SwimKeeper Privacy Policy
Effective date: September 23, 2026
Last updated: September 23, 2026
SwimKeeper (“SwimKeeper,” “we,” “us”) is a private, family-controlled swim‑performance journal operated by KCB Systems LLC (d/b/a SwimKeeper), a Pennsylvania limited liability company. This policy explains what we collect, how we use it, and the choices you have. We built SwimKeeper to be private by default — nothing about your family is public unless a future feature is one you explicitly turn on, and version 1 ships no such public features at all.
If you have questions, contact us at privacy@swimkeeper.app.
1. Who can use SwimKeeper
SwimKeeper accounts are for parents and legal guardians who are 18 or older. A parent/guardian creates the account and the household, and adds and controls the swimmer profiles within it (which may be those of their own children, including children under 13).
Children do not create their own accounts. SwimKeeper does not permit independent account creation by anyone under 13, and we do not knowingly let a child register or provide information to us directly. All information about a swimmer is entered and managed by the parent/guardian who controls the household.
2. Information we collect
We practice data minimization — we collect only what the private tracker needs.
Account information (about the parent/guardian):
- Email address
- Password (stored only as a salted hash by our authentication provider — we never see or store your plaintext password)
- A display name you choose
Household and swimmer information (entered by the parent/guardian):
- Household name
- For each swimmer: a preferred name or nickname; date of birth (used to calculate age at the time of each swim and to match age‑group standards); and a competition category (used to compare against the correct published time standards). An optional “standards comparison” preference may also be set.
Swim data you enter:
- Meets (name, dates, course, optional sanctioning bodies)
- Race results (event, time, place, status), optional splits, and optional private race notes
- Goals, and the time standards / cut sets you create or import and the swimmers you subscribe to them
Other:
- Feedback you choose to send us through the app: the message itself, plus the screen it was sent from, your app version, platform, and build
- If you request beta access: your email address, and — if you choose to provide them — your name and whatever you tell us in the free‑text “about your swimmer” field
- Limited technical data that our providers process to operate and secure the service (for example, server logs and IP address at the infrastructure layer)
- Limited product and reliability telemetry — page views and error reports — used to keep the service working and to understand which parts of it people use. See Section 5 for exactly who processes this and what it excludes.
We do not sell or rent your information, we do not use advertising trackers or ad networks, we do not build behavioral profiles of you or your children, and we do not track you across other websites.
3. How we use information
We use the information above only to:
- Provide and operate the tracker — store your family’s swim history and compute derived values such as personal bests, season bests, age at swim, and progress toward goals and standards;
- Authenticate you and send essential service email (for example, sign‑in verification and password reset);
- Respond to feedback or support requests you send us;
- Keep the service secure, debug problems, and prevent abuse;
- Comply with legal obligations.
We do not sell or rent your information, we do not use it for advertising or behavioral tracking, and we do not build advertising profiles of you or your children.
4. Children’s information (COPPA‑aware)
Protecting children’s data is central to how SwimKeeper is built:
- A swimmer profile — including a child’s name and date of birth — is provided and controlled by the parent/guardian, who has the authority to do so.
- Swimmer profiles are private by default and visible only to the parent/guardian members of that household. Version 1 has no public swimmer profiles, no public search or directory of minors, no social graph or following, and no messaging or free‑form comments.
- A swimmer’s full date of birth is never displayed publicly and is used only for age and standards calculations within the household.
- A parent/guardian can review, export, and permanently delete their children’s information at any time (see Sections 6 and 7).
The U.S. Children’s Online Privacy Protection Act (COPPA) governs the online collection of personal information from children under 13. Because a parent enters and controls their child’s information here, and because that information stays private to the household, we design to honor parental control and the rights described in this policy. If you believe a child has provided us information outside of a parent‑controlled household, contact us at privacy@swimkeeper.app and we will delete it.
5. How information is shared
We share information only as needed to run the service:
-
Service providers (processors). These providers process data on our behalf to operate the service and are bound to protect it:
- Supabase — database, authentication, and backend hosting. Your account and all of your family’s swim data live here.
- Cloudflare — web hosting and content delivery for our app and website; bot protection (Turnstile) on our beta‑access form; email routing for our contact addresses; and Cloudflare Web Analytics, which counts page views and performance timings. Cloudflare Web Analytics is cookieless, does not fingerprint you, and does not track you across other sites.
- Resend — transactional email. This includes essential account mail (sign‑in verification, password reset) and internal notifications to us when you send feedback or request beta access; the contents of those submissions pass through Resend in order to reach us.
- Sentry — error monitoring on the web app, when enabled. It is configured to send only the error type and the code location (file, function, line) where it happened. Error message text, browsing breadcrumbs, request data, and user identifiers are stripped before anything leaves your device.
We do not send your family’s swim data — swimmer names, birth dates, times, splits, or notes — to any analytics or error‑monitoring provider. Page addresses within the app do contain internal record identifiers (random strings such as
/swimmers/8f3c…), which are included in web‑analytics page views. These identifiers are meaningless outside your own account and are never accompanied by a name or any other detail about your family. -
Legal reasons: if required by law, or to protect the rights, safety, and security of our users or the service.
-
Business transfers: if SwimKeeper is involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction, subject to this policy.
We do not sell personal information, and we do not share it with advertising networks or data brokers.
6. Your choices and rights
Through the app, a parent/guardian can:
- Access their household’s data at any time;
- Export a full copy of the household’s journal (JSON) and per‑swimmer results (CSV) from the You screen;
- Correct any information by editing it directly;
- Delete their account, which permanently removes the household and everything in it — swimmers, meets, results, splits, notes, goals, seasons, submitted feedback, and the account itself (see Section 7).
Depending on where you live, you may have additional rights (such as access, correction, deletion, or portability). To exercise them, use the in‑app tools above or contact privacy@swimkeeper.app.
7. Data retention and deletion
We keep your information for as long as your account is active. When a parent/guardian deletes their account in the app, we permanently delete the household and all swimmer and swim data associated with it, and the parent’s account, in dependency‑safe order; this action cannot be undone.
8. Security
We protect data with row‑level security enforced at the database layer (each household can access only its own data), encryption in transit (HTTPS), and hashed‑password authentication. No system is perfectly secure, but we work to protect your family’s information and to limit what we collect in the first place.
9. Where data is processed
SwimKeeper is offered to households in the United States, and your account and swim data are stored in the United States (our database is hosted in the US East region). Some of our providers operate global networks — Cloudflare, for example, serves and protects our site from the location nearest you — so limited technical data such as IP addresses may be processed outside the United States.
10. Changes to this policy
We may update this policy as the product evolves (for example, when we add new processors or introduce opt‑in sharing features). We will revise the “Last updated” date and, for material changes, provide a more prominent notice.
11. Contact us
Questions or requests about this policy or your data: privacy@swimkeeper.app · KCB Systems LLC (d/b/a SwimKeeper), Pennsylvania, USA.