Privacy
Privacy Policy
Effective 18 September 2026. Version 2.0.
This Privacy Policy explains how MB Elzee group (“we”, “us”, “Elzee”) processes personal data when you use the iOS application GoSwipe: Photo Cleaner (the “App”) and the website swipe.elzeego.com (the “Site”). It is written to meet Articles 13 and 14 of the EU General Data Protection Regulation (“GDPR”) and Apple’s App Store requirements.
In short
- Your photos and videos are processed only on your iPhone. They are never uploaded.
- We store a user id, your sign-in email (if shared), subscription status, and swipe counts.
- We do not sell personal data, show third-party ads, or track you across apps or websites.
- You can delete your account, and all server-side data, from Settings in the App.
1. Who is responsible (data controller)
MB Elzee group, a small partnership (mažoji bendrija) registered in the Republic of Lithuania.
- Company code: 306274598
- VAT number: LT100017807418
- Registered address: Pievų g. 7, LT-19152 Širvintų r., Lithuania
- Privacy contact: privacy@elzeego.com
- General support: support@elzeego.com
- Telephone: +370 657 79026
We have not appointed a Data Protection Officer because the scale and nature of our processing do not require one under Article 37 GDPR. Privacy requests are handled by the partnership’s management at the address above.
2. Your photos never leave your iPhone
The App asks for access to your photo library through the iOS permission system. It reads your library locally on your device to display photos and videos so you can decide what to keep. The following never leave your device and are never received by us:
- photo and video files, thumbnails, or any pixel data;
- photo library asset identifiers, album names, or file names;
- EXIF and other media metadata, including capture location, dates, and camera details;
- face, object, or scene recognition data of any kind.
Your keep and let-go decisions, and the Bin queue, are stored in a local database on your iPhone only. Deletions you confirm are carried out by iOS itself through the system confirmation sheet; iOS moves those items to its Recently Deleted album, where Apple retains them for approximately 30 days. We have no access to that album.
You can grant full or limited library access. With limited access, the App only sees the items you selected. You can change this at any time in iOS Settings → Privacy & Security → Photos.
3. What personal data we process, and why
We process the minimum data needed to run an account, enforce the free allowance, and honour your subscription. Legal bases refer to Article 6(1) GDPR.
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| User id (created by us), sign-in provider name, provider account id | Created at sign-in with Apple or Google | Create and operate your account; authenticate you | Contract, Art. 6(1)(b) |
| Email address (or Apple “Hide My Email” relay address) | Shared by Apple or Google when you sign in, if you allow it | Identify your account; respond to support and legal requests | Contract, Art. 6(1)(b) |
| Session data: session token, expiry, IP address, device user-agent string | Generated when you sign in and use the App | Keep you signed in; detect abuse and unauthorised access | Contract, Art. 6(1)(b); legitimate interest in security, Art. 6(1)(f) |
| Aggregate usage counters per calendar day: number of swipes, items kept, items queued, bytes freed; your device time zone | Sent by the App | Enforce the free allowance; show your statistics; prevent quota circumvention | Contract, Art. 6(1)(b) |
| Subscription status: whether GoSwipe Pro is active, product identifier, expiry and renewal state, RevenueCat event ids | Received from RevenueCat, which receives it from Apple | Unlock paid features; restore purchases; handle billing disputes | Contract, Art. 6(1)(b); legal obligation for accounting records, Art. 6(1)(c) |
| Server request logs: IP address, request path, status, timestamp, user-agent | Generated automatically by our servers | Operate, secure, and debug the service; rate limiting | Legitimate interest in security and reliability, Art. 6(1)(f) |
| Correspondence you send us | You | Answer your request; keep a record of complaints | Legitimate interest, Art. 6(1)(f); legal obligation where a request is made under data-protection or consumer law, Art. 6(1)(c) |
Usage counters are totals only. They are not linked to any specific photo or video, and they cannot be used to reconstruct what you kept or removed.
We do not collect: photos or videos, precise or coarse location, contacts, advertising identifiers (IDFA), health data, payment card details, browsing history, or any data for profiling or targeted advertising. We do not use third-party analytics or advertising SDKs. We do not engage in “tracking” as defined by Apple’s App Tracking Transparency framework and will never ask for that permission.
4. Payments and purchases
GoSwipe Pro subscriptions are sold and billed exclusively by Apple through the App Store. Apple is an independent controller of your payment and billing data under its own privacy policy. We never receive your card number, bank details, or billing address.
We use RevenueCat, Inc. (United States) as our processor to validate App Store receipts and tell us whether your subscription is active. RevenueCat receives your user id, an anonymised app-user id, Apple transaction identifiers, product identifiers, and purchase and expiry timestamps. RevenueCat does not receive your email address or photos.
5. Who we share data with
We share personal data only with the following categories of recipients:
- Hosting — Hetzner Online GmbH (Germany). Our API and database run on servers located in the European Union. Database backups are stored with the same provider in the EU.
- Subscription infrastructure — RevenueCat, Inc. (United States), acting as our processor under a data-processing agreement (see Section 4).
- Identity providers — Apple Inc. (Sign in with Apple) and Google LLC (Google Sign-In), each acting as an independent controller when you choose to sign in with them. They tell us who you are; we tell them nothing about how you use the App.
- Apple, for diagnostics — if you have enabled Share with App Developers in iOS Analytics settings, Apple may share aggregated, de-identified crash and performance data with us. This is controlled entirely by you in iOS settings.
- Public authorities and legal advisers — only where required by law, a binding order, or to establish, exercise, or defend legal claims.
We do not sell personal data and do not share it with data brokers, advertisers, or analytics networks. Where we use processors, we have written contracts that meet Article 28 GDPR and require them to protect your data at least as well as we do.
6. International transfers
Your account data is stored in the European Union. Where a processor or identity provider is located outside the European Economic Area — in particular RevenueCat, Apple, and Google in the United States — we rely on the safeguards permitted by Chapter V GDPR: the European Commission’s Standard Contractual Clauses and, where the recipient is certified, the EU–US Data Privacy Framework. You may request a copy of the relevant safeguards by writing to privacy@elzeego.com.
7. How long we keep data
| Data | Retention |
|---|---|
| Account, email, usage counters, subscription status | Until you delete your account in the App or ask us to delete it. If we decide to remove long-inactive accounts in future, we will give prior notice to the email on file |
| Sessions | Expire 30 days after last use; deleted at sign-out or account deletion |
| Database backups | Rolling 14 days, then automatically destroyed. Deleted accounts disappear from backups within that window |
| Server request logs | No longer than 30 days |
| Subscription event records | For the period required by Lithuanian accounting and tax law (up to 10 years) where they form part of a financial record; otherwise deleted with the account |
| Support correspondence | Up to 3 years after the matter is closed, to handle follow-up questions or claims |
8. Deleting your account
Open the App, go to Settings → Delete account, and confirm. This immediately and permanently deletes your user record, sessions, usage counters, and subscription status from our production database and instructs RevenueCat to delete the matching customer record. Backups purge within 14 days. You do not need to contact us or explain why.
Deleting your account does not cancel an active Apple subscription; cancel it in your Apple ID subscription settings so you are not charged again. It also does not affect items already in your iPhone’s Recently Deleted album, which is managed by iOS.
You may also request deletion by email at privacy@elzeego.com. We will verify that you control the account, then delete within 30 days.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- rectify inaccurate or incomplete data (Art. 16);
- erase your data (Art. 17) — available directly in the App;
- restrict processing in certain circumstances (Art. 18);
- receive a copy of the data you provided in a machine-readable format and have it transmitted to another controller (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- not be subject to automated decisions with legal or similarly significant effects — we make none (Art. 22).
To exercise a right, email privacy@elzeego.com from the address linked to your account, or include your user id from Settings → Account. We respond within one month; this may be extended by two further months for complex requests, in which case we will tell you. Requests are free unless manifestly unfounded or excessive.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania, ada@ada.lt, vdai.lrv.lt. You may instead contact the authority in the EU/EEA country where you live or work.
10. Security
Data in transit is protected with TLS. Session tokens are stored in the iOS Keychain on your device, not in shared app storage. Our servers are hardened Linux hosts with firewalling, rate limiting, and regular security updates; administrative access is limited to named personnel using key-based authentication. Authorisation and cookie headers are redacted from application logs. No system is perfectly secure; if we become aware of a personal data breach that is likely to result in a high risk to you, we will notify you and the supervisory authority as required by Articles 33 and 34 GDPR.
11. Children
The App is not directed to children under 13, and we do not knowingly collect personal data from them. If you are under the age of digital consent in your country (16 in some EU member states; 14 in Lithuania), you may use the App only with the consent of a parent or guardian. If you believe a child has created an account, contact us and we will delete it.
12. The website
The Site is static. It sets no cookies, uses no analytics, and loads no third-party scripts or fonts. Our web server records standard access logs (IP address, requested page, timestamp, user-agent) for security and capacity purposes, retained for no longer than 30 days, on the basis of our legitimate interest in operating a secure service.
13. Changes to this policy
We may update this policy to reflect changes in the App, in law, or in our processors. The effective date and version at the top will change. For material changes that affect how we use your personal data, we will notify you in the App or by email before they take effect. Previous versions are available on request.
14. Contact
MB Elzee group
Pievų g. 7, LT-19152 Širvintų r., Lithuania
privacy@elzeego.com ·
support@elzeego.com