Privacy Policy

Last updated: May 2026

1. Introduction

SwiftReplyAgent ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect information when you use the SwiftReplyAgent service available at swiftreplyagent.com.

SwiftReplyAgent is operated from Malta and complies with the EU General Data Protection Regulation (GDPR).

2. Information We Collect

We collect the following categories of information:

  • Account information: name, email address, organisation name, and authentication credentials.
  • Uploaded documents: brochures, price lists, schedules, FAQs and other files you choose to upload to your agents' knowledge bases.
  • Email content: the subject and body of emails you explicitly choose to generate reply drafts for. This information is processed only for the duration necessary to generate the requested response.
  • Usage data: token usage, number of agents, run history, and basic product analytics.
  • Technical data: IP address, browser type, device information, and access logs for security purposes.

3. How We Use Your Data

  • To provide, maintain, and improve the SwiftReplyAgent service.
  • To generate AI-powered reply drafts based on the documents and email content you submit. Email content is processed only when you explicitly request a draft reply from within a supported email client.
  • To monitor usage against your plan's quotas and to bill you correctly.
  • To communicate service updates, security notices, and customer support replies.

AI Service Providers

SwiftReply uses carefully selected third-party AI inference providers to generate AI-powered responses.

Customer data is processed solely for the purpose of generating the response explicitly requested by the user and is not used by SwiftReplyAgent to train, improve or develop generalized artificial intelligence or machine learning models.

SwiftReply requires that AI inference providers process customer data only for inference and not for generalized model training.

We do not sell your data to third parties.

SwiftReplyAgent does not use your documents, email content or other customer data to train, improve or develop generalized artificial intelligence or machine learning models.

Where third-party AI inference providers are used to generate responses, customer data is processed solely for the purpose of generating the requested reply and is not shared for model training or secondary purposes.

The use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data Storage and Security

Your data is encrypted in transit (TLS) and at rest. We host data in EU and US data centres operated by reputable cloud providers under appropriate data protection agreements.

Access to your data is restricted to authorised personnel who require it to operate the service. We follow industry-standard security practices including least-privilege access, regular security reviews, and audit logging.

5. Email Platform Data

When you use SwiftReplyAgent with Gmail™ or Microsoft Outlook, only the email you have currently opened and explicitly selected for processing is accessed.

Email content is transmitted securely to SwiftReplyAgent solely to generate the AI-powered draft reply that you requested.

SwiftReplyAgent does not scan mailboxes, access other emails, or process email content in the background.

SwiftReplyAgent creates draft replies only. Emails are never sent automatically. You remain in full control of reviewing, editing and sending any generated draft.

6. Your Rights

Under GDPR you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data.
  • Export your data in a portable format.
  • Object to or restrict certain processing activities.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, contact [email protected].

7. Cookies

We use a small number of essential cookies for authentication and session management. We use privacy-respecting analytics to understand product usage. We do not use advertising or third-party tracking cookies.

8. Data Retention

We retain your account data for as long as your account is active. If you delete your account, your documents and personal data are removed from our active systems within 30 days, with backups purged within 90 days.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or through an in-product notice.

10. Contact

For privacy questions, contact [email protected].

This policy is governed by the laws of Malta and the European Union.