Privacy
Last updated 2 September 2026.
This page describes what we collect, why, who else sees it, how long we keep it, and how to make us delete it. It is written to be read, not to be survived.
Who we are
LeadSwarm is operated by TORRIN PEEDO-KAY, a sole trader in Australia, ABN 20 803 629 001, trading as LeadSwarm (“we”, “us”). We are the entity responsible for the information described here: the APP entity under the Australian Privacy Act 1988 (Cth), and the data controller under the UK and EU General Data Protection Regulation where that applies to you.
Contact for anything on this page, including access, correction, erasure and complaints: support@leadswarm.io. Write “Privacy” in the subject line and it is routed as a privacy request rather than as support.
This policy covers leadswarm.io, the LeadSwarm web application at
/app, and the LeadSwarm API.
This website sets no cookies
These marketing pages store nothing on your device, set no cookies, and load no analytics, advertising or session-recording script. There is no consent banner because there is nothing to consent to.
An earlier version of this site did run first-party analytics: it wrote two random identifiers into your browser's storage and recorded page views, scroll depth, the referring link and your browser's user-agent string. That was never disclosed here, so it was removed rather than documented. If we ever measure this site again we will say so on this page before we start.
The signed-in application at /app is different, and does need
storage to work: our identity provider, Clerk, sets a session cookie so you
stay signed in. That cookie is strictly necessary to provide the service you
asked for, and it is not used to profile you or to advertise.
What we collect about you, and why
| What | Why | Lawful basis |
|---|---|---|
| Email address, and name and company if you give them | To sign you in, attribute your data to you, and contact you about your account | Performance of our contract with you (GDPR Art 6(1)(b)); collection reasonably necessary for our functions (APP 3) |
| Authentication credentials, including any two-factor settings | To let you sign in, and to keep other people out of your account | Performance of our contract with you |
| Your Stripe customer and subscription identifiers, your plan and its billing period | To show your plan, your allowance and your invoices | Performance of our contract; compliance with tax and record-keeping obligations (Art 6(1)(c)) |
| What you create in the product: searches, prospects, campaigns, tags, notes, follow-ups, outreach drafts and templates, export history | Because it is the product. It is yours; we hold it for you | Performance of our contract with you |
| Usage counters: how many searches and website checks you have run in the current billing period | To enforce your plan's allowance and show you where you are against it | Performance of our contract with you |
| Short-lived rate-limit counters keyed to a truncated one-way hash of your IP address | To stop one caller exhausting the service for everyone else | Our legitimate interest in keeping the service available (Art 6(1)(f)) |
| Server logs from our hosting provider, and error reports if error tracking is enabled | To find and fix faults | Our legitimate interest in a service that works (Art 6(1)(f)) |
Card numbers are entered on Stripe's own hosted checkout. They are never sent to, seen by, or stored on our servers.
Secrets are never rendered back to you and never written to a log, not even a prefix. We do not sell your personal information, we do not disclose it for advertising, and we do not use it to train machine-learning models.
Business information LeadSwarm discovers
The core of the product finds businesses through search results and then fetches their public websites. The information gathered — business name, website, publicly listed phone numbers and email addresses, business address, ratings, and technical characteristics of the website — is information those businesses have published publicly. The source is the search provider's results and the business's own website; we collect it from nowhere else.
Some of that information may identify a person, for example a
firstname@business.com address at a sole trader. We treat it as
personal information and handle it accordingly. Our lawful
basis for holding it is our legitimate interest, and our customers'
legitimate interest, in business-to-business research (GDPR Art 6(1)(f));
under the Privacy Act it is collected because it is reasonably necessary for
the function the product performs. We have weighed that against the interests
of the people involved, which is why the limits below are hard limits:
- We collect it only from publicly accessible sources.
- We do not attempt to bypass login walls, paywalls or anti-bot controls.
- We do not buy, sell or trade contact databases.
- We do not enrich it from data brokers.
- We do not send email on your behalf. LeadSwarm helps you draft and organise outreach; you send it yourself, from your own mail client.
- We do not collect special-category data, and we do not build profiles of individuals — the scores describe a business's website, not a person.
If you are a business owner, or a person whose details appear in a business listing, you can object to us holding that information and ask for it to be removed. Email support@leadswarm.io with the business name and website and we will remove it. We do not require you to justify the request.
Your responsibilities
You decide who to contact and what to say. You are responsible for complying with the laws that apply to you, including the Australian Spam Act 2003 and Privacy Act 1988, the US CAN-SPAM Act, and the GDPR and e-privacy rules in the markets you work in. LeadSwarm is a research and prioritisation tool, not a permission to contact anyone.
Who processes your data
We use a small number of processors to run the service. This is the whole list.
| Processor | What it handles | Where it processes it |
|---|---|---|
| Clerk | Sign-in and account management: your email address, name, credentials and two-factor settings | United States |
| Stripe | Payments, invoicing and fraud prevention: your card details, billing address, and any tax ID you supply | Australia and the United States |
| Neon | The managed PostgreSQL database holding your account, searches, prospects and everything else you create | United States |
| Vercel | Application hosting, content delivery and server logs | United States |
| SerpAPI | Receives your search terms and locations to return search results | United States |
Clerk, Neon, Vercel and SerpAPI act as our processors: each is bound by a written agreement to handle the data only on our instructions. Stripe is our processor for the subscription records we hold, and an independent controller for the payment itself, its fraud checks and its own compliance obligations, under Stripe's privacy policy.
We do not share your data with anyone else. We will disclose it if the law compels us to, and we will tell you when we are allowed to.
Sending data overseas
Every processor above is outside Australia, and the countries are named in the table — the United States, and Australia for part of Stripe's processing. Under Australian Privacy Principle 8 we take reasonable steps to ensure each overseas recipient handles your information consistently with the Australian Privacy Principles, principally through the data-protection terms in our agreement with them.
Where the GDPR applies to you, transfers out of the EEA or the UK rely on the transfer terms in each provider's own data processing agreement — the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies — together with the technical measures described under Security below. Ask us and we will tell you which mechanism is relied on for a particular transfer. If a provider ever stops offering an adequate mechanism we will replace the provider rather than continue the transfer.
How long we keep it
| Data | Kept for |
|---|---|
| Your account, and everything in your workspace | While your account is open. Erased when you close it — see below |
| Finished search job records | 30 days, then swept automatically, so last week's run is still openable |
| Rate-limit counters | Discarded as soon as the counting window expires — minutes, not days |
| Payment and invoice records | Held by Stripe under its own retention rules, which is where the Australian record-keeping obligation sits. We keep no copy of them ourselves |
| Server logs and error reports | Under the retention settings of our hosting and error-tracking providers. They contain request paths and status codes, never credentials or secrets |
Getting a copy, and deleting your account
Both are self-service, in the app, without asking us first. Open Settings → Account.
- Export. Downloads a JSON file containing every row we hold that belongs to you, across every table, plus your account record.
- Close account. You type your own email address to confirm. We then cancel your Stripe subscription, ask Clerk to delete your sign-in identity, and permanently delete every row belonging to you. Named one by one, so there is no doubt about what “your data” means: your account, your searches and search jobs, your prospects, your campaigns, your tags, your workspace settings, your usage records and usage events, the record of the provider calls your searches made, your export history, and your outreach drafts, outreach templates and outreach events. The response tells you how many rows were removed from each table.
It is not reversible and there is no recycle bin, so export first if you want the data. Deleting your account inside Clerk's own profile panel has the same effect: Clerk notifies us and we run the identical erasure.
What survives is not about you: an anonymous record that a Stripe webhook was processed, and Stripe's own invoice records under the retention rules above. If you would rather we did it for you, email support@leadswarm.io and we will do it within 30 days and confirm in writing.
Your rights
Wherever you are, you can ask us to give you a copy of your personal information, correct it, or delete it. If the GDPR applies to you, you also have the right to restrict or object to processing, to receive your data in a portable machine-readable format (the export above is that format), and to withdraw consent where we relied on it — though for the processing described here we rely on contract, legal obligation and legitimate interests rather than consent. We do not make decisions about you by automated means that produce legal or similarly significant effects.
To exercise any of them, use Settings → Account, or email support@leadswarm.io. We respond in writing within 30 days and we do not charge for it. We may ask you to confirm you control the account's email address, because handing your data to someone impersonating you would be the worse outcome.
If you are not happy with our answer
Tell us first. Email support@leadswarm.io with “Privacy complaint” in the subject line. We will acknowledge it, investigate, and respond in writing within 30 days, telling you what we found and what we are doing about it.
If you are not satisfied with that response, you can escalate:
- Australia — the Office of the Australian Information Commissioner, oaic.gov.au or 1300 363 992.
- European Economic Area — the data protection authority in the country where you live or work.
- United Kingdom — the Information Commissioner's Office, ico.org.uk.
You do not have to complain to us first, but it is usually faster.
Security
Data is transmitted over TLS and stored in a managed PostgreSQL database with access restricted to the service. Every query that touches a customer resource filters on the owning account, so one account cannot read another's rows; a request for someone else's record answers “not found” rather than confirming it exists. Sign-in and credential storage are handled by Clerk, not by us — we hold no passwords. Outbound website fetches run through a guarded fetcher that refuses private and internal network addresses.
No system is perfectly secure. If a data breach is likely to result in serious harm we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires; where the GDPR applies we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify you directly when the risk to you is high.
Children
LeadSwarm is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, email us and we will delete it.
Changes to this policy
If we change something that materially affects you — a new processor, a new purpose, a shorter or longer retention period — we will update the date at the top and email account holders before it takes effect.
Contact
Questions, corrections, removal requests and complaints: support@leadswarm.io.