Privacy Policy
How SwrlSite handles your information.
The short version. SwrlSite collects and processes information needed to deliver the website, consultation, or managed AI service requested. The AI Receptionist handles calls only. The AI Front Desk Suite handles calls and SMS/MMS at its core; email, website chat, forms, calendar, CRM workflows, and other integrations are processed only when the accepted order expressly includes them and they are activated. We do not sell personal information or share it for cross-context behavioral advertising. You may ask to access, correct, export, or delete your information, subject to legal and contractual retention requirements.
1. Who we are
SwrlSite is the public brand of Swrl LLC ("SwrlSite," "we," "us," or "our"). This Privacy Policy explains how we handle information when you visit our website, request a website or call, use our public AI assistant, or receive a managed AI service. For a client AI service, the client business decides why and how its customer information is used and provides the required notices and instructions; SwrlSite generally processes that information to provide the accepted service.
2. Information we collect
Information you provide directly.
- Website requests: whether you need a new site or rebuild, your business name, industry, market or service area, business description, contact details, form entry point, any website or public business-profile URL you provide, and whether you optionally asked us to contact you about the request by call or text. Marketing email consent is collected separately.
- Call requests: your name, email, phone or WhatsApp number, business name, the type of call requested, and any notes you add.
- Email and marketing signups: your email address and optional first name, with your separate consent.
- Project reviews and edit requests: if you are a client, the approval, edit notes, and corrections you submit through a private review link.
- Direct messages: anything you choose to send us by email or other contact.
- Client AI interactions: phone numbers, call audio and transcripts when recording is enabled with the required disclosure, SMS/MMS content and media, contact and intake details, interaction history, summaries, priorities, routing, consent and opt out status, and provider delivery records.
- Expressly scoped channels: when an accepted order enables them, inbound email content and metadata, website chat messages, submitted form fields, calendar activity, CRM records, attachments expressly allowed by the workflow, and the results returned by approved integrations.
Information collected automatically. When you browse the site we record limited, privacy-respecting analytics: the pages viewed, the date and time, and the referring website's domain (not the full URL). To count repeat visits without identifying you, we generate a one-way, salted hash that rotates every day; we do not store your IP address, full user-agent string, or any cookie-based identifier in our analytics. Our hosting and security infrastructure may keep short-lived server logs for reliability and abuse prevention, and we record limited rate-limiting signals (such as a truncated network identifier) to protect our forms from abuse.
Google Maps and Places. Some business-search features use Google Maps Platform to display public business results. Google may process request and device information under the Google Privacy Policy. For founder prospect discovery, we keep the founder-entered search query and Google Place ID; other Google-derived business details remain transient, and facts selected for our records are verified independently from the business's public website.
What we do not want. Please do not submit passwords, payment card data, government identifiers, private customer records, medical information, legal records, or other sensitive personal information through our forms. We do not request or need it.
3. How we use information
- To research, generate, deliver, publish, and support the website or rebuild you requested.
- To respond to your requests, schedule calls, and prepare a founder-reviewed proposal when you ask for one.
- To send transactional messages about a website or other request you submitted (these are not marketing).
- To contact you about your request by email and, only when you select or request contact by call or text, by phone call, text message, or WhatsApp. Standard message and data rates may apply; you can reply STOP to opt out of texts, and we do not send automated or marketing text messages without the consent required for that use.
- To send occasional marketing email only if you separately opted in, with an unsubscribe link in every message.
- To operate, secure, debug, and improve the site, including aggregate analytics about how the site is used.
- To prevent fraud and abuse and to comply with legal obligations.
4. Automated website building and AI processing
Existing-site rebuilds use automated software that visits the public website you submit, captures desktop and mobile screenshots, and extracts visible content such as headings, navigation, calls-to-action, and metadata. New-site and rebuild requests may also use the business name, industry, market or service area, business description, optional public profile, and public market research. This evidence is sent to a third-party AI provider (currently OpenAI) to help plan and generate the requested website. Your contact name, email address, and phone number are deliberately excluded from the AI analysis prompt.
Automated research and AI-generated website content can be incomplete or wrong. Review the website before publishing it and ask us to correct factual errors. A human reviews scope before any separate proposal is sent. Our use of third-party AI is subject to that provider's terms; we do not authorize the use of submitted content to train third-party public models beyond what the provider's standard business terms permit.
Website chat assistant. Our site offers an optional chat assistant. When you use it, the messages you type and the recent conversation are sent to our third-party AI provider (currently OpenAI) to generate replies, and the conversation is logged so we can maintain quality, prevent abuse, and improve the assistant. Conversation logs are deleted when no longer needed, generally within about 90 days. The assistant is scoped to questions about SwrlSite and does not require an account. Its answers are AI-generated, can be incomplete or wrong, and are not a quote, contract, or guarantee. Please do not enter passwords, payment details, or other sensitive personal information into the chat.
Public AI phone line. Our business phone line is answered by an AI agent for calls. When you call, the greeting tells you up front that you are speaking with an AI assistant and that the call is recorded and transcribed; if you prefer not to be recorded, you can hang up and reach us by email instead. For each call we keep the recording, a transcript, your phone number, and the details you choose to share, such as your name, your business, and what you need. The conversation is sent to our third-party AI provider (currently OpenAI) during the call to generate the agent's replies and afterward to write a short summary for our team. Contact details you share are saved in our customer records so we can follow up on your request. A requested text or booking-link message is processed only when that channel is enabled and the required consent exists. Any text messaging follows the rules in this policy, including STOP opt-out handling. Call recordings, transcripts, and summaries are kept like the lead and contact records described below: while you are a prospect or client and for a reasonable period afterward, then deleted when no longer needed. You can ask us to delete them at any time.
5. Client AI service data
Enabled channels only. The AI Receptionist processes calls only. The AI Front Desk Suite processes calls and SMS/MMS as its core. Inbound email, website chat, forms, calendar, CRM workflows, attachments, and other integrations are processed only when the accepted order expressly includes them and they have been implemented, tested, approved, and activated. We do not treat an unfinished or disabled adapter as an active data source.
Purpose and roles. We process client customer information to answer or route inquiries, collect approved intake details, provide approved responses, schedule or hand off under the client's rules, maintain the tenant CRM and interaction history, monitor quality and security, reconcile provider outcomes, and support the service. The client business is responsible for the lawfulness of its instructions, consent, recording and transcription decisions, notices, escalation rules, and customer relationships.
Tenant isolation and human review. Client information is kept in tenant-scoped records and is not intentionally exposed to another client. Important or high consequence requests are routed for human review under the accepted workflow rather than used for automatic legal, medical, financial, safety, refund, pricing exception, or contract decisions.
Providers. Depending on the selected channels, service providers may include SignalWire for telephony and messaging, OpenAI for approved AI processing, Resend for email delivery, cloud hosting and database providers, calendar or CRM providers selected for the order, and Stripe for billing. They process information to provide their contracted services and under their applicable business terms.
Training. We do not use a client's customer content to train our own public models. Third party processing follows the provider's applicable business terms and the accepted order; we do not promise a broader restriction than those terms provide.
6. Website screenshots and third-party content
Website rebuilds capture screenshots and extracted text from the public URL you submit. New-site builds may use your business description and an optional public business-profile link for market research. By submitting information you confirm you own the business or are authorized to request the build. We do not bypass logins, paywalls, or technical access controls.
7. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only:
- With service providers that operate the applicable service, including cloud hosting and database infrastructure, SignalWire for telephony and messaging, OpenAI for approved AI processing, Resend for email delivery, selected calendar or CRM providers, and Stripe for payments. We do not receive or store your full payment card details; payments and subscriptions are handled by Stripe.
- For legal reasons, to comply with applicable law, lawful requests, or to protect the rights, safety, and property of SwrlSite, our users, or the public.
- In a business transfer, if Swrl LLC is involved in a merger, acquisition, or sale of assets, subject to this policy.
- With your direction or consent.
Text messaging. Mobile phone numbers and text-message opt-in consent are never sold, and never shared with third parties or affiliates for marketing or promotional purposes. We use your number only to send the messages you asked for (for example, replies to your texts or a booking link you requested on a call) through our messaging provider acting on our instructions. Reply STOP at any time to opt out of texts.
8. How long we keep information
- Website screenshots and generated build/proposal files are stored privately for up to about one year and then deleted when no longer needed, unless deleted sooner or unless we need to keep them for a legitimate, documented business or legal reason.
- Lead and contact records (website, call, and project information) are kept while you are a prospect or client and for a reasonable period afterward for follow-up and recordkeeping.
- Marketing subscribers are kept until you unsubscribe, after which we retain a minimal suppression record so we do not email you again.
- Analytics records are retained for a limited period (by default about 13 months) and contain no direct identifiers.
- Chat assistant conversations are retained for about 90 days for quality and abuse prevention, then deleted when no longer needed.
- Billing and subscription records (service, status, and payment history from our payment processor) are kept while a managed service is active and for a reasonable period afterward to meet tax, accounting, and legal obligations. Full payment-card details are held by Stripe, not by SwrlSite.
- Client AI records follow the retention, export, and deletion terms in the accepted order. Provider records, call recordings, transcripts, messages, email or chat content, attachments, CRM history, and audit records may have different approved periods. Legal holds, security evidence, billing records, and opt out suppression records may be retained when required.
Private website-status and proposal links use long, unguessable tokens and are set to not be indexed by search engines. Treat these links as confidential and do not post them publicly.
9. Your choices and rights
- Access, correction, deletion: you can ask us to confirm what information we hold about you, correct it, or delete it.
- Marketing opt-out: click unsubscribe in any marketing email, or contact us. Opting out of marketing does not stop transactional messages about a request you made.
- Website-request deletion: ask us to delete your request, its screenshots, and generated files at any time.
- Your project and subscription data: after a project or managed service ends you keep your website, files, domain, portable business data, and customer-controlled accounts. We provide the standard export and included credentials under the accepted order and retain our own records only as long as needed for legitimate business, tax, security, or legal purposes.
- Client customer requests: if your information was handled for one of our clients, contact that business first. We will assist the client with verified access, correction, export, or deletion requests as required by the accepted order and applicable law.
To exercise any of these, email us at the address in the Contact section. We will verify your request and respond within the time required by applicable law. We will not discriminate against you for exercising your rights.
10. U.S. state privacy rights
Depending on your state of residence (for example, California, and other states with comprehensive privacy laws), you may have the right to know or access the personal information we collect, to request correction or deletion, to obtain a portable copy, and to opt out of the "sale" or "sharing" of personal information or targeted advertising. SwrlSite does not sell personal information and does not share it for cross-context behavioral advertising or targeted advertising. We do not use your information to make decisions that produce legal or similarly significant effects about you. To exercise a state privacy right, contact us as described below; you may use an authorized agent where the law allows.
11. Cookies and analytics
We use only essential, first-party cookies required for the site to function and to keep web forms secure (for example, session and anti-forgery cookies). We do not use third-party advertising or social-media tracking cookies. Our usage analytics are first-party and cookieless: they rely on a daily-rotating, non-identifying hash rather than persistent identifiers, so we can understand traffic trends without building a profile of you. Because we do not use cross-site tracking, we honor browser "Do Not Track" / Global Privacy Control signals by design.
12. International users
SwrlSite is operated from the United States and is intended primarily for U.S. small businesses. If you access the service from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your country. Where the EU/UK GDPR applies, our legal bases for processing are: performance of a request or contract (delivering the website or other service you asked for), your consent (marketing email), and our legitimate interests (operating, securing, and improving the service), and you may have additional rights of access, rectification, erasure, restriction, portability, and objection.
13. Children's privacy
The service is intended for business owners and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
14. Security
We use reasonable administrative and technical safeguards, including transport encryption (HTTPS), access controls, unguessable private links, and short data-retention windows for generated artifacts. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
15. Changes to this policy
We may update this policy as the service evolves or the law changes. When we do, we will revise the "Last updated" date above and, for material changes, take additional steps where required by law. Continued use of the service after an update means you accept the revised policy.
16. Contact us
Questions or privacy requests? Email contact@swrlsite.com.
Swrl LLC
This page describes our current practices in plain language. It is provided for transparency and is not legal advice. Please have it reviewed by a licensed attorney before relying on it for compliance.