Privacy policy
Last updated 27 August 2026
The short version
We collect your email address so you can sign in, and we keep a record of every transaction you submit because a billing system that cannot show its work is not worth trusting. We do not run advertising, we do not use third-party analytics, and we do not sell anything to anyone.
What we collect
| Data | Why | Kept |
|---|---|---|
| Email address | Sign-in and service notices | While your account is open |
| Sign-in codes | Authentication | Stored hashed, expire in ten minutes |
| Session tokens | Keeping you signed in | Stored hashed, expire after 30 days |
| API key | Authenticating your submissions, and showing it to you again in the dashboard | Encrypted at rest, while your account is open |
| Transaction records | Billing, support and dispute resolution | While your account is open |
| Deposit records | Crediting your balance and reconciling payments | While your account is open |
| Server logs | Operating and securing the service | Short lived, and never containing API keys |
Transaction data
When you submit a transaction we record its signature, size, transport, outcome, latency, and the amount charged. We also retain the submitted bytes themselves as billing and dispute evidence. Those bytes are the same public data you broadcast to the Solana network, but we treat them as sensitive: access is restricted, and they are never exposed through the dashboard, sent to any third party, or included in ordinary logs.
Your API key
Your key is stored encrypted with AES-256-GCM under a key held outside the database, so that it can be shown to you again in the dashboard rather than exactly once at creation. This is a deliberate trade-off and we would rather state it plainly than not: an attacker with both the database and the encryption key could read customer API keys. Because balances are prepaid, the exposure from a compromised key is limited to the balance on that account, and keys cannot sign transactions or move funds from any wallet.
What we do not do
- No advertising, and no advertising identifiers.
- No third-party analytics or session recording.
- No selling, renting or sharing of personal data.
- No tracking cookies. The only cookie we set is the one that keeps you signed in.
Who we share with
We use a small number of processors to run the service:
- an email provider, to deliver sign-in codes;
- infrastructure providers hosting our servers and database;
- Solana RPC providers, used to verify deposits on chain.
We also disclose data where we are legally required to.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete your account and the personal data attached to it. Some records must be retained for a period to meet accounting obligations, and we will tell you if that applies. Write to support@swqos.com and we will respond within thirty days.
Security
Everything is served over TLS. Sign-in codes and session tokens are stored as hashes, never in the clear. API keys are encrypted at rest. The administrative interface to our relay is not reachable from the internet at all. No system is perfectly secure, and we will tell affected customers promptly if we ever have a breach that puts their data at risk.
Changes
If we change this policy materially we will email the address on your account before the change takes effect.
Contact
Privacy questions go to support@swqos.com.