PRIVACY

Privacy Policy.

This policy explains how Schwen Scalability ("we," "us") collects, uses, and shares personal information, and the choices you have. It covers both the information we collect about our own clients and prospects, and — separately — the data we process on our clients' behalf when we host their sites, apps, databases, and email.

Template — not legal advice. This is a template for review by qualified counsel, not legal advice. It should be reviewed and completed before it is relied upon.

1. Our Two Roles

As a controller. When you interact with us as a client or prospect — through our site, intake, or portal — we decide how your personal information is used, and this policy governs.

As a processor.When we host a client's website, application, database, or email, we process the personal data of that client's end users on the client's behalf and under their instructions. For that data, the client is the controller and their privacy policy governs; we act as a service provider / processor and handle the data only to provide the services. A Data Processing Addendum (DPA) is available to clients on request — email matthew@schwen.me.

2. Information We Collect

3. How We Use Information

We do not sell or share your personal information for cross-context behavioral advertising, and we do not use advertising trackers.

4. Legal Bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the services you request); legitimate interests (to secure, operate, and improve the services, and to communicate with prospects), balanced against your rights; consent (for Google Analytics and where required for certain communications); and legal obligation (to meet our compliance and record-keeping duties). Where we act as a processor, we process on the documented instructions of the client controller.

5. Subprocessors & Sharing

We use a small set of trusted subprocessors to deliver the services (for hosting, databases, email delivery, DNS, source-code storage, and AI). A current list, and what each does, is on our Subprocessors page. We may also share information with our payment processor, with professional advisors, to comply with law or lawful requests, or in connection with a merger, acquisition, or sale of assets (with continued protection of your information). We do not sell your personal information.

6. AI Assistant

Our intake and portal assistants use Anthropic to generate responses and project-preparation material. We send the relevant conversation, saved project details, and extracted uploaded-document text or image descriptions to Anthropic as model context. An original uploaded image is also sent to Anthropic once so it can be described; text and PDF uploads are parsed by our server and their extracted text is used. We use those calls to provide the requested assistant features, not to build or train our own model. Anthropic's handling of API data is also governed by its applicable terms and privacy commitments.

7. Google Sign-In (When Available)

If Google Sign-In is configured and you choose it, Google's sign-in script runs in your browser and returns an identity token. Our server asks Google to validate that token. For intake verification we may save the verified email address, name, and Google profile-image URL; portal sign-in uses the verified email address to determine whether an existing project account is eligible. Email-code sign-in remains available without Google.

8. Private GitHub Project Context

After a verified intake completes and the GitHub integration succeeds, the system creates a private repository in a Schwen-managed GitHub account for that engagement. It copies the project summary and intake transcript into INTAKE.mdand copies extracted document text or image descriptions into Markdown context files. The original uploaded binary file is not copied by this workflow. The repository also receives a seed Project Brain/Graphify graph so later project work can use the same context. Repository creation is deferred or skipped when verification or the GitHub integration is unavailable.

9. Data Retention & Deletion

We keep personal information for as long as needed to provide the services and for legitimate business and legal purposes (such as billing records and dispute resolution). Current limitation: there is not yet a fixed automated deletion schedule for intake database rows or the private GitHub context repository. A deletion request may therefore require coordinated manual removal from the intake database and GitHub. Data may not disappear immediately from provider backups or logs; their handling depends on provider terms and any legal obligations. Hosted-service export and termination expectations are described in our Terms. You may request access, export, correction, or deletion at any time; we will confirm what was removed and identify any data we must retain.

10. Security

We use administrative, technical, and organizational safeguards appropriate to the risk — including access controls, encryption in transit, least-privilege practices, and reputable infrastructure providers. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

11. Breach Notification

If we become aware of a personal-data breach affecting your information, we will notify affected clients without undue delay and cooperate as needed to meet applicable notification obligations. Where we act as a processor, we will notify the client controller so they can meet their own obligations.

12. International Transfers

We and our subprocessors may process information in the United States and other countries. Where required, we rely on appropriate transfer mechanisms (such as the EU Standard Contractual Clauses and UK equivalents) to protect personal information transferred across borders.

13. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent.

EEA/UK (GDPR). You may exercise the rights above and lodge a complaint with your local supervisory authority.

California (CCPA/CPRA).You may request to know, delete, and correct personal information, and to opt out of "sale" or "sharing" — though we do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising your rights.

To exercise any right, email matthew@schwen.me— we'll respond promptly and within the timeframes required by law, no forms. If you are an end user of a client's hosted service, please contact that client (the controller); we will support their response.

14. Cookies & Analytics Choices

Necessary storage supports sessions, authentication, security, and preferences. Google Analytics is optional: its script does not load, and no analytics cookie or measurement request is made, until you affirmatively allow it. Analytics is excluded from every client-portal route. The Google Analytics property is configured without Google Signals or advertising personalization, and event-level analytics data is retained for 14 months. We do not use advertising trackers.

You can allow, refuse, or later withdraw analytics consent using . Withdrawing consent stops future analytics collection and removes accessible Google Analytics cookies from this site. Browser controls can also block cookies, though disabling necessary storage may break sign-in.

15. Children

Our services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.

16. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will provide reasonable notice (for example, by email or in your portal) and update the "last updated" date below.

17. Contact

Questions or requests: matthew@schwen.me.

Schwen Scalability · Last updated: July 31, 2026 · schwenscalability.com