Last updated: August 28, 2026. Prior versions are archived and available on request.
Who we are
Swarmio ("Swarmio", "the service") is operated by IO Services LLC, a limited liability company incorporated in the State of Delaware, United States.
Postal address: IO Services LLC, 8 The Green, Ste B, Dover, DE 19901, United States Email: support@ioservices.io
IO Services LLC is the data controller for the personal data described in this policy, except where this policy says otherwise (see People research, where you are the controller for the searches you run).
This policy explains what we collect, why, how long we keep it, who we share it with, and the control you have over it. It is a notice, not a contract — your use of Swarmio is governed by the Terms of Service.
Who this policy covers
- Users — anyone with a Swarmio account, including automated agents operating under an account.
- Visitors — anyone browsing the site or opening a shared report.
- Research subjects — people who are the subject of a people-research run. You did not sign up for Swarmio, but you still have rights. See People research and Your rights below.
What we collect
From you, directly
| Category | What it includes | Why |
|---|---|---|
| Account details | Email address, authentication state, account settings | To create and secure your account |
| Your content | Questions, briefs, prompts, uploaded files, settings, and the runs, chats, schedules, and reports they produce | To perform the work you request |
| Optional profile data | Persona details, diary ("Friend") entries, astrology birth details | To personalize the service, only if you choose to provide them |
| Support correspondence | Emails you send us and our replies | To answer you and keep a record |
Automatically
| Category | What it includes | Why |
|---|---|---|
| Credit ledger | Balances, grants, purchases, per-run usage | To meter and bill correctly |
| Payment metadata | Stripe payment confirmations and identifiers; for crypto, the transaction hash you submit and its on-chain verification result | To process payments and resolve disputes. We never see or store your card number. |
| Technical and log data | IP address, browser and device type, timestamps, pages and endpoints requested, error traces | Security, abuse prevention, debugging |
| Agent registration data | Agent ID and signup IP for automated-agent accounts | Abuse attribution |
| Delivery records | Email, webhook, and in-app notification delivery status | To confirm your scheduled results were sent |
About other people
If you upload files, write prompts, or run people research that contains information about third parties, we process that data on your instructions. You are responsible for having a lawful basis to give it to us. See People research.
Legal bases for processing
For users in the EU, UK, and Switzerland, we rely on the following bases under GDPR Article 6:
| Purpose | Legal basis |
|---|---|
| Providing the service, running your work, delivering results | Performance of a contract (Art. 6(1)(b)) |
| Billing, credit ledger, payment records, tax records | Contract and legal obligation (Art. 6(1)(b), 6(1)(c)) |
| Security, abuse prevention, rate limiting, fraud detection | Legitimate interests (Art. 6(1)(f)) — protecting the service and its users |
| Service emails and operational notices | Contract (Art. 6(1)(b)) |
| Optional persona, diary, and astrology features | Consent (Art. 6(1)(a)), withdrawable at any time by deleting the data in the app |
| Marketing email, where offered | Consent (Art. 6(1)(a)), withdrawable via the unsubscribe link |
| People-research subject data | You act as controller; we act as your processor. See People research. |
Withdrawing consent does not affect processing that already happened.
AI providers and model training
This is the section most people want, so we state it plainly.
- To perform your work, we send your prompts, uploaded files, and retrieved source material to third-party large language model providers. This is necessary and unavoidable for the service to function.
- We do not use your content to train our own models.
- Our LLM providers are DeepSeek (which performs all agent reasoning — api.deepseek.com) and OpenAI (podcast scripting and text-to-speech — api.openai.com). We use no-training or zero-retention API configurations where a provider offers them. Where a provider retains API data for abuse monitoring, that retention is set by the provider's own policy and is typically up to 30 days. Provider privacy terms: DeepSeek · OpenAI.
- Diary ("Friend") entries and persona data are sent to LLM providers only when you use a feature that requires them. They are not used for any other purpose.
- We do not sell your data. We do not share it for cross-context behavioral advertising. We do not run advertising of any kind.
Sensitive information
Do not enter data into Swarmio that you are not authorized to process, and avoid entering special-category data unless you need to.
- Special-category data under GDPR Article 9 — health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic or biometric data, sex life or sexual orientation — should not be entered into Swarmio. The diary ("Friend") feature in particular may tempt you to record it. If you do enter it, you do so on your own instruction and at your own risk, and you confirm you have a lawful basis under Article 9.
- Astrology birth details (date, time, place of birth) are stored to generate entertainment content only. They are not used for identity verification or any other purpose.
- Do not enter government identification numbers, payment card numbers, credentials, or health records.
We do not knowingly use special-category data to make decisions about you.
People research
Swarmio can research named individuals. Because the person being researched has not agreed to anything, this capability carries specific rules.
Roles. When you run a people-research search, you are the data controller for that search and IO Services LLC acts as your processor. You are responsible for having a lawful basis for the search and for complying with applicable law. We process the search on your documented instruction and for no other purpose.
Our controls.
- Searches are purpose-bound: you must state a permitted purpose before a run begins.
- Searches are depth-limited and rate-limited.
- Every search is audit-logged with the requesting account, the stated purpose, the subject, the timestamp, and the sources consulted. Audit logs are retained for 24 months and are used for abuse investigation, legal compliance, and responding to subject requests.
- Prohibited purposes are listed in the Terms of Service and include employment, credit, housing, insurance, and tenancy screening; stalking, harassment, or intimate-partner monitoring; and any use regulated by the US Fair Credit Reporting Act. Swarmio is not a consumer reporting agency and its output is not a consumer report.
If you are a research subject. You have rights over data we hold about you even though you have no account. You can:
- Ask what we hold about you and receive a copy.
- Ask us to correct or delete it.
- Object to the processing.
- Add yourself to our opt-out register, which blocks future searches against you across all accounts.
Email support@ioservices.io with the subject line "People Research Request." We may ask for enough information to locate the record and confirm you are the person concerned. We will not use that verification information for any other purpose. We respond within 30 days.
Where GDPR Article 14 applies and we hold your data as controller, we will provide notice within one month of first obtaining it, unless doing so is impossible, involves disproportionate effort, or would prejudice the purpose of a lawful investigation.
Who we share data with
We share only what is needed, only with the following categories, and never for their own marketing.
| Recipient | Purpose | Location |
|---|---|---|
| Supabase | Authentication and database hosting | US (Oregon) |
| Stripe | Card payment processing | US / global |
| Resend | Transactional email delivery | US |
| DeepSeek, OpenAI | Model inference | Varies — see provider policies linked above |
| Hetzner | Application hosting | US (Ashburn, VA) |
| Websites your runs browse | Research runs necessarily contact the sites they read | Varies |
We also disclose data when legally required — to comply with a valid subpoena, court order, or lawful government request; to enforce our terms; to investigate abuse or fraud; or to protect the rights, safety, or property of any person. Where we are permitted to notify you first, we will.
If IO Services LLC is acquired, merged, or sells substantially all of its assets, your data may transfer to the successor, subject to this policy. We will notify you before any such transfer takes effect.
Current sub-processor list: available on request from support@ioservices.io; the table above is the complete list of categories today. Business customers may subscribe to change notifications by email. We give 30 days' notice before adding a new sub-processor.
International transfers
We operate from the United States. If you are in the EEA, UK, or Switzerland, your data is transferred to and processed in the United States and in any region where our sub-processors operate.
For those transfers we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum where applicable, together with supplementary technical measures including encryption in transit and at rest. Copies of the relevant transfer mechanisms are available on request from support@ioservices.io.
If we are required under GDPR Article 27 to appoint a representative in the EEA or the UK, we will name that representative here.
How long we keep data
| Data | Retention |
|---|---|
| Run history and artifacts | Deleted 20 days after creation, unless you pin ("save") a run — pinned runs are kept until you delete them |
| Chats | Until you delete them, or until account deletion |
| Persona, diary, astrology data | Until you delete it, or until account deletion |
| Account records | Life of the account, then deleted within 30 days of account deletion |
| Credit ledger, invoices, payment records | 7 years after the transaction, for accounting and tax purposes |
| Server and security logs | 90 days |
| Agent registration data (agent ID, signup IP) | 12 months |
| People-research audit logs | 24 months |
| Email and notification delivery records | 30 days |
| Opt-out register entries | Indefinitely, so the opt-out keeps working |
Backups. Deleted data may persist in encrypted backups for up to 35 days after deletion. Backups are not used to restore individual records and age out on a rolling cycle. We do not resurrect deleted data from backups except to recover from a system failure.
Security
We protect your data with:
- TLS encryption for all data in transit and encryption at rest for stored data.
- Role-based access controls; staff access is limited to those who need it and is logged. Administrative access is restricted to operator-designated accounts.
- Authentication handled by Supabase Auth. We never see or store your password.
- Isolation of run execution environments.
No system is perfectly secure. You are responsible for keeping your password, API keys, and agent credentials confidential, and for securing any webhook endpoint you configure to receive results.
Breach notification
If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where GDPR requires it, and we will notify you without undue delay where the breach is likely to result in a high risk to your rights or where US state law requires it. Notice will describe what happened, what data was involved, what we are doing, and what you should do.
Your rights
Regardless of where you live, you can:
- Access — get a copy of the data we hold about you.
- Correct — fix inaccurate data.
- Delete — remove your data. You can delete runs, chats, persona, diary, and astrology data yourself in the app. For full account deletion, email support@ioservices.io.
- Export — receive your data in a portable, machine-readable format.
- Object or restrict — object to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved.
- Withdraw consent — for anything we process on the basis of consent.
- Complain — to us first, and then to a supervisory authority.
How to exercise them. Email support@ioservices.io. We will verify your identity, usually by confirming control of the account email. We respond within 30 days (GDPR) or 45 days (CCPA/CPRA), and will tell you if we need an extension. There is no charge unless a request is manifestly unfounded or excessive.
Limits. We keep ledger, invoice, and tax records after account deletion because the law requires it. We keep opt-out register entries so the opt-out continues to work. We may retain data needed to establish, exercise, or defend legal claims.
If you are in the EEA, UK, or Switzerland
You may lodge a complaint with your national data protection authority. In the UK this is the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner. You do not need to contact us first, though we would like the chance to help.
If you are in California
Under the CCPA as amended by the CPRA:
- We collect the categories of personal information listed in What we collect above. Sources, purposes, and recipients are described in that section and in Who we share data with.
- We do not sell personal information and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16.
- You have the right to know, delete, correct, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising any of them. We do not offer financial incentives tied to your data.
- You may use an authorized agent, who must provide written proof of authorization.
If you are in another US state
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana — have comparable rights of access, correction, deletion, portability, and opt-out, plus a right to appeal a denied request. To appeal, reply to our decision email and we will review within 45 days.
Automated decision-making
Swarmio produces AI-generated analysis and reports at your request. We do not use automated processing to make decisions that produce legal or similarly significant effects about you. Automated systems do flag accounts for abuse review; a human reviews before any account is suspended, and you can contest a suspension at support@ioservices.io.
Children
Swarmio is not intended for anyone under 18, and you must be 18 or older to hold an account. We do not knowingly collect data from children under 13. If we learn we have, we delete it promptly. If you believe a child has given us data, email support@ioservices.io.
Cookies and local storage
We use your browser's local storage to hold your session and preferences. We use strictly necessary cookies for authentication and security.
We use no tracking cookies, no advertising pixels, and no third-party analytics. Because we set no non-essential cookies, we do not show a consent banner. If we ever add analytics, we will update this policy and obtain consent where required.
Public sharing
- A report you explicitly share gets a public link. Anyone with the link can read it. Un-sharing revokes the link. Do not share reports that contain personal or confidential data.
- Shared links are served with a
noindexdirective and are not submitted to search engines. We cannot prevent someone with the link from copying or reposting the content. - Curated "sample" runs are published by IO Services LLC from platform-operated accounts. They may appear on the homepage, in the sitemap, and in search results. Your runs are never published as samples.
Changes to this policy
We may update this policy. The date at the top shows the current version. For material changes we will give notice by email to account holders at least 30 days before the change takes effect, and will summarize what changed. Continued use after the effective date accepts the updated policy. Archived versions are available on request.
Contact
IO Services LLC 8 The Green, Ste B Dover, DE 19901 United States support@ioservices.io
For privacy requests, put "Privacy Request" in the subject line. For people-research opt-outs, put "People Research Request."