Legal
Privacy Policy
Effective date: August 15, 2026
1. Who We Are & This Policy
SwiftyQuill ("we", "us", or "our") operates the voice-first note-taking and AI workspace available at https://swiftyquill.com(the "Service"). This Privacy Policy explains what information we collect when you use SwiftyQuill, how we use and protect it, and the rights you have over your data.
This policy applies to all users of the Service, including registered accounts, guests who only browse our public site, and users who connect external tools (such as Google, WhatsApp, or MCP clients) to their workspace. By using the Service, you agree to the practices described here.
2. Information We Collect
Information you provide directly:
- Account details — username, email address, a securely hashed password, and an optional profile picture when you register or sign in.
- Content you create — your notes, titles, tags, colors, pinned/starred state, and any audio recordings (voice memos) or images you upload.
- Personalization — settings such as your language preference for transcription and interface theme choices.
- Sharing activity — the fact that you shared a note with another SwiftyQuill user.
- Communications — any reports, bug reports, or support messages you send us.
Information we collect automatically:
- Usage & technical data — IP address, browser type and device information, and approximate location inferred from your IP address, used for security and diagnostics.
- Transaction and subscription data — if you subscribe or pay, we keep a record of the plan, payment status, currency, and a transaction reference. We do not store your full card number; payments are authorized through a third‑party payment processor.
- Connection data — records of MCP connections, plugin connections (e.g., Google), agent runs, and linked accounts, including access scopes and timestamps.
3. How We Use Your Information
- Provide, operate, and maintain the Service, including storing and syncing your notes and media.
- Transcribe your audio recordings and generate summaries, action items, key insights, and tags using our AI provider.
- Run your personal AI agent when you invoke it, including executing tasks you request against your connected tools.
- Verify your account, reset passwords, and send service or security emails.
- Enforce our rules and keep the platform safe — including detecting abuse, spam, and content that violates our standards.
- Analyze aggregate, non‑identifying usage trends to improve features and performance.
- Comply with legal obligations and protect our rights and the rights of other users.
4. Legal Bases for Processing (GDPR)
If you are located in the EEA, UK, or Switzerland, we process personal data on the following legal bases:
- Performance of a contract — to provide the Service you request and to manage your subscription.
- Consent — for optional features such as connecting third‑party services, where you can withdraw consent at any time.
- Legitimate interests — to secure the platform, prevent fraud and abuse, and improve the Service, balancing that against your rights.
- Legal obligation — where we must retain or disclose data to comply with law.
5. AI Processing of Your Content
SwiftyQuill uses artificial intelligence to give your voice memos and notes structure. To do this, the Service sends the content required for the specific task to our AI provider (currently the Groq platform) using models such as whisper-large-v3 (speech‑to‑text) and llama-3.3-70b-versatile (structuring and agent execution).
Important: this means audio, transcripts, and note text you process through AI features are transmitted to and processed by our third‑party AI provider. We only send what is needed for the task you requested. We do not use your content to train our own models, and we do not sell your content.
Your notes remain private to your account unless you explicitly share them or connect them to an external service. You can disable AI‑dependent features simply by not using them; note‑taking itself does not require AI processing.
6. Third‑Party Services & Data Sharing
We share information only with the service providers needed to run SwiftyQuill, and only as required to deliver the Service:
- AI provider (Groq) — receives audio and text as described in Section 5.
- Hosting, database & storage (Cloudflare R2, PostgreSQL) — store your notes, transcripts, and uploaded media securely.
- Email provider (Resend) — delivers verification, password‑reset, and transactional emails.
- Authentication providers (NextAuth, Google Sign‑In) — handle sign‑in flows; if you sign in with Google, we receive the profile information you authorize.
- Payment processor — processes subscription payments. Full card details are handled by the processor and never stored by us.
We do not sell your personal information, and we do not allow third parties to use your data for their own purposes. We may disclose data when required by law, to enforce our terms, or to protect the safety of our users.
7. Connected Services, Plugins & MCP
SwiftyQuill lets you connect external services — such as your Google account (calendar/Drive), WhatsApp, and external MCP clients and AI assistants — to your workspace. When you connect a service:
- We record the connection, the access scopes you granted, and your connection preferences.
- We access that service's data only when you explicitly request it (for example, running an agent task).
- Tokens are encrypted at rest and scoped to the minimum permissions you approve.
- You can disconnect or revoke any connection at any time, after which we stop accessing that service and remove associated tokens.
Once data leaves SwiftyQuill to a third‑party service you connected, that service's own terms and privacy policy apply.
8. Cookies & Local Storage
We use strictly necessary cookies and local storage to keep you signed in and to remember preferences such as your theme. We do not use third‑party advertising or tracking cookies for cross‑site behavioural advertising.
You can clear cookies and site data through your browser at any time; doing so may sign you out.
9. Data Security
- Passwords are hashed using a one‑way cryptographic hash (bcrypt) before storage.
- All traffic to and from the Service is encrypted in transit (TLS).
- Connection tokens and credentials for connected services are encrypted at rest and never returned in plaintext.
- Access control lists, role‑based permissions, and audit logs help prevent and detect unauthorized access.
- We review and limit access to personal data to authorized personnel only.
10. Data Retention
We keep your personal data only for as long as needed to provide the Service and to comply with legal, accounting, or security obligations. You may delete your account and your content at any time; when you do, we delete or anonymize your notes, recordings, and account data, except where we are required by law to retain limited records (for example, payment and audit records).
11. International Data Transfers
SwiftyQuill operates globally and may process data in the United States and other jurisdictions where our providers are located. Where personal data is transferred out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses to protect your data.
12. Your Rights & Choices
For all users, you can:
- Access and export your notes and account data.
- Delete individual notes or your entire account.
- Manage connections — revoke Google, WhatsApp, or MCP access at any time.
- Withdraw consent for optional AI or connected-service features.
Under the GDPR (EEA/UK/Switzerland), you also have the right to: access, rectify, request erasure, restrict processing, object to processing, and data portability. You may also lodge a complaint with your local supervisory authority.
Under the CCPA/CPRA (California), you have the right to: know what personal information we collect, use, and disclose; request deletion of your personal information; and opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information — as those terms are defined under the CCPA — and we do not use your data for cross‑context behavioural advertising. You also have the right to non‑discrimination for exercising these rights.
To exercise any of these rights, contact us at support@swiftyquill.com. We will respond within the timeframe required by applicable law (generally 30 days) and may need to verify your identity first. Authorized agents may submit requests on your behalf.
13. Children & COPPA
SwiftyQuill is not directed at children under 13 years of age (or under 16 in the EEA, per GDPR). We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact support@swiftyquill.com and we will promptly delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date below and, where appropriate, notify you within the Service. Continued use of the Service after changes take effect means you accept the updated policy.
15. Contact Us
If you have questions or requests regarding privacy, please contact us at support@swiftyquill.com or write to SwiftyQuill, care of our support team, and we will respond promptly.