Our Commitment to Privacy

At Swatchery, a product of Samoremi LLC ("Samoremi," "we," "us," or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your information when you use our color palette tool with community features and user accounts.

100% Local Processing: All images you upload are processed entirely in your browser using WebAssembly. We never upload, transmit, or store your images on our servers. EXIF metadata is automatically stripped before processing.

TL;DR: Swatchery only stores your account information and the palettes you choose to save. Your images are processed locally and never leave your device. We use Firebase for authentication and storage, and Google Analytics/AdSense for analytics and ads. You can delete your account at any time, and we never sell your data.

1. Information We Collect

1.1 User Account Information

When you create an account with Swatchery, we collect:

  • Email Address: For authentication, account recovery, and important notifications
  • Password: Securely hashed by Firebase Authentication (we never see your plain password)
  • Username: Unique identifier (3-20 characters), immutable after creation
  • Age Verification: Confirmation that you are 13 years or older (COPPA compliance)
  • Legal Acceptance: Records of when you accepted our Terms of Service and Privacy Policy, including version numbers

1.2 Profile Information (Optional)

You may choose to add:

  • Bio: Up to 150 characters describing yourself
  • Social Links: Up to 5 social media or website links
  • Privacy Settings: Public or private profile preference

1.3 Palette Data

When you create and save color palettes, we store:

  • Palette Names: Custom names you give to your palettes (up to 50 characters)
  • Color Codes: The actual color values in your palettes (1-30 colors per palette)
  • Public/Private Status: Whether your palette is visible to the community
  • Attribution Data: If you saved a palette, we track the original creator's username and palette name
  • Interaction Metrics: Number of times your public palettes have been saved by other users
  • Creation Dates: When palettes were created and last modified

1.4 Authentication Data

We support two authentication methods:

  • Email/Password: Traditional account creation with email verification
  • Google OAuth: Sign in with your Google account (we receive your email, name, and profile photo from Google, but only store your email)

1.5 Usage Analytics

With your consent, we collect analytics data to improve our service:

  • Session Information: Session ID, timestamp, browser type, operating system
  • Device Information: Screen resolution, viewport size, user agent string
  • IP Address: Used for geographic location (country level) and security

We track user interactions including:

Core Features: Page views, palette extraction and export events, image uploads (with file type and method)

Authentication: Sign-in, account creation, password resets, email verification, and account deletion

Advertising: Ad impressions, clicks, and performance milestones

Performance: Web Vitals data (page load times, responsiveness) and error tracking for bug fixes

1.6 What We DON'T Collect

Privacy-First Features:

  • Your Images: Never uploaded or stored on our servers
  • EXIF Metadata: Automatically stripped before processing
  • Location Data: No GPS or precise location tracking
  • Financial Information: We don't process payments or store credit cards
  • Device Fingerprinting: We don't create device fingerprints for tracking purposes. Google Analytics may use device characteristics to identify sessions.
  • Cross-Site Tracking: We don't track you across other websites

2. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Enable account creation, palette storage, and community features
  • Authentication: Verify your identity and manage your account
  • Communication: Send account-related emails (verification, password resets, important updates)
  • Community Features: Display public profiles, public palettes, and user interactions
  • Improve the Service: Analyze usage patterns to enhance features and fix bugs
  • Security: Detect and prevent abuse, spam, and violations of our Terms
  • Legal Compliance: Comply with legal obligations and enforce our Terms
  • Advertising: Display relevant ads to support our service

3. Browser Storage and Cookies

We use browser storage and cookies to enhance your experience. Here's what we store and why:

3.1 Browser localStorage

We store data in your browser's localStorage (not traditional cookies) to enhance your experience. This data never leaves your device and is never sent to our servers:

Essential Storage (Required)

Necessary for the app to function properly:

  • Your consent preferences for analytics
  • Your theme preference (light/dark/system mode)
  • Firebase authentication state

Feature Storage

Improves your experience by remembering your work and preferences:

  • Recent colors for quick access (up to 20 colors)
  • Color extraction algorithm preferences
  • Tutorial and lesson progress
  • Pending actions after login (e.g., save palette)

Security & Performance

Protects against spam and abuse:

  • Rate limiting data (prevents automated abuse)
  • Re-authentication tracking (for sensitive operations)

Ad Performance (Stored Locally)

Track ad metrics in your browser only:

  • Ad impression and click counts (kept for 30 days)
  • Ad blocker detection history (24 hours)

Note: Ad metrics stay on your device. Only aggregate milestones (e.g., "100 impressions reached") are sent to Google Analytics for performance analysis.

View technical details (localStorage key names)

Essential: swatchery-consent, theme, firebase:authUser:*

Features: paletteStudioRecentColors, extractionSettings, colorTheoryProgress, swatchery_pending_action

Security: rate_limit_*, ad-blocker-detections, ad-blocker-message-dismissed

Ad Metrics: swatchery_ad_metrics

3.2 Third-Party Cookies

We don't set cookies directly, but third-party services we use may set cookies:

For detailed cookie names and retention periods, see our Cookie Policy.

4. Third-Party Services

We use several third-party services to provide Swatchery. Each service has its own privacy policy and may collect data as described below:

To learn more about how Google uses information from sites that use their services, visit How Google uses data when you use our partners' sites or apps.

Firebase (Google)

We use Firebase for authentication, database storage (Firestore and Realtime Database), hosting, cloud functions, analytics, and security (App Check/reCAPTCHA).

Data Collected: User accounts, profile data, palettes, usage patterns, IP addresses, request logs, and security validation data

Data Location: United States (Google Cloud servers)

Firebase Privacy Policy

Google OAuth (Sign in with Google)

Optional authentication method.

Data Received: Email, name, profile photo (only email is stored)

Google Privacy Policy

Google Analytics 4

Web analytics (requires your consent).

Data Collected: Usage patterns, session data, and user interactions

Retention: 14 months

Google Privacy Policy

Google AdSense

Advertising platform.

Data Collected: Ad impressions, clicks, and performance metrics

Note: Ads are always enabled

Ad Partners: Google AdSense may work with third-party advertising partners. A list of Google's advertising partners is available at Google's Ad Technology Providers.

Google Ads Privacy

Cloudflare

Content delivery network (CDN), security, and DDoS protection.

Data Collected: IP addresses, request logs, security challenge responses

Cookies: __cf_bm (30 min), cf_clearance (varies), __cfruid (session)

Data Location: Global edge network

Cloudflare Privacy Policy

Google Fonts

Typography for our website.

Data Collected: IP address, font requests (no cookies set)

Google Fonts Privacy FAQ

reCAPTCHA v3 (Google)

Bot protection and security.

Data Collected: Hardware/software information, mouse movements, browser plugins, IP address

reCAPTCHA Privacy Policy

4.1 Data Transfers

All data processed by Firebase and Google services is stored on servers in the United States. By using Swatchery, you consent to your data being transferred to and processed in the United States.

5. Advertising

Swatchery is an ad-supported service. Here's how our advertising works:

Personalized vs. Non-Personalized Ads: By default, we show non-personalized ads that don't track your behavior. If you consent to "Advertising Cookies" in our consent banner, we will show personalized ads based on your interests, which helps us generate revenue to keep Swatchery free. You can change this preference at any time in Cookie Settings.

5.1 How Ads Work

  • Ads Always Enabled: Our service displays advertisements from Google AdSense
  • Ad Personalization: Google may personalize ads based on your browsing activity. You can control ad personalization through Google's Ad Settings
  • You Can Use Ad Blockers: We respect your choice to use ad blocking software

5.2 Ad Metrics

We track ad performance locally in your browser:

  • Impression counts (how many times you see ads)
  • Click counts (when you click on ads)
  • Daily breakdown (last 30 days)
  • Click-through rates

Important: Ad metrics are stored in your browser's localStorage only. We don't store your individual ad interaction data on our servers. Aggregate ad performance metrics (like milestone counts) are sent to Google Analytics for analytics purposes.

Note: While we use both Google Analytics and Google AdSense, we don't directly use analytics data to target ads. However, both services are provided by Google and send data to Google's servers. We cannot control how Google uses data across its services.

5.3 Managing Ad Preferences

You have several options:

  • Google Ad Settings: Visit Google Ads Settings to manage ad personalization
  • Industry Opt-Out Tools: Use NAI Consumer Opt-Out to manage interest-based advertising
  • Use Ad Blockers: Browser extensions or DNS-level ad blocking

6. Community Features and Public Information

Swatchery includes community features where users can share palettes and interact with each other.

6.1 Public vs. Private Profiles

You control your profile visibility:

  • Public Profiles: Your username, bio, social links, and public palettes are visible to all users
  • Private Profiles: Your profile shows only "This profile is private" and your palettes are hidden from the community

Note: Your privacy setting applies to ALL your palettes. You cannot make individual palettes public or private.

6.2 What's Visible to Others

When your profile is public, other users can see:

  • Your username, bio, and social links (if provided)
  • All your saved palettes
  • How many palettes you've created
  • How many times your palettes have been saved by others

6.3 Palette Attribution

When you save someone else's palette:

  • The original creator's username is recorded
  • Your username is added to their palette's "saved by" list
  • If you make your saved palette public, attribution to the original creator is displayed

6.4 User Search and Discovery

  • User Search: Users can search for public profiles by username or display name
  • Palette Search: Public palettes are searchable by name
  • Leaderboard: Top creators are displayed based on how many times their palettes have been saved
  • Community Feed: Public palettes appear in the community feed

6.5 Search Engine Indexing

By default, your public profile and palettes are NOT indexed by search engines. You can change this in your profile settings by enabling "Allow search engine indexing."

7. How We Protect Your Information

We implement multiple security measures to protect your data:

7.1 Technical Security

  • HTTPS/TLS Encryption: All data transmission is encrypted
  • Password Hashing: Passwords are hashed using industry-standard algorithms by Firebase
  • Secure Authentication: Firebase Authentication provides enterprise-grade security
  • Local Image Processing: Your images never leave your device
  • EXIF Stripping: Image metadata is automatically removed before processing

7.2 Access Controls & Abuse Prevention

  • Email Verification: Required before full account access
  • Database Security Rules: Database-level protection prevents unauthorized access
  • Re-authentication: Sensitive operations (like account deletion) require recent login
  • Rate Limiting: Prevents spam and automated attacks
  • Content Moderation: Multi-layer profanity filtering and input validation
  • XSS Prevention: All user-generated content is sanitized
  • Bot Protection: reCAPTCHA detects and prevents automated abuse

7.3 Important Security Notes

While we implement strong security measures, no system is completely secure. We cannot guarantee absolute security. You use the Service at your own risk. Please choose a strong, unique password and keep your credentials confidential.

8. Data Retention

We retain different types of data for different periods:

Your Images

Never stored - Processed locally and immediately discarded

Account & Palettes

Until you delete - Retained as long as your account is active

Browser Storage

Until you clear - Stored locally until you clear browser data

Analytics Data

14 months - Google Analytics retention period

Logs & Security Data

30-90 days - For security monitoring and troubleshooting

8.1 Account Deletion

When you delete your account:

  • Immediately: Your authentication credentials and account access are removed
  • Within 30 Days: Your profile, palettes, and username reservation are permanently deleted (including backups)
  • Retained: Anonymized analytics data (per Google's retention policy)

8.2 Saved Palettes and Attribution

When other users save your public palettes to their collections, those copies persist independently. However, if you delete your account or remove a palette, the attribution (your username and profile link) will be removed from those saved copies. The palette colors and metadata remain, but without creator attribution.

9. Your Rights and Choices

9.1 Access Your Data

You have the right to access your personal data. You can export all your data (profile and palettes) in JSON format from your account settings. The export includes your complete profile, all palettes, and creation timestamps.

Rate Limit: 3 exports per 10 minutes

9.2 Update Your Information

You can update most of your information from your account settings:

  • Email & Password: Can be changed (requires re-authentication)
  • Bio, Social Links, Privacy Settings: Can be updated at any time
  • Username: CANNOT be changed after account creation (immutable)

9.3 Delete Your Account

You can delete your account at any time from account settings:

  1. You must re-authenticate (sign in again) within the last 5 minutes
  2. Deletion is permanent and cannot be undone
  3. All your data is deleted within 30 days (see Section 8.1 for details)
  4. No refunds for prepaid services (if applicable)

9.4 Manage Consent

You can manage your consent choices at any time:

  • Analytics Consent: Withdraw consent to stop analytics tracking
  • Advertising: Advertising cookies are always enabled to support our ad-funded service. You can control ad personalization through Google's Ad Settings, use browser ad blockers, or manage third-party cookies in your browser settings.
  • Do Not Track: We respect the Do Not Track (DNT) browser header

Effect of Withdrawal: When you withdraw analytics consent, we immediately stop tracking new events. Previously collected data is retained per our retention policy (14 months).

9.5 GDPR Rights (EU Residents)

If you are in the European Economic Area (EEA), you have additional rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restriction: Request limitation of processing
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to certain types of processing
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

9.6 CCPA Rights (California Residents)

If you are a California resident, you have these rights:

  • Right to Know: Request disclosure of personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: We do not sell personal information
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

9.7 How to Exercise Your Rights

To exercise any of these rights:

  • Data Export: Use the export feature in your account settings
  • Account Deletion: Use the delete account feature in account settings
  • Other Requests: Contact us at contact@swatchery.com

We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.

10. Children's Privacy (COPPA Compliance)

10.1 Age Requirement

Swatchery is not intended for children under 13 years of age (or 16 in the EU). You must be at least 13 years old to create an account and use our service.

10.2 Age Verification

When you create an account, you must certify that you are at least 13 years old by checking a confirmation box and accepting our Terms of Service and Privacy Policy. We store a record that you have verified your age, including the timestamp of verification.

10.3 What We Do Not Collect from Children

We do not knowingly collect personal information from children under 13. Our age gate and verification process are designed to prevent children under 13 from creating accounts.

10.4 If We Discover a Child Under 13

If we learn that we have collected information from a child under 13, we will immediately terminate the account and delete all associated data without contacting the child directly.

10.5 For Parents and Guardians

If you believe your child under 13 has created an account on Swatchery, please contact us immediately at contact@swatchery.com with your child's username or email, your relationship to the child, and your contact information. We will verify your identity and delete the account promptly.

11. International Data Transfers

Swatchery is hosted in the United States, and all data is stored on Firebase servers operated by Google in the United States.

11.1 Data Location

  • Primary Storage: United States (Firebase/Google Cloud)
  • CDN: Global content delivery network for faster performance

11.2 Legal Basis for Transfers

By using Swatchery, you consent to the transfer of your data to the United States. Google (Firebase's parent company) complies with applicable data protection laws and uses Standard Contractual Clauses for international transfers where required.

11.3 EU-US Data Transfers

For EU residents, data transfers to the US are based on your explicit consent, necessity for contract performance (providing the service), and Google's Standard Contractual Clauses.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements.

12.1 How We Notify You

We will always update the "Last Updated" date at the top of this policy. For material changes, we may also:

  • Send an email to your registered email address
  • Display a prominent notice on our website
  • Require you to review and accept the updated policy before continuing to use the Service

We will provide reasonable notice for material changes to this policy.

12.2 Your Acceptance

Continued use of the Service after changes take effect constitutes acceptance of the new Privacy Policy. If you do not agree to the changes, you must stop using the Service and may delete your account.

12.3 Review Regularly

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Samoremi LLC (operating as Swatchery)

Email: contact@swatchery.com

Response Time: We aim to respond to all inquiries within 5 business days

Data Protection Requests: For GDPR or CCPA requests, please clearly state your request type and jurisdiction in your email subject line

Effective Date: This Privacy Policy is effective as of the date shown at the top of this page.