Effective date: 23 September 2026 · Last updated: 4 October 2026
App: SeatExchange: Courtesy Swap (Android, package com.krishinnovationlabs.seatexchange)
Developer: Krish Innovation Labs
SeatExchange helps passengers on the same train, flight, bus or ferry swap seats by mutual agreement. This policy explains what data we collect, why, which third-party services process it, and how to delete it.
No sign-up. SeatExchange creates an anonymous account ID automatically. We never ask for your name, email address or phone number, and there is no profile.
Other passengers never see who you are. They see a handle like "Passenger #204", the type of seat you have, and what you are looking for. No name, no phone number, no photo.
We do not read your messages or your photos. SeatExchange has no permission to read SMS, your photo gallery or your files, and never requests one. If you want a ticket read, you share, paste or pick that one message, screenshot, photo or PDF yourself. It is read on your phone and discarded.
We never ask for your location. Not once, not optionally. Trip reminders are timed from the travel date and departure time you enter, not from where you are.
Your trip deletes itself roughly two hours after you arrive — automatically, whether or not you ever open the app again.
No advertising and no analytics. There is no ad SDK, no analytics SDK and no crash-reporting SDK in this app.
Anonymous account ID — What exactly: A random ID from Firebase Authentication (anonymous sign-in). Why: So our security rules can tell one device from another. It is never written into anything another passenger can see. Where: Google Firebase.
Trip details — What exactly: Type of vehicle, service number and travel date (e.g. "FLIGHT 6E204, 25 Sep 2026"). Why: Placing you in the right Trip Room, which is how you find the other passengers on your own vehicle. Where: Your phone and Google Firebase (Cloud Firestore).
Your seat — What exactly: Your seat or berth number and, for trains and ferries, your coach or deck. Why: Showing you on the seat map. Other passengers see only the seat type; your exact seat goes only to a passenger you send a swap request to, or whose request you accept. Where: Your phone and Google Firebase. Other passengers cannot see your seat number unless you send them a swap request, or accept theirs.
Your swap preference — What exactly: Which kinds of seat you would move to, and optionally one reason from a fixed list ("travelling with a child", "needs more leg room", …). Why: Matching, and letting the other person judge the request. Where: Google Firebase.
Trip handle — What exactly: A handle like "Passenger #204" and an opaque token, both derived on your phone from a random value that never leaves it, combined with the trip. Why: Identifying you inside one Trip Room. A different trip produces a completely different handle and token, so your trips cannot be linked together. Where: Google Firebase.
Messages — What exactly: The text you send in a swap chat. Why: Arranging the swap. Limited to 240 characters, and phone numbers, email addresses and links are removed automatically before sending. Where: Google Firebase.
Swap passes — What exactly: The seats swapped, the handles involved, and a verification code both phones calculate. Why: Proof that a swap was agreed in person, if crew ask. Where: Your phone only.
Purchases — What exactly: Whether you have Swap Tokens left, and the Google Play purchase token of each purchase. Why: Granting tokens exactly once, and never twice. Where: Your phone. Payment details are handled only by Google Play — we never see them.
Tickets you scan, paste, share or pick (barcode, SMS or email text, screenshot, photo, PDF) — What exactly: Nothing is kept except the trip details listed above. Why: The ticket is read on your phone to fill in the trip form; the image, PDF and text are never saved or uploaded. Where: Nowhere.
Travel country — What exactly: The country you chose, e.g. "India". The first time, the app suggests one from the country code of your mobile network or SIM card, or your phone's language setting. This needs no permission and is not your location. You confirm it or pick another. Why: Setting up the trip form for how tickets are written there (coach and seat labels, seat map, date order). It does not affect prices and is not sent to other passengers. Where: Your phone only.
Departure time (optional) — What exactly: The time your vehicle leaves, if you type it in or your ticket shows it, e.g. "16:35". Why: Timing your trip reminder, about two hours before departure. Where: Your phone only. It is not uploaded and other passengers never see it.
SeatExchange has no analytics SDK, crash-reporting SDK, advertising SDK, social login, contacts access, location access or microphone access. The Google libraries listed in section 7 may send their own technical diagnostics to Google, as described there.
Your name. A boarding-pass barcode contains the passenger's name. Our parser reads past those characters and never returns them, so there is no field in the app that could hold it. Printed tickets and e-tickets show the name too: when you pick a screenshot, photo or PDF, the page is read on your phone, only the service number, date, coach and seat are kept, and the rest of the text, name included, is discarded with the image.
Your messages. SeatExchange does not hold the READ_SMS permission and never will. The ticket parser only ever sees text you deliberately share or paste into it.
Your photos and files. SeatExchange holds no photo, media or storage permission. When you pick a screenshot or PDF, Android's own picker gives the app that one file and nothing else, and the app does not keep a copy.
Your location, or which devices are near you. SeatExchange holds no location, Bluetooth or nearby-Wi-Fi permission, so it cannot tell whether you are at a station or an airport. Two passengers find each other by the coach, deck or cabin and seat number shown once a swap request is accepted, never by where their phones are.
A travel history. Your handle and token are different on every trip, and your trip data is deleted a couple of hours after arrival. There is nothing to build a history from.
If you choose to scan a boarding pass, photograph a ticket or scan a swap code, SeatExchange asks for camera access at that moment. The barcode and the ticket's printed text are read on your device by on-device models (bundled in the app, or provided by Google Play services). A ticket photo is held in memory only while it is read. No image, frame or preview is saved, transmitted or logged. Screenshots and PDF e-tickets you pick or share are read the same way, on your phone, and not kept. You can refuse camera access and use the app fully by picking a screenshot, pasting your booking message or entering your trip details by hand.
Notifications are optional. SeatExchange asks for permission on the Trip Room screen, never at start-up, and you can turn them off at any time in Settings → Notifications or in your phone's settings. The app works fully without them.
If you allow them, SeatExchange shows two kinds:
A trip reminder, about two hours before the departure time you entered, or at 08:00 on your travel day if you didn't enter one. It is scheduled on your phone from your trip details.
Swap request updates: someone asked for your seat, or a passenger accepted or declined your request, or it expired. While you have an active trip, from the day before travel until the trip is deleted, your phone checks your Trip Room about every 30 minutes when it has a network connection, and only if notifications are on. This check reads the same Trip Room data the app shows on screen. It sends nothing new and is never based on your location.
SeatExchange does not use a push-notification service (such as Firebase Cloud Messaging), so no device token is created or sent anywhere. Notifications never contain a seat number or chat text, and a locked phone shows only a generic line. Ending a trip, or Delete my data, cancels every scheduled reminder and check.
Swap Tokens are bought through Google Play's in-app billing. Google Play processes the payment; SeatExchange receives only a purchase token confirming the purchase happened. We never see your card, address or Google account details.
A Swap Token is held in escrow when you send a swap request and is only spent when both passengers confirm the swap in person. If the other passenger declines, or the request expires, the token returns to your wallet automatically. Refunds of money paid to Google Play are handled under Google Play's own refund policy.
New users get two free welcome swaps. To stop them being claimed again by clearing the app's data, SeatExchange keeps a tiny hidden file on your phone, in Download/.seatexchange/, that says only that the welcome swaps were claimed. It contains no identifier and no personal data, never leaves your phone, and you can delete it with any file manager.
Google Firebase (Authentication, Cloud Firestore, App Check) — What it processes: Anonymous ID, trip and swap data listed above. Why: Running Trip Rooms, and keeping modified apps out.
Google Play Integrity (used by App Check) — What it processes: Signals about whether the app and device are genuine. Why: Keeping modified apps and scripts out of Trip Rooms.
Google Play Billing — What it processes: Your purchase. Why: Selling Swap Tokens.
Google ML Kit (barcode scanning and text recognition, runs on your phone) — What it processes: Camera frames, screenshots, photos and PDF pages stay on your phone. The library may send Google technical diagnostics such as device model, app version and performance data, with a per-installation identifier that Google says is not intended to identify you. Why: Reading boarding-pass and swap-code barcodes, and the printed text of tickets.
Google processes this data as our service provider under Google's own privacy terms. We do not sell data, and we do not share it with anyone else.
Every document SeatExchange writes carries an expiry timestamp set to roughly two hours after the end of your travel day, and Google Cloud Firestore deletes it automatically at that time. On your phone, a background task removes the trip, its swap passes and any stale token holds on the same schedule. Nothing about a journey is designed to outlive the journey.
In the app: Settings → Delete my data. This removes your current trip, your offer in the Trip Room, your swap passes, and the random value your handles are derived from — so every future handle is different too.
Uninstalling the app also removes everything stored on your device, apart from the small welcome-swaps file described in section 6, and anything already in the Trip Room expires on its own schedule.
Swap Tokens you have already bought remain associated with your Google Play purchase, not with SeatExchange. To request anything else, email krishinnovationlabs@gmail.com and we will respond within 30 days.
SeatExchange is intended for adults (18 and over) and is not directed at children. It involves arranging to meet another passenger in person aboard a vehicle. We do not knowingly collect data from children; if you believe a child has used the app, email us and we will delete what we can identify.
Data on your phone is stored in app-private storage, protected by Android's file-based encryption. Data in transit uses TLS. Access to Trip Room data is restricted by Cloud Firestore security rules — in particular, another passenger's exact seat number is not sent to your device at all unless they have accepted your swap request. Swap requests can be read only by the two passengers involved.
No system is perfect. If you believe you have found a security problem, please email krishinnovationlabs@gmail.com.
Depending on where you live, you may have the right to access, correct or delete your data, or to object to how it is used. Because SeatExchange holds no name, email or account, most of this is done directly in the app (Settings → Delete my data), and the rest expires on its own. For anything else, email krishinnovationlabs@gmail.com. You can also complain to your local data protection authority.
If this policy changes materially, the effective date above changes and the new version is published at this address before the change takes effect in the app.
Krish Innovation Labs — krishinnovationlabs@gmail.com