Privacy Policy
Last updated: July 25, 2026 ยท Effective: July 25, 2026
SwarmLabs ("we") is committed to protecting your privacy. This policy explains what data we collect, how we use and store it, and the rights you have. We follow a data-ownership principle โ your experimental data belongs to you; we do not sell or share your research data with third parties.
1. Data we collect
1.1 Data you provide
- Email address โ for account registration, sign-in, and important notices
- Password โ stored only as a one-way hash; the plaintext is never stored
- Experiment parameters & configurations โ parameters you enter, engines you select, optimization settings
- Project names & notes โ research projects and notes you create
1.2 Data collected automatically
- Usage logs โ API call records, experiment run counts, credit consumption records
- Technical information โ browser type, access time, time spent on pages (for performance optimization)
- Transaction records โ credit purchases, subscription payments (processed via the Creem payment platform)
1.3 Data we do not collect
- We do not collect your real name, national ID, or phone number (unless you provide them voluntarily during payment
- We do not collect biometric information
- We do not track your browsing behavior on third-party sites
- We do not read your contacts or social graph
2. How data is used
| Purpose | Data involved | Legal basis |
| Providing the virtual experiment service | email, experiment parameters, credit balance | Contract performance |
| Account management & authentication | email, password hash, session token | Contract performance |
| Processing payments | email, purchase records | Contract performance |
| Product improvement & bug fixes | usage logs, error reports | Legitimate interest |
| Sending service notifications | email | Legitimate interest |
Our commitment: We will never sell your experimental data, research parameters, or usage behavior to third parties. We will never use it to train third-party AI models. Your research intellectual property belongs to you.
3. Data storage & security
3.1 Storage locations
- User account data โ stored in Cloudflare KV (global edge network), encrypted in transit (TLS 1.3). Includes: email, password hash (PBKDF2-SHA256), credit balance, subscription plan, transaction records (last 50), Creem customer ID (
_creem_customer_id) and subscription ID (_creem_sub_id, used to match renewal credit grants), daily credit usage and reset time
- Experiment run data โ stored in Cloudflare Workers memory (session-scoped); raw experiment inputs are not persisted
- Payment data โ handled by the Creem payment platform; SwarmLabs does not store card details. We retain only the Creem-assigned customer ID and subscription ID for payment matching; no payment credentials are stored
- Literature retrieval data โ fetched in real time via the Crossref API; original paper content is not cached
3.2 Security measures
- Passwords are stored with a one-way hash and cannot be reversed
- All API communication is forced over HTTPS (TLS 1.3)
- Webhook callbacks are verified with HMAC-SHA256 signatures to prevent forgery
- CORS policy is restricted to trusted domains
- Regular security scans: XSS, CSRF, configuration-leak checks
- KV data uses TTL expiry so inactive data is auto-cleaned
4. Third-party services
SwarmLabs uses the following third-party services, each with its own privacy policy:
| Service | Purpose | Data processed |
| Cloudflare | Hosting, KV storage, CDN | IP address, request logs |
| Creem | Payment processing | email, payment information |
| Crossref | Academic literature search | search keywords |
5. Data retention
- Account data โ retained for the life of the account, purged within 30 days of deletion
- Transaction records โ retained for 7 years (tax-compliance requirement)
- Usage logs โ retained for 90 days
- Session token โ auto-expires after 7 days
6. Your rights
Under applicable data-protection laws (including the GDPR and other regulations such as China's Personal Information Protection Law where relevant), you have the right to:
- Access โ request a copy of your personal data
- Rectification โ request correction of inaccurate data
- Erasure โ request deletion of your account and associated data
- Data portability โ export your data in a structured format
- Objection โ object to certain data-processing activities
- Withdraw consent โ withdraw previously given consent at any time
To exercise any of these rights, email privacy@swarmlabs.tools.
7. Cookie usage
SwarmLabs uses only the essential session storage (sessionStorage) needed to keep you signed in. We do not use tracking cookies or third-party advertising trackers.
8. Children's protection
SwarmLabs is built for researchers and adult scholars; it is not directed at children under 13. We do not knowingly collect personal data from minors.
9. International data transfers
Your data may be processed and stored across Cloudflare's global edge network. Cloudflare handles cross-border transfers in accordance with the GDPR and other applicable data-protection regulations.
10. Policy updates
We may update this Privacy Policy from time to time. For material changes we will notify you by email or through the site. Continued use of the service after an update constitutes acceptance of the revised policy.