Privacy Policy

Swell is operated by Forgewell, LLC. This policy explains the data Swell needs to run scheduling, billing, analytics, and publishing workflows.

Last updated July 5, 2026.

Information Swell Processes

Swell stores account details, workspace settings, connected social account metadata, provider token references, uploaded media, post captions, scheduled publishing state, analytics events, tracked links, support correspondence, and operational history.

Billing and Payments

Swell uses Stripe to process subscription checkout and customer portal workflows. Swell does not store raw card numbers. Stripe may process billing contact details, payment methods, invoices, tax data, and subscription state under its own privacy terms.

Company and Privacy Contact

Swell is operated by Forgewell, LLC, 56 Broad St STE 14266, Boston, MA 02109. Privacy, legal, export, deletion, and DPA requests should be sent to legal@growonswell.com. Forgewell, LLC's registered agent is Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713 US.

Cookies and Security

Swell uses HTTP-only session cookies, CSRF protection, and login throttling to protect accounts and workspaces.

Analytics and Session Replay

Swell uses first-party analytics to measure page views, events, conversions, web performance, bot visits, and campaign attribution. When session replay is enabled by a workspace, Swell may collect privacy-masked interaction timelines, viewport changes, clicks, scrolls, and page paths so workspace owners can debug product experience and attribution issues. For paid traffic and other visitor-facing installs, customers should present a tracking notice and require affirmative visitor consent before enabling persistent browser identifiers, autocapture, or replay. Replay masks rendered text and form input values globally by default, but customers must still block sensitive media, embedded content, and whole private regions. Replay should not be used to collect passwords, payment card numbers, health data, government identifiers, or other sensitive values.

Retention

Analytics and replay records are retained according to the workspace plan unless a shorter legal, security, or operational limit applies: Starter workspaces keep up to 30 days, Growth up to 180 days, and Scale up to 730 days. Bot-visit records default to 180 days. Backups, logs, billing records, security records, and legal holds may persist for a limited period after primary records are deleted.

Social Platforms and Publishing

Connected social platforms process only the account, media, caption, schedule, token, and provider response data needed to publish and report status.

Subprocessors and Service Providers

Swell may use hosting, database, storage, email, billing, error-monitoring, social platform, revenue, paid-ad, and AI media-generation providers to operate the service. Current provider categories include DigitalOcean, AWS-compatible storage, Resend, Stripe, OpenAI, HeyGen, Google, Meta, LinkedIn, X, TikTok, Pinterest, Bluesky, and similar customer-connected platforms. Providers process data only as needed to provide, secure, monitor, support, and improve Swell workflows.

AI Provider Processing

When customers request AI-assisted captions, images, localization, video, voice, or creative edits, Swell may send prompts, source media, instructions, and generation settings to configured AI providers. Customers should not submit secrets, regulated personal data, or third-party content they do not have rights to use in AI generation requests.

DPA Posture

Swell is operated by Forgewell, LLC as a small-business SaaS service. A standard data processing addendum is available for paid customers that need one before sending personal data to Swell; email legal@growonswell.com with the workspace name and required contracting details.

Exports and Deletion

Workspace owners can request export, deletion, or anonymization of workspace content, analytics events, replay records, tracked links, and integration metadata by emailing legal@growonswell.com. Deletion is subject to identity verification, provider-side deletion limits, backup expiry, security records, billing records, and legal obligations.