PRIVACY
Privacy Policy.
This policy explains how Schwen Scalability ("we," "us") collects, uses, and shares personal information, and the choices you have. It covers both the information we collect about our own clients and prospects, and — separately — the data we process on our clients' behalf when we host their sites, apps, databases, and email.
1. Our Two Roles
As a controller. When you interact with us as a client or prospect — through our site, intake, or portal — we decide how your personal information is used, and this policy governs.
As a processor.When we host a client's website, application, database, or email, we process the personal data of that client's end users on the client's behalf and under their instructions. For that data, the client is the controller and their privacy policy governs; we act as a service provider / processor and handle the data only to provide the services. A Data Processing Addendum (DPA) is available to clients on request — email matthew@schwen.me.
2. Information We Collect
- Account & contact information — name, email, company, and similar details you provide when you sign up, book a call, or contact us.
- Intake conversation content — what you tell our intake AI assistant and in the portal about your project, needs, and goals. The AI assistant processes this conversation content to run onboarding and help scope your project.
- Uploaded documents & project details — text and PDF files are converted to extracted text; uploaded images are sent to Anthropic for a text description. The extracted text or image description is stored with the intake and used as project context. The current upload limit is eight files per intake session.
- Usage & telemetry — service telemetry for your own projects (such as uptime and latency), and basic technical logs (IP address, device/browser, timestamps) used to operate and secure the services.
- Public-site analytics, only with consent — if you choose "Allow analytics," Google Analytics receives public-page URLs, referral and campaign information, approximate location derived from IP address, device/browser information, and interactions such as page views, scrolling, outbound clicks, project-intake starts, and completed intakes. We do not send intake answers, account details, uploaded files, email addresses, names, or client-portal activity to Google Analytics.
- Cookies and local storage — a small number of cookies or browser-storage values are used for sessions, sign-in, security, preferences, and your analytics choice. Google Analytics cookies are created only after you allow analytics. We do not use advertising trackers.
- Payment information — when you subscribe or pay an invoice, Stripe processes the payment through its hosted pages. We receive limited billing, subscription, invoice, and payment-status metadata but do not see or store your full card or bank-account number.
- Client end-user data (as processor) — whatever personal data your hosted site, app, or database collects from your end users. We process this only on your behalf, per Section 1.
3. How We Use Information
- to provide, provision, operate, secure, and support the services;
- to run onboarding and intake, including via the AI assistant, and to scope and deliver consulting work;
- to communicate with you — verify your email, book calls, send expected service emails (welcome, reminders, sign-in codes), send a limited intake follow-up sequence, and respond to inquiries. Sales and intake-recovery emails include a preference link; opting out does not suppress essential account, billing, security, or service notices;
- to bill for subscribed services and invoices through our payment processor;
- with your consent, to understand public-site traffic and improve the paths people use to contact us or begin an intake;
- to monitor, troubleshoot, and improve reliability and performance; and
- to comply with law and enforce our Terms and Acceptable Use Policy.
We do not sell or share your personal information for cross-context behavioral advertising, and we do not use advertising trackers.
4. Legal Bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the services you request); legitimate interests (to secure, operate, and improve the services, and to communicate with prospects), balanced against your rights; consent (for Google Analytics and where required for certain communications); and legal obligation (to meet our compliance and record-keeping duties). Where we act as a processor, we process on the documented instructions of the client controller.
5. Subprocessors & Sharing
We use a small set of trusted subprocessors to deliver the services (for hosting, databases, email delivery, DNS, source-code storage, and AI). A current list, and what each does, is on our Subprocessors page. We may also share information with our payment processor, with professional advisors, to comply with law or lawful requests, or in connection with a merger, acquisition, or sale of assets (with continued protection of your information). We do not sell your personal information.
6. AI Assistant
Our intake and portal assistants use Anthropic to generate responses and project-preparation material. We send the relevant conversation, saved project details, and extracted uploaded-document text or image descriptions to Anthropic as model context. An original uploaded image is also sent to Anthropic once so it can be described; text and PDF uploads are parsed by our server and their extracted text is used. We use those calls to provide the requested assistant features, not to build or train our own model. Anthropic's handling of API data is also governed by its applicable terms and privacy commitments.
7. Google Sign-In (When Available)
If Google Sign-In is configured and you choose it, Google's sign-in script runs in your browser and returns an identity token. Our server asks Google to validate that token. For intake verification we may save the verified email address, name, and Google profile-image URL; portal sign-in uses the verified email address to determine whether an existing project account is eligible. Email-code sign-in remains available without Google.
8. Private GitHub Project Context
After a verified intake completes and the GitHub integration succeeds, the system creates a private repository in a Schwen-managed GitHub account for that engagement. It copies the project summary and intake transcript into INTAKE.mdand copies extracted document text or image descriptions into Markdown context files. The original uploaded binary file is not copied by this workflow. The repository also receives a seed Project Brain/Graphify graph so later project work can use the same context. Repository creation is deferred or skipped when verification or the GitHub integration is unavailable.
9. Data Retention & Deletion
We keep personal information for as long as needed to provide the services and for legitimate business and legal purposes (such as billing records and dispute resolution). Current limitation: there is not yet a fixed automated deletion schedule for intake database rows or the private GitHub context repository. A deletion request may therefore require coordinated manual removal from the intake database and GitHub. Data may not disappear immediately from provider backups or logs; their handling depends on provider terms and any legal obligations. Hosted-service export and termination expectations are described in our Terms. You may request access, export, correction, or deletion at any time; we will confirm what was removed and identify any data we must retain.
10. Security
We use administrative, technical, and organizational safeguards appropriate to the risk — including access controls, encryption in transit, least-privilege practices, and reputable infrastructure providers. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
11. Breach Notification
If we become aware of a personal-data breach affecting your information, we will notify affected clients without undue delay and cooperate as needed to meet applicable notification obligations. Where we act as a processor, we will notify the client controller so they can meet their own obligations.
12. International Transfers
We and our subprocessors may process information in the United States and other countries. Where required, we rely on appropriate transfer mechanisms (such as the EU Standard Contractual Clauses and UK equivalents) to protect personal information transferred across borders.
13. Your Rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent.
EEA/UK (GDPR). You may exercise the rights above and lodge a complaint with your local supervisory authority.
California (CCPA/CPRA).You may request to know, delete, and correct personal information, and to opt out of "sale" or "sharing" — though we do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising your rights.
To exercise any right, email matthew@schwen.me— we'll respond promptly and within the timeframes required by law, no forms. If you are an end user of a client's hosted service, please contact that client (the controller); we will support their response.
14. Cookies & Analytics Choices
Necessary storage supports sessions, authentication, security, and preferences. Google Analytics is optional: its script does not load, and no analytics cookie or measurement request is made, until you affirmatively allow it. Analytics is excluded from every client-portal route. The Google Analytics property is configured without Google Signals or advertising personalization, and event-level analytics data is retained for 14 months. We do not use advertising trackers.
You can allow, refuse, or later withdraw analytics consent using . Withdrawing consent stops future analytics collection and removes accessible Google Analytics cookies from this site. Browser controls can also block cookies, though disabling necessary storage may break sign-in.
15. Children
Our services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
16. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will provide reasonable notice (for example, by email or in your portal) and update the "last updated" date below.
17. Contact
Questions or requests: matthew@schwen.me.
Schwen Scalability · Last updated: July 31, 2026 · schwenscalability.com