Facts and privacy.What it costs, what we store, who else gets a file.
A plain account of how faceswap.ing works, for people deciding whether to upload a photo and for the tools that answer questions about us. Prices, limits and retention periods on this page are read from the same constants the app charges and deletes by.
Checked against the code on Oct 5, 2026.
What it is and what it costs.
faceswap.ing does one thing. It puts a face you supply into a photo or a video, and you pay per swap from a prepaid balance.
| One photo | 5 swapz | $0.05 |
|---|---|---|
| A photo, in a swap of 20 or more | 3 swapz | $0.03 |
| A second of video, up to 480p | 3 swapz | $0.03 |
| A second of video, up to 720p | 4 swapz | $0.04 |
| A second of video, up to 1080p | 6 swapz | $0.06 |
| A second of video, up to 1440p | 9 swapz | $0.09 |
| A second of video, up to 4K | 15 swapz | $0.15 |
What is a swapz?
The unit every price is written in. One swapz sells for $0.01. You buy swapz in packs and each swap spends some. Swapz you buy never expire, and they cannot be turned back into money.
What does a photo cost?
$0.05 for one photo. In a swap of 20 photos or more, every photo is $0.03.
How is video priced?
By the second of footage and by frame size, from $0.03 a second up to 480p to $0.15 a second up to 4K. Those rates hold up to 30 fps, and footage processed at a higher frame rate costs proportionally more. Every video is billed for at least 10 seconds. Options and extra faces add to the price, and the quote shows the total before the swap starts.
What do the packs cost?
There are 5 packs, from $10 to $1,000. Packs from $100 add bonus swapz, up to 15% on the $1,000 pack. No subscription is sold and nothing renews.
Is anything free?
Once. A new account gets 25 swapz when its email address is verified, which covers 5 photos at the single-photo price. The files are the same ones a paying account gets. At most 3 grants a day go to one IP address.
Is there a watermark?
Not unless you ask for one. A watermark exists as an option, it is off by default, and switching it on does not change the price.
What if a swap fails?
The quoted price is held from the balance when a swap starts, and the swap is settled on what actually ran. A file that fails is refunded in swapz, automatically. Refunds are never paid in money.
What can I upload?
Photos as JPG, PNG, WEBP, BMP, HEIC, and HEIF, up to 50 MP and 50 MB. Videos as MP4, MOV, AVI, MKV, and WEBM, up to 1 GB a file. How long a video can run depends on its frame: 5 min up to 1440p and 4 min 30 s up to 4K, at up to 30 fps with no options. One swap takes up to 200 files and 4 GB.
The whole rate card and a calculator are on the pricing page. The refund policy says what comes back and when.
What happens to your files.
They sit in storage we control. Some are on a clock and some are not, and the table says which.
Where are my files stored?
In a Cloudflare R2 bucket that we control. An upload goes from your browser straight to the bucket, and a finished generation is copied there from the swap service.
Who can open a stored file?
Everyone in your team sees the team's uploads, saved faces and generations in the app. A stored file also has a public address on our own domain. That address is not listed anywhere and is built from long generated ids, but it does not ask for a sign-in, so anyone you give it to can open the file until the file is deleted.
What does deleted mean here?
The file is removed from the bucket, and the app stops serving it and will not use it in a swap. The 30-day deletion runs once a day, so files go within about a day of that mark. The swap's record stays and is marked as expired.
Are my uploads used to train a model?
No. Nothing in the app or in the moderation service uses an upload, a face or a generation to train or tune a model. The app stores no face embedding and no biometric template. A saved face is a name and its photos, and each swap sends those photos again.
| What | Kept for | To remove it sooner |
|---|---|---|
| Generations, the results of a swap | 30 days after the swap finishes. | Delete the generation or the whole swap. |
| The photos and videos you swap into | 30 days after the swap that used them finishes. A file that a newer swap or a saved face still uses stays for that. | Delete the generation made from the file. |
| Uploads that no swap points at | No time limit. That is an upload you never used, or one left behind when you deleted a swap whole. | Write to faceswaping@proton.me. |
| Face photos | No time limit. The 30-day deletion does not touch them, whether the face was saved to your library or used once. | Deleting a saved face takes it out of your library and keeps its photos. Write to faceswaping@proton.me to have them erased. |
| A file the automated check refuses | Deleted at once. | Nothing to do. |
| A file the check never answered for | Set aside after about a day, where nothing serves it, until a person decides. No time limit. | Write to faceswaping@proton.me. |
| The record of a swap | Kept after its files are gone: what went in, the options, the cost and how it ended. | Deleting the swap deletes the record. One audit line stays, with the swap's id and who deleted it. |
| The swap service's copy | 24 hours after the swap finishes, unless the service publishes another figure. | Deleting the swap asks the service to drop it. |
Who else receives a file.
A file leaves our storage for two jobs, the swap and the automated check.
Does anyone not in the table below receive my files?
No. The checkout, the email provider and the page-view counter never receive a file. Files are not sold and are not given to anyone for advertising.
Who receives other data about me?
Vercel hosts the app and counts page views. NOWPayments runs the checkout. Resend delivers email, so it receives your address and the message. Google or Discord take part only if you sign in with them. The public support board is run by Featurebase, and what you post there is public.
| Who | What it receives | What it keeps |
|---|---|---|
| Cloudflare R2, the storage | Every upload, face photo and generation. | Each file until it is deleted, as in the table above. |
| The swap service, which runs the model | Links to the face photos, to the photos and videos to swap into and to a lip-sync audio track, with the options you chose. It also reads a file when you ask the studio to list the faces in it. | Its copy and the result for 24 hours after the swap finishes, unless it publishes another figure. |
| The moderation service | A short-lived link to each photo, video and face you upload. A file given to the API by link is passed on as that link. The same service makes a thumbnail when your browser could not, and builds the zip when you download several generations at once. | It has no database and does not keep the file it checks. A zip is stored so that you can download it. |
| The moderation model that the moderation service calls | Each photo, as an image. From a video, 5 to 20 still frames at reduced size. The request carries the image and nothing about your account. | That is governed by its provider's terms, not ours. |
What we know about you.
An account requires an email address and nothing else. This is what gets recorded around it.
- Signing in
- An emailed code or link, a password, a passkey, or a Google or Discord account. A second factor from an authenticator app is optional. Signups from disposable email domains are refused.
- Your account
- Your email address, and your Google or Discord id if you sign in that way. A password is stored as a hash. A username is made from the part of your email before the @, and a display name is optional.
- Each session
- Its IP address, your browser's user agent, and the approximate place the host reports for that address: city, region, country and coordinates. The city, region and country are also recorded once at signup. Your sessions are listed under Settings, Security. The email that reports a sign-in from a new device quotes that IP address.
- IP addresses in rate limits
- Sign-in, sign-up and the signup grant are counted against the IP address itself, and those counters are deleted within 3 days. The report form counts a keyed hash of the address and stores no address.
- Where you came from
- If you arrive from another site or a tagged link, a cookie keeps the referring site's host name, the campaign tags and the page you landed on for 30 days. They are saved with your account at signup. No IP address and no user agent is part of that record.
- Affiliate links
- Following one records a click: the page it led to, your browser's user agent and at most a keyed hash of your IP address, never the address. A click that leads to no signup is deleted after 37 days. One that does is kept.
- Age and consent
- Before your first swap you confirm that you are 18 or older and that everyone whose face you upload is an adult who agreed to it. The date of that confirmation is stored on your account.
- Payments
- For each purchase we keep the pack, the amount in US dollars, the invoice id, its status and the account that paid. Checkout asks for no card number, no billing name and no postal address.
- Page views
- Counted by the host without a cookie: the page path and the referrer. Pages whose address is itself a key, the affiliate portal and invitations, send nothing, and every query parameter except campaign tags is removed first. There is no other tracker and no advertising pixel.
- Logs
- One line for each request, with your account, team and organization ids and what the request did. The line we write holds no IP address, no user agent and no email address.
- Sent through Resend, and only for the account: sign-in codes and links, verification, password resets, invitations, security notices and download links. There is no marketing email.
The cookies we set
- Session
- Keeps you signed in. With several accounts signed in, there is one for each.
- Last sign-in method
- Lets the sign-in page show which method you used last time.
- Sign-in steps
- Short-lived, during a two-factor check, a passkey prompt or a Google or Discord sign-in.
- Language
- Set when the language you are reading in differs from your browser's, so the site opens in it next time.
- First visit, fsw_src
- Holds where you came from, as described above, for 30 days. Deleted at signup.
- Affiliate click, fsw_ref
- Holds the id of the click for 30 days, so a signup can be credited to the affiliate.
- Sidebar
- Remembers whether the app's sidebar is open.
None of the cookies we set is for advertising.
What is refused, and how to report something.
The automated check is narrow. The rules are wider, and a person enforces them.
What does the automated check refuse?
A file flagged for sexual content involving minors, or for self-harm. No other category blocks a file automatically. A refused file is deleted and never reaches a swap.
Is everything else allowed?
No. The content policy requires the consent of every person shown and that everyone shown is an adult. It forbids material meant to harass, deceive or impersonate. A person enforces those rules when something is reported.
How is a file checked?
Every photo, video and face photo you upload is checked before the app serves it or swaps with it. A photo is checked whole. A video is checked on 5 to 20 sampled frames, so what lies between them is not seen. Generations are not checked, and neither is an audio track.
What if the check does not answer?
The file waits. It is not served and cannot be used in a swap. The check is tried again over the following day, and a file it never answers for is set aside for a person to decide. A file given to the API by link is refused outright when it cannot be checked.
What do I have to confirm?
Before your first swap, that you are 18 or older and that everyone whose face you upload is an adult who has agreed to it. A swap launched with an API key needs the same confirmation on the account.
How do I report something?
Use the report form, which needs no account, or write to faceswaping@proton.me with a link. The form takes your name, your email address, the links and what you want to say about them, and it stores no IP address. You get a reference to quote, and a person reads every report.
What happens after a report?
When a report is upheld, a person removes the material from storage and the account is banned, as the content policy describes. Every report is kept, whatever was decided.
The rules are in the content policy. The form is on the report page.
How to delete your data.
What each delete removes and what it leaves. Closing the account is not the step that removes your files.
Can I delete my data myself?
Partly. You can delete generations, swaps and saved faces in the app, and close the account under Settings. Closing the account does not delete files, and face photos and unused uploads have no delete of their own. For those, write to faceswaping@proton.me.
- One generation
- Removes the result and the photo or video it was made from, unless another swap or a saved face still uses that file. It works once the swap has settled, which happens when it finishes.
- A whole swap
- Removes its results and its record, and asks the swap service to drop its copy. The photos and videos you uploaded for it stay in storage. To remove those too, delete the generations one at a time instead.
- A saved face
- Takes the face out of your library. Its record and its photos stay, so that earlier swaps still show which face they used.
- Your account
- Closes the account, ends every session and disables your API keys. It is refused while other people are members of your organization. The account record, with its email address, is kept and marked closed. Files, saved faces and unspent swapz are not deleted with it, and the 30-day deletion keeps running on finished swaps.
- Always kept
- Payment records, the ledger of swapz granted and spent, the audit log, and any report made about your content. They are the record of what was paid for and what was done.
- Everything else
- Write to faceswaping@proton.me for a copy of your data, or to have removed what you cannot remove yourself: face photos, unused uploads, the files of a closed account.
How to pay, and why only crypto.
One hosted invoice, paid once from your own wallet.
How do I pay?
Choose a pack, from $10. The app raises an invoice with NOWPayments and sends you to its page. There you pick a coin and send the amount from your own wallet or exchange account. The swapz are added once the network confirms the transfer.
Why is there no card payment?
With no card form there is no card on file. Nothing can renew, there is nothing to cancel, and we cannot charge you a second time. You see the amount before you send it, and you are the one who sends it.
What does the checkout learn about me?
For a pack, we send NOWPayments the amount in US dollars and an order reference made of the pack's name and a random id. We send no email address and no name. The invoice page is theirs, and what it records about a payment is covered by their own policy.
Can a payment be reversed?
No. A transfer on a blockchain is final, and neither we nor NOWPayments can pull it back. A payment that arrives short is credited in proportion to what arrived.
Who runs it.
Who operates faceswap.ing?
The terms name the operator as Faceswaping (the Company). The legal documents give no postal address, and this page does not add one.
How do I reach a person?
Write to faceswaping@proton.me. Support, abuse reports and requests about your data all arrive in that inbox. There is also a public support board at faceswaping.featurebase.app.
- PricingThe rate card, the packs and a calculator.
- How to payThe checkout, step by step, and what happens when a payment is short or late.
- API referenceThe same swaps from your own code, at the same prices.
- Privacy policyThe same facts as this page, as the document you agree to.
- TermsThe agreement an account accepts.
- Refund policyWhat is refunded, and that refunds are paid in swapz.
- Content policyConsent, age, and what may not be made.
- Report contentThe form for a person whose face or work is in material here.