SWAVE · Last updated: 2026-08-03
This Privacy Policy explains what information SWAVE ("we", "us", "our" — ARTSTRIO GAMES PTE. LTD. ) collects when you use the SWAVE mobile app (the "App"), why we collect it, and how you can control it. By using the App you agree to the practices described here.
When you register or sign in, we collect your email address through our authentication provider, Supabase Auth. You can sign up with an email and password, or sign in with Google or with Apple — in those cases the provider returns your email address and a stable user identifier to us. We never receive your Google or Apple password.
Your account record also stores an optional display name and avatar image if you set one, plus the account creation and update timestamps.
To provide core features, we store, linked to your account:
This data is functionally required for the App to work as intended. It is not shared with advertisers and is not used to target advertising.
If you purchase a subscription, the purchase itself is made with Apple (App Store in-app purchase) or Google (Google Play Billing). The store returns a purchase receipt to the App, which sends it to our server for validation against Apple's and Google's own APIs. We store the result: subscription status, the plan you bought, the platform, the original transaction identifier, whether auto-renewal is on, and the current period end date. We also store the renewal and cancellation notifications Apple and Google send our server about your subscription.
We never receive or store your payment card details, billing address, or store account password — those stay entirely with Apple and Google.
The App shows advertising to users who are not subscribed. Ads are delivered through TopOn (an ad mediation SDK, operated by AnyThink), which in turn requests ads from ad networks — currently Google AdMob . To select, deliver, cap and measure those ads, the ad SDKs collect:
We do not send your email address, watch history, or favorites to any ad network. Ad frequency limits (how often an ad may appear, and a daily cap on rewarded unlocks) are enforced using counters stored on your own device.
The advertising identifier is also sent to our marketing-attribution provider, Adjust; see §4. Unlike the ad SDKs above, Adjust is used whether or not you are subscribed.
The Android build of the App also includes the Google Play and Samsung Galaxy Store install referrer libraries, which can report how the App was installed. See Third-Party SDKs for the full component list.
To understand how people navigate the App — and so decide what to fix and what to commission next — we record a defined set of usage events through PostHog , a product-analytics service. Those events are:
Each event carries your app version, language, whether you were a subscriber at the time, and the device and network information any HTTP request reveals (device model, operating system version, IP address — from which an approximate, city-level location can be inferred). Events are attached to a pseudonymous identifier — your SWAVE account ID . If you are not signed in, events are recorded anonymously and are not linked to any account.
No advertising identifier is sent to PostHog, and session recording (session replay) is switched off — we do not record your screen, your taps, or anything you type. Your email address, display name and account contents are never sent. A copy of the paywall and purchase-funnel events is also written to our own Supabase database, so we can reconcile them against subscription records.
Apart from the PostHog events described in §1.5 and the Adjust attribution SDK described in §4, the App contains no other analytics or attribution SDK: there is no Firebase, no Google Analytics, no Singular, no AppsFlyer, and no crash-reporting SDK. We do not collect your contacts, photos, precise GPS location, microphone, message content, biometrics, or health data.
Structured data (accounts, favorites, watch progress, unlocks, subscription status) is stored in Supabase (hosted PostgreSQL). Access is enforced by row-level security policies scoped to your account, so one user cannot read another user's rows.
Video, subtitles and cover images are stored on Huawei Cloud object storage and delivered over HTTPS through a Huawei Cloud CDN. Playback addresses are signed by our server and expire after a short period; requesting one tells our CDN provider your IP address, as any HTTP request does.
The product-analytics events described in §1.5 are processed by PostHog on its United States cloud, under a pseudonymous account identifier and separately from the account database above.
| Data | Purpose |
|---|---|
| Email address, display name, avatar | Account authentication, cross-device sign-in, support communication |
| Watch progress & favorites | Core app functionality (resume playback, saved lists) |
| Subscription status & purchase receipts | Unlocking paid content, entitlement checks, fraud prevention, purchase restoration |
| Episode unlocks | Honouring unlocks you earned by watching a rewarded video, and enforcing the daily cap |
| Product-analytics events | Understanding how the App is used so we can improve the catalogue, the player and the purchase flow |
| Advertising & device identifiers | Serving, capping and measuring ads for users who are not subscribed; and marketing attribution — measuring which advertising campaign produced an install, subscription or ad revenue |
Where the GDPR applies, we rely on: performance of our contract with you (account, playback, subscriptions); your consent (advertising identifiers, whether used for personalized advertising or for marketing attribution); and our legitimate interests (security, fraud prevention, keeping the service working, and measuring how the App is used so we can improve it).
We share data only with the service providers necessary to run the App:
A per-SDK breakdown, with links to each provider's own privacy policy, is in Third-Party SDKs .
We do not sell your personal information , and we do not share it for cross-context behavioural advertising beyond the advertising identifiers described in §1.4.
We keep your account data for as long as your account exists. You can delete your account from inside the App — About → Delete account — or on the web at swave.pencil-stub.com/swave/legal/delete-account.html .
Deletion is immediate and permanent: your authentication record is removed, and your profile, favorites, watch progress, unlocks and subscription rows are deleted with it. It cannot be undone, and it does not cancel an active store subscription — cancel that in the App Store or Google Play (see Membership Terms ).
Copies may briefly persist in routine encrypted backups and server logs held by our infrastructure providers until those age out on their normal schedule. Purchase and tax records that we are legally required to keep are retained for the period the law requires, in a form no longer linked to your account.
You may access, correct, or delete your personal data at any time. Your profile and email are editable in the App; deletion is described in §6.
Depending on where you live you may have additional rights — for example, under the GDPR: access, rectification, erasure, restriction, portability, objection to processing, withdrawal of consent, and the right to lodge a complaint with your supervisory authority; or under the CCPA/CPRA: the right to know what we collect, to delete it, and to opt out of sale or sharing (we do not sell or share personal information as those terms are defined). We will not discriminate against you for exercising any of these rights. Contact us using the details in §9 and we will respond within the time your law allows.
The App is not directed at children under 13 (or under 16, or the higher minimum age required by your local law — for example where the GDPR sets that threshold), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
SWAVE is operated by ARTSTRIO GAMES PTE. LTD. , based in Singapore . This policy is governed by the laws of Singapore , without regard to conflict-of-law principles.
Questions about this policy or your data? Contact us at blueming333@gmail.com .
We may update this policy as the App evolves. Material changes will be reflected by updating the "Last updated" date above; continued use of the App after a change constitutes acceptance of the revised policy.