Privacy Policy
Swell · Updated August 23, 2026
Swell collects as little as it can. This page says exactly what it collects, why, and where that data goes — in plain words, with no exceptions hiding in the footnotes.
What the app stores on your device
on-device, plus a small account record on the developer's Convex backend in the United States if you create one
What the app collects
Your account
Swell's account is optional, created in the Profile tab either with Sign in with Apple or with an email address, a display name, and a password. With email sign-up the server stores the email, the name, and a salted cryptographic hash of the password — the password itself is never stored and cannot be recovered from what is. With Sign in with Apple the server stores the anonymous identifier Apple issues, your display name, and the email you chose to share (which may be Apple's private relay address); no password exists at all. Nothing else you do in the app is tied to the account or uploaded: your spot list, boards, sessions, friends, and profile photo stay on your device. Settings › Delete Account removes the account record from the server immediately.
What the app does not collect
Swell does not collect:
- usage analytics, telemetry, or crash reporting of any kind
- your location
- health or fitness data
- a push notification token
- an advertising identifier (IDFA) — there is no advertising and no ad network in the app
- anything about what you do in other apps or on the web
I do not sell your data, rent it, share it with data brokers, or use it for advertising. There is no ad network, no attribution SDK, and no analytics SDK belonging to anyone else in the app.
Services the app talks to
To do its job, Swell makes requests to these services:
- Convex — the developer's own backend: the worldwide spot catalog, spot search, offshore wave-model forecasts, and your account if you create one. What's sent: what you type into spot search; the public identifier of the spot you're viewing; and, only if you create an account, your email address, the display name you choose, and a salted hash of your password — never the password itself.
- Open-Meteo — wave, swell, sea-surface temperature, and wind forecasts. What's sent: the fixed, public coordinates of the surf spot you're viewing — not your location.
- NOAA CO-OPS — tide predictions. What's sent: the public identifier of the tide station you're viewing and the date.
- Apple — the in-app purchase, and Sign in with Apple if you use it. What's sent: the purchase is handled entirely by Apple and the developer never sees your payment details or your Apple Account; Sign in with Apple hands the developer only a verified anonymous identifier, plus your name and email if you chose to share them.
As with any request to any website, these services can see your device's IP address when the app asks them for data. That is how the internet works and I have no way to prevent it. The app sends them no identifier of its own, and nothing that says who you are.
Purchases
Purchases are processed entirely by Apple. Your payment details never reach me — I receive Apple's aggregate sales reports, which do not identify individual buyers. Apple's handling of the transaction is covered by Apple's privacy policy.
Children
Swell is not directed at children under 13, and it does not knowingly collect personal information from anyone, of any age.
Deleting your data
Deleting the app removes everything stored on your device.
Changes to this policy
If this policy changes, the date at the top of the page changes with it, and anything material will be called out in the app's release notes. The current version always lives at this URL.
Contact
Questions about this policy, or about anything Swell does with data — email natetedesco@icloud.com. Swell is made and published by Nate Tedesco, an individual developer.