Legal
Privacy Policy
Effective July 19, 2026 · Draft
This policy describes what Swath ("we", "us") collects, how we use it, and the choices you have. It covers our website, API, webhooks, and MCP server (the "Service").
1. What we collect from customers
- Account data: the email address you sign up with, plan, and billing status. Payment card details are handled by our payment processor (Stripe) and never touch our servers.
- Usage data: API request logs (endpoint, timestamp, credits, key ID, IP address) used for metering, rate limiting, abuse prevention, and support.
- Monitor configuration: the coverage polygons and webhook URLs you register.
- Site analytics: our website uses first-party, aggregate-only page counters (page path, referrer domain, and day). No analytics cookies are set, no IP addresses or device identifiers are stored for analytics, and browsers sending Do Not Track or Global Privacy Control signals are not counted.
2. Property data in the Service
The Service returns information about real property, which can include owner-occupancy status and other parcel attributes. Sources:
- NOAA MRMS radar — U.S. government data in the public domain. Contains no personal information.
- County parcel, assessor, and permit records — public records, licensed to us through data vendors and normalized into one schema.
We act as a provider of public-records-derived data to business customers. We do not collect data directly from homeowners, and we do not sell customer account data to anyone.
3. How we use data
- Operate, meter, and secure the Service.
- Send transactional email (key creation, billing, service notices). No marketing email without consent.
- Aggregate, de-identified statistics (e.g. storms verified per month) for product analytics.
4. Sharing
We share data only with processors needed to run the Service (hosting, database, payments, email delivery), under contracts limiting their use of it; or when required by law. We do not sell or share personal information for cross-context behavioral advertising.
5. Your rights — CCPA/CPRA and state privacy laws
If you are a California resident, the CCPA/CPRA gives you rights to know, access, correct, and delete personal information we hold about you, and to opt out of sale or sharing (we do neither). Residents of Texas (Texas Data Privacy and Security Act), and of other states with comprehensive privacy laws, have analogous rights. To exercise any right, email build@vibecodebeast.com — we will verify and respond within the statutory window, and we will not discriminate against you for exercising your rights.
Publicly available government records (such as county assessor data) are generally exempt from these statutes; where an exemption does not apply, we honor verified requests against our property dataset as well.
6. Retention and security
Account and usage records are retained while your account is active and for the period required for tax and audit purposes. API keys are stored only as salted hashes. Traffic is encrypted in transit; databases are encrypted at rest by our hosting provider.
7. Changes and contact
We will post any changes on this page with a new effective date. Contact: build@vibecodebeast.com.