Public Builder Privacy Policy

Last Updated: October 2026 (Applies to v2.1.1 and above)

🛡️ No Sign-In Required • Anonymous Use • Ephemeral Data

1. Introduction & Anonymous Use

Welcome to public.swaplab.net (the "Public Service"), a specialized build engine operated by SwapLab. This service is designed for rapid prototyping, testing, and debugging without the need for user accounts or authentication.

Users typically choose this service for various reasons: lacking a GitHub account, facing account access issues, or simply desiring a completely zero-trace identity footprint.

Zero-Knowledge Identity: We do not know who you are. We do not collect your name, email address, GitHub credentials, or payment information on this specific service. You are identified solely by a temporary, random "Guest ID" generated by your browser.
Assumption of Risk: By using this Public Service, you agree that you are using it completely at your own risk. If you require private, persistent storage or official production release builds, please use our authenticated service at private.swaplab.net.

2. Debugging, Release Builds & Keystore Security

The primary purpose of this public option is for debugging, such as comparing the final file sizes of debug-apk versus release-apk/aab. While artifacts generated here are fully valid and can be uploaded to app stores, we strongly recommend using our Private service for official production releases.

Keystore Recommendation

If you are generating a release build for testing purposes on this public engine, DO NOT use your personal or production keystore. Always create a new, temporary keystore for testing. You can easily generate one securely using our free tool at keystore.swaplab.net.

Zero-Knowledge Keystore Encryption (E2EE)

If you do choose to use a keystore, rest assured that no files or passwords are uploaded to us in plain text.

  • Frontend Encryption: Your keystore file and metadata (passwords, alias) are encrypted End-to-End (E2EE) using military-grade AES-256-GCM directly inside your browser before anything is transmitted over the network.
  • Verifiable Transparency: You can independently verify this by opening your browser's Developer Tools (Network Tab). You will see that the network payload contains only unrecognizable ciphertext, not your secrets. This transparency is also logged in your UI terminal.

3. Information We Collect (And Don't Collect)

A. No Personal Information

Unlike our main service, this Public Builder does not collect:

  • ❌ No Names or Email Addresses.
  • ❌ No GitHub OAuth Tokens or Passwords.

B. Technical Data (What We DO Collect)

To operate the build engine securely, we process:

  • Network Logs: Your IP address is logged temporarily for rate-limiting purposes (to prevent abuse/DDoS) and security monitoring.
  • Browser Guest ID: A random string stored in your browser's local storage to track the progress of your active build.

4. Data Lifecycle: "Ephemeral by Design"

This service operates on a strictly ephemeral (short-lived) basis. We do not want your data. Once the job is done, the data is gone.

Phase 1: Input Data (Project Source)

Depending on your chosen input method, your project source is handled securely:

  • Option A (ZIP Upload): Your .zip file is temporarily uploaded to Cloudflare R2. The file is extracted strictly inside the isolated Docker container. Immediately after extraction, our backend uses the Cloudflare API to permanently delete the uploaded .zip file from R2 before the build process even advances to the next stage.
    ▶️ Watch how we destroy your Cloudflare R2 files in real-time
  • Option B (Git Repository): We directly clone the public repository into the ephemeral Docker container. No source files are ever uploaded to our storage buckets.
Phase 2: Build Environment (Docker)
  • Isolation & Destruction: Your code is compiled inside a fresh, isolated container. Once finished, the entire container is destroyed. No residual code remains in memory or on the disk.
Phase 3: Output Data (Your APK/AAB/ZIP)
  • Strict 1-Hour Expiry: The final build artifact is uploaded solely to generate a download link. We permanently delete all artifacts after 60 minutes.

5. Transparency & The Public Repository

To build trust in an anonymous service, your builds are orchestrated through a Public GitHub Repository (public-build-swaplab-engine).

Log Privacy (Silenced Jobs)

We have explicitly configured our Actions runners to execute silenced jobs. The detailed build logs (which might contain your file names or paths) are NOT printed to the public GitHub console. They are streamed securely via WebSocket only to your browser session.

6. Security Scanning

Just because it's anonymous doesn't mean it's unsafe. We apply rigorous security standards:

  • Malware Scan: Every uploaded project is scanned before processing.
  • Dependency Audit & Static Analysis: We run standard security checks to detect vulnerabilities and dangerous code patterns.

7. Limitations & Liability

AS-IS SERVICE: This Public Builder is provided "AS IS" and "AS AVAILABLE" without any warranties.

  • We are not responsible for any data loss resulting from the 1-hour auto-deletion policy.
  • We do not guarantee the successful compilation of every project uploaded.
  • Use of this service for illegal purposes, hosting malware, or mining cryptocurrency is strictly prohibited.

8. Contact

Since we do not collect email addresses for this service, we cannot proactively contact you. If you have privacy concerns regarding a specific build, you must provide the Build ID (e.g., `pub-xxxx`) available in your browser logs.

Email: swaplab.help@gmail.com