Privacy Policy
Last updated
Who runs SwimScript
SwimScript is operated by spinrag, LLC, a limited liability company registered in New York, USA. spinrag, LLC decides what SwimScript does with your information and is responsible for it.
If you are in the EU or the UK, the GDPR or the UK GDPR applies to your information wherever we happen to be.
Questions about anything on this page go to [email protected].
We are reachable at [email protected]. If you need a postal address — for a formal notice, or because your own obligations require one — ask and we will provide it.
What SwimScript stores about you
Only what the application needs in order to work. There is no file storage, no document archive and no copy of anything you upload.
| What we hold | Why we hold it |
|---|---|
| Your email address | Required. It is how your account is identified and how we would reach you. |
| Your name, if your account has one | So teammates see a person rather than an address. Your personal workspace is named after you when you first sign in — from your name if we have one, otherwise from the part of your email address before the @. |
| An identifier for your sign-in account | Issued by Kinde, our sign-in provider, so we can recognise you when you come back. |
| Which teams you belong to, and what you may do in each | So a team's practices are shown to its members and to nobody else. |
| The practices, sets and section headings you write | They are the point of the product. |
| Who wrote each practice, and when it was written or last changed | So a team can tell one coach's work from another's. |
| The date you asked us to delete your account, if you have | So the thirty days described below can be counted, and so the deletion can be undone inside them. |
That is the whole list. There is no phone number, no address, no payment detail, no date of birth and no photograph.
Practice content is free text, and that matters
A practice is whatever you type. There are no restrictions on what may go in it, so if you write a swimmer's name into a set note — "Katie: hold 1:28" — that name is stored, and SwimScript has no way to know it is there or to treat it differently from a stroke or a send-off.
This is a deliberate design decision, not an oversight: a planning tool that rejected the notes a coach actually writes would be useless. But it means you decide what personal information about other people ends up in SwimScript, and it is worth deciding on purpose.
If the person you are about to write about is a child, read Children's data first. Today the answer there is no.
Where the data comes from
Your email address, your name and your team memberships come from Kinde when you sign in.
Everything else you typed, pasted or imported yourself.
Word documents you import
When you drag a .docx practice onto SwimScript, the file is not uploaded. It is opened and read inside your own browser, you are shown what was understood from it, and only the practice text you confirm is sent to us. The document itself never leaves your computer, and no copy of it is kept.
This is worth stating plainly because it is the opposite of what importing usually means.
Trying SwimScript without an account
You can write practices in SwimScript before you have signed up for anything. Those practices are kept in your own browser — the same place a website keeps your preferences — and they are never sent to us. We do not have a copy, and there is nothing for us to look at.
A few things follow from that, and they are worth knowing before you rely on it.
- A small number are kept. Enough to see whether SwimScript reads your practices the way you write them. It is a trial, not a filing cabinet.
- They are on that browser and nowhere else. Not on your phone, not on the pool laptop, and not recoverable by us if the computer is lost.
- Clearing your browsing data clears them. So does a private window closing, and so does some cleanup software. There is no copy anywhere else, so that is final.
- Signing up brings them with you. The first time you sign in, the practices in your browser are moved into your own workspace, and this policy then covers them like anything else you write. They are removed from the browser once they have arrived safely — and only once they have.
Only you can remove these
If you ask us to delete practices you wrote before signing up, we cannot do it — we have never had them. They are on your computer, in your browser, and we can no more reach into it than any other website can.
Clearing this site's data in your browser settings removes them — the same control that clears cookies. Deleting a practice from the page removes it too.
We would rather say this plainly than describe a deletion right we are in no position to honour.
Practices kept on your device for offline reading
A practice is written the night before and read on a pool deck, where the wifi is often bad and sometimes absent. So a copy of each practice you open is kept in your browser, and SwimScript will show and print it when it cannot reach the network.
- It is a copy, never the original. What you write still goes to your account. The copy is only there to be read; it cannot be edited, and nothing you do to it is saved.
- The recent ones. Around twenty practices, oldest dropped first. Enough for a season's worth of deck use, not an archive.
- It is cleared when you sign out, and again if you delete your account. Signing in on a different account clears it too, so one coach's practices do not sit in a browser another coach then uses.
- Anyone with the device can read it. This is the honest limit of storing anything on a computer: while it is there, it is there for whoever holds the machine. If that matters — a shared pool laptop, a borrowed tablet — sign out when you finish, which empties it.
- Clearing your browsing data clears it, the same control that clears cookies. Nothing is lost by doing so; the practices are in your account.
We can see none of this. It is on your device and never sent to us.
Cookies
SwimScript sets two cookies of its own. Both are first-party, both exist to make the application work, and neither is used to track you or to build a profile.
| Cookie | What it is for | How long it lasts |
|---|---|---|
ss_workspace | Remembers which workspace you were last looking at, so a reload does not put you back in a different one. | One year |
ss_return_to | Remembers the page you were trying to reach, so that signing in returns you to it instead of the home page. | Fifteen minutes |
Neither can be read by scripts running in the page, and neither is sent along when you are on somebody else's site.
Practices written before you have an account are also kept in your browser, but not in a cookie — they are stored locally and are never sent to us at all. They are described under Trying SwimScript without an account, and the browser control that clears cookies for this site clears them too.
Kinde sets its own cookies to keep you signed in. Those are Kinde's, described by Kinde's own privacy notice, and SwimScript does not control them.
There is no cookie banner, deliberately. A banner exists to ask permission for the cookies that need it — analytics, advertising, anything that follows you between sites. SwimScript sets none of those. The two above are strictly necessary for the application to function, which is the case where consent is not required, so asking for it would be theatre rather than a choice. The same reasoning covers the practices kept in your browser during a trial: they are there because you asked for a practice to be kept, they go nowhere, and there is nothing to consent to sharing.
Analytics: there are none
SwimScript runs no analytics, no tracking and no advertising. There is no Google Analytics, no Google Tag Manager, no Microsoft Clarity, no Sentry, no PostHog, no Mixpanel, no session recording, no heatmap, no advertising pixel and no third-party script of any kind. The pages load nothing from anyone else's server.
It is a choice rather than an accident, and one we intend to keep. A tool that watches a coach write practices in order to sell what it learned is not the tool we want to build.
Who else can see your data
Two companies, and no others.
- Kinde handles sign-in. It holds your email address, your name and your team memberships, because it is the system that checks who you are. SwimScript never sees or stores your password.
- SendGrid sends the email SwimScript needs to send, handling the address it goes to and the contents of the message. There is one such message today, described below.
Everything else is ours. SwimScript runs on infrastructure spinrag, LLC operates rather than on a cloud provider, so no other company is in the path of a page load or is handed anything in the course of using the application.
The backups are the exception, and are kept off our own hardware on purpose — a copy that burns with the original is not a backup. They sit with a storage provider, encrypted, holding the files and reading nothing from them.
There is no analytics provider, no advertising network, no customer support tool, no CRM and no AI service in the path. Your practices are not used to train anything.
Your data is held on servers in New York State, in the United States, on hardware spinrag, LLC operates itself rather than renting from a cloud provider.
If you are in the UK or the European Economic Area, that means your data is transferred to and stored in the United States.
Who can see your practices inside SwimScript
Practices belong to a workspace. Your personal workspace is yours alone. Everyone in a team workspace can see everything in that workspace, and coaches and admins there can change it.
A practice stays in the workspace it was written in. When copying one into a team arrives it will copy rather than move, so your original stays yours either way.
When someone deletes their account, the practices they wrote in a team stay with the team — a squad should not lose next week's sessions because a coach moved on — and their name is cleared from them, so a person who has left is no longer recorded as the author. This is how it behaves today.
If they were a team's last admin, admin passes to the longest-standing member left behind, so nobody is locked out of a workspace they are still using. If nobody at all is left, the team and its practices are kept exactly as they are rather than deleted, and the next member of that team to sign in picks it up again.
How long it is kept
For as long as your account exists, and then thirty days. Nothing expires on a timer while you are using it and nothing is archived elsewhere.
Deleting a practice deletes it. It is removed rather than hidden, and its sections and sets go with it.
Deleting your account is described in the next section. The short version is that the thirty days are a window in which a mistake can be undone, not a period in which we keep using anything.
The database is backed up, and a backup is a copy. Deleting something removes it from SwimScript at once, and from every backup made afterwards — but a backup taken while it existed still holds it, and is not edited after the fact.
We keep them until they age out. Today there is no expiry set, so a deleted practice can persist in a backup indefinitely; we are setting that to thirty days to match the deletion window below, and this page will say when it is.
Server logs record the ordinary mechanics of serving a page — a request, its outcome, and when. They are not used to build any picture of you, and they hold no practice content.
Getting your data out, or getting rid of it
Both are buttons. They are on the Your data page, reached from the account menu at the top right, and neither needs a request to us.
Taking your practices with you
Download my data gives you a zip file containing:
- one markdown file per practice — the same notation SwimScript reads, so a file pastes straight back into the app, and it is plain text, so any editor opens it;
practices.json, the same practices structured for a machine, with sets, intervals, equipment and totals broken out;account.json, with your email address, your name and the workspaces you belong to.
It holds everything in your own personal workspace and everything you wrote in a team. It does not hold practices other people wrote in a team you belong to — those belong to the team, not to you.
Deleting your account
Delete your account does all of this the moment you confirm it:
- you are signed out, and cannot sign in again;
- you leave every team you belonged to;
- the practices you wrote in a team stay with the team, with your name taken off them;
- if you were a team's last admin, admin passes to the longest-standing member left, and a team with nobody left is kept rather than deleted;
- your own personal workspace and every practice in it are held for thirty days.
Thirty days later, the account and your personal workspace are deleted permanently — the practices, their sections, their sets, the section names you taught it, and the account record itself. Nothing is archived, and nothing is kept back for our own use.
The exception is the backups described above. The live database forgets you on the thirtieth day; a backup taken before then forgets you as it ages out.
Until that date it can be undone. Email [email protected] and we will put it back. After it there is nothing left to put back, and we will not be able to help.
The window exists for exactly one reason: a mis-click should not cost a coach four years of practices. Everything that anybody else can observe happens immediately; the only thing the thirty days hold is the part nobody but you could see.
Practices you wrote before signing up are not covered by any of this, and never were: they are in your browser rather than with us, so they are not ours to delete. Clearing your site data removes them. See Trying SwimScript without an account.
The offline copies described under Practices kept on your device are different: those are copies of your account's practices, and deleting your account clears them from the browser you confirmed it in. A browser you have not signed out of since is one we cannot reach — clearing that site's data removes them.
When somebody adds you to a team
An administrator of a team can add you to it by typing your email address. If you have never used SwimScript, an account is created for you and we email you to say so — who added you, which team, and how to sign in. The message goes through SendGrid, named above.
Your address is held from that moment, because it is now an account. It is the same address the administrator already had, and the mail names them, so you can tell where it came from. Reply to it and we will take you out of the team and remove the account.
We send nothing else. There is no mailing list to be on, no newsletter, and no second message if you do not sign in.
Your sign-in account is a separate account
Signing in is handled by Kinde, and the account there is not the same account as this one. Deleting your account here removes everything SwimScript holds. The sign-in account is separate, and comes out on request rather than along with it — it is still standing after you delete here. Ask us at [email protected] and we will remove it by hand.
The deletion page says which of the two applies before you confirm, so what happens to each is on the screen in front of you rather than only here.
Both of those reach a person rather than a button, so: we answer within two business days. That covers undoing a deletion inside the thirty days, and removing the sign-in account at Kinde.
Children's data
SwimScript is intended to support teams that include swimmers under 18. Age-group clubs and school teams are most of competitive swimming, and a planning tool that cannot be used for them is not much of a planning tool.
You must be 13 or over to hold an account. Under 13 is a hard line, because the law that protects children that age requires a parent's consent that SwimScript has no way to ask for. Between 13 and 18 you are welcome: a swimmer writing their own sets and a seventeen-year-old assistant coach are both real people in this sport, and there was never a reason to bar them.
We do not verify your age. Nothing asks it and nothing checks it, so the rule is a condition of use rather than something the software enforces — and this page will not claim otherwise. If we learn an account belongs to someone under 13 we will close it and delete what is held, rather than wait to be asked.
Do not use SwimScript to store information about anyone else under 18 — not in a practice, not in a set note, not anywhere.
That rule is absolute rather than cautious, and you are owed the reason: protecting a child's data properly takes a way to obtain a parent's consent before anything is stored, a way for that parent to see and delete what is held, and a notice written for parents rather than for coaches. SwimScript has none of the three, so it does not accept the responsibility that comes with holding the data.
It is about who a practice is about, not who wrote it. Your own practices are your own, whatever age you are; the restriction exists to protect somebody who never signed up and cannot speak for themselves.
This page makes no claim to meet COPPA, the GDPR or any other rule protecting children, and the restriction above is how it stays out of their way. If that ever changes, this section is rewritten and you are told, as described under Changes to this policy.
Security
A workspace's practices are shown only to the people who belong to it, and that boundary is checked automatically on every change we make. Sign-in is handled by Kinde; SwimScript never handles your password.
No system is perfectly secure, and this page does not claim otherwise.
Changes to this policy
The date at the top of this page is the date it last changed.
If we change something material — what we collect, who we share it with, what we do with it — we will email the address on your account as well as changing that date. Small corrections, like a clearer sentence or a fixed typo, get the date only.
Account email is being set up as this is written, so until it works a material change will be announced on this page rather than sent to you.
Contact
Privacy questions, requests about your data, and anything else on this page: [email protected].