PlayShare Swap — Privacy Policy
Last updated: October 2, 2026
PlayShare Swap — the iOS app and the website at playsw.app ("the app", "we", "us") — helps people find others nearby to swap or sell physical video games. This policy explains what information the app and the website collect, why, who it is shared with, how long it is kept, and what choices you have.
Who is responsible for your data: Roman Korenev, an individual developer based in Armenia.
Contact: devkorenev@gmail.com
1. Information we collect
1.1 Account and sign-in information
You can create an account with email and password, Sign in with Apple, or Sign in with Google. Sign-in is handled by Google Firebase Authentication. You can sign in on the website with the same account and the same three methods.
- Email address. We store it on your profile. Other users never see it.
- With Sign in with Apple, the app asks Apple only for your email. If you choose "Hide My Email", we receive an Apple relay address instead of your real one. We don't ask Apple for your name.
- With Google Sign-In, we take only the email address and the account identifier from the Google account you pick.
- On the website, Continue with Apple and Continue with Google take you to Apple's or Google's own sign-in page and back. We receive the same email address and account identifier as in the app, and nothing else.
- Password. Firebase Authentication processes it. On the website, your browser sends it straight to Firebase Authentication (see 1.13). We never receive or store it on our own server.
- User ID. Firebase assigns a unique account identifier, and we use it as your ID everywhere in the app.
1.2 Profile information
- Display name. You choose it, it may match someone else's, and other signed-in users can see it. Until you set one, your username is shown in its place.
- Username. You choose it, and other signed-in users can see it. Anyone, even signed out, can check whether a username is already taken.
- City and country. You pick your city by searching or by letting the app detect it (see 1.3). We store the city, its country code, and a display label for your location. Other signed-in users can see your city and display location, and the app uses them to show you people and games nearby.
- Currency. Taken from your location and used to show prices. Other signed-in users can see it.
- Consoles you own. Other signed-in users can see them.
- Successful exchange count. Shown on your profile to other users.
1.3 Location
If you tap to detect your location, the app asks for "While Using the App" location permission and requests one position fix at about 100 m accuracy. Then:
- Apple's geocoding service (through Apple's MapKit/CoreLocation) turns the position into a city name. Searching for a city by name also goes to Apple's MapKit search.
- We send your city, country and currency to our server, together with approximate coordinates rounded to two decimal places (about 1 km). The coordinates come either from that position fix or from the city you picked in search — in both cases they identify a city, not your address. Other users never see them. Today they aren't used for matching, which works by city; they are kept so that "within N km" matching can be added later without asking you again.
- The app doesn't track your location in the background and doesn't ask for a new position unless you tap to detect it again.
You don't have to share your location. You can type your city instead.
1.4 Your games
- Games you mark as in library, for share (with whether you'll swap, sell or both, and an optional price), and wishlisted.
- Other signed-in users can see all three lists, including prices on games for share. Listings of suspended accounts are hidden.
- Anyone, without an account, can see the games you mark for share on
playsw.app/games: the title, console, your city, and your terms and price. Your display name, username and anything else that points to you are not shown, and copies of the same game in the same city appear as one entry. Your library and wishlist are never on it. - Game details (title, cover art, release year, rating, summary) come from IGDB (see section 3) and are stored in a shared game catalogue that isn't linked to you.
1.5 Exchange and purchase requests
When you propose a swap, a purchase or a counter-offer, we store: who proposed it and who received it, the games involved (with titles and prices as they were at that moment), any agreed cash top-up (amount, currency, which side pays), the status (pending, accepted, completed, cancelled, declined), and when each side confirmed. The app only records what you agreed. It does not process payments. Any money changes hands between the two of you, outside the app.
1.6 Chat messages
Once an exchange is accepted, the two people involved can chat in the app or on the website. Our server writes each message (sender, text and time) to Google Firebase Cloud Firestore; the app reads it from there, and on the website our server reads it and shows it on the page without keeping a copy. Only the two participants can read the chat.
- A chat is deleted when its exchange ends, whether completed, cancelled or declined, or when either participant closes it. A clean-up job that runs once a day also removes any chat left behind this way.
- If you report someone from a chat, the last 50 messages of that chat are copied into the report so they can be reviewed after the chat is gone (see 1.8).
- The text of a new message also appears in the push notification sent to the recipient (see 1.7), so it passes through Google's and Apple's push services.
1.7 Push notifications
If you allow notifications, we store your device's Firebase Cloud Messaging token with your account so we can notify you about new requests, accepted exchanges, counter-offers, confirmations, chat messages, and wishlisted games that become available in your city (at most one alert per game per day). We keep a record of when each wishlist alert was sent. When you sign out, the app removes the token, and it is deleted with your account.
1.8 Favourites, blocks, reports and moderation
- Favourites and blocks. We store the users you favourite and block. Blocking stops messages in both directions, cancels every open exchange between you — pending proposals are declined, agreed exchanges are cancelled and their chat is deleted — and hides each of you from the other's nearby lists. A blocked user can see that you've blocked them.
- Reports. You can report a user as a commercial seller, as abusive, or as a scam. We store who reported whom, the reason, the chat it came from and a copy of its last 50 messages (see 1.6), and the outcome of the review.
- Moderation. Reports are reviewed by the developer named at the top of this policy, in a private moderation console, and an account may be suspended. When an account is suspended, we record the date and hide its listings. If you believe your account was suspended by mistake, write to devkorenev@gmail.com; we review such requests and lift suspensions we find to be mistaken.
1.9 Information stored only on your device
- Your password is not stored by the app. iOS itself may offer to save it when you sign in, and to fill it for you next time (Password AutoFill). That copy is held by iOS in your own password store, not by us. If you have iCloud Keychain switched on, Apple syncs it to your other Apple devices; Apple states this store is encrypted so that Apple cannot read it. We never receive that copy and we are not told whether you accepted the offer. You choose whether to save it, and you can delete it at any time in iOS Settings → Passwords. Face ID or Touch ID, if you use them to fill it, are handled entirely by iOS, and the biometric data never leaves your device or reaches us. This is the one item in this section that can leave your device. Earlier versions of the app kept their own copy of the password in the device's Keychain; updating to this version deletes it.
- Last account used on this device (user ID, username, email, and whether you used Sign in with Apple), kept in the app's local settings to fill in a support email if the account is suspended.
- A local cache of game data and cover images, used for speed.
- These are removed when you delete your account from the app. Deleting the app also removes the local settings and cache.
1.10 Camera and photos
The app can read game titles off a photo of your shelf, so you don't have to type them.
- The camera is used only while the scanner screen is open. iOS asks for permission the first time, and you can refuse or withdraw it in iOS Settings; the rest of the app works without it.
- Choosing a photo instead. You can pick a picture from your photo library rather than taking one. This uses the iOS photo picker, which hands the app only the picture you choose — the app has no access to the rest of your library and doesn't ask for it.
- The picture never leaves your device. Reading the text is done on the device by Apple's Vision framework, offline. We don't upload the photo, don't store it on our server, and don't save it to your photo library. The full photo is held in memory while you review what was found and discarded when you close the scanner.
- Games waiting to be sorted out. A scanned game you set aside for later — no match found yet, or one worth checking — is kept on your device only: the text read for it and a small cropped image of that game's case from the photo. They stay until you add or remove them, and at most the 200 most recent are kept. They are deleted when you sign out or delete your account, and when you delete the app. They are excluded from iCloud and computer backups and are never sent to us.
- What does leave your device is the text the app believes is a game title — the same words you would have typed — sent to our server to be looked up in the game catalogue, and passed on by our server to IGDB if you go on to look a title up there (see section 3). Nothing else recognized in the picture is sent, kept, or linked to your account.
- Games you then choose to add are stored exactly as if you had added them by hand, under section 1.4.
1.11 Technical information
- Our server sees your IP address with each request, as every web server does. It uses the IP to limit how often the signed-out username check, the website's sign-in and its public pages can be called.
- Logs. The API, which also serves the website's pages, writes a line for each request — time, method, path (without the part after a
?, such as search text), response status, IP address, and the account id when the request is signed in. These logs stay on the server in rotating files (three files of 10 MB per service), so only the most recent entries exist; they are not copied anywhere else and are not used to build a profile of you. The reverse proxy in front of the API keeps no access log. - Analytics: we don't use any analytics service. The Firebase SDKs that remain in the app (Authentication, Firestore, Cloud Messaging) generate a Firebase installation identifier for the device, which Google uses to deliver notifications and to run those services — not for advertising. The website loads no Firebase SDK and no analytics.
- We don't use advertising, don't track you across other companies' apps or websites, and don't use the advertising identifier (IDFA).
1.12 Your public page
You can publish a page at playsw.app/<your username> from the Account screen. It is off unless you turn it on, and turning it off removes the page immediately — the address then answers exactly as it does for a name nobody holds.
While it is on, anyone can see it without an account or an app: your display name, username, city and display location, consoles, and the games you marked for share with their terms and prices. A second switch, off on its own, adds your wishlist to the same page.
Your library, your email, your exchange history and your exchange count are never on it. We record the date you turned the page on. The page is marked noindex, so search engines are asked not to list it — but a page anyone can open can be copied, archived or shared by anyone who has the link, and we cannot take those copies back.
1.13 Using the website
You can use your account on playsw.app as well as in the app: your games, games nearby, exchanges, chat and your account settings, including deleting your account. What you do there is stored exactly as when you do it in the app, as described above.
- Cookies. When you sign in, the website keeps you signed in with one cookie,
ps_session, for up to 14 days or until you sign out. It holds a session token signed by Google Firebase, is sent only over HTTPS, and can't be read by the page's scripts. While you sign in with Apple or Google, a second cookie,ps_social, holds a one-time code for up to 10 minutes, so that the answer from Apple or Google can be matched to your sign-in. The website sets no other cookies and stores nothing else in your browser — no analytics, no advertising, no tracking. - The sign-in pages (sign in, create account, reset password) run a small script of ours that sends your email and password from your browser directly to Google Firebase Authentication, so Google sees your browser's IP address there. Continue with Apple and Continue with Google send your browser to Apple's or Google's own page. No other page of the website loads a script from anyone else; game covers load from IGDB's image servers, as in the app (see section 3).
2. Why we use your information
- To run the app: to create and secure your account, show your listings and profile to other users, find people and games in your city, handle exchange requests, deliver chat messages and notifications, and let you block or report users.
- To add games without typing: to read the titles on a photo of your shelf, on your device, and to look those titles up in the game catalogue.
- To keep the community safe: to review reports, suspend accounts that break the Terms and Conditions, and keep evidence from reported chats.
- To support you: to answer your emails.
If you are in a region with data protection law of the GDPR type, our legal bases are: performance of a contract for running the app and your account, legitimate interests for safety, moderation and preventing abuse, and your consent for location and push notifications, which you can withdraw at any time in iOS Settings.
We don't sell your personal information, and we don't use it for advertising.
3. Who we share it with
- Other users see what's listed as visible in section 1: display name, username, city and display location, currency, consoles, exchange count, your game lists and prices. The other person in an exchange also sees its details and your messages.
- Anyone at all, with no account, sees your public page if you have switched one on — see 1.12 — and, without your name, which games are for share in your city, with their prices — see 1.4.
- Service providers that process data on our behalf:
- Google (Firebase): Authentication (email, password, sign-in — on the website, directly from your browser on the sign-in pages), Cloud Firestore (chat messages, stored in Google's European Union region), and Cloud Messaging (push notifications).
- Apple: Sign in with Apple (in the app and on the website), push delivery (APNs), and location search and geocoding (MapKit / CoreLocation).
- Google Sign-In: if you choose to sign in with Google, in the app or on the website.
- IGDB (owned by Twitch / Amazon): the game details in the app come from IGDB. When you search for a game — by typing, or by scanning a shelf and choosing to look a title up there — the app sends the search text to our server, which asks IGDB on your behalf and passes the results back, so IGDB sees our server's address rather than your device's. Your search text is held in memory on our server for a few minutes, so that a title several people look up isn't fetched over and over; it is not written to our logs and not linked to your account. Cover images load directly from IGDB's image servers, so IGDB sees your device's IP address when it serves one. For a game whose cover we don't already have, our server looks the artwork up on IGDB first, and the app then loads the image from IGDB's image servers the same way. On a public page (1.12) and on
playsw.app/games(1.4) the covers also load directly from IGDB's image servers, so IGDB sees the IP address of anyone who opens those pages; we ask the browser not to send them the page address. We don't send IGDB any account information. - Our server host: users, games, exchanges, reports, favourites, blocks and device tokens are stored in a PostgreSQL database on a virtual private server rented from Inferno Solutions, located in the Netherlands.
- Backblaze: encrypted copies of that database (backups) are stored with Backblaze in its EU Central region, in the Netherlands. They are encrypted on our server before they leave it, and Backblaze can't read them.
- Legal reasons: we may disclose information if the law requires it, or where it is necessary to protect the rights and safety of users.
International transfers
Google, Apple and IGDB/Twitch are international companies and may process data outside your country, including in the United States, under their own data transfer terms and standard contractual clauses. Our own server, its backups and the chat database are in the European Union.
4. How long we keep it
- Account, profile, games, favourites, blocks, device tokens: until you delete your account.
- Chat messages: deleted when the exchange ends or a participant closes the chat. Messages copied into a report are kept with the report (see below).
- Finished exchanges (completed, cancelled, declined): kept as your exchange history for two years, then deleted. The number of successful exchanges shown on your profile is a running count and stays after the individual records are gone. After you delete your account, the other person's copy of a record stays, including the games, titles and prices, but it no longer links to you.
- Reports: a resolved report is deleted two years after it is resolved. A report about you is deleted when your account is deleted. A report you filed is kept, with your identity removed from it.
- Server logs: only the most recent entries, as described in 1.11 — a few days of traffic at most. Database backups are kept for no longer than 30 days, so a deleted account can persist in a backup for up to that long.
5. Deleting your account
You can delete your account at any time in the app, in the Account screen, or on the website, on the Account page. For security, you must have signed in within the last 5 minutes. Deleting your account:
- cancels your open exchange requests (the other person is notified) and deletes their chats;
- deletes your profile, game lists, consoles, favourites, blocks, device tokens and wishlist alerts from our server;
- deletes your Firebase Authentication account;
- clears the remembered account and cached data on that device, along with any password an older version of the app had saved there. A password you let iOS save is yours to remove in iOS Settings → Passwords; the app cannot delete it. On the website, deleting your account also signs you out and removes the session cookie.
Finished exchanges and reports you filed are kept without your identity, as described in section 4.
If something fails partway through, email us and we'll finish the deletion. You can also ask us by email to delete your data if you can no longer sign in.
6. Your rights and choices
- Location, camera and notifications: you can turn them off at any time in iOS Settings. Refusing the camera only disables the shelf scanner.
- Your public page: switch it, and the wishlist on it, on or off at any time in the Account screen. Both are off until you turn them on.
- Access, correction, deletion: you can edit your display name, username, city and consoles in the app or on the website, and delete your account there too. For a copy of your data, or for any other request, email devkorenev@gmail.com. We answer within 30 days.
- Depending on where you live, you may also have the right to object to or restrict certain processing, to receive your data in a portable form, and to complain to your country's data protection authority.
7. Children
PlayShare Swap is for people aged 17 and over, as stated in the Terms and Conditions. The app has open chat between users and helps arrange meetings in person, so it is not directed at children, and we don't knowingly collect information from anyone under 17. If we learn that an account belongs to a child, we delete it. If you are a parent or guardian and believe your child has created an account, write to devkorenev@gmail.com and we will remove it.
8. Security
Connections to our server and to Firebase use HTTPS. The website's session cookie is sent only over HTTPS and can't be read by the page's scripts. Database backups are encrypted before they leave our server. The database is reachable only by the app's server, which connects with an account that owns nothing else on that machine. The app does not store your password: a password you let iOS save for AutoFill (see 1.9) is held by iOS, never sent to us, and synced to your other devices only if you have iCloud Keychain switched on. No system is completely secure, and we can't guarantee absolute security.
9. Changes to this policy
We'll update the date at the top when this policy changes. For significant changes we'll also tell you in the app, in the same way we announce changes to the Terms and Conditions, before they take effect.