BlackSwipe ← Back to the site

Legal

Privacy Policy

Last updated: 19 August 2026

Before you upload this page

Replace every bracketed field below with your real details — controller name, address, contact address and your hosting provider. Delete this box afterwards. The page is not usable as long as the brackets are still in it.

1Who is responsible

Responsible for the processing of personal data described here is [CONTROLLER NAME], [STREET ADDRESS], [POSTCODE AND CITY], [COUNTRY], reachable at [CONTACT EMAIL].

This policy covers two separate things: this website, and the BlackSwipe application you install on your PC. They handle data very differently, so they are described separately below.

2This website

Hosting and server logs

The site is hosted by [HOSTING PROVIDER]. As with any web server, the host records access data — IP address, time of request, requested file, referrer and browser identification. This is needed to deliver the page and to keep the server secure. Legal basis: legitimate interest, Art. 6(1)(f) GDPR.

No analytics of our own

We do not run any analytics, tracking pixels or advertising scripts, and we do not set cookies of our own. The page itself loads no external fonts, images or scripts beyond the checkout described below.

Checkout (Sell.app)

Buying is handled by our resale partner Sell.app. When you press a buy button, a checkout window loads from cdn.sell.app. From that moment on, Sell.app processes data as its own controller.

What the checkout transmits to Sell.app when you open it:

  • Page address, referrer and browser identification — so the order can be attributed to this site.
  • A session identifier generated by the checkout.
  • Advertising identifiers already present in your browser, if any — this can include Google Analytics client and session IDs, Facebook fbc/fbp cookies and TikTok ttclid. These are read from your browser by the checkout, not set by us.
  • The email address you enter, so the licence can be delivered.
  • Payment data — handled entirely by Sell.app and the respective cryptocurrency network. We never see or store it.

Legal basis: performance of the contract, Art. 6(1)(b) GDPR. For Sell.app’s own processing, see their privacy policy.

Note that a cryptocurrency payment is recorded permanently in a public blockchain. Transaction amounts and wallet addresses are visible to anyone and cannot be deleted — by us or by anyone else.

3The application

This is the part that matters most, so it is spelled out completely.

What leaves your machine

The application makes exactly one kind of outgoing request: a licence check, sent on activation and about every five minutes afterwards. It contains:

  • A SHA-256 hash of your Windows MachineGuid — used to bind the licence to one device. The hash is not reversible; we cannot derive your machine ID, your name or your hardware from it.
  • Your licence key — so we can tell which licence is being checked.
  • The application version — so older builds can be told what changed.

That is the complete request. Legal basis: performance of the contract, Art. 6(1)(b) GDPR, and our legitimate interest in preventing licence abuse, Art. 6(1)(f) GDPR.

What never leaves your machine

  • Your configuration, logs, screenshots and all statistics. They live in your local app data folder and are never uploaded.
  • Anything you farm — loot values, attack counts, donation totals, run times.
  • Your Supercell account. The application attaches to an emulator you are already signed into. It never asks for, sees or stores game credentials.
  • The game itself is not modified, its memory is not read, and no code is injected.

The signed licence lease is stored locally and encrypted with Windows DPAPI under your Windows user account, so another user on the same machine cannot read it.

4How long data is kept

  • Server logs — deleted or anonymised after a short period by the host.
  • Licence records (key, device hash, validity) — kept for as long as the licence is valid, plus the period required for tax and accounting purposes.
  • Order and email data — kept by Sell.app under their own retention rules.

5Who else receives data

We pass data on only where it is needed to run the service: our hosting provider, and Sell.app for payment and delivery. We do not sell data and we do not pass it on for advertising.

6Your rights

Under the GDPR you may request access to the data we hold about you, and its correction, deletion or restriction. You may object to processing based on legitimate interest, and you may request a copy of your data in a portable format.

To exercise any of these, write to [CONTACT EMAIL]. Please note that a device hash on its own cannot be traced back to you — to identify your records we will need your licence key or order email.

You also have the right to lodge a complaint with a data protection supervisory authority.

7Changes to this policy

If the software or the checkout starts handling data differently, this page will be updated and the date at the top changed.