Privacy Policy
Effective 2026-07-14 (first published 2026-07-08). TranSwynt is an early, validation-stage project run by SWYNT (see the Imprint for who is responsible) — this policy will be revisited as the app grows.
What data we collect
You can try TranSwynt without an account: the demo pages work with no login, and a trip you check there is used only to answer that one request — we don't save it. Checking your own custom trip and saving trips require an account.
Your account. We store the email address you sign up with. Your password is handled by Supabase (the login and database service we use) and is never stored in readable form — we couldn't look it up if we wanted to. Sign-up confirmation and password-reset emails are sent through Supabase.
Saved trips. If you save a trip (up to 5 active at a time), we store its details — flight numbers, travel dates, station names, planned times, and your connection buffer — together with the trip's last known delay state, so we can tell whether a new delay is actually news. Saved trips stay stored until you delete them or your account.
Delay alerts. When a saved trip starts with a flight, we register that flight with our flight-data provider (AeroDataBox, below) so their servers can notify ours the moment its status changes. That notification contains no personal data — we treat it purely as a nudge to re-check your trip ourselves. If your trip is newly delayed, or back on schedule, we email you at your account address. We only email you about your own trips and account — no newsletter, no marketing.
Cookies and local storage. There are no advertising or analytics cookies and no tracking scripts on this site. When you sign in, your login session is kept in your browser's local storage so you stay signed in between visits; signing out removes it.
Tester feedback
The tester pages (/test and /demo) include short feedback questions. Answers are anonymous by default: we store what you selected and wrote, the page it came from, your screen width, and — if you arrived through an invite link — a short tag naming the community or channel the link was shared in (never anything identifying you personally).
At the end of the feedback flow you can optionally leave an email address. If you do, we use it once, to tell you what changed as a result of tester feedback — no newsletter, no marketing, and we don't share it. Leave the field empty and no contact detail is stored at all. To have a left email removed, write to info@swynt.eu.
Third parties we share data with, and why
To answer "is my trip on track," we have to ask the services that actually know the real-time status:
- AeroDataBox (via RapidAPI) — receives your flight number and date, to look up flight status and delays. For saved trips that start with a flight, AeroDataBox also holds a standing alert subscription for that flight (the flight number, date, and the address of our server to notify) until you delete the trip.
- Anthropic (Claude API) — if you use the optional "Upload a ticket" feature, the photo or PDF you choose is sent to Anthropic's AI service to read the trip details off it. The file is used only to answer that one request; we don't store it, and Anthropic does not use API data to train its models by default. Don't upload files containing information you don't want processed — you can always type the trip in manually instead.
- Transitous — when we search for an alternative connection that needs a transfer, the stations and times involved are sent to Transitous, a free, community-run public journey planner. Nothing that identifies you is included in the search.
- DB (Deutsche Bahn) — for German train connections, we download DB's own public static schedule file and a public live-delay feed (both via gtfs.de, Germany's official open-data timetable source) and match stations locally on our server. Your search text is not sent to DB.
- SNCF — for French train connections, we download SNCF's own public static schedule file directly and match stations locally on our server. Your search text is not sent to SNCF.
- FlixBus — for bus connections, we download FlixBus's own public schedule file directly and match stations locally on our server. Your search text is not sent to FlixBus.
These providers may be located outside the European Economic Area, and process data under their own respective privacy policies, which we don't control.
Services that store data for us
- Supabase — hosts our database and handles sign-in. Your account email, saved trips, and tester feedback live there, in a database hosted in the EU (Ireland).
- Resend — delivers our alert and notification emails. To do that, it receives your email address and the message content, which can include your trip details. Alert emails come from
alerts.swynt.eu.
Error monitoring and hosting
If something breaks while handling your request, technical error details are sent to Sentry (error-tracking service, EU data region) so we can find and fix the problem. We deliberately strip trip details (flight numbers, station names) from these reports before they're sent — Sentry only receives what's needed to debug a crash, not what you searched for.
An uptime-monitoring service (UptimeRobot) periodically checks that the app is running, using a check that contains no personal data.
The app itself is hosted on Railway, which may retain standard server/access logs as part of running the infrastructure.
What we don't do
We don't sell your data, run advertising, or build user profiles. We don't share your trip details with anyone beyond the specific providers above, needed to answer your specific request.
Your rights
You can see, edit, and delete your saved trips in the app at any time — deleting a trip also cancels its delay monitoring. To delete your whole account and everything attached to it, or to ask for a copy or correction of what we hold about you, email info@swynt.eu — there's no self-serve account deletion yet, so we do it by hand, promptly. The same address is the right place if you believe a third-party provider above has retained something you'd like addressed. You also have the right to lodge a complaint with your local data protection authority.
Children
This service is not directed at children under 16.
Changes
This is a young, actively developed project — this policy will be updated as the app grows, and re-dated when it changes materially.