Security Policy
Last updated: 2 September 2026
Trust is the foundation of a local marketplace. This policy describes the measures Sayswapp takes to keep your account and data safe, what we expect from members, and how to tell us if something looks wrong.
1. Account protection
- You sign in with your email address, mobile number or Google account. We never store your password in plain text.
- Sessions are issued as time-limited tokens and can be ended at any time by signing out from the You tab.
- Keep your sign-in details private. Sayswapp will never ask you for your password or a one-time code by phone or chat.
2. Data in transit and at rest
- All traffic between your device and Sayswapp is encrypted using HTTPS (TLS).
- Your recordings, photos, videos and messages are stored with our hosting provider and protected by access controls.
- Database access is restricted row by row, so members can only read and change the records they are permitted to — for example, only the two people in a conversation can read that conversation.
- AI transcription and translation happen on our servers; your keys and credentials are never exposed to the browser.
3. Live capture only
Photos and videos of items are captured live inside the app. Gallery uploads are not permitted. This makes it much harder to post fake or copied images and helps buyers trust that what they see is really there.
4. Contact details
Your phone or WhatsApp number is shown only through the contact methods you switch on, and only to members viewing your listing or a request you have accepted. You can change or remove these at any time.
5. Staying safe when trading
- Sayswapp connects buyers and sellers; payments and hand-overs happen directly between members.
- Meet in public places, inspect items before paying and avoid sending money in advance to people you have not met.
- Never share one-time codes, bank logins or identity documents in chat.
- Report suspicious listings or messages to security@sayswapp.com.
6. Monitoring and abuse prevention
We keep basic logs to detect abuse, spam and attempts to gain unauthorised access. Accounts that break these rules or our terms may be suspended or removed.
7. Incident response
If we become aware of a security incident that affects your personal data, we will investigate, take steps to contain it and notify affected members and regulators where required.
8. Reporting a vulnerability
If you believe you have found a security weakness in Sayswapp, please email security@sayswapp.com with enough detail to reproduce it. Please do not access other members’ data or disrupt the service while testing. We will acknowledge your report and keep you informed as we fix it.
9. Changes to this policy
We review this policy regularly and update the “last updated” date whenever it changes.