Privacy
What we hold, and why
Last updated 5 October 2026. WireSwan is operated by FELYRA STUDIO S.R.L., registered office Strada Soporului 8D, Bloc B1, Scara 3, Etaj 0, Ap. 148, Cluj-Napoca, Cluj County, Romania, trade register no. J2026020138008, tax ID (CUI) 54353095, not registered for VAT. Questions go to contact@wireswan.app.
The short version
We hold what is needed to run your account and serve the websites you publish. There is no analytics, no advertising and no tracking. The only script from another company is Stripe’s, and only on the two pages where money is handled: the page where an owner pays and the page where a developer sees their payouts. We do not sell data and we never will.
Two different roles
For your account — name, email, sign-in — we decide what is held and why, so we are the data controller.
For the websites you publish, you decide. We store and serve what you upload, so there we are a processor acting on your instructions. If those sites hold other people’s personal data, that remains your responsibility and you need your own basis for holding it.
Why we are allowed to hold it
- To give you the service you asked for
- Your account, your sites, invitations and the emails that make them work. Article 6(1)(b) — performance of a contract with you. Without this data there is no service to provide.
- To keep the service standing up
- Session records, rate limiting, server logs, and keeping an eye out for abuse. Article 6(1)(f) — our legitimate interest in a service that works and is not attacked. You may object to this; write to us and we will weigh it.
- Because the law requires it
- Records of payments, kept for the ten years Romanian accounting law requires. Article 6(1)(c).
- To be able to show what was agreed
- When you accept the developer or owner agreement we record when, the version, which points you ticked, and the address and browser it came from. Article 6(1)(f) — our legitimate interest in being able to prove an agreement if it is ever disputed, including to a bank. These records are kept after an account is closed, for as long as a claim could be brought, and for nothing else.
- Because you said yes
- The launch list, and nothing else. Article 6(1)(a). Every email from it carries a one-click way out, and leaving deletes the address.
We send no marketing to developers or owners on the strength of having an account. An account gets the emails the service needs to run and nothing more.
What we hold
- Your account
- Name, email address, whether that address is verified, and a profile picture if you upload one. A password is stored only as a hash, never as the password. Signing in with Google stores the identifier Google gives us, not your Google password.
- Your sites
- The files you upload, the versions we keep of them, the text and images your client edits, and the domain names connected to each site.
- Invitations
- The email address you invite, the agreed monthly price, and a one-time link stored only as a hash, so a copy of our database could not be used to claim a site.
- The launch list
- If you ask to be told when hosting opens, we keep your email address and which page you asked from. We also keep a one-way fingerprint of the address you connected from, used only to stop one machine signing up fifty times; the address itself is never stored. One email, then it is deleted.
- Who sees your address
- A developer’s name, profile picture and email address are shown to the owners of the websites they built here, so an owner can reach the person who made their site. Nobody else sees them: not other developers, not other owners, and nowhere public. An owner’s address is shown only to the developer of their own site.
- Payments
- Card details never reach us: they are typed into Stripe’s form and stay with Stripe. We keep what each payment was for, the amount, the fees, its status, and when the developer’s share is released. Before paying, an owner says whether they buy as a business or as a private person, and gives the name, tax ID and address that go on the invoice; we keep that with each payment, and the developer who was paid sees it, so the invoice can be issued. A private person’s request to start at once, and confirmation that their website was already delivered, are kept with the time they were given. A developer’s identity documents and bank details are collected and kept by Stripe; we see only whether their account can be paid.
- Agreements
- The record of each agreement you accepted, as described above: the time, the version, the points ticked, and the IP address and browser it was accepted from.
- Technical records
- Sign-in sessions, and IP addresses used briefly to limit repeated sign-in attempts. Web server logs record requests to hosted sites.
How long
An unpaid preview is removed 14 days after it was created, or after the last invitation for it was sent, and never later than 30 days after it was created; we email you before that happens. We keep up to 10 earlier versions of a published site, fewer when they are large. Sessions expire after 30 days without use, a sign-in link after 10 minutes, a domain verification request after 7 days, an invitation after 14.
Closing your account deletes your profile, your sessions and your picture at once. A developer deletes their websites first. An owner’s website is not deleted with their account: it stays with the developer who built it, and the owner’s email address is removed from its history. What is kept: the record of each agreement you accepted, and the record of each payment and its invoice, for as long as accounting and tax law require.
The records used to limit repeated sign-in attempts, which include the address you connected from, are deleted after 24 hours. Web server logs are kept for 30 days.
Who else touches it
Only these, and only to do the job named:
- Hetzner Online GmbH — Servers and storage (Germany).
- Resend — Sending account and invitation emails (Ireland (US company)).
- Let's Encrypt (ISRG) — Certificates for hosted sites (United States).
- Stripe Payments Europe, Ltd. — Card payments, invoices, and identity checks for developers who are paid (Ireland (US company)).
- Oblio Software S.R.L. — Invoices for websites sold and hosted by the operator itself, reported to the Romanian tax authority's e-Factura system as the law requires (Romania).
Stripe handles payments. Card details are typed into Stripe’s own fields and never reach us. For the payment itself Stripe acts as a controller in its own right, under its own privacy policy. If you choose to sign in with Google, Google learns that you signed in to WireSwan; we receive your name, email address and Google’s identifier for you, and nothing else. Invoices the operator issues for its own websites are reported to the Romanian tax authority (ANAF) through e-Factura, because the law requires it.
Data leaving the EU
The servers, the databases and every file of every website are in Germany and do not leave it. Our email provider sends from Ireland, so the messages themselves stay in the EU — but the company behind it is American and could in principle be reached by a US authority, so that relationship rests on the European Commission’s Standard Contractual Clauses. The same clauses cover the certificate authority, which is in the United States and sees only the domain names of hosted sites.
Stripe Payments Europe is in Ireland and may transfer payment data to Stripe in the United States under the EU–US Data Privacy Framework and Standard Contractual Clauses. Nothing else goes anywhere. There is no analytics provider, no advertising network, and no content delivery network in front of your site.
If something goes wrong
If personal data is lost, exposed or reached by someone who should not have reached it, we will tell the Romanian supervisory authority within 72 hours of finding out, as the law requires. If the breach is likely to put you at real risk we will tell you directly, in plain words: what happened, what was involved, and what to do about it. We will not wait until we have a complete account before telling you something has happened.
If you need a processing agreement
For the websites you publish here you are the controller and we are your processor, which means you may need this in writing. These are the commitments, and we will sign a formal agreement on request — write to contact@wireswan.app.
- We process the content of your sites only to host and serve them, and only on your instructions. Never for our own purposes, never to train anything.
- Everyone with access is bound to confidentiality. In practice that is one person.
- Data is encrypted in transit. Each site is served from its own directory on its own hostname, apart from the application and from every other site, and nothing uploaded is ever executed on the server.
- The processors we use are the ones listed above. We will tell you before adding another, and you may object.
- We will help you answer a request from someone whose data is on your site, and help with an impact assessment if you need one.
- You can take a full copy of your site at any time from your own dashboard, without asking us. When you close your account or delete a site, the files are deleted.
- We will give you whatever you need to satisfy yourself that this is true, and submit to an audit if your own obligations require one.
Cookies
Only the cookies the service cannot work without, which is why there is no consent banner. None of them is for advertising or analytics, and none follows you to other websites.
- __Secure-wireswan.session_token keeps you signed in. It holds a session reference and nothing else, and lasts thirty days, renewed each day you use the site.
- __Secure-wireswan.state exists only while you sign in with Google, to make sure the answer coming back from Google belongs to the sign-in you started. It is gone after five minutes.
- ws_mode remembers whether you last chose the developer or the owner side, if you have one account for both. It is set only when you use that switch, and forgotten when you sign in again.
- __stripe_mid and __stripe_sid are set by Stripe on the pages where you pay or see your payouts, to recognise fraudulent payments. Stripe’s own payment fields also keep cookies on Stripe’s domain, under Stripe’s privacy policy.
Your light or dark preference is kept in your browser’s own storage and never reaches us. If we ever add a cookie that is not strictly necessary, it will be off until you say yes to it.
Your rights
You can close your account yourself, from your profile page, and it is gone — not deactivated. You can also ask for a copy of what we hold about you, ask us to correct it, or ask us to delete something specific. You may also ask us to restrict how we use your data, object to processing that rests on our legitimate interest, and receive the data you gave us in a form you can take elsewhere. Write to contact@wireswan.app and we will answer within 30 days. If you are in the EU or UK you may also complain to your data protection authority; in Romania that is the ANSPDCP.
One exception: records of a payment are kept for as long as tax law requires, and cannot be deleted on request.
Two things we are often asked. Nothing here is decided automatically: no profiling, no scoring, no decision about you taken by a machine. And this service is not for children — accounts are for people running a business, and we do not knowingly hold a child’s data. If you believe we have, tell us and it will be removed.
Changes
If we change how data is handled in a way that affects you, we will email you before it takes effect rather than quietly editing this page.