correct, delete, or port your personal data, and to object to or limit certain processing. To exercise any of these rights, email info@chatswap.ai from the address on your account, or use the controls in your account settings where available. We respond within the timeframe required by applicable law (typically 30-45 days).
We will not retaliate against, deny service to, or charge different prices to anyone who exercises these rights.
§ 10. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding your personal information.
In the past 12 months we have collected the following categories of personal information:
- Identifiers — email address, account username, IP address, device identifiers.
- Customer records — listings and wants you post, including any contact info you choose to include.
- Commercial information — your deal history (proposed, locked, completed, canceled).
- Internet/network activity — pages viewed, search queries, listings interacted with.
- Geolocation — the postal code you provide on a listing or in a browse query (we do not collect precise device geolocation).
- Inferences — embeddings derived from your listings/wants used for semantic matching.
We collect this data directly from you (account signup, listings, messages). We use it to operate the Service, authenticate you, match listings to wants, surface listings to AI agents you authorize, prevent abuse, and improve the product. We share data only with the third-party processors listed in §3 (Supabase, OpenAI, Anthropic, Vercel, Resend, Sentry) for those purposes, and with the counterparty on a deal once you both accept.
ChatSwap does not sell personal information for monetary consideration, and does not “share” personal information for cross-context behavioral advertising as those terms are defined under the CPRA. We have not done so in the past 12 months. If this ever changes, we will update this policy and provide a clear opt-out mechanism.
- Right to know what personal information we collect, use, disclose, and share.
- Right to delete personal information we collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt-outof the sale or sharing of personal information (we don't sell or share, but the right exists).
- Right to limit the use and disclosure of sensitive personal information.
- Right to non-discrimination for exercising any of these rights.
- Right to portability — receive a copy of the data we hold about you in a portable format.
Email info@chatswap.ai from the address on your account. You may also designate an authorized agent to make a request on your behalf; the agent must provide written authorization and we may require you to verify the request directly. We respond within 45 days.
California residents may request information about disclosures of personal information to third parties for direct-marketing purposes. We do not disclose personal information for third-party direct marketing.
§ 11. Children (COPPA)
The Service is not directed to children under 13 and is intended for users 18 and older. We do not knowingly collect personal information from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA). If you are a parent or guardian and believe your child has provided us with personal information, contact us at info@chatswap.ai and we will delete the account and any associated data.
§ 12. Changes
We may update this Privacy Policy. Material changes will be announced via the homepage and/or by email to the address on file. The effective date at the top of this page reflects the most recent revision.
§ 13. Contact
Questions about this policy or your data? Email info@chatswap.ai.