Privacy Policy

Last updated: August 28, 2026. Prior versions are archived and available on request.

Who we are

Swarmio ("Swarmio", "the service") is operated by IO Services LLC, a limited liability company incorporated in the State of Delaware, United States.

Postal address: IO Services LLC, 8 The Green, Ste B, Dover, DE 19901, United States Email: support@ioservices.io

IO Services LLC is the data controller for the personal data described in this policy, except where this policy says otherwise (see People research, where you are the controller for the searches you run).

This policy explains what we collect, why, how long we keep it, who we share it with, and the control you have over it. It is a notice, not a contract — your use of Swarmio is governed by the Terms of Service.

Who this policy covers

What we collect

From you, directly

CategoryWhat it includesWhy
Account detailsEmail address, authentication state, account settingsTo create and secure your account
Your contentQuestions, briefs, prompts, uploaded files, settings, and the runs, chats, schedules, and reports they produceTo perform the work you request
Optional profile dataPersona details, diary ("Friend") entries, astrology birth detailsTo personalize the service, only if you choose to provide them
Support correspondenceEmails you send us and our repliesTo answer you and keep a record

Automatically

CategoryWhat it includesWhy
Credit ledgerBalances, grants, purchases, per-run usageTo meter and bill correctly
Payment metadataStripe payment confirmations and identifiers; for crypto, the transaction hash you submit and its on-chain verification resultTo process payments and resolve disputes. We never see or store your card number.
Technical and log dataIP address, browser and device type, timestamps, pages and endpoints requested, error tracesSecurity, abuse prevention, debugging
Agent registration dataAgent ID and signup IP for automated-agent accountsAbuse attribution
Delivery recordsEmail, webhook, and in-app notification delivery statusTo confirm your scheduled results were sent

About other people

If you upload files, write prompts, or run people research that contains information about third parties, we process that data on your instructions. You are responsible for having a lawful basis to give it to us. See People research.

Legal bases for processing

For users in the EU, UK, and Switzerland, we rely on the following bases under GDPR Article 6:

PurposeLegal basis
Providing the service, running your work, delivering resultsPerformance of a contract (Art. 6(1)(b))
Billing, credit ledger, payment records, tax recordsContract and legal obligation (Art. 6(1)(b), 6(1)(c))
Security, abuse prevention, rate limiting, fraud detectionLegitimate interests (Art. 6(1)(f)) — protecting the service and its users
Service emails and operational noticesContract (Art. 6(1)(b))
Optional persona, diary, and astrology featuresConsent (Art. 6(1)(a)), withdrawable at any time by deleting the data in the app
Marketing email, where offeredConsent (Art. 6(1)(a)), withdrawable via the unsubscribe link
People-research subject dataYou act as controller; we act as your processor. See People research.

Withdrawing consent does not affect processing that already happened.

AI providers and model training

This is the section most people want, so we state it plainly.

Sensitive information

Do not enter data into Swarmio that you are not authorized to process, and avoid entering special-category data unless you need to.

We do not knowingly use special-category data to make decisions about you.

People research

Swarmio can research named individuals. Because the person being researched has not agreed to anything, this capability carries specific rules.

Roles. When you run a people-research search, you are the data controller for that search and IO Services LLC acts as your processor. You are responsible for having a lawful basis for the search and for complying with applicable law. We process the search on your documented instruction and for no other purpose.

Our controls.

If you are a research subject. You have rights over data we hold about you even though you have no account. You can:

Email support@ioservices.io with the subject line "People Research Request." We may ask for enough information to locate the record and confirm you are the person concerned. We will not use that verification information for any other purpose. We respond within 30 days.

Where GDPR Article 14 applies and we hold your data as controller, we will provide notice within one month of first obtaining it, unless doing so is impossible, involves disproportionate effort, or would prejudice the purpose of a lawful investigation.

Who we share data with

We share only what is needed, only with the following categories, and never for their own marketing.

RecipientPurposeLocation
SupabaseAuthentication and database hostingUS (Oregon)
StripeCard payment processingUS / global
ResendTransactional email deliveryUS
DeepSeek, OpenAIModel inferenceVaries — see provider policies linked above
HetznerApplication hostingUS (Ashburn, VA)
Websites your runs browseResearch runs necessarily contact the sites they readVaries

We also disclose data when legally required — to comply with a valid subpoena, court order, or lawful government request; to enforce our terms; to investigate abuse or fraud; or to protect the rights, safety, or property of any person. Where we are permitted to notify you first, we will.

If IO Services LLC is acquired, merged, or sells substantially all of its assets, your data may transfer to the successor, subject to this policy. We will notify you before any such transfer takes effect.

Current sub-processor list: available on request from support@ioservices.io; the table above is the complete list of categories today. Business customers may subscribe to change notifications by email. We give 30 days' notice before adding a new sub-processor.

International transfers

We operate from the United States. If you are in the EEA, UK, or Switzerland, your data is transferred to and processed in the United States and in any region where our sub-processors operate.

For those transfers we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum where applicable, together with supplementary technical measures including encryption in transit and at rest. Copies of the relevant transfer mechanisms are available on request from support@ioservices.io.

If we are required under GDPR Article 27 to appoint a representative in the EEA or the UK, we will name that representative here.

How long we keep data

DataRetention
Run history and artifactsDeleted 20 days after creation, unless you pin ("save") a run — pinned runs are kept until you delete them
ChatsUntil you delete them, or until account deletion
Persona, diary, astrology dataUntil you delete it, or until account deletion
Account recordsLife of the account, then deleted within 30 days of account deletion
Credit ledger, invoices, payment records7 years after the transaction, for accounting and tax purposes
Server and security logs90 days
Agent registration data (agent ID, signup IP)12 months
People-research audit logs24 months
Email and notification delivery records30 days
Opt-out register entriesIndefinitely, so the opt-out keeps working

Backups. Deleted data may persist in encrypted backups for up to 35 days after deletion. Backups are not used to restore individual records and age out on a rolling cycle. We do not resurrect deleted data from backups except to recover from a system failure.

Security

We protect your data with:

No system is perfectly secure. You are responsible for keeping your password, API keys, and agent credentials confidential, and for securing any webhook endpoint you configure to receive results.

Breach notification

If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where GDPR requires it, and we will notify you without undue delay where the breach is likely to result in a high risk to your rights or where US state law requires it. Notice will describe what happened, what data was involved, what we are doing, and what you should do.

Your rights

Regardless of where you live, you can:

How to exercise them. Email support@ioservices.io. We will verify your identity, usually by confirming control of the account email. We respond within 30 days (GDPR) or 45 days (CCPA/CPRA), and will tell you if we need an extension. There is no charge unless a request is manifestly unfounded or excessive.

Limits. We keep ledger, invoice, and tax records after account deletion because the law requires it. We keep opt-out register entries so the opt-out continues to work. We may retain data needed to establish, exercise, or defend legal claims.

If you are in the EEA, UK, or Switzerland

You may lodge a complaint with your national data protection authority. In the UK this is the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner. You do not need to contact us first, though we would like the chance to help.

If you are in California

Under the CCPA as amended by the CPRA:

If you are in another US state

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana — have comparable rights of access, correction, deletion, portability, and opt-out, plus a right to appeal a denied request. To appeal, reply to our decision email and we will review within 45 days.

Automated decision-making

Swarmio produces AI-generated analysis and reports at your request. We do not use automated processing to make decisions that produce legal or similarly significant effects about you. Automated systems do flag accounts for abuse review; a human reviews before any account is suspended, and you can contest a suspension at support@ioservices.io.

Children

Swarmio is not intended for anyone under 18, and you must be 18 or older to hold an account. We do not knowingly collect data from children under 13. If we learn we have, we delete it promptly. If you believe a child has given us data, email support@ioservices.io.

Cookies and local storage

We use your browser's local storage to hold your session and preferences. We use strictly necessary cookies for authentication and security.

We use no tracking cookies, no advertising pixels, and no third-party analytics. Because we set no non-essential cookies, we do not show a consent banner. If we ever add analytics, we will update this policy and obtain consent where required.

Public sharing

Changes to this policy

We may update this policy. The date at the top shows the current version. For material changes we will give notice by email to account holders at least 30 days before the change takes effect, and will summarize what changed. Continued use after the effective date accepts the updated policy. Archived versions are available on request.

Contact

IO Services LLC 8 The Green, Ste B Dover, DE 19901 United States support@ioservices.io

For privacy requests, put "Privacy Request" in the subject line. For people-research opt-outs, put "People Research Request."

Swarmio — AI that does real work.

Back to Swarmio