Not ready to publish. The company details in lib/legal.ts are still placeholders. Fill them in before submitting anything to Google or Stripe — both read this page by hand, and a policy with gaps in it fails review.

Privacy Policy

What SwiftLeads collects, why it exists, who else sees it, and how to make it go away. Written to be read rather than to be survived.

Last updated: 22 August 2026

The short version

  • We store your account, the companies you find, and the emails you send through the app.
  • Emails go from your own Gmail. We never read your mailbox — that permission was deliberately removed.
  • We do not sell anything to anyone, ever, and we do not use your data to train AI models.
  • You can delete everything yourself, from Settings, without asking us.

The rest of this page is the same thing with the detail attached.

Who is responsible

SwiftLeads operates SwiftLeads and is the data controller for your account. Write to legal@swiftleads.app about anything on this page.

For the lead data inside your account — the companies you searched for and the people you contacted — you are the controller and we are your processor. You decide who to contact and what to say; we hold it and act on your instructions.

What we collect

Your account. Name and email address, through our sign-in provider. We never see or store a password.

What you sell. The description of your service and any notes you add. This is the input to every score the app produces, which is the only reason it is stored.

Leads. Business information from Google Places — company name, address, phone, website, rating, public reviews — plus what our models concluded about each one. Business contact details, not personal profiles.

Messages. Emails you send through SwiftLeads and replies that come back through it, so a conversation is still there tomorrow.

Calendar events, if you connect a calendar: title, time, location and attendee addresses, for the next 60 days, so a booked meeting can move the lead by itself.

Usage. Which searches ran and what they consumed, so the app can show you where your plan went.

Payments. Handled entirely by Stripe. We receive a subscription status and the last four digits of a card. Card numbers never reach our servers.

Google user data

If you connect a Google account, SwiftLeads asks for the narrowest set of permissions that makes the product work. Each one, and exactly what it is used for:

  • gmail.send — to send the emails you write and press send on, from your own address. Nothing is ever sent automatically.
  • calendar.events — to read events in the next 60 days and check whether any attendee is one of your leads, so that lead can be moved to “Meeting”.
  • calendar.calendarlist.readonly — to list the names of your calendars so you can choose which ones to watch. It gives us the list only, never event contents.
  • userinfo.email — to know which address we are sending from.
We cannot read your mailbox. SwiftLeads previously asked for permission to read Gmail in order to notice replies. That permission is gone. Replies now reach us because each outgoing message carries a reply address on our own domain — we record the reply, then forward it straight to your inbox. We have no ability to see anything else in your email, including messages that SwiftLeads did not send.

Your Google refresh token is encrypted at rest with AES-256-GCM. It is used only for the actions above. Disconnecting at myaccount.google.com/permissions takes effect immediately, and deleting your SwiftLeads account revokes it for you.

SwiftLeads' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular: we do not transfer Google user data to others except as necessary to provide or improve SwiftLeads, to comply with the law, or as part of a merger or acquisition. We do not use it for advertising. We do not allow humans to read it, except with your explicit permission for a specific problem you have asked us to fix, where it is necessary for security, or where the law requires it.

AI, and what is never done with your data

SwiftLeads sends company information — names, categories, public reviews, and the description of what you sell — to OpenAI in order to score leads and draft messages. It is processed to answer that request and returned.

Your data is not used to train anybody's model.Not ours, not our providers'. We hold API agreements that exclude training, and we do not sell, rent or share your data with advertisers or data brokers under any circumstances.

Why we are allowed to hold it

To provide the service. Your account, your leads, your messages — without them there is no product. This is contractual necessity.

Legitimate interest. Keeping the service secure, preventing abuse, and understanding which features are used.

Legal obligation. Invoices and tax records, which we have to keep for the period Romanian law requires.

Who else sees it

Only the companies that have to, in order for the product to work. Each is bound by a data processing agreement:

CompanyWhat forWhere
VercelHosting and delivery of the applicationEU / USA
SupabaseDatabase — leads, messages, settingsEU (Ireland)
ClerkAccounts and sign-inUSA
StripePayments and invoicingEU / USA
GooglePlaces data, and sending mail from your own GmailEU / USA
OpenAIScoring companies and drafting messagesUSA
ResendNotification email we send to youEU / USA

Some are outside the EU. Those transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision. If you need our DPA for your own records, ask at legal@swiftleads.app and we will send it.

How long we keep it

Your account and its contents stay for as long as the account exists.

Delete your account and everything goes within 30 days, including from backups. The one exception is invoices, which tax law requires us to keep.

The do-not-contact list survives deletion, deliberately. When somebody unsubscribes from your outreach, their address is kept — as a one-way fingerprint — so it cannot be emailed again. An opt-out that could be erased by deleting an account would not be an opt-out.

What you can demand

Under GDPR you can see your data, correct it, take it elsewhere, have it deleted, object to how it is used, and complain to a regulator. Most of it does not need us at all:

  • See and export it — the Leads page exports everything to a spreadsheet at any time, including after you cancel.
  • Delete it — Settings → Export & privacy → Delete my account. It removes every record, revokes our access to your Google account, and cannot be undone.
  • Anything else — write to legal@swiftleads.app. We answer within 30 days.

In Romania the supervisory authority is the ANSPDCP. We would rather you told us first, but you do not have to.

If SwiftLeads emailed you and you are not a customer

You were contacted by a business using SwiftLeads to send its own email. They chose you and wrote the message; we provided the tool. Every email carries a working unsubscribe link, and using it stops that sender permanently — we enforce it, they cannot override it.

To have your details removed entirely, write to legal@swiftleads.app and we will act on it and tell the sender.

Security

Everything travels over HTTPS. Google tokens and calendar links are encrypted at rest. Database access is restricted to the application, and every request is scoped to the account that made it.

No system is perfect. If we ever suffer a breach affecting your data, we will tell you and the regulator within 72 hours of finding out. If you think you have found a vulnerability, please write to legal@swiftleads.app.

Age

SwiftLeads is a tool for businesses and is not offered to anyone under 18. We do not knowingly collect data from children.

Changes

If we change anything that matters, we will email you before it takes effect. The date at the top of this page always reflects the last real change. Continuing to use SwiftLeads after that means you accept the new version.