NoiseOff / Privacy

Privacy Policy

How NoiseOff connects social accounts, uses privacy-masked AI screening, applies on-device policy, and protects your private workflow.

Company
SW Cosmos Inc.
Last updated
August 28, 2026
Support
info@swcosmos.com
01

About This Policy

NoiseOff is provided by SW Cosmos Inc. This Privacy Policy explains how the NoiseOff iOS app processes information when you connect a supported social platform, import comments or replies, choose protection settings, take an explicit moderation action, create an evidence export, delete stored items, or contact support.

Contact: info@swcosmos.com

02

Supported Connections And Authorization

NoiseOff uses official authorization and API flows for Instagram, Threads, YouTube, and Facebook. Instagram requires a Business or Creator account. Facebook requires an eligible Page and the Page access assigned by Meta. YouTube requires a Google account with an accessible YouTube channel. Available read and moderation capabilities depend on the permissions, roles, and review status granted by each provider.

You choose the provider account and approve the requested access on the provider’s own authorization screen. NoiseOff does not receive your provider password. Provider access and refresh tokens are encrypted server-side and are not returned to the app after the authorization exchange.

03

Information NoiseOff Processes

Installation and settings data: an anonymous, installation-scoped Supabase account identifier; your protection profile and blocked terms; notification and retention preferences; app language; and the state needed to synchronize your private NoiseOff session.

Connection data: the connected platform, provider account or Page label, a protected or pseudonymous provider account identifier, granted permissions, connection and token-expiry state, sync timestamps, and limited error status needed to operate and secure the connector.

Comment and moderation data: text and source fields returned by the official platform API, provider timestamps, source identifiers and links when available, the moderation safety envelope and final on-device classification, your classification override or evidence-hold choice, and the status of an explicit hide or restore request. NoiseOff does not automatically publish replies or delete source comments.

04

How Comments Are Protected

SW Cosmos server functions fetch authorized comments or replies only to deliver the requested import. Plaintext comment content passes through those functions transiently and is not written to the NoiseOff database by the import function.

Before AI screening, NoiseOff makes a best-effort attempt to replace common identifiers—including recognizable email addresses, phone numbers, payment-card numbers, government identifiers, IP addresses, URLs, social handles, and common Korean or English address patterns—with placeholders. Masking reduces exposure but cannot guarantee that every identifier or contextual clue is removed.

The masked text is sent to OpenAI’s moderation API to obtain a safety signal for app functionality. OpenAI does not receive the original unmasked comment from this NoiseOff moderation request. The result returned to NoiseOff is a versioned envelope containing hashes, category scores, flags, and limited masking metadata—not the original or masked text. NoiseOff does not write either text form to its application logs or plaintext database fields.

Your iPhone verifies that the returned envelope is bound to the exact captured comment, combines the safety signal with local rules and your settings, and makes the final display decision on the device. A remote result cannot downgrade a local threat, privacy-risk, or blocked-term decision. If AI screening is unavailable, incomplete, or invalid, NoiseOff falls back to its fail-closed local policy.

Before cloud synchronization, the app encrypts each original, available source reference, and safety signal on the device with AES-256-GCM. The key is stored as this-device-only Keychain data and is not designed for cross-device recovery. Supabase receives ciphertext plus limited unencrypted routing fields such as the platform, record identifier, timestamps, expiry, and explicit user state. The server cannot use the device-only key to decrypt those originals.

05

Storage And Retention

You can select a seven-day, thirty-day, ninety-day, or until-deleted retention setting in the app. An earlier deletion request, an item’s applicable platform rule, or a shorter provider requirement takes priority. Expired records stop appearing and are removed through the app’s cleanup and synchronization process rather than being promised for deletion at an exact minute.

A Threads record placed on an evidence hold may remain until you remove it. Instagram and Facebook records follow the selected retention period. YouTube API data, including evidence records, is deleted no later than 30 days after collection even when you select a longer or until-deleted setting.

Connection records and encrypted provider credentials remain while the connection is active. Disconnecting removes NoiseOff’s stored credential and stops future imports. YouTube disconnect also asks Google to revoke the credential. For Facebook, NoiseOff removes its encrypted Page token, but Meta may keep the account-level app permission until you remove NoiseOff in Facebook Settings → Apps and Websites. You can separately verify or revoke NoiseOff in every provider’s own account-permission settings.

After full account deletion completes, NoiseOff may retain an identifier-free completion receipt for up to 60 days. That receipt contains a one-way HMAC of a random deletion token and completion timestamps, but no NoiseOff authentication UUID or provider identifier. If deletion is interrupted and must be retried, a protected retry receipt may temporarily retain the anonymous Supabase authentication UUID, the token HMAC, status, and timestamps for up to 60 days so the same deletion can safely finish. These receipts are not used for advertising, analytics, or tracking.

06

Evidence Exports

When you deliberately create an evidence bundle, NoiseOff may include the captured content, available source metadata, classification and moderation context, rendered files, and integrity hashes. Export files are plaintext outside the encrypted NoiseOff store and are protected by the destination, account, or person you choose to share them with.

An evidence export is a NoiseOff-generated record, not a provider webpage screenshot, certified forensic image, or guarantee that every provider field was available. It is not legal advice and is not certified legal evidence. Preserve provider originals when possible and consult a qualified professional when needed.

07

Service Providers And International Processing

SW Cosmos uses Supabase for anonymous authentication, database storage, and server functions; OpenAI to process masked comment text and return a moderation safety signal; Meta services for Instagram, Threads, and Facebook authorization and APIs; Google services for YouTube authorization and APIs; and Apple platform security and sharing features used by the iOS app. These providers process information as needed to provide their services under their applicable terms, privacy controls, contracts, and production account configuration.

NoiseOff uses OpenAI moderation for app functionality, not advertising or NoiseOff analytics. We do not promise a particular OpenAI retention period here because applicable handling can depend on the service terms and production configuration in effect. Masked text may still constitute personal information or user content under applicable law, so this Policy does not treat masking as guaranteed anonymization.

Information may be processed in the United States and other locations where these providers operate. Server secrets and provider credentials are not bundled in the app.

08

Ads, Analytics, And Tracking

The NoiseOff iOS app contains no advertising SDK, does not track you across other companies’ apps or websites, does not sell personal information, and does not send comment content to analytics, crash reporting, or support systems.

The public SW Cosmos website uses Google Analytics to understand aggregate page visits and site performance. The website may process browser, device, page, approximate-region, and cookie or similar identifier information under Google’s applicable controls. This website analytics is separate from the NoiseOff iOS app.

09

Your Choices And Deletion

You can decline a platform connection, withhold optional management permission, change protection and retention settings, disconnect each platform, or revoke access in the provider’s settings.

NoiseOff uses an anonymous installation-scoped cloud session rather than a named NoiseOff login. To delete the full NoiseOff account, open Settings → Privacy & Storage → Delete NoiseOff account. After you confirm, NoiseOff requests revocation of connected-provider access, removes the associated stored credentials—including its encrypted Facebook Page token—deletes NoiseOff cloud records, hard-deletes the anonymous authentication account, and purges local imported records, settings, pending synchronization data, provider sessions held by the app, temporary evidence files, and the device-only encryption key. Meta may keep Facebook’s account-level app permission until you remove NoiseOff in Facebook Settings → Apps and Websites. If a provider or network step cannot be confirmed, NoiseOff keeps the deletion in a restricted retry state rather than reporting false completion.

Full NoiseOff account deletion does not delete posts, replies, comments, profiles, Pages, channels, or accounts that remain on a source platform. Evidence files that you previously exported or shared are outside the NoiseOff app and cloud store and are not removed; delete those copies from every destination yourself. Deleting the app without using the in-app deletion control may not revoke provider access or remove server-side data.

10

Security, Changes, And Contact

NoiseOff uses encrypted network connections, owner-scoped access controls, encrypted server-side provider credentials, device-only content encryption keys, and limited server secrets. No storage or transmission system can be guaranteed completely secure.

We may update this policy as NoiseOff, provider requirements, or legal obligations change. The updated version will show a new effective date. Privacy questions, access requests, and verified deletion requests may be sent to info@swcosmos.com.