Privacy Policy
This policy explains what TyKo Sales LLC collects when you use SweepVault, why, and who else sees it. It is written to describe what the software actually does, including the parts where data does leave your machine.
The website
There are no analytics scripts, no advertising pixels, no third-party trackers, and no cross-site tracking cookies anywhere on sweepvault.app or catalog.sweepvault.app. Nothing on these pages is loaded from anyone else's server. Pages are sent with a no-referrer policy.
The catalog page runs a small script of our own so filters update without reloading. It is served from our origin, talks only to our origin, and measures nothing about you. Every filter also works with scripts disabled.
We do keep a first-party log of page visits: the path, a small allowlisted set of filter/search/sort values if you used any, a timestamp, and your account username if you were signed in. It is written by our server as it handles your request, not by anything running in your browser, and it never leaves our infrastructure. We use it to tell whether the site is being used and which pages people actually open. Entries are kept for 180 days and then deleted automatically.
We set a signed session cookie so you stay logged in, lasting about 30 days. Connecting Discord briefly sets one more, for ten minutes, purely to carry a security token across the redirect. Neither is used for tracking.
Your account
You sign in through Whop. From Whop we receive and store:
- your Whop user ID, email address and username;
- your subscription status, plan, and licence key;
- timestamps for account creation, last login, and last subscription check.
We never see your password or your payment details. Whop handles authentication and billing; card data never reaches our servers.
Connecting Discord (optional)
If you choose to connect your Discord account, we ask Discord for two permissions: to see who you are, and to add you to our server. We then store your Discord user ID and display name, when you connected, and which member role we last applied.
We use this to add you to the server and to recognise you there. In practice that means:
- a bot command can tell you your own subscription status;
- when you open a support ticket, it shows our staff your account name, subscription status and plan, so you don't have to prove who you are every time you ask a question;
- our staff can look up a member's subscription status to answer a support request;
- subscription events — connecting, disconnecting, a role changing — are recorded in a private staff-only channel so we notice problems.
Your member role itself is granted and removed by Whop, our subscription provider, based on whether your subscription is active.
We do not request access to your email address through Discord, we cannot read your Discord messages, and we do not see any other server you are in. You can disconnect at any time from your account page, which removes the roles we granted and deletes the stored Discord identifiers.
The desktop application — what leaves your machine
This is the part worth reading carefully.
The app connects to mailboxes you configure and stores messages in a local database on your computer. The full contents of your mailbox stay on your device. We do not upload your mail, and we cannot read your inbox.
However, to identify which sweepstakes a prize email refers to, the app sends a limited set of fields from that email to our matching service:
- the email subject line;
- the sender's domain (for example
example.com); - the brand and a short prize description parsed from the message;
- a sweepstakes name extracted from the subject or body;
- the time the message was received.
A redaction pass strips patterns such as addresses and identifiers from the description before it is used. The subject line and sender domain are sent as they appear. This means some content derived from your email does reach our servers, and we would rather say so plainly than claim otherwise.
The app also sends anonymous usage counters — numeric totals plus a random install identifier — so we can see how many installs are active. No email content, sender name, or address is included in those counters.
Who else receives data
- Whop — authentication, subscriptions, payments.
- Cloudflare — hosting, database, and network security for the website and API.
- A large-language-model provider — the matching service may send the redacted fields listed above to a language model to resolve which sweepstakes an email refers to.
- Discord — if you join the community server, or connect your Discord account so your member role can follow your subscription. Discord's own policy governs what they hold.
We do not sell your personal information, and we do not share it for advertising.
Retention
Account records are kept while your account exists and for a reasonable period afterwards for billing and legal records. Discord identifiers are kept only while the connection is active — disconnecting deletes them. Matching requests are cached to avoid repeat processing. Local app data lives on your machine until you delete it.
Your choices
- You can ask for a copy of the account data we hold, or ask us to delete it, by emailing us. Deleting your account ends your access.
- You can uninstall the desktop app at any time; that stops all data leaving your machine.
- Subscription and payment data is managed in Whop.
Depending on where you live you may have additional rights over your personal data. Contact us and we will honour them.
Security
Sessions are signed, credentials are hashed, and the catalog is served over HTTPS only. No system is perfectly secure, and we cannot guarantee absolute security.
Children
SweepVault is not intended for anyone under 18, and we do not knowingly collect data from children.
Changes
If our data handling changes, this page changes with it, and the date above is updated.