Privacy Policy
Last updated: August 5, 2026
The short version
- Your workspace data is yours. We never sell it, and it is never used to train public AI models.
- Each workspace is isolated. Your content, contacts and connected accounts are not pooled with anyone else's.
- We use AI providers under contract to generate and check content. They are bound by no-training terms.
- We only set cookies that are strictly necessary to keep you signed in. There is no advertising or analytics tracking on this site.
- You can export your data or ask us to erase your account at any time — see Your rights.
This summary is for orientation only. The sections below are the policy.
1. Who we are, and which role we are in
Be More Swan provides AI assistants that plan, draft, review and publish work on behalf of small businesses. We are based in the United Kingdom. You can reach us about anything in this policy at privacy@bemoreswan.com.
Our role under UK GDPR depends on the data:
- For the business data you put into your workspace — your content, your brand material, your contacts and leads, and the data we read from accounts you connect — we are a data processor, handling it on your instructions. You are the controller of that data, and our Data Processing Agreement governs it. You accept the DPA when you set up your organisation, and can review it in Settings → My Agreements.
- For your account, login, billing and support data, and for operating, securing and improving the platform itself, we are a data controller.
Where we act as processor, the customer whose workspace holds your data is the first place to direct a request. We will help them respond, and we will tell you who they are if you ask us.
2. What we collect
Account and identity
Your name, email address, a hashed password, your organisation and job details, your role and team memberships, invitations you send or accept, and your record of accepting our Terms and DPA.
Billing
Your plan, subscription status, invoices, payment history and billing contact details. Card details are entered directly with Stripe and are never stored on our systems — we hold only the payment method's last four digits, brand and expiry as returned by Stripe.
Workspace content
Everything you or your assistants create and store: brand voice and guidelines, goals, onboarding answers and operating instructions, drafts, scheduled and published posts, blog articles, images, video, audio, text overlays, knowledge-base documents you upload, and the assistant's working memory about your business.
Data from accounts you connect
When you connect a third-party account we store an access token, held encrypted, plus the identifiers that platform gives us and the data the feature needs. Depending on what you connect, that can include social page and account IDs, post performance and follower counts, search-performance metrics, email you send and receive through a connected mailbox for outreach, calendar entries, and records from a connected CRM or helpdesk. We never store your password for those platforms. See our Data Deletion Instructions for exactly what a social connection holds and how to remove it.
Contacts, leads and people you communicate with
Contact records you create or import, leads discovered from public web sources on your instruction, email correspondence in outreach threads, replies received, and any suppression or do-not-contact markers attached to them. This is third-party personal data that we process on your behalf — see section 6.
Support and communications
Messages you send through our contact form, support tickets, issue reports, email you send to our support address, and the notifications and emails we send you.
Technical and usage data
Sign-in events, session records, audit logs of significant actions, security-event records, error and diagnostic logs, API call records for connected integrations, and page-view events used to detect when an account is struggling. IP addresses recorded in audit and security tables are truncated before they are stored — the final octet of an IPv4 address, or everything after the first 64 bits of an IPv6 address, is discarded, so we retain subnet-level signal for abuse detection without an individually identifying address.
We do not ask for, and ask that you do not put into your workspace, special category data (health, biometrics, race, religion, political opinions, sex life or orientation), criminal offence data, or payment card numbers.
3. Where it comes from
- From you and your team — everything you type, upload or configure.
- From platforms you connect — only after you complete that platform's own authorisation screen, and only within the permissions you grant there.
- From public web sources — where you run a lead discovery search, we query a search provider and read publicly available business pages to build lead records. We look for business contact details, not personal ones.
- Generated by the platform — drafts, scores, metrics, provenance records and audit entries created as your assistants work.
4. Why we use it, and our lawful basis
Where we act as a controller, we rely on the following bases:
- Performance of a contract — creating and running your account, provisioning assistants, generating and publishing your content, taking payment, and providing support.
- Legitimate interests — securing the platform and detecting abuse, keeping audit trails, diagnosing faults, measuring how features are used so we can improve them, preventing fraud and non-payment, and sending service messages about your own account. We balance these against your interests, and you can object at any time.
- Legal obligation — retaining billing and tax records, responding to rights requests, and reporting personal data breaches.
- Consent — where you opt in to optional emails, or authorise an integration that requires your explicit permission. You can withdraw consent at any time; withdrawing it does not affect processing already carried out.
Where we act as a processor, we process only on your documented instructions, as set out in the DPA.
5. AI processing — what the assistants do with your data
Your assistants send parts of your workspace data to AI providers so they can do the work you asked for. This is worth understanding in detail.
- What is sent. The instructions you configured, the relevant part of your brand and business context, the content being drafted or reviewed, and any material you explicitly attach. We send the context a task needs, not your whole workspace.
- No training on your data. Our AI providers are contractually bound not to train their models on data we send through their APIs. Your data is never used to build or improve another customer's assistant.
- Safety screening. Prompts pass through a content moderation check before generation, and generated content passes through a quality and compliance review before it can be approved. Both create records against your workspace.
- Search and retrieval. Knowledge-base documents you upload are split into chunks and converted into numerical embeddings so assistants can search them. Those embeddings are stored in your workspace and scoped to it.
- Media generation. Where you ask for an AI image or video, the prompt is sent to our media generation provider and the result is stored in your workspace.
- Human control. Assistants draft; they do not decide. Content reaches a review queue for a person to approve, unless you have explicitly enabled automatic publishing and the content meets the conditions you set. AI-assisted output is labelled, and provenance records are kept.
- No solely automated decisions with legal effect. Nothing in the platform makes a decision about you that produces legal effects or similarly significant effects within the meaning of Article 22.
6. If you are a contact, lead or prospect
You may be reading this because a Be More Swan customer holds a record about you, or emailed you using our platform. In that case the customer is the controller of your data and we are their processor.
- Lead records are built from information you or your business published publicly, or from details you gave the customer directly.
- Every outbound email identifies the sender and carries a way to opt out. Asking to be removed adds you to that customer's permanent suppression list, which is checked before any further send.
- A lead marked as do-not-contact is blocked at the point of sending, including in the middle of a sequence already in progress.
- You can email privacy@bemoreswan.com to object, to ask for erasure, or to find out which customer holds your record. We will pass the request to them and support them in acting on it.
7. Who we share it with
We do not sell personal data and we do not share it for advertising. We share it in three situations only.
Sub-processors acting on our behalf
These providers process data so we can run the service. Each is under a written data processing agreement.
| Provider | What it does | Region |
|---|---|---|
| Anthropic | Primary AI model behind assistant drafting, chat and review | US |
| OpenAI | Content moderation screening; voice narration of our own product tour copy | US |
| Voyage AI | Embedding of knowledge-base content so assistants can search it | US |
| fal.ai | AI image and video generation from prompts you or your assistants supply | US |
| Neon | Managed PostgreSQL database — the primary store for your workspace | EU (eu-west) |
| Cloudflare R2 | Object storage for uploaded and generated media and documents | EU-configured bucket |
| Netlify | Hosting, serverless functions and scheduled jobs | US / global edge |
| Amazon Web Services | Serverless video rendering for posts with overlays | EU (eu-west-2, London) |
| Stripe | Payment processing and subscription management | US |
| Resend | Transactional and notification email delivery | US |
| SendGrid (Twilio) | Receiving inbound email replies and routing them into your workspace | US |
| Serper | Web search queries used by lead discovery runs you start | US |
| Pexels | Stock imagery search — a search term is sent, no personal data | US |
| Canva | Importing designs, only where you connect a Canva account | Australia / US |
A full sub-processor register listing each processor's name, the data transferred, its legal transfer basis, its region and the date we last reviewed it is available on request from privacy@bemoreswan.com. We will notify you 14 days before adding a new sub-processor that handles your personal data.
Platforms you choose to connect
When you connect an account and instruct an assistant to act on it, we send data to that platform on your behalf — for example publishing a post to Facebook, Instagram, Threads, LinkedIn, X, TikTok or YouTube, sending an email through your connected mailbox, publishing an article to your blog, or writing a record to a connected CRM, helpdesk, project or accounting tool. Those platforms are independent controllers of what they receive and their own privacy policies apply. You choose which are connected, and you can disconnect any of them at any time.
Legal and corporate
We disclose personal data where we are legally required to, to establish or defend legal claims, or to protect the rights and safety of our users. If the business is ever sold or reorganised, data may transfer to the acquirer under the same commitments; we would tell you before that happened.
8. International data transfers
Your workspace database sits in an EU region and video rendering runs in AWS London. Some of the providers above are in the United States, so personal data may be transferred there.
Those transfers are covered by Standard Contractual Clauses under the UK IDTA and EU Commission Decision 2021/914, except for Stripe, where we rely on the UK–US Data Privacy Framework adequacy. For SCC transfers we have carried out a Transfer Impact Assessment evaluating: (1) the US legal framework, including FISA 702 and the EO 14086 safeguards, (2) each provider's contractual commitments, and (3) technical supplementary measures — minimising personal data in prompts, contractual no-training clauses, and limiting the context sent to AI APIs to what a task needs. The assessment forms part of our Article 30 Records of Processing Activities and is available on request.
9. How long we keep it
We keep personal data only as long as we need it. In practice:
| Data | Retention |
|---|---|
| Your account and workspace content | For as long as your account is open, then erased after deletion (see below) |
| Sign-in session | 7 days, then you are signed out |
| Unverified sign-ups that were never confirmed | Deleted once the verification link expires |
| Media attached to published posts | 30 days after publication, then the stored file is deleted |
| Media attached to rejected content | 7 days |
| Archived posts | 30 days in the archive, then removed |
| Empty drafts nobody worked on | 7 days |
| Generated brand cards never attached to anything | 30 days (media a person has edited or kept is exempt) |
| In-app notifications and integration call logs | 90 days |
| Data export download links | 72 hours, then the link expires |
| Account deletion cooling-off window | 24 hours, during which you can cancel the request |
| Audit logs and security event records | Retained as evidence; not user-deletable |
| Records that you accepted our Terms and DPA | Retained as consent evidence (Article 28(9)) |
| Record that an erasure took place | Retained in anonymised form as proof we acted |
| Invoices, payments and billing records | 7 years (HMRC requirement) |
When an account is deleted, we remove the workspace records and delete the stored files held for that organisation. Deletion completes within 30 days, as UK GDPR requires. The last three rows above survive it, because we are required to keep them. Cancelling a subscription is not the same as deleting an account — see the Data Deletion Instructions.
10. How we protect it
- Isolation. Every workspace is tenant-scoped, enforced in the data layer, and covered by automated tests that fail the build if one tenant could reach another's rows or files.
- Encryption. Traffic is encrypted in transit with TLS. Access tokens and integration credentials are additionally encrypted at the application layer with AES-256-GCM before they are stored, under keys we rotate. Plaintext credentials are never logged and never returned to a browser.
- Minimised logging. IP addresses are truncated before storage, and prompts and payloads are filtered so credentials never reach the logs.
- Staff access. Support access to a customer account requires a super-admin role, is time-limited to 15 minutes, records the reason in an immutable audit log, and is blocked from taking payment, changing a password or deleting an account.
- Breach response. If a personal data breach occurs and it is likely to result in a risk to you, we will notify the ICO within 72 hours and tell you where the law requires it.
More detail on our controls is on the Trust & Security page.
11. Your rights
Under UK GDPR you have the right to:
- Access a copy of the personal data we hold about you.
- Rectify anything inaccurate — most of it you can correct yourself in Settings.
- Erase your data, subject to the records we are legally required to keep.
- Restrict or object to processing based on our legitimate interests.
- Port your data to another provider in a machine-readable format.
- Withdraw consent where consent is what we relied on.
To exercise any of these, email privacy@bemoreswan.com from the address on your account, or use the data controls in Settings. We acknowledge requests within 5 working days and respond within one month, which we may extend by two further months for complex requests — we will tell you if that happens. We may need to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
A data export is delivered as a downloadable file, and the download link expires after 72 hours for security. Account deletion has a 24-hour cooling-off window with a cancel link emailed to you, in case the request was not made by you.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113), or to your local supervisory authority in the EU.
12. Cookies and similar technologies
We use strictly necessary cookies only. There is no advertising network, no analytics tracker and no third-party pixel on this site, which is why you are not asked to accept cookies.
aura_session— keeps you signed in. HttpOnly, Secure, SameSite=Lax, expires after 7 days.aura_impersonation— set only during an audited support session, and expires after 15 minutes.
Two third-party services load code in your browser when you use the app: Stripe, on the checkout and billing pages, for payment security and fraud prevention; and a public code CDN that serves the editor libraries used in the content studio. Both receive your IP address as an unavoidable part of serving a request. Neither is used to profile you.
We also record page views inside the signed-in app against your account, so we can tell when someone is stuck and offer help. That is first-party, stays in your workspace database, and is never shared.
13. Google API Services — Limited Use Disclosure
Be More Swan's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained through Google API connections (including Gmail, Google Calendar, Google Drive, YouTube and Search Console) will only be used to provide or improve user-facing features that are prominent in Be More Swan's user interface. This data will not be used for advertising, will not be transferred to third parties except as necessary to provide the Services or as required by law, and will not be used to train AI foundation models. Human access to this data is restricted to cases where it is necessary to provide the Services, to comply with applicable law, or where you have given express consent.
14. Data from social platforms
Data we obtain through Meta (Facebook, Instagram, Threads), LinkedIn, X, TikTok and YouTube connections is used solely to publish the content you approve and to report back on how it performed. It is not sold, not used for advertising, and not used to train AI models. Where a platform tells us you have removed our app, we revoke the connection and delete the stored token without waiting for you to ask.
Full details of what each connection holds, and how to remove one, are in our Data Deletion Instructions.
15. Ownership, export and migration
You keep full ownership of your workflows and your proprietary business data. You can request an export of your data at any time, and you can ask us to delete your account at any time.
Migration policy
On request we will provide a plain-text export of your assistant's job instructions and workflow logic. While you own that logic, the technical architecture and integrations we have built are proprietary to Be More Swan. We do not provide migration of technical infrastructure or "plug-and-play" files to third-party agencies. If you switch providers we will hand over your documented instructions, and once you confirm, securely purge your account-specific assistant memory and associated data.
16. Children
Be More Swan is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, contact privacy@bemoreswan.com and we will delete it.
17. Changes to this policy
We update this policy when our service or the law changes. The date at the top always reflects the current version. We notify active subscribers of significant changes by email before they take effect, and we will always give notice before a change that reduces your protections.
18. Contact us
Privacy and data protection: privacy@bemoreswan.com
Anything else: hello@bemoreswan.com
Related pages: Terms of Service · Trust & Security · Data Deletion Instructions