Privacy Policy
The short version
The EchoSwarm app has no sign-up. There is no name, no email address and no password, and the app never asks for one. It creates a random account identifier on your device the first time it runs, and that identifier is the only thing that links you to your swarms. This website has one form, described in section 2, and it is the only place we ask for an address.
The text you write (the scenario and the agent personas) is sent to an AI provider so the agents can talk. We name those providers below and ask for your permission before the first prompt leaves your device. We do not run ads, we do not use analytics or tracking SDKs, and we do not sell or rent anything to anyone.
1. Who is responsible
Ahmet Cetin is the data controller for the EchoSwarm app. Contact: ahmet@kenwea.com.
2. What we store, and why
| Data | Why we have it | Kept for |
|---|---|---|
| Device account identifier — a random value generated on your device at first launch, plus the access token derived from it. | It is the entire account system. Without it we cannot show you your own swarms or apply your subscription. | Until you delete your data or uninstall and never return. |
| What you type — the scenario, the agent names and the persona descriptions for each swarm. | It is the input the AI agents are built from, and it is what we show you when you reopen a past swarm. | Until you delete the swarm or your data. |
| What the agents generate — the dialogue turns, the connections between agents, and the closing summary. | So a run can be reopened, replayed and exported. | Same as above. |
| Agent memory vectors — numeric embeddings of the dialogue, stored next to it. | They let an agent recall what was said earlier in its own run. | Same as above. |
| Subscription state — whether the purchase is active, its expiry, and the opaque transaction identifier from Apple or Google. | To unlock the paid tier and to honour a restore on a new device. | As long as the account exists, plus what tax law requires of the stores (the stores hold the transaction records, not us). |
| Operational data — app version, platform, request timestamps, error records, and counters used for rate limiting and the fair-use cap. | To keep the service up, to stop abuse, and to tell an out-of-date app to update. | Rolling, at most 90 days. |
| Reports you send — when you flag an agent's output as offensive, the flagged message and its swarm. | Both app stores require us to act on reports about AI output, and we cannot review what we cannot see. | 12 months. |
The launch-list form on this website
Everything above is about the app, which asks for nothing. The website has one form, on the front page, and it is the only place we ever ask for an email address. It exists to send you one message: the download link, on the day the app is available. Not a newsletter, and not a list we sell, rent, or hand to anyone. That message will still include an unsubscribe link and a link back to this page, exactly as any commercial email must.
| Data | Why we have it | Kept for |
|---|---|---|
| Your email address | To send the link, and to reply if you write back. | Until you ask us to delete it. |
| Your IP address | Stored with the request so automated abuse of the form can be spotted. | 90 days. |
Submissions are written to a file on our own server, not to a third-party form service, and are not shared with anyone. Write to ahmet@kenwea.com to have yours erased — the address you sent it from is enough to find it.
3. What we never collect
- Your name, phone number or postal address — anywhere. Your email address, anywhere in the app; the website's one form is the sole exception and is described in section 2.
- Your location, contacts, photos, microphone or camera. The app does not request those permissions.
- Advertising identifiers. EchoSwarm contains no advertising SDK, no analytics SDK and no third-party tracker. Nothing in the app follows you to another app or website.
- Payment card details. See section 6.
4. The AI providers
EchoSwarm cannot work without sending your scenario and persona text to a large language model. We ask for your explicit permission on first run, before anything is sent, and we name the providers there as well as here:
- DeepSeek (DeepSeek models) — generates the agent dialogue and the session summary, on both the free and the paid tier. DeepSeek is based in China, and we reach it through OpenRouter rather than calling it directly.
- Alibaba Cloud (Qwen models) — computes the embeddings used for agent memory on every tier. These requests also go through OpenRouter, not through Alibaba's own DashScope endpoint.
- NVIDIA Corporation (NIM) — the standby dialogue provider. Your text reaches NVIDIA only if the provider above is unavailable and the app falls back to it.
- OpenRouter LLC (OpenRouter API), United States — the routing service that carries our dialogue and embedding requests to the providers above, so your text passes through OpenRouter on the way.
What each provider receives: the scenario, the personas, the dialogue so far in that run, and our own instructions to the model. What it does not receive: your device account identifier, your subscription state, or any other swarm.
These providers act as our processors under their API terms, which do not permit them to use API inputs to train their models. They are not permitted to use your text for their own purposes. If we ever change providers, this page and the in-app consent screen change with it, and you are asked again.
If you withdraw consent, the app stops sending prompts. Existing swarms remain readable, but no new dialogue can be generated.
5. Where the data lives
Swarms are stored in a PostgreSQL database on a server we rent and administer ourselves. It is not a shared consumer cloud service and no third-party analytics platform has access to it.
The AI providers named in section 4 process requests on their own infrastructure, which is located outside Switzerland and the EEA. Where a transfer out of the EEA or the UK requires a safeguard, it rests on the provider's standard contractual clauses. Traffic between the app, our server and the providers is encrypted with TLS.
6. Payments
The subscription is sold and billed by Apple or Google, not by us. Card numbers, billing addresses and tax details are handled entirely inside the store and are never visible to us. What we receive is a signed receipt that we verify with the store, and from it we keep only the transaction identifier, the product, and the expiry date.
Cancel or manage the subscription in the App Store or Google Play account settings. Deleting your EchoSwarm data does not cancel a subscription. The store owns that, and you have to cancel it there.
7. Your rights
If you are in the EEA or the UK, the GDPR gives you the right to access, correct, erase, restrict, object to, and port your data. If you are in Switzerland, the Federal Act on Data Protection (FADP) gives you equivalent rights.
Because the account is anonymous, we usually cannot identify you from an email alone — we have no name or address to match against. Two ways to exercise your rights:
- In the app — Settings has Export session (your data as a file, on the paid tier) and Delete my data, which erases the account and everything attached to it from our server immediately and irreversibly.
- By email — write to ahmet@kenwea.com and include the account identifier shown at the bottom of the Settings screen, so we can find the right account. See the deletion page.
We answer within 30 days. If you believe we have handled your data badly, you may complain to your local supervisory authority. In Switzerland that is the Federal Data Protection and Information Commissioner (FDPIC).
8. Legal basis (EEA/UK)
- Contract — creating the anonymous account, storing your swarms, and running the subscription.
- Consent — sending your text to the AI providers in section 4. Withdrawable at any time in Settings.
- Legitimate interests — rate limiting, abuse prevention, and keeping the service running securely.
9. Children
EchoSwarm is not intended for children. The agents' dialogue is generated by a language model and is not suitable for a young audience, so the app is rated for teenagers and above on both stores. We do not knowingly store data from a child below the age of digital consent in their country. If you believe a child has used the app, write to ahmet@kenwea.com and we will delete the account.
10. Security
Traffic is TLS-only. The access token is held in the platform keystore (Keychain on iOS, EncryptedSharedPreferences on Android), not in plain application storage. Database access is restricted to the application server. No system is perfect, and we will tell affected users and the relevant authority if a breach ever warrants it.
11. Changes to this policy
If we change how data is handled in a way that affects you (a new provider, a new category of data), we update the effective date at the top, and the app asks for consent again where consent is the basis. Continuing to use the app after a purely editorial change means the updated page applies.
12. Contact
Ahmet Cetin
ahmet@kenwea.com