Swallow Privacy Policy

Last updated: July 2026

This Privacy Policy describes how Llow Group Limited, trading as Swallow (“Swallow”, “we”, “us” or “our”), collects, stores, uses and discloses personal data regarding individuals who:

  • Visit or otherwise interact with our website www.swallow.app, our web or mobile applications, or any subdomain (collectively the Sites); or
  • Use the Swallow pricing operations platform, APIs, MCP server or any other Swallow product or service (together with the Sites, the Swallow Services), whether as an individual account holder, as a user of a customer organisation, or as an administrator on behalf of a customer organisation.

Please read this Privacy Policy carefully. You are not legally required to provide us with personal data, but without it we may be unable to provide the Swallow Services to you.

This Privacy Policy forms part of our Terms and Conditions. Capitalised terms not defined here have the meaning given in the Terms.

1. Data controller and Data Protection Officer

Swallow is the data controller for personal data described in this Policy, except where we act as data processor on behalf of a customer (see section 10).

Controller
Llow Group Limited (company no. 14334541)
3rd Floor
86–90 Paul Street
London EC2A 4NE
United Kingdom

Data Protection Officer
Callum Rimmer
contact@llow.io

ICO registration
We are registered with the UK Information Commissioner’s Office (registration C1340741).

2. Data we collect

2.1 Account and profile data

When you register, we collect your name, email address, workplace or company name, password (stored as a hash, not in clear), and, optionally, other profile details you provide.

If you sign up via a federated identity provider (for example a magic-link email flow or a social login such as Google or Microsoft), we receive the identifiers and profile details that provider passes to us.

2.2 Authentication and API usage data

We collect API keys, OAuth client IDs and secrets you issue, MCP session tokens, request logs (including timestamp, endpoint, tool name, response size and error status), IP address, user agent string and quota accounting data.

2.3 Customer Data you submit

This includes pricing models, projects, tests, calculations, uploaded spreadsheets, custom prompts and any other content you enter into the Swallow Services.

You retain ownership of Customer Data. See the Terms and Conditions for the licence you grant us to host and process it.

2.4 Billing data

If you subscribe to a paid tier, our payment processor Stripe collects your payment details (card number, billing address and related information) directly.

We receive from Stripe a customer identifier, subscription status, invoice history and the last four digits of your card, but we do not store your full card details.

2.5 Automatically collected data

We collect connectivity, technical and aggregated usage data including:

  • IP address
  • General location
  • Device and browser attributes
  • Session identifiers
  • Cookie and tracking technology data (see our Cookie Policy)
  • Activity timestamps
  • Pages visited on the Sites

2.6 Communications

We keep records of correspondence with our support team, feedback you submit and any calls with our team where we notify you that recording is taking place.

3. Uses

3.1

We use personal data to:

  • Provide, operate and secure the Swallow Services
  • Authenticate users and enforce access controls and quotas
  • Provide customer support and technical assistance
  • Invoice, collect payment and administer subscriptions
  • Send transactional communications including billing notices, service updates and security alerts
  • Send marketing communications where required by law and with your consent where applicable
  • Analyse and improve the Swallow Services using aggregated, anonymised or pseudonymised usage statistics
  • Detect, investigate and prevent fraud, abuse and security incidents
  • Comply with legal and regulatory obligations

3.2

We do not sell your personal data.

3.3

We do not use Customer Data or your prompts to train third-party large language models.

Requests sent to our AI subprocessors (Google Gemini and Anthropic Claude) are transmitted under contractual terms that prohibit those providers from using the data to train their public models.

3.4 Automated decision making

The Swallow Services use machine learning models (including large language models and structured extraction models) to suggest inputs, structure content and assist in authoring pricing models.

These tools assist your work but do not produce decisions with legal or similarly significant effects. You remain responsible for any decisions or outputs you produce using the Swallow Services.

4. Legal basis (UK/EU GDPR)

For users in the United Kingdom or European Economic Area, our lawful bases are:

  • Contract — processing necessary to provide the Swallow Services
  • Legitimate interests — securing the platform, preventing fraud, understanding usage and communicating about your account
  • Legal obligation — complying with tax, accounting and other legal requirements
  • Consent — non-essential cookies and marketing communications where consent is required

You may withdraw consent at any time.

5. Data location and international transfers

5.1

The Swallow Services and supporting infrastructure, including hosting, authentication, databases, backups and disaster recovery systems, are located in the United States.

5.2

Where personal data is transferred outside the United Kingdom or European Economic Area, we rely on appropriate safeguards including:

  • UK Extension to the EU-US Data Privacy Framework
  • International Data Transfer Agreement (IDTA)
  • European Commission Standard Contractual Clauses

6. Service providers

6.1

We engage selected third-party providers to help operate the Swallow Services.

These may include providers of:

  • Hosting
  • Content delivery networks
  • Security services
  • Payment processing
  • Fraud prevention
  • Analytics
  • Email delivery
  • Marketing
  • Monitoring
  • Session recording
  • Remote access
  • Data enrichment
  • AI model inference
  • Advertising
  • Customer support
  • Legal, compliance and financial advice

6.2

These providers may access personal data only where necessary to perform services on our behalf and only for the purposes agreed in our contracts with them.

6.3

Where Swallow acts as data controller, these providers act as data processors.

Where Swallow acts as data processor for a customer, these providers act as subprocessors.

7. Data retention

7.1

We retain personal data only for as long as necessary to provide the Swallow Services, comply with legal obligations and defend legal claims.

7.2 Typical retention periods

  • Account data: lifetime of the account plus six years after closure
  • Customer Data: lifetime of the account plus the export period described in the Terms and Conditions
  • API request logs: 90 days in hot storage and 12 months for aggregated or anonymised analytics
  • Billing records: six years
  • Marketing consent records: while consent remains active plus a reasonable audit period

7.3

We may retain personal data for longer where required by law or in connection with an active dispute.

8. Data security

8.1

We apply industry standard technical and organisational measures including:

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest
  • Role based access controls
  • Secret management
  • Audit logging
  • Least privilege operating practices

No online service can guarantee absolute security.

8.2

If we become aware of a personal data breach affecting your personal data, we will notify you and the appropriate supervisory authority where required by law.

9. Your rights

9.1

Where UK or EU GDPR applies, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request erasure
  • Restrict processing
  • Object to processing
  • Receive a copy of your data
  • Withdraw consent where processing relies on consent

9.2

To exercise your rights, email contact@llow.io.

We may need to verify your identity before responding.

9.3

If we process your data on behalf of a customer organisation, please contact that organisation’s administrator.

9.4

If you believe we have handled your data unlawfully, you may complain to the UK Information Commissioner’s Office on 0303 123 1113 or via ico.org.uk, or to your local supervisory authority within the EEA.

10. Controller and processor roles

10.1

For visitors, individual account holders and administrators, Swallow acts as the data controller.

10.2

Where a customer organisation provides access to the Swallow Services for its employees or contractors, that customer acts as data controller and Swallow acts as data processor under our Data Processing Agreement.

10.3

If your data is processed on behalf of a customer organisation, please contact that organisation directly with any requests.

11. Cookies and tracking

11.1

The Sites use cookies and similar technologies as described in our Cookie Policy.

Non-essential cookies are only used with your consent.

Our API and MCP endpoints do not use cookies and instead authenticate using bearer tokens.

12. Communications

12.1

We may send transactional communications relating to billing, service availability, security notifications and password resets. These cannot be opted out of while your account is active.

12.2

We may also send marketing communications where permitted by law and where you have consented where required.

You can unsubscribe at any time using the link in each email or by contacting contact@llow.io.

13. Children

The Swallow Services are not intended for individuals under 16 years of age.

If we become aware that we have collected personal data from a child, we will delete it.

14. External links

The Sites may contain links to third-party websites.

We are not responsible for their privacy practices and encourage you to review their privacy policies before providing personal data.

15. Updates

We may update this Privacy Policy from time to time.

Where changes are material, we will notify you through the Sites or by email.

Continued use of the Swallow Services after changes take effect constitutes acceptance of the updated policy.

16. Contact

For any questions, requests or complaints relating to this Privacy Policy or your personal data:

Llow Group Limited (trading as Swallow)
Attn: Data Protection Officer
3rd Floor
86–90 Paul Street
London EC2A 4NE
United Kingdom

Email: contact@llow.io