SWFLJOHN
Privacy Policy
This policy explains what information SWFLJOHN handles when you browse its public pages, connect an optional service, publish a numbered inventory, or configure an approved tool.
- Effective
- August 27, 2026
- Last updated
- September 1, 2026
1. Scope
This policy applies to swfljohn.com, including its public Pokémon GO event calendar, GPX downloads, numbered public inventory, optional Discord sign-in and alerts, and optional TikTok tools.
You can browse the public Events and Trade pages without signing in or creating a SWFLJOHN account.
2. Information we handle
Public browsing and technical data
When you request a page, Cloudflare may process standard network and security information such as an IP address, browser and device information, requested URL, timestamps, and security signals. SWFLJOHN does not use advertising cookies, advertising pixels, or cross-site behavioral advertising.
Discord sign-in
If you choose Discord sign-in, SWFLJOHN requests Discord’s identify permission only. The site may receive and retain your Discord user ID, username, display name, and avatar identifier to verify your access and show your approved tools. It does not request your Discord password, email address, messages, friends list, or payment information.
TikTok connection, drafts, and direct posts
If you choose to connect TikTok, SWFLJOHN may receive a TikTok account identifier, basic profile information, access and refresh tokens, granted permissions, and upload or publishing status. The site uses this information only to connect the account, show its connection status, and send media you select to TikTok as a draft or direct post. TikTok tokens are encrypted, are not displayed publicly, and are retained only while needed to provide the connection.
Media, file names, file size, captions, privacy selection, interaction settings, commercial-content choices, AI-content choice, publishing identifier, status, and error details may be temporarily stored and transmitted to TikTok. A draft still requires the additional action TikTok requests; a direct post is submitted for publication after you review the choices and expressly confirm the post.
Notification preferences
If you configure event notifications, the site may store your selected time zone, event categories, schedules, optional location and radius, Discord role ID, delivery history, versioned consent record, direct-message channel identifier, and Discord webhook destination. The consent record includes the wording version and first and latest confirmation times. Webhook URLs are encrypted before storage. A direct-message or self-service server-channel subscription can be paused or deleted from the alert settings page.
Numbered public inventory
When the operator deliberately publishes an account, the site assigns it a persistent public number that is stored separately from the private account label. The public page may display the inventory snapshot time, level, XP, Stardust, coin balance, Pokémon and bag usage or capacity, and selected Pokémon attributes needed for the inventory. The public response does not include the private account label, Pokémon nicknames, Favorite status, exact caught time, or caught origin.
A persistent number and a distinctive collection are pseudonymous, not guaranteed anonymous. Someone who already knows other facts about an account may be able to recognize it. Unpublished accounts are not available through the public inventory API.
Browser preferences
The Events and Trade pages may remember selected filters, search text, calendar month, date, and display preferences in your browser’s local storage. Approved private dashboards may also remember selected tools and account labels on the administrator’s own device. These preferences stay on that device until replaced or browser data is cleared.
Trade memberships
If a password-protected Trade membership is issued to you, the site stores its username, display label, visibility permissions, and a salted password hash. The original Trade password is not stored in readable form.
3. How information is used
- Provide the public event calendar, GPX downloads, and deliberately published numbered inventory.
- Authenticate approved Discord users and enforce their feature permissions.
- Deliver requested Discord event notifications, including direct messages you explicitly opt into, and test notification destinations.
- Remember notification preferences, consent evidence, permitted Trade views, and publication choices.
- Protect the site, rate-limit sign-in attempts, diagnose errors, and prevent abuse.
- Monitor reliability and improve the site.
SWFLJOHN does not sell or rent personal information and does not use it for targeted advertising.
4. What is public
Event information, venue coordinates, GPX routes, and deliberately published Trade inventory are available without sign-in. A numbered account page can include its persistent public number, snapshot time, level, XP, Stardust, coin balance, storage usage, bag usage, and selected Pokémon details such as species, form, CP, IVs, level, moves, Shiny, Lucky, Shadow or Purified status, costume, background, size, Dynamax or Gigantamax status, buddy level, and traded status.
The private account label, Discord identity, Pokémon nickname, Favorite flag, exact caught timestamp, and caught origin are not intentionally included in the public inventory response. Public inventory is pseudonymous and should not be treated as impossible to recognize.
Discord profiles, notification settings, direct-message channel identifiers, webhook destinations, private membership settings, and sign-in information are not intentionally published. A direct message is visible to its recipient; information sent to a webhook becomes visible in its destination Discord channel according to that server’s and channel’s permissions.
5. Service providers and disclosures
Information is shared only as needed to operate a feature you request:
- Cloudflare provides hosting, network security, storage, database services, and operational logging.
- Discord provides optional identity authentication and receives notifications sent by the SWFLJOHN bot or to webhook destinations you configure.
- TikTok provides optional identity authorization and receives media and metadata you choose to upload as a draft or direct post.
The site may disclose information when reasonably necessary to comply with law, protect users or the service, investigate abuse, or enforce access restrictions. Some public event and Pokémon images are loaded from the published source or image host; those hosts receive normal network request information. External links and map or deep-link providers have their own privacy practices and receive information when you choose to open their services. See Sources & Notices for the principal public data and artwork sources.
6. Cookies and sessions
SWFLJOHN uses essential, secure, HTTP-only cookies for sign-in, connected-service authorization, and request protection:
- The Discord OAuth state cookie lasts up to 10 minutes and helps prevent forged sign-in callbacks.
- A TikTok OAuth state cookie may be used briefly to prevent forged connection callbacks.
- The Discord session cookie lasts up to 7 days.
- A password-protected Trade membership session, when used, lasts up to 7 days.
- An approved administrator recovery session lasts up to 1 hour.
Signing out clears the applicable SWFLJOHN session cookie. Cloudflare may set strictly necessary security cookies when required to protect or deliver the site.
7. Retention
SWFLJOHN uses the following operational retention periods unless a longer period is reasonably necessary for security, a dispute, or law:
- Completed or terminal Discord direct-message and server-webhook delivery records: generally 90 days after completion, then removed in bounded maintenance batches. Unresolved delivery records may remain until resolved, and a maintenance backlog may extend removal.
- Notification settings, encrypted webhook destination, and consent evidence: until the subscription is deleted or no longer needed. A short-lived rate-limit record may remain until its cooldown expires.
- TikTok connection tokens: until disconnect, revocation, or refresh-token expiry. TikTok upload and publishing history: up to 90 days. Disconnect removes the local connection and local upload history; it does not delete content already sent to TikTok.
- Numbered inventory: the latest private snapshot may remain while the account is managed. Public access ends when publication is disabled; the private operational snapshot may remain available only to approved administrators.
- Private administrative command history: terminal entries are subject to a 30-day and 200-row retention target when command state is maintained; active work is retained until it reaches a terminal state.
- Sessions and browser preferences: for the periods in Section 6 or until you sign out or clear browser data.
Cloudflare, Discord, TikTok, linked sources, and device backups may apply their own limited security or backup retention. SWFLJOHN uses the retention targets above and removes or de-identifies records when they are no longer needed.
8. Security
The site uses HTTPS, signed and secure session cookies, access controls, encrypted Discord webhook and TikTok token storage, salted password hashes, bounded request sizes, rate limits, and private-by-default publication settings. No online service can guarantee absolute security. Do not share passwords or webhook URLs with anyone who should not control the associated membership or Discord channel.
9. Your choices
- Use the public Events and Trade pages without signing in.
- Decline Discord authorization or sign out at any time.
- Remove SWFLJOHN from your Discord authorized-app settings.
- Disconnect TikTok through SWFLJOHN or remove SWFLJOHN from your TikTok authorized-app settings.
- Pause or delete a direct-message subscription or self-service Discord server webhook from the Discord Alerts page.
- Ask the administrator to disable a numbered public inventory page or correct its displayed information.
- Ask the SWFLJOHN administrator to correct or delete your access profile, notification preferences, webhook settings, or other information associated with your Discord ID, subject to security or legal retention needs.
10. Children
SWFLJOHN’s signed-in tools are not directed to anyone under 13 or below the minimum age required in their country. The site does not knowingly collect personal information from a child below that age. A parent or guardian who believes a child submitted personal information should contact the administrator so it can be reviewed and removed where appropriate.
11. Third-party policies
12. Contact and requests
To ask a privacy or security question or request access, correction, unpublication, or deletion of user-facing service information, contact the SWFLJOHN administrator through the Discord community, channel, or direct communication through which you received access. Direct-message and server-channel subscriptions can also be deleted from Discord Alerts. Include enough information to identify the relevant profile or public number, but never send a password or webhook secret.
13. Changes to this policy
This policy may be updated when the site’s public features, providers, or data practices change. The current version will remain available at this URL with a revised “Last updated” date.