SwipeAssist — Privacy Policy

Last updated: September 22, 2026

1. Overview

SwipeAssist ("the Extension") is a Chrome browser extension that automates the like action on tinder.com, pairs.lv and with.is. We are committed to protecting your privacy and being transparent about the data we handle.

2. Data We Collect

2.1 Data stored locally on your device

All of the above data is stored in chrome.storage.local on your device only. It is never transmitted to our servers or any third party.

2.2 Sign-in

SwipeAssist does not use Google sign-in (OAuth) and does not require you to be signed in to Chrome. It does not read your Chrome profile information. The identity and identity.email permissions were removed in v6.1.0.

There are exactly two ways to activate Pro, and neither involves an account or an email address:

Activation by email address was discontinued on 22 September 2026. The extension no longer has a field for it, does not ask for it, and does not transmit it.

2.3 Data sent to our server

Activation with a license key sends the key once to our verification API (POST /api/verify) to check that the subscription is active. After that, only a SHA-256 hash of the key is sent periodically, so that a cancellation takes effect. The free trial is decided entirely on your device and sends nothing. Email-address activation was discontinued on 22 September 2026; the extension no longer asks for or transmits an email address.

Your IP address is processed transiently for rate-limiting purposes and is not stored persistently.

2.4 Error Reports (Optional)

When you choose to send an error report via the support page, the following data is transmitted to our server:

Error reports and messages sent through our contact form are processed by our server hosted on Vercel, and a record is kept in a private Google Sheet that only we can open (see "Google Workspace" below). Alert notifications are sent from that sheet, or via SendGrid. No data is shared with third parties beyond these service providers.

3. Data We Do NOT Collect

4. Permissions Explained

PermissionWhy we need it
storageSave your settings, statistics, and subscription status locally
activeTabInteract with the active dating site tab to perform swipe actions
Hosts: tinder.com / pairs.lv / with.isInject the content script that performs the automated like actions
Host: swipeassist.vercel.appTwo things: (1) checking that the license key you pasted belongs to an active subscription — the key is sent once at activation, and afterwards only a SHA-256 hash of it; (2) a periodic check of whether the extension has been remotely paused, and of the revoked-key list (see below), which sends nothing about you at all. No email address is involved in either.

5. Remote pause check

About every 30 minutes while the extension is running, it requests /api/status on our server. The response tells the extension two things: whether we have paused it (for example, because a target site changed and the extension would otherwise misbehave), and which license keys have been revoked. This request contains no personal data — it is a plain GET with no identifiers, and your license key is never transmitted. The revocation list is compared against a hash stored on your device. If the request fails, the extension keeps working normally.

6. Third-Party Services

For completeness, these are all the network requests the extension makes:

Nothing else leaves your device. Error reports are never sent automatically; they are sent only if you go to the support page yourself and choose to send one (see 2.4).

On pairs.lv the extension also runs a small script in the page context. It does two things. First, it wraps window.fetch and XMLHttpRequest and reads only the request URL, the HTTP method and the response status code — never request or response bodies, and never headers — so it never sees your credentials; this is how the extension can tell whether a like actually went through instead of guessing from the screen. Second, as a last resort when an ordinary click does not register, it reads the framework's own click handler off the button element and calls it directly, so the like button can be pressed reliably. It reports back only whether that press succeeded. Nothing observed or read this way leaves your device.

7. Your Data: Export & Deletion

Open the extension and go to the Stats tab. Under Your stored data:

Narrower options, if you want to keep the rest: Reset Stats (same tab) clears only the statistics, and Reset session count clears only the current session counter.

Uninstalling the extension, or clearing extension data in Chrome settings, also removes everything.

If you bought Pro, the email address you gave Stripe at checkout is held by our payment processor as part of your subscription record. The extension never receives it. Deleting local data does not cancel a subscription — see the cancellation page, or contact us via support to have the record removed.

8. Children's Privacy

SwipeAssist is not intended for use by anyone under the age of 18. We do not knowingly collect data from minors.

9. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated date.

10. Contact

If you have questions about this privacy policy, please contact us via the support page, the contact form, or email abqdaisuki610@gmail.com directly.


SwipeAssist — プライバシーポリシー

最終更新: 2026年9月22日

1. 概要

SwipeAssist(以下「本拡張機能」)は、tinder.com / pairs.lv / with.is 上でのいいね操作を自動化する Chrome 拡張機能です。ユーザーのプライバシー保護に努めています。

2. 収集するデータ

2.1 端末にローカル保存されるデータ

上記のデータはすべて chrome.storage.local に端末上のみで保存されます。サーバーや第三者への送信は一切行いません。

2.2 ログインについて

本拡張機能は Google ログイン(OAuth)を使用せず、Chrome へのログインも必要としません。Chrome のプロフィール情報を読み取ることもありません。identity および identity.email の権限は v6.1.0 で削除しました。

Pro の有効化は次の2つの方法のみです。(1) ポップアップのボタンから始める7日間の無料トライアル(完全に端末内で判定・通信なし)、(2) ライセンスキーの入力。メールアドレスによる有効化は 2026年9月22日に廃止しました。拡張機能はメールアドレスを入力させず、送信もしません。

2.3 サーバーに送信されるデータ

ライセンスキーで有効化すると、そのキーが照会API(POST /api/verify)に1回だけ送信され、契約が有効かを確認します。以後は、解約が反映されるようにキーの SHA-256 ハッシュだけを定期的に送信します。無料トライアルは完全に端末内で判定するため、通信は発生しません。それ以外のデータ送信も行いません。

レート制限のためにIPアドレスが一時的に処理されますが、永続的には保存されません。

2.4 エラーレポート(任意)

サポートページからエラーレポートを送信した場合、以下のデータがサーバーに送信されます:

エラーレポートおよびお問い合わせフォームからいただいた内容は、Vercel 上のサーバーで処理され、当方のみが開ける非公開の Google スプレッドシートに記録を残します(下記「Google Workspace」をご覧ください)。通知メールはそのスプレッドシートから、または SendGrid 経由で送信されます。これら以外の第三者とデータを共有することはありません。

3. 収集しないデータ

4. リモート停止の確認

本拡張機能は、動作中およそ30分ごとに当方サーバーの /api/status に 問い合わせます。応答から分かるのは次の2点です。拡張機能が一時停止されていないか (対象サイトの仕様変更などで誤動作するおそれがあるときに停止するための仕組みです)、 および失効したライセンスキーの一覧です。この通信に個人情報は含まれません。 識別子を伴わない単純な取得要求で、ライセンスキーを送信することもありません。 失効の照合は、端末内に保存されたハッシュとの突き合わせで行います。通信に失敗した 場合、拡張機能はそのまま通常どおり動作します。

5. 第三者サービス

念のため、拡張機能が行う通信は次のものがすべてです。

これ以外に端末から出ていくものはありません。エラーレポートが自動で送信されることはありません。お客様ご自身がサポートページを開いて送信を選ばれた場合にのみ送信されます(2.4 参照)。

また pairs.lv では、ページ側の world で小さなスクリプトを動かしています。役割は2つあります。ひとつは window.fetch と XMLHttpRequest を包んで、リクエストのURL・メソッド・レスポンスのステータスコードだけを読むこと。リクエスト・レスポンスの本文もヘッダも読まないため、ログイン情報に触れることはありません。いいねが本当に成立したかを、画面の見た目から推測せずに判定するために使っています。もうひとつは、通常のクリックが効かなかったときの最後の手段として、ボタンに付いているフレームワーク側のクリック処理を直接呼び出すことです。いいねボタンを確実に押すためのもので、返すのは「押せたかどうか」だけです。ここで観測・取得した内容が端末の外に出ることはありません。

6. データの書き出しと削除

拡張機能を開き、統計タブの「保存されているデータ」から操作できます。

一部だけ消したい場合は、同じタブの「統計をリセット」で統計のみ、 「セッション数をリセット」で現在のセッション数のみを消せます。

拡張機能をアンインストールする、または Chrome の設定から拡張機能のデータを 消去する方法でも、すべて削除されます。

Pro をご購入いただいた場合、決済時に Stripe へご入力になったメールアドレスは、 決済事業者側の契約記録として保持されます(拡張機能がそれを受け取ることはありません)。 端末内のデータを削除しても解約にはなりません。 解約のご案内をご確認いただくか、 記録の削除をご希望の場合はサポートまでご連絡ください。

7. 連絡先

本ポリシーに関するお問い合わせ: サポートページ、お問い合わせフォーム、または abqdaisuki610@gmail.com まで直接ご連絡ください。