SwiftsAI Privacy Policy

Last updated: May 8, 2026

This Privacy Policy explains how SwiftsAI ("SwiftsAI", "we", "us" or "our") collects, uses, shares and protects personal data in connection with the SwiftsAI social-media scheduling, publishing, analytics and team-collaboration platform (the "Service"), the websites at ai.appswifts.com and related sub-domains (the "Site"). It applies to visitors to the Site, account holders, members of customer workspaces, prospects, and anyone else who interacts with us. By using the Site or the Service you acknowledge this Policy. For our contractual terms, see our Terms of Service.

1. Who We Are (Data Controller)

SwiftsAI is operated by AppSwifts, the entity responsible for data collection and processing. For all privacy questions, requests and complaints you can reach us at support@appswifts.com.

2. The Service in Brief

SwiftsAI lets you connect 30+ social-media and chat channels and centrally schedule, publish, analyse and collaborate on content. The platform includes a calendar and scheduling engine, a media library, a publishing queue, analytics, AI-assisted content generation, team and workspace management, and integrations with third-party platforms. Some features depend on your plan and on the platforms you choose to connect.

3. Data We Collect

3.1 Account & Identity Data

  • Name, email address, password (stored as a salted hash), profile picture, organisation name, role, language and timezone preferences.
  • If you sign in via a social-login provider (e.g. Google), the basic profile fields and email returned by that provider.
  • Workspace and team membership, invitations sent and accepted, and the permissions granted within a workspace.

3.2 Connected Platform Data

When you connect a third-party social or messaging account to SwiftsAI we receive and store, via that platform's API:

  • OAuth access & refresh tokens (encrypted at rest), the scopes you granted, the platform username and identifier, and account-level metadata (e.g. profile picture, follower counts, page IDs, channel IDs).
  • Content and engagement data needed to provide the Service: posts you create or schedule, posts already published, comments, replies, post-level analytics (impressions, clicks, reach, video retention, etc.), and audience-level aggregates the platform exposes.
  • For YouTube specifically, the Service uses YouTube API Services. Your use of those features is also subject to the YouTube Terms of Service and the Google Privacy Policy. You can revoke SwiftsAI's access to your Google data at any time at Google Security Settings.

3.3 Content You Upload

Text, images, video, audio, captions, links, hashtags, schedules, prompts, comments, approval notes, calendar metadata and any other content you upload to or generate within the Service.

3.4 Billing Data

Plan, subscription status, invoice history, billing email, billing address and tax identifiers. Card details and bank-account details are collected and stored directly by our payment processors (e.g. Stripe); SwiftsAI only receives a tokenised reference, the last four digits, the brand, and the expiry month/year.

3.5 Logs, Usage & Device Data

  • IP address, user-agent, browser type and version, operating system, device identifiers, referrer URL, language preference, approximate location derived from IP (country/region).
  • Application telemetry: pages visited, features used, posts created/published/failed, API calls made, error reports, performance metrics, and crash data.
  • Session and authentication data, including login timestamps, session tokens and security events (e.g. password changes).

3.6 Communications & Support Data

Messages you send to us by email, in-app chat, via support tickets or via our community channels; surveys, feedback and feature requests.

3.7 Cookies & Similar Technologies

We use cookies, local storage, pixels and SDKs for authentication, security, preferences, analytics and (on the Site) marketing attribution. You can manage non-essential cookies through your browser settings; disabling strictly-necessary cookies will break parts of the Service.

4. How We Use the Data & Legal Bases

  • Provide the Service — authenticate users, create and manage your account and workspaces, store and publish your content to connected platforms, return analytics, and provide customer support. (Performance of contract.)
  • Bill and collect payment — issue invoices, manage subscriptions, prevent payment fraud, comply with tax law. (Performance of contract; legal obligation.)
  • Secure the Service — detect and prevent abuse, fraud, account takeover, brute-force attacks, spam and infrastructure attacks. (Legitimate interests.)
  • Operate, maintain and improve the Service — debug, monitor uptime, measure performance, A/B-test features, build aggregated usage analytics. (Legitimate interests.)
  • Communicate with you — send service-related messages (receipts, security alerts, post-failure notices) and, where you have opted in, marketing communications. (Performance of contract; consent.)
  • Comply with law — respond to lawful requests, enforce our rights, defend claims. (Legal obligation.)

We do not use the content of your scheduled posts, your connected-platform content, or your private messages to send you advertising, and we do not sell that data.

5. AI-Assisted Features

SwiftsAI offers optional AI features that generate or rewrite captions, hashtags, image prompts, video scripts and analytics summaries. To provide them we transmit your prompts and the inputs you choose to include to third-party model providers (for example OpenAI and similar) acting as our sub-processors. We instruct those providers not to use your inputs or outputs to train their models. AI outputs are generated probabilistically and may be inaccurate; you remain responsible for reviewing them before publishing.

6. Who We Share Data With

We do not sell personal data and we do not rent it to third parties. We share data only with:

  • Sub-processors and infrastructure providers — including cloud hosting, CDN, database providers, error-monitoring, customer-support platforms, email providers, payment processors and AI-model providers.
  • Connected third-party platforms — when you schedule or publish content, we transmit it to the platform you selected.
  • Other members of your workspace — content, schedules, comments and approval activity are visible to the other people in your workspaces.
  • Professional advisors — accountants, auditors, lawyers, under confidentiality.
  • Authorities — when legally required to disclose data.
  • Successor entities — in the event of a merger, acquisition, or sale of assets.

7. International Data Transfers

SwiftsAI uses sub-processors in various jurisdictions. Where personal data subject to the GDPR or UK GDPR is transferred to a country without an adequacy decision, we rely on the European Commission Standard Contractual Clauses, supplemented by encryption in transit and at rest and access controls.

8. Data Retention

  • Account data — kept while your account is active. After closure, retained for up to 90 days, then deleted or anonymised.
  • OAuth tokens — kept while the connection is active; revoked tokens are deleted promptly.
  • Billing records — retained for the period required by tax law (typically 7 years).
  • Logs — operational and security logs are typically retained for up to 12 months.
  • Backups — encrypted backups roll off within 30–90 days after deletion from the live system.

9. Security

We maintain administrative, technical and physical safeguards designed to protect personal data. These include: encryption of data in transit (TLS) and of sensitive data at rest; encryption of OAuth tokens; password hashing with a modern algorithm; role-based access controls; audit logging; and incident-response procedures. No system is fully secure, and we cannot guarantee absolute security.

10. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and receive a copy in a portable format;
  • Request correction of inaccurate or incomplete data;
  • Request deletion of your data, subject to retention obligations;
  • Object to or restrict certain processing, including direct marketing;
  • Withdraw consent where processing is based on consent;
  • Lodge a complaint with your supervisory authority.

To exercise your rights, email support@appswifts.com. We will respond within the timeframe required by applicable law (typically 30 days).

11. Children

The Service and the Site are intended for business use and are not directed to children. We do not knowingly collect personal data from children under the age of 18.

12. Marketing & Cookie Choices

You can unsubscribe from marketing emails at any time using the unsubscribe link in any such email. You can manage cookie preferences via your browser settings.

13. Third-Party Sites and Services

The Site and the Service link to and integrate with third-party services. Their handling of your data is governed by their own privacy policies, not this one.

14. Changes to this Policy

We may update this Privacy Policy from time to time. If a change is material we will provide reasonable notice (for example by email or in-product notice) before it takes effect.

15. Contact Us

For privacy questions, requests, or complaints, email support@appswifts.com.