Legal

Privacy Policy

Last updated: 26 September 2026

Your recordings are your own. This page explains what data we process, who has access to it, where it's processed and how to delete it.

Data controller

The controller of the personal data collected through SwiftBOL (swiftbol.com) is SwiftBOL, a sole trader (autónomo), tax ID (NIF) to be published, with address at Spain (postal address available on request at support@swiftbol.com). For any privacy question or to exercise your rights, write to support@swiftbol.com. The full identification details required by Article 10 of Spain's LSSI-CE are listed in the Legal Notice.

We haven't appointed a data protection officer because, given the type and volume of processing, we aren't required to; the controller handles every request directly.

What data we process

Account data: your first and last name, your email and your password (stored hashed by our authentication provider; nobody at SwiftBOL can see it), the date you verified your email, your plan and your usage counters (audio minutes and AI creations).

If you sign in with Google: when you choose “Continue with Google”, “Sign up with Google” or the “Continue as…” prompt Google shows on the sign-in page, Google confirms your identity and gives us your name, email, profile photo and an identifier for your Google account (only the basic “openid”, “email” and “profile” permissions). We use your name and email to create and maintain your account; the photo and identifier are kept by our authentication provider to link your account and are not used for anything else. We never receive your Google password and we don't access your Gmail, contacts, Drive, calendar or any other data in your Google account. SwiftBOL's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

If you sign in with Microsoft: when you choose “Continue with Microsoft”, Microsoft confirms your identity and gives us your name, email and an identifier for your account (only the basic “openid”, “email” and “profile” permissions). We use them as with Google, only to create and maintain your account; we never receive your password and we don't access your Outlook mail, files, calendar or any other data in your Microsoft account.

Proof of acceptance: when you accept the Terms and, when you buy a plan, the renewal terms, we keep the version accepted, the date, and the IP address and browser (user agent) you used.

Content: the audio you upload or record; the transcripts, summaries, chapters and tasks generated from it; the names you give to speakers; your questions and the answers in “Ask your audio”; the translations, tests, flashcards and documents you create; your folders; and whether a session has an active public link. Also your glossary and, on the Unlimited plan, your custom instructions.

Payments: Stripe collects your card details and, when needed, your billing address or tax ID. We give it your email and account ID, and we only receive your customer ID, your subscription status and your renewal date; we never see or store your full card number.

Communications: what you send us through the contact form (name, email, company and message), through in-app support (your email, account ID, plan, the page you wrote from, IP address and message), by email or, where available, via WhatsApp.

Referral program: your invite code and, if you signed up through someone else's link or paid with their code, their code. To know whether you count towards their reward we check whether you've completed a transcription and that your email isn't from a temporary-email service; the person who invited you only sees in their dashboard how many people signed up and how many count, never who. We record the free months you earn and, if you pay for a subscription, the balance we credit to you in Stripe.

Technical data: your IP address, browser and the time of each request, which we use for anti-abuse rate limits (stored hashed and only for minutes or hours), and error reports, which store your internal account ID but never your email or name. The first time you visit, our hosting provider infers from your IP the country you're connecting from so we can pick the site language; we don't store it.

Cookieless visit statistics: to know how many people use the site, from which cities and countries, on what kind of device and system, where they came from (for example an ad, a campaign or the site that linked to us) and which pages, and which part of each page, they visit (for example “pricing” or the open tab in the dashboard), the site tells our server which page is open while you have it in front of you (every 30 seconds). We don't store your IP or anything on your device: each visitor is recorded with a pseudonymous code (a hash of the connection and browser computed with a secret key) that changes every day, so we can't tell who you are or follow you from one day to the next. The location is the approximate city inferred from your connection, with coordinates rounded to about 10 km, and for private addresses (shared links, sign-in links and sessions) only the type of page is kept. Only SwiftBOL's owner views this data, in an internal dashboard.

Where it comes from: almost everything comes from you or is generated as you use the service. Stripe tells us the status of your payments, our hosting provider infers the country and approximate city from your IP and, if you arrive through an invite link, we get the code of the person who invited you.

What is required: to create an account we need your email and a password (or your Google or Microsoft account), and your acceptance of the Terms; without them we can't provide the service. To buy a paid plan, we also need the payment details Stripe asks for. Everything else is optional or generated as you use the service.

Recordings of other people

Before recording or uploading audio, you must confirm that you have the consent of the people in it. Obtaining that consent, having a legal basis to process their data, and complying with the law that applies to the recording is your responsibility. Avoid uploading recordings with particularly sensitive data (for example, health data) about other people unless you have a clear legal basis for it.

If you use SwiftBOL for your work, you are the controller of the voices and third-party data in your recordings and SwiftBOL acts as your processor: we only process that content on your instructions and to provide the service. If you need to sign a data processing agreement (GDPR Art. 28), write to support@swiftbol.com.

If your voice appears in a recording someone else uploaded to SwiftBOL (GDPR Art. 14): that data (your voice, what you say and, if mentioned or assigned, your name) comes to us from the person who uploaded the recording, and we only process it to provide them with the service described in this policy, with the providers and retention periods set out here; the basis is our contract with that person and the consent they state they obtained. Because we can't identify or contact you, we publish this information here. You can exercise your rights with whoever recorded you or by writing to support@swiftbol.com with details that let us locate the recording.

Artificial intelligence and AI providers

SwiftBOL uses third-party AI models: Groq (Whisper transcription), Deepgram (transcription when you ask to identify speakers, on the Unlimited plan only; for large files; or as a fallback) and OpenAI (summaries, chat, translations, tests, flashcards and documents, and fallback transcription). Each one only receives what the task needs: the audio, the transcript or the summary and, where relevant, your glossary or custom instructions.

We don't use your audio or transcripts to train AI models. Under their API terms, OpenAI and Groq don't use the data we send them to train their models, and our requests to Deepgram are opted out of its model improvement programme. These providers may keep data temporarily (usually up to 30 days) solely to monitor abuse or fix errors, and then delete it.

Speaker identification only separates the voices within each recording (Person 1, Person 2…), which you can then name. Deepgram does it while processing each file, and the only thing it returns to us, and that we store, is the label for each segment. SwiftBOL doesn't recognise anyone or create, store or use voiceprints or other biometric identifiers to identify anyone.

Everything SwiftBOL generates (transcripts, summaries, chapters, tasks, translations, tests, flashcards, documents and the answers from “Ask your audio”, which is an AI assistant, not a person) is produced automatically, isn't reviewed by anyone before you see it, and may contain errors: check it before relying on it. We tell you this in line with the transparency obligations of Regulation (EU) 2024/1689, the AI Act.

Who else has access to your data

Processors, which handle data on our behalf, under contract and only to provide their service to us: Supabase (database, authentication and audio storage; our project is hosted in Frankfurt, Germany), Vercel (hosting for the website and the app, which runs in Frankfurt, plus cookieless visit analytics), Groq, Deepgram and OpenAI (AI, see the previous section), Stripe (payments), Resend (email delivery) and Upstash (anti-abuse counters, which only store hashed identifiers for minutes or hours).

Independent controllers: Stripe also processes some data on its own account to prevent fraud and meet its own legal obligations. Google (Google Ireland Limited) receives the data from the Google Ads tag (the cookieless signals and, if you accept, the measurement cookies) and processes it as an independent controller under its own privacy policy; see the Cookie Policy. If you message us on WhatsApp, WhatsApp (Meta) handles that conversation under its own privacy policy.

Your team: if you belong to a team space and share a session with it, the people in the team see its title, date and length, the summary, chapters, key points, action items (with any names in them), study questions and the transcript, and can comment on it; never the audio. Each person in the team also sees the others' names and emails. Sharing stops when you turn it off, leave the team or the team is deleted. Comments are stored with the session and deleted with it.

Integrations you connect: if you connect Slack, Zapier, Make or another automation service in Settings → Integrations, we send to the address you provide the summary of the sessions you send (or of all of them, if you turn on automatic sending): title, summary, key points, action items with their owners and a link to the session and, to Zapier, Make and similar services, also the chapters and the transcript. We do this because you ask us to (performance of the contract, art. 6(1)(b) GDPR). That service processes the data as an independent controller under its own terms, and may be outside the European Economic Area. You can disconnect it at any time by deleting the address in Settings.

Meeting bot and Google Calendar: if you send the SwiftBOL bot to a meeting (or let it join the ones in your calendar), Recall.ai (Recall.ai, Inc., United States) acts as our processor from its servers in Frankfurt, Germany, where the recording is processed: the bot joins the call as "SwiftBOL Notetaker", visible to everyone, posts in the meeting chat (on Zoom, Google Meet and Teams) that it is recording, records the meeting's audio and hands it to us to transcribe and summarize like any other recording. If you connect Google Calendar, we only read your events for the next 36 hours (title, time, video call link, whether you declined and whether you organize it) to schedule the bot; we only store the link, title and time of the meetings a bot is sent to, never the rest of your calendar, and we use that data for nothing else. SwiftBOL's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Recording other people requires telling them: you confirm you do before sending the bot or turning on the calendar.

HubSpot and Salesforce: if you connect them and send a session, we send your CRM account the title, summary, key points, action items and a link to the session, attached to the contact whose email you give. HubSpot and Salesforce process them as part of your account with them, under their own terms. The access keys for Google Calendar, HubSpot and Salesforce are stored encrypted and deleted when you disconnect.

Sign-in with Google: if you use it, Google (Google Ireland Limited in the European Economic Area; Google LLC elsewhere) processes your sign-in as an independent controller under its own privacy policy (policies.google.com/privacy), and knows you signed in to SwiftBOL with your account. We don't share your account's content with Google.

Sign-in with Microsoft: if you use it, Microsoft (Microsoft Ireland Operations Limited in the European Economic Area) processes your sign-in as an independent controller under its own privacy statement (privacy.microsoft.com), and knows you signed in to SwiftBOL with your account.

Public links: if you turn on a session's link, anyone who has it can see your first name, the title, the date and length, the summary, chapters, key points, tasks (including any names in them), study questions, and the tests and flashcards you've created. The audio and the full transcript are never shown. We ask search engines not to index these links, but anyone who receives one can pass it on; you can turn it off at any time. The Google tag doesn't load on public links.

We only disclose data to authorities when a legal obligation or a valid order requires it and, unless the law forbids it, we tell you first.

International transfers

Your account, audio, transcripts and summaries are stored on Supabase servers in Frankfurt, Germany, and the app runs on Vercel servers in the same city. However, to provide the service some data is processed outside the European Economic Area, mainly in the United States: the audio, transcripts and summaries processed by OpenAI, Groq and Deepgram; the emails sent by Resend; the payments handled by Stripe; and the data Google receives through the Google Ads tag. Several of our providers (including Supabase, Vercel, Upstash and Recall.ai) are also US companies that may access data to give us technical support.

These transfers rely on the EU-US Data Privacy Framework where the provider is certified under it, or on the European Commission's Standard Contractual Clauses included in its data processing agreement. You can ask us for information about these safeguards, or a copy, at support@swiftbol.com.

Security

Traffic is encrypted in transit with TLS and our providers store data encrypted at rest. Audio is kept in private storage with no public access: only your account can play it back, through temporary links that expire after one hour.

Requests made from your browser are restricted by rules in the database itself (row-level security), and our server checks on every request that the session belongs to your account. Public links use a long random token, not a sequential number; when you turn a link off its token is destroyed, and if you share the session again a new one is created.

No system is infallible. If a security breach affects your data, we'll notify the Spanish Data Protection Agency (AEPD) and, where the law requires it, you as well.

How long we keep it

Account and content: for as long as you have an account. Your sessions (including the audio, so you can listen again), transcripts, summaries, chats and creations are kept until you delete them. Deleting a session also deletes its audio and chat.

Audio that never gets processed: if a transcription fails or is refused (for example, because you have no hours left), the audio is deleted straight away, and any uploaded file that never gets linked to a session is removed by the automatic daily clean-up (within about 48 hours at most). In Live Mode we don't keep the audio, only the text.

Error reports: deleted automatically after 90 days. Anti-abuse counters: expire on their own within one minute to 24 hours. Technical logs at our hosting provider: the short period that provider sets. Cookieless visit statistics: deleted automatically after 60 days. Your cookie choice: 12 months in your browser.

Support and contact messages: as long as needed to handle your request and follow up on any claims.

Referral program: attributions and months earned, for as long as you have an account; payment and tax details of a commission from the previous program, for the periods tax and commercial law require (up to 6 years).

If you delete your account from Settings, we cancel your subscription (if you have one) on the spot and immediately delete your account, profile, sessions, audio, chats and creations, your referral program data and your acceptance records. They disappear from backups within 30 days at most.

After your account is deleted we only keep billing data (invoices and payments, stored in Stripe) for the periods the law requires: 6 years under Article 30 of the Spanish Commercial Code and, for tax purposes, the 4-year limitation period of the Spanish General Tax Act. Error reports may remain for up to 90 days, but they only contain an internal ID that no longer matches any account.

Your rights

From the dashboard you can, at any time, export your sessions, correct your details, turn off public links, delete sessions, or delete your account with all its content.

If you signed in with Google, you can remove SwiftBOL's access to your Google account at any time at myaccount.google.com/permissions. Your SwiftBOL account keeps existing (to sign in, set a password with “Forgot your password?”) until you delete it from Settings.

You can also exercise your rights of access, rectification, erasure, objection, restriction of processing and data portability, and withdraw any consent you've given at any time (without affecting processing carried out before), by writing to support@swiftbol.com from your account email. We'll reply within one month.

If you think we haven't handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the data protection authority of your EU/EEA country of residence.

Cookies and ad measurement

We use the technical cookies needed to keep you signed in and remember your language, a cookie that remembers the invite code if you arrive through an invite link, and two cookieless statistics systems (Vercel Web Analytics and our own).

To measure which ads bring visits, sign-ups and subscriptions we use the Google Ads tag in its “consent mode”, with ad personalisation always off. Until you decide, the tag loads with every permission denied: it doesn't store or read cookies and, at most, sends Google technical signals without cookies or advertising identifiers (like any internet request, they carry your IP address and browser details). Only if you press “Accept” does it use measurement cookies. If you press “Reject” or your browser sends the Global Privacy Control signal, it doesn't load. You can change your choice at any time from “Cookie settings” at the bottom of the site. Each cookie is described in the Cookie Policy.

Notice for US residents (including California)

Given our size, US state privacy laws (such as those of California, Virginia, Colorado, Connecticut, Utah, Texas or Oregon) may not apply to us, but we give all US users the information and rights in this section.

Notice at collection: we collect the categories of data described in “What data we process”: identifiers (name, email, IP address, account ID); customer records and commercial information (your plan and payments, handled by Stripe); audio information (your recordings and the voices in them); internet activity (technical logs, visit statistics and, with your consent, measurement cookies); approximate, never precise, location (the city inferred from your IP); and account login details (email and password), which are sensitive personal information that we only use to provide the service. We collect them from you and from your use of the service, for the purposes and retention periods set out in this policy, and disclose them to the service providers listed in “Who else has access to your data”.

We don't sell your personal information for money and we don't use it for personalised or cross-context behavioral advertising. The only disclosure some state laws might treat as a “sale”, “sharing” or “targeted advertising” is Google Ads measurement, which runs with ad personalisation turned off. You can opt out by pressing “Reject” in “Cookie settings” or by using the Global Privacy Control signal, which we treat as an opt-out request. We don't respond to “Do Not Track” signals, which have no common standard. We don't disclose personal information to third parties for their own direct marketing, and we don't sell or share the data of anyone under 16.

Biometric data: SwiftBOL doesn't create, store or use voiceprints or other biometric identifiers to identify anyone, within the meaning of Illinois's BIPA, Texas's CUBI or similar laws. Speaker identification (Unlimited plan only, and only when you ask for it) is done by Deepgram analysing each recording's audio while processing it, and it only returns labels such as “Person 1”, which can't be used to recognise anyone in other recordings.

Your rights: to know what data we hold about you and access it, get a portable copy, correct it, delete it, opt out of sale, sharing, targeted advertising and profiling, and not be discriminated against for exercising these rights. Write to support@swiftbol.com from your account email, which we use to verify your identity; an authorised agent can also do so with your written permission. We'll reply within 45 days, extendable by another 45 if necessary and we tell you why. If we deny your request, you can appeal by replying to our answer; we'll respond within 45 days at most and, if we uphold the denial, you can contact your state's Attorney General.

United Kingdom residents

If you live in the UK, the UK GDPR and the Data Protection Act 2018 apply, with the same rights described in “Your rights” (access, rectification, erasure, objection, restriction and portability). You can complain to the Information Commissioner's Office (ico.org.uk).

Transfers of your data from the UK to the United States rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, or on the UK Addendum to the standard contractual clauses. Non-essential cookies are only used with your consent, as UK law (PECR) requires.

Mexico residents: privacy notice

This policy is also our privacy notice (aviso de privacidad) under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties. The controller is SwiftBOL, at the address given under “Data controller”; you can reach us at support@swiftbol.com.

Primary purposes, needed to provide the service: creating and managing your account, processing your audio and generating what you ask for, billing subscriptions, support and protecting the service. Secondary purposes: we don't use your data for marketing or advertising; ad measurement with cookies only runs if you accept it, and you can reject it under “Cookie settings”.

We don't ask for sensitive data. If you choose to upload recordings that contain it, we process it only to provide the service you request, and you must have the consent of the people in them.

The providers listed under “Who else has access to your data” process data on our behalf under contract (remisiones), so your consent is not required. We make no transfers to third parties that would require it.

ARCO rights (access, rectification, cancellation and opposition) and withdrawal of consent: email support@swiftbol.com from your account email with your name, the right you want to exercise and the data it concerns. We will reply within 20 business days and, where applicable, act on it within the following 15 business days.

If you believe we haven't handled your request properly, you can contact Mexico's authority for personal data held by private parties (currently the Secretaría Anticorrupción y Buen Gobierno). Any change to this notice will be published on this page.

Canada residents

If you live in Canada, the federal PIPEDA applies and, if you live in Quebec, the Act respecting the protection of personal information in the private sector (Law 25). The person in charge of the protection of personal information is SwiftBOL, reachable at support@swiftbol.com.

Your data is stored and processed outside Canada, in the European Union and the United States, by the providers listed above, under contracts that require them to protect it adequately; there it may be subject to those countries' laws.

By default SwiftBOL uses the most private option: public links are off until you turn them on, and measurement cookies aren't used until you accept them.

You can access your data, correct it, request a portable copy and withdraw your consent by emailing us. If you're not satisfied, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, to the Commission d'accès à l'information (cai.gouv.qc.ca).

We only send you service-related emails; never commercial messages without your consent, as Canada's anti-spam law (CASL) requires. If a security incident poses a risk of significant harm, we will notify the authority and you.

Children

SwiftBOL is not directed at children under 14 (or the minimum age set by the law of your country, if higher), and in no case at children under 13 within the meaning of the US COPPA; we don't knowingly collect their data. If you're between 14 and 18, you need permission from a parent or guardian to buy a paid plan. If you believe a child under that age has given us their data, write to us and we'll delete it.

Changes to this policy

If we change this policy in a significant way, we'll email you before the change takes effect and update the date at the top of this page.

Questions about this document? Email support@swiftbol.com.