Switchly Privacy Policy

Last updated: September 12, 2026

This policy explains how Switchly handles information when you use the Switchly Windows desktop application and the Switchly Creator licensing service.

1. Data that stays on your Windows device

Switchly is designed so that provider browser sessions stay local. Cookies, local storage, IndexedDB, provider session state, and isolated WebView2 profile folders are stored on your device and are not uploaded to the Switchly licensing service.

Local application data can also include provider account labels, workspace metadata, groups, projects, prompts, recent-workspace state, download metadata, diagnostics, and other settings required for the desktop experience.

2. Data handled by the Switchly licensing service

When you sign in to a Switchly account or use Switchly Creator, the service may process:

Switchly does not intentionally collect provider passwords, provider cookies, provider access tokens, provider page contents, complete WebView2 profile folders, or hardware fingerprints through the licensing service.

3. Why this data is used

Service data is used only to authenticate your Switchly account, deliver and verify Creator entitlements, enforce the Creator device limit, process subscription payments, prevent duplicate payment application, provide account controls, operate backups, and protect the service against abuse.

4. Payments and email delivery

Creator checkout is handled by Midtrans. Payment details such as card numbers or online-banking credentials are entered on Midtrans-controlled surfaces and are not stored by Switchly. Switchly stores only the order, transaction identifiers, amount, cadence, and status needed for entitlement and accounting records.

A third-party email delivery provider is used to send one-time sign-in codes. That provider receives the destination email address and message content needed to deliver the code.

5. Other providers opened inside Switchly

When you open services such as Google Flow or other supported web services, browser traffic goes to that service. Those providers operate under their own terms and privacy policies. Switchly does not become the controller of data you submit directly to those services merely because they are displayed in an isolated WebView2 session.

6. Service providers and disclosures

Switchly may use infrastructure, encrypted backup storage, email delivery, payment processing, and Microsoft Store distribution providers to operate the product. Information is disclosed only as needed for those functions, legal obligations, security, fraud prevention, or dispute handling. Switchly does not sell personal data or provide personal data to advertising networks or data brokers.

7. Retention

Data Retention
Switchly account identity and active subscription metadata Until the account is deleted or the data is no longer needed to provide the account.
Expired authentication challenges Up to 24 hours after expiration.
Expired or revoked authentication sessions Up to 30 days after expiration or revocation.
Deactivated Creator device records Up to 90 days after deactivation.
Billing orders and payment event records Up to 10 years for accounting, dispute, audit, and legal recordkeeping needs, or longer when required by law.
Encrypted operational database backups Up to 30 days before normal backup rotation removes them.

8. Delete your Switchly account

A signed-in user can open Manage Switchly Creator in the desktop app and choose Delete Switchly account. Deletion removes the account email, authentication records, subscription record, and Creator device records from the active licensing database. Existing billing and payment records are retained for the period described above but are detached from the deleted Switchly user identity.

Account deletion does not automatically delete provider browser profiles stored locally on your PC. Those local profiles can be removed separately from Switchly's Accounts interface. Copies of deleted server data may remain in encrypted backups until the backup retention period expires.

9. Security

Switchly uses HTTPS for service traffic. Desktop account tokens are protected with Windows DPAPI. Server-side session tokens and one-time verification codes are stored as hashes rather than plaintext. Creator entitlements are cryptographically signed. Production database backups are encrypted before off-host storage.

10. Your choices

You can sign out, deactivate Creator devices, delete your Switchly account, remove local provider profiles, or uninstall the application. For account, billing, support, privacy, or data-access requests, contact ferdi.lpu@gmail.com.

11. Changes to this policy

This policy may be updated when Switchly's features, service providers, or data practices change. The current version will remain available at this URL with its updated date.