Privacy and security

Where your keys, requirements and generated code live, and what leaves the device.


rdn-swarm is built so that your work stays yours. There is no rdn-swarm account and no rdn-swarm server in the path of your runs. This page lists exactly what is stored, where, and what leaves your phone. The Privacy Policy is the formal version.

What's stored on your phone#

API keys
Encrypted on the device. On Android: AES-256-GCM under a master key in the hardware-backed Android Keystore, which can't be extracted. On iPhone: device-only items in the system Keychain.
Requirements docs
Your doc library, stored locally.
Runs
Generated files, screenshots, the event log, scorecards, notes and the per-call token ledger, in a local database.
Settings
Role and model assignments, scorecard settings, catalog overrides, theme.

What leaves your phone#

  1. Requests to the AI providers you assigned. Your requirements, the code under review and screenshots (in Visual or Interactive QA mode) go directly to that provider, with your key as the authorization. Each provider's own terms and privacy policy apply to that data.
  2. The model catalog download. At launch and when you sync the catalog, the app downloads public price files from swarm.reidell.net/prices. This is a plain download: it sends no key, no run data and nothing that identifies you.
  3. Ads. Unless you buy Remove ads, the app shows ads from Google AdMob. The ads software talks to Google directly and sends what ads need: approximate location from your IP address, device identifiers (the advertising ID on Android) and ad interactions. It has no access to your keys, requirements, code or runs. See the Privacy Policy for details and your choices.
  4. Anything you choose to share, such as exporting a run zip or a requirements .md file to another app.

That's all. There is no analytics SDK and no account.

Keys#

  • A key is used only in the authorization header of requests to that provider's API.
  • Keys are never written to logs. The app's network logging redacts every key-bearing header.
  • The app refuses a key containing characters that aren't valid in a request header, such as spaces or invisible characters picked up when copying, rather than risk it appearing in an error message.
  • Remove a key from its provider page in Settings with Remove key from this device. Uninstalling the app also removes all keys.

Backups#

The app is excluded from cloud backup. On Android, Auto Backup is disabled, and the encrypted keys couldn't be decrypted on another device anyway. On iPhone, keys are device-only Keychain items and the run database is excluded from iCloud backup. If you lose or reset your phone, your runs go with it, so export any run you want to keep. See Export formats.

Running generated apps#

App Preview, Visual QA and the acceptance-test runner load the generated app in a sandboxed web view. It is served from a private in-app address. It can't read your phone's files, can't open other apps' content, and can't open new windows by itself. Generated code is still code you didn't write: review it before you publish or deploy it anywhere.

Deleting data#

  • A run: History → tap the run → Delete run. This removes the run's files, screenshots, log, notes and stats from the phone.
  • A requirements doc: open the doc library on the Requirements tab and tap the trash icon.
  • Everything: uninstall the app.