Swervo Join the beta

Legal

Privacy Policy

Version 1.10 · Effective

This document is a draft under attorney review. Items shown in brackets are not final. It is not legal advice.

Applies to the Swervo Android app and the optional companion server you can run on your own PC.

1. The short version

Swervo runs on your phone. In the default phone-only mode the only things that leave the phone are the address lookups and the map downloads in section 5 (the lookups differ between beta and release builds), your speech to Android's recogniser if you use voice commands, and, once an update channel is configured, a signed update check (section 5). If you choose to pair your own PC, the phone also sends its records to that PC, which you control. One exception in the sideload edition, only if you choose it: shift-data sharing is off until you tick its box (on the Beta setup screen or Home's one-time prompt) or turn on "Share shift data to improve Swervo" in Settings. While it is on, the offers from each shift, with the positions involved rounded as section 2 describes, and diagnostic events are uploaded to a spreadsheet we control (section 2 rows "Shift data" and "Diagnostic events"). We run no other service that receives your data, and the Google Play edition uploads nothing. Problem reports leave the phone only when you tap "Send a problem report" and pick where to send it.

2. What the app collects, why, and where it lives

Data Why Where it lives
Screen content of delivery apps read through Android's Accessibility Service: offer cards, task lists, drop-off steps (payout, restaurant, addresses, distances, deadlines, button labels). The service is limited by its configuration to the delivery apps only (DoorDash Dasher, Uber Driver, Grubhub for Drivers, Walmart Spark); it cannot read any other appTo evaluate offers, respond at the level you chose, and guide drop-offsPhone (app-private). Offer text is kept in the order record. PC if paired.
Map capture of the offer card, taken in memoryTo read map pins for the drop-off areaSent only to a paired PC, which keeps it 30 days. The phone stores no screenshot or map image.
Delivery-app notificationsFast offer detectionPhone
Location, about every 15 seconds during an active shift; not collected when no shift is activeArrival, pickup and delivery detection; mileage; route estimatesPhone; PC if paired
Order and shift records: offers seen, verdicts and reasons, taps performed, pickups, deliveries, recorded payouts, times you stopped Autopilot, shift times; for accepted orders, the restaurant and drop-off coordinatesReports, learning, earningsPhone; PC if paired
Shift data (sideload edition only; optional, off until you tick its box or turn on "Share shift data" in Settings): for every offer in every shift, the platform (which delivery app), restaurant, pay, verdict and reason, whether you accepted, how many seconds that took and how the app detected it, the local time, weekday and hour, minutes and miles, with every upload the app version, edition and your phone's time zone, and the positions involved: your position when the offer arrived and your destination, each rounded to about 110 m (if your destination is your home, that area is sent, not the exact point), the customer drop-off area (about 110 m) and the restaurant (about 1 m), plus a random per-install identifierTo improve Swervo's verdictsUploaded to a Google Sheet we control, after each shift ends, when the app opens, when you turn sharing on, and whenever a diagnostic event is recorded, only while sharing is on. Not linked to your name or account. Deleted automatically within about a day of turning 12 months old, or sooner from Settings. Never sold or shared.
Delivery outcomes (sideload edition only; only after you tick version 3 of the shift-data question): for every offer, what you did (took it, skipped it, stopped the countdown or let it expire), whether that went against the verdict, which version of our decision rules produced it, and any thumbs up or thumbs down and reason you give after a shift; for offers you took, the minutes waiting at pickup, driving to pickup and to drop-off, and in total, the actual pay and tip read from the delivery app's screen or typed by you (never an estimate), and whether and how it was cancelled. Never the text on your screen, and no position beyond the shift-data row aboveTo measure and improve Swervo's verdictsUploaded with the shift data, to the same Sheet under the same identifier, only while sharing is on. A yes to the earlier version of the question does not cover it; Home asks once. Same retention and deletion. Never sold or shared.
Diagnostic events (sideload edition only, sent only while you share shift data): what Start, going online and setup did (each event's kind and status, the Autopilot level, which setup items are missing, and the text of the Start result message, which names apps and statuses), the app version with every upload, the phone model and Android version with the setup event, with the same per-install identifier; never a position or addressFinding and fixing a tester's problem without asking them to send a reportKept on the phone (the last 500) and uploaded to the same Google Sheet as soon as each is recorded; deleted automatically within about a day of turning 12 months old, or with Settings → Delete my uploaded shift data
Decision Records: one record per offer the app evaluated: the offer as read (platform, restaurant, pay, distances, deadline), the verdict, its reason and the version and settings of the rules that produced it, what the app did and what you did, and for offers you took the times of arrival, pickup and delivery, the pay and tip and where those figures came from, and any thumbs up or down you gave. Positions follow the "Keep offer positions" switch: the drop-off area to about 110 m and your own position to about 1.1 km, or none when the switch is off. The text read from the screen is kept with house and unit numbers, coordinates and customer names removed, and cut to 1,000 charactersTo show you why each verdict was given, to measure whether verdicts were right, and to test changes to the rules against real offersPhone (app-private), deleted 30 days after the session's last write; "Delete offer maps" in Settings deletes them all. PC if paired: the PC receives the records without the screen text and deletes them 30 days after their last event. Nothing from a Decision Record is sent to us unless you agreed to share delivery outcomes (row above), and then only the fields listed there
Quest mode: a bonus you type in: orders left, the bonus amount, the deadline and, if you choose, the platform. The app never reads a bonus from a delivery app's screen or notificationsTo count eligible offers toward the bonus you enteredPhone (one setting); PC if paired. Cleared when the quest completes, expires or you clear it
Routes (only when directions from a paired PC are in use): the ordered stops of the route, including your current position, exactTo calculate directionsSent to your own paired PC only, which calculates the route itself from map data it holds and keeps no log of positions or street names. Never sent to us or to any mapping company. Phone-only drivers: no route request leaves the phone
Offer positions for the Test Shift map: for each offer the app evaluated, your position when it arrived, the restaurant's coordinates, the customer drop-off area (never the exact address or the customer's name), and your shift destinationTo draw the detour map in Test Shift review so you can see why an offer was judged the way it wasPhone only. Deleted after 30 days; "Delete offer maps" in Settings removes every saved position and keeps the verdicts; "Keep offer positions for Test Shift maps" in Settings turns it off; never included in problem reports
Drop-off recordings ("DoorStep"): the text labels shown on delivery-app screens during a drop-off, no images. These can include customer first names, addresses, gate codes and delivery notes.To learn and guide the drop-off flowPhone only, app-private. Deleted automatically after 30 days; delete any time in Settings.
Settings: home and destination addresses and coordinates, cost per mile, thresholds, platform toggles, Autopilot level, shift schedulesOperationPhone; PC if paired
Restaurant intelligence: names, coordinates, observed waits, blacklist flagsVerdictsPhone; PC if paired
Debug screen dumps: text of delivery-app screens, written only in debug builds with spy mode onDiagnosing screen-reading bugsApp-specific external storage; deleted after 30 days
Diagnostics: crash files, the app's own log lines, readiness lights, settings with secrets and home/destination removedFixing problemsPhone, until you send or clear
Consent records: document, version, time in UTC and local, time zone, app version, Autopilot level chosenProof that you saw and accepted each documentPhone; included in problem reports
PC pairing credentials (only if you pair a PC): one-time pairing code, device tokenAuthenticating your phone to your PCPhone and your PC
Session archives: snapshots of past shifts (orders, payouts, miles, counts)HistoryPhone until you delete them in Settings

Not collected: platform logins or passwords; payment cards (payments, if any, are handled by Stripe under the Subscription Terms); contacts; photos; audio (voice commands use Android's SpeechRecognizer and the app stores no recording); advertising identifiers.

3. Customer information

Delivery apps show customer names, addresses and notes. The app processes them only to help you complete the delivery you accepted, keeps them inside the order record and the drop-off recording on your phone, and sends them nowhere except to a PC you paired. Under the platforms' terms you are responsible for handling customer information; the 30-day prune and the delete button in Settings exist to help you keep nothing longer than needed.

4. Permission self-repair

With a permission you grant once from a PC over USB, the app can re-enable its own accessibility service and notification listener if Android disables them, only during an active, unpaused shift and only while recovery is enabled in Settings. This changes only Swervo's own two settings. It is disclosed here because it touches a system setting.

5. Third parties that receive data

Recipient What When
Photon (photon.komoot.io, built on OpenStreetMap data; "© OpenStreetMap contributors" is shown where the suggestions appear)The text you type in the home and destination fields during setupAll builds: address suggestions while typing on the setup screen
OpenFreeMap (tiles.openfreemap.org, operated by Hyperknot Software Kft., Hungary, and delivered through Cloudflare; map data © OpenStreetMap contributors, © OpenMapTiles; credited on the map)Requests for the map tiles, fonts and icons for the area a map shows, carrying the tiles' map coordinates, your IP address and the app's user agent. The app sends no GPS position, account or identifier, but the area shown is usually where you are, so these requests can reveal your approximate or precise location to OpenFreeMap and Cloudflare. OpenFreeMap states that its logs do not contain IP addresses, except for up to 30 days during a security incidentAll builds: only while a map is on screen (the Map screen, the Test Shift offer map and the driving view). While you are driving with Swervo directions the map stays on screen and follows you, so these requests continue for the whole drive. Tiles you have seen are cached on the phone and are not requested again
Android Geocoder (Google-backed on most phones)Addresses and coordinatesAll builds: turning a setup address into coordinates. Release builds only: the Home destination search and naming the town of a drop-off
Google Places Autocomplete and Geocoding APIs (maps.googleapis.com)The text you type in the Home destination search; the address you pickDebug and beta builds only, which carry a Google Maps key: called directly from the phone for the Home destination search and its lookup. Release builds ship no Google key and use Photon and Android's Geocoder for that search instead. The setup screen never uses Google Places in any build
Update manifest host ([address published when the update channel is switched on]) and Android DownloadManagerA request for the signed update manifest (no personal data in the request beyond what any HTTPS request carries: your IP address and the app's user agent); the APK download itselfOnly when an update channel is configured in the build; off until then. The manifest's signature and the APK's SHA-256 and signing certificate are verified before anything is installed, and installation always asks you
Google speech services through Android's SpeechRecognizerYour spoken commands; may be sent to Google for recognition depending on your phone's settingsOnly when you use voice commands
Android text-to-speech engineVerdict textWhile speaking; on-device on most phones
Google Maps Platform (routing, geocoding, static map images)Addresses and coordinatesOnly through a paired PC; see the row above for the phone-side Places/Geocoding calls in debug and beta builds
OpenStreetMap OverpassDrop-off coordinates, to check for apartment or hotel buildingsOnly through a paired PC
Anthropic (Claude API)The offer map capture and the fields extracted from itOnly through a paired PC; never in phone-only mode
Tailscale (optional)Encrypted transport between your phone and your PC; Tailscale sees connection metadata, not your recordsOnly if you set it up
Shizuku (optional, on-device)Screen-reading and wireless-debugging commandsOnly if you installed it
Swervo (us), through a Google Apps Script web app and a Google Sheet in our Google accountShift data and diagnostic events, as described in section 2, with a per-install identifierSideload edition only, and only while you have chosen to share shift data. Google, as the host of that Sheet, processes it under Google's terms for our account.
Delivery platformsOnly the taps the app performs inside their appsAt the level you chose
Whoever you send a problem report toThe report zipOnly when you tap "Send a problem report" and choose a recipient

When the update channel is on, the update check is the only regular contact the app has with a server of ours; it sends no identifier and no records. We do not sell personal information. We do not use advertising or analytics SDKs. We do not share data with data brokers. There is no server of ours between your phone and any of the services above.

6. Problem reports

A report is a zip built on your phone. It contains app and device facts, the app's own recent log lines, recent crash files, your consent records, and your settings with secrets (anything named token, secret, password, key, auth, cookie, credential or PIN) and your home and destination addresses and coordinates replaced by "[removed]". It may still contain restaurant names, offer amounts, timestamps and delivery-app text that appeared in the log. It leaves the phone only when you tap Send and pick where it goes.

7. Retention

Data Kept until
Order, shift and restaurant recordsYou reset the session (which archives it) or uninstall. On the PC: until you delete the database.
Session archivesYou delete them in Settings, clear app data, or uninstall
Map capturesNever stored on the phone; the PC deletes them after 30 days
Drop-off recordings30 days, or when you delete them
Offer positions for the Test Shift map30 days after the session's last write, or when you delete them; off entirely if you turn the setting off
Decision RecordsPhone: 30 days after the session's last write, or when you tap "Delete offer maps and decision records". Paired PC: 30 days after the record's last event
Quest you enteredUntil it completes, expires or you clear it
Cached map tilesKept by the map component within its own size limit; removed by Android Settings → Apps → Swervo → Clear cache, or uninstalling
Debug screen dumps30 days
DiagnosticsUntil sent or cleared
Consent recordsWhile the app is installed
Shift data and diagnostic events uploaded to us (sideload)Deleted once 12 months old: the collector checks for expired rows every day (a daily check run from our computer, and on every upload or deletion request), so a row is removed within about a day of turning 12 months old; deleted sooner with Settings → Delete my uploaded shift data or on request by install identifier

The retention sweep runs every time the app opens and every time Settings opens. Uninstalling deletes all app-private data on the phone; PC data must be deleted separately.

8. Your choices and how to delete data

  1. 1. Stop collection. Home → Autopilot → Observe (no taps). Android Settings → Accessibility → Swervo → Off stops all screen reading. Notification access → Off. Location → Deny.
  2. 2. Delete the current shift. Home → menu → Reset session. This archives the shift, then clears it.
  3. 3. Delete drop-off recordings. Settings → Device & Reliability → Delete drop-off recordings → Delete.
  4. 4. Delete archived sessions. Settings → Device & Reliability → Delete archived sessions → Delete. Copies you exported elsewhere are not affected.
  5. 4a. Delete offer maps and Decision Records / stop keeping offer positions. Settings → Device & Reliability → Delete offer maps and decision records removes every saved position and every Decision Record on the phone; Settings → Keep offer positions for Test Shift maps → Off stops positions being kept in either.
  6. 5. Delete everything on the phone. Android Settings → Apps → Swervo → Clear data, or uninstall.
  7. 6. Delete PC data. Delete data/delivery.db (which holds the PC's Decision Records), the uploads/ folder and the offer archive on your PC.
  8. 7. Revoke self-repair. Settings → Recovery → Off, or run adb shell pm revoke <package> android.permission.WRITE_SECURE_SETTINGS.
  9. 8. Unpair the PC. Settings → Server → Unpair, or revoke the device on the PC's security page.
  10. 9. Stop sharing or delete shift data (sideload). Settings → Device & Reliability → Share shift data to improve Swervo → Off stops future uploads. Delete my uploaded shift data on the same screen deletes every row this phone sent (offers, uploads and diagnostic events) from our spreadsheet and shows what was deleted. If it says deletion isn't available yet, email support@swervo.app with the install identifier shown above that button.

8. Editions

If a Google Play edition of Swervo is published, it contains Observe, Test Shift, reports and maps only: it reads offers and speaks, and never taps. It does not include Autopilot, scheduled go-online, drop-off guidance that opens the delivery app's camera step, the self-update channel or permission self-repair. Everything in this policy about those features applies only to the edition downloaded directly from us. Both editions keep your data on your phone.

8a. Precise location and the law

Your position during a shift, and the coordinates above, are "precise geolocation," which state privacy laws (California, Maryland, Kentucky, Connecticut, Virginia, Colorado, Oregon, Texas and others) treat as sensitive data. Those laws regulate companies that collect and control such data. In the Play edition Swervo does not receive it: it is generated and kept on your own phone, by software you run, for your own use. In the sideload edition we receive the positions described in section 2 only if you chose to share shift data (it is off until you do), with your own position and destination rounded to about 110 m; we never sell or share them, we delete them once they are 12 months old, and you can stop sharing or delete them at any time. We design to the strictest of those laws anyway: location is kept only where it is needed for a feature you chose, kept briefly, rounded where it concerns other people, and deletable.

9. Security

App data lives in Android app-private storage. PC pairing uses one-time codes and revocable device tokens; browser access to the PC requires a secure transport. No system is perfectly secure, and the security of a PC you pair is your responsibility.

10. Children

Swervo is not for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has used it, contact us and we will help delete the data.

11. Your rights

Depending on where you live you may have rights to access, correct, delete or port personal data, and to opt out of sales or targeted advertising (we do neither). Because the data is on your own device, you can exercise most of these rights directly with section 8. For anything else, contact support@swervo.app.

12. Changes

We update the effective date and version at the top, record changes in the changelog, and show material changes in the app.

Contact

[publisher's legal name, to be added], [mailing address, to be added], support@swervo.app.