← LeadSwarm

Privacy

Last updated 2 September 2026.

This page describes what we collect, why, who else sees it, how long we keep it, and how to make us delete it. It is written to be read, not to be survived.

Who we are

LeadSwarm is operated by TORRIN PEEDO-KAY, a sole trader in Australia, ABN 20 803 629 001, trading as LeadSwarm (“we”, “us”). We are the entity responsible for the information described here: the APP entity under the Australian Privacy Act 1988 (Cth), and the data controller under the UK and EU General Data Protection Regulation where that applies to you.

Contact for anything on this page, including access, correction, erasure and complaints: support@leadswarm.io. Write “Privacy” in the subject line and it is routed as a privacy request rather than as support.

This policy covers leadswarm.io, the LeadSwarm web application at /app, and the LeadSwarm API.

This website sets no cookies

These marketing pages store nothing on your device, set no cookies, and load no analytics, advertising or session-recording script. There is no consent banner because there is nothing to consent to.

An earlier version of this site did run first-party analytics: it wrote two random identifiers into your browser's storage and recorded page views, scroll depth, the referring link and your browser's user-agent string. That was never disclosed here, so it was removed rather than documented. If we ever measure this site again we will say so on this page before we start.

The signed-in application at /app is different, and does need storage to work: our identity provider, Clerk, sets a session cookie so you stay signed in. That cookie is strictly necessary to provide the service you asked for, and it is not used to profile you or to advertise.

What we collect about you, and why

WhatWhyLawful basis
Email address, and name and company if you give them To sign you in, attribute your data to you, and contact you about your account Performance of our contract with you (GDPR Art 6(1)(b)); collection reasonably necessary for our functions (APP 3)
Authentication credentials, including any two-factor settings To let you sign in, and to keep other people out of your account Performance of our contract with you
Your Stripe customer and subscription identifiers, your plan and its billing period To show your plan, your allowance and your invoices Performance of our contract; compliance with tax and record-keeping obligations (Art 6(1)(c))
What you create in the product: searches, prospects, campaigns, tags, notes, follow-ups, outreach drafts and templates, export history Because it is the product. It is yours; we hold it for you Performance of our contract with you
Usage counters: how many searches and website checks you have run in the current billing period To enforce your plan's allowance and show you where you are against it Performance of our contract with you
Short-lived rate-limit counters keyed to a truncated one-way hash of your IP address To stop one caller exhausting the service for everyone else Our legitimate interest in keeping the service available (Art 6(1)(f))
Server logs from our hosting provider, and error reports if error tracking is enabled To find and fix faults Our legitimate interest in a service that works (Art 6(1)(f))

Card numbers are entered on Stripe's own hosted checkout. They are never sent to, seen by, or stored on our servers.

Secrets are never rendered back to you and never written to a log, not even a prefix. We do not sell your personal information, we do not disclose it for advertising, and we do not use it to train machine-learning models.

Business information LeadSwarm discovers

The core of the product finds businesses through search results and then fetches their public websites. The information gathered — business name, website, publicly listed phone numbers and email addresses, business address, ratings, and technical characteristics of the website — is information those businesses have published publicly. The source is the search provider's results and the business's own website; we collect it from nowhere else.

Some of that information may identify a person, for example a firstname@business.com address at a sole trader. We treat it as personal information and handle it accordingly. Our lawful basis for holding it is our legitimate interest, and our customers' legitimate interest, in business-to-business research (GDPR Art 6(1)(f)); under the Privacy Act it is collected because it is reasonably necessary for the function the product performs. We have weighed that against the interests of the people involved, which is why the limits below are hard limits:

If you are a business owner, or a person whose details appear in a business listing, you can object to us holding that information and ask for it to be removed. Email support@leadswarm.io with the business name and website and we will remove it. We do not require you to justify the request.

Your responsibilities

You decide who to contact and what to say. You are responsible for complying with the laws that apply to you, including the Australian Spam Act 2003 and Privacy Act 1988, the US CAN-SPAM Act, and the GDPR and e-privacy rules in the markets you work in. LeadSwarm is a research and prioritisation tool, not a permission to contact anyone.

Who processes your data

We use a small number of processors to run the service. This is the whole list.

ProcessorWhat it handlesWhere it processes it
Clerk Sign-in and account management: your email address, name, credentials and two-factor settings United States
Stripe Payments, invoicing and fraud prevention: your card details, billing address, and any tax ID you supply Australia and the United States
Neon The managed PostgreSQL database holding your account, searches, prospects and everything else you create United States
Vercel Application hosting, content delivery and server logs United States
SerpAPI Receives your search terms and locations to return search results United States

Clerk, Neon, Vercel and SerpAPI act as our processors: each is bound by a written agreement to handle the data only on our instructions. Stripe is our processor for the subscription records we hold, and an independent controller for the payment itself, its fraud checks and its own compliance obligations, under Stripe's privacy policy.

We do not share your data with anyone else. We will disclose it if the law compels us to, and we will tell you when we are allowed to.

Sending data overseas

Every processor above is outside Australia, and the countries are named in the table — the United States, and Australia for part of Stripe's processing. Under Australian Privacy Principle 8 we take reasonable steps to ensure each overseas recipient handles your information consistently with the Australian Privacy Principles, principally through the data-protection terms in our agreement with them.

Where the GDPR applies to you, transfers out of the EEA or the UK rely on the transfer terms in each provider's own data processing agreement — the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies — together with the technical measures described under Security below. Ask us and we will tell you which mechanism is relied on for a particular transfer. If a provider ever stops offering an adequate mechanism we will replace the provider rather than continue the transfer.

How long we keep it

DataKept for
Your account, and everything in your workspace While your account is open. Erased when you close it — see below
Finished search job records 30 days, then swept automatically, so last week's run is still openable
Rate-limit counters Discarded as soon as the counting window expires — minutes, not days
Payment and invoice records Held by Stripe under its own retention rules, which is where the Australian record-keeping obligation sits. We keep no copy of them ourselves
Server logs and error reports Under the retention settings of our hosting and error-tracking providers. They contain request paths and status codes, never credentials or secrets

Getting a copy, and deleting your account

Both are self-service, in the app, without asking us first. Open Settings → Account.

It is not reversible and there is no recycle bin, so export first if you want the data. Deleting your account inside Clerk's own profile panel has the same effect: Clerk notifies us and we run the identical erasure.

What survives is not about you: an anonymous record that a Stripe webhook was processed, and Stripe's own invoice records under the retention rules above. If you would rather we did it for you, email support@leadswarm.io and we will do it within 30 days and confirm in writing.

Your rights

Wherever you are, you can ask us to give you a copy of your personal information, correct it, or delete it. If the GDPR applies to you, you also have the right to restrict or object to processing, to receive your data in a portable machine-readable format (the export above is that format), and to withdraw consent where we relied on it — though for the processing described here we rely on contract, legal obligation and legitimate interests rather than consent. We do not make decisions about you by automated means that produce legal or similarly significant effects.

To exercise any of them, use Settings → Account, or email support@leadswarm.io. We respond in writing within 30 days and we do not charge for it. We may ask you to confirm you control the account's email address, because handing your data to someone impersonating you would be the worse outcome.

If you are not happy with our answer

Tell us first. Email support@leadswarm.io with “Privacy complaint” in the subject line. We will acknowledge it, investigate, and respond in writing within 30 days, telling you what we found and what we are doing about it.

If you are not satisfied with that response, you can escalate:

You do not have to complain to us first, but it is usually faster.

Security

Data is transmitted over TLS and stored in a managed PostgreSQL database with access restricted to the service. Every query that touches a customer resource filters on the owning account, so one account cannot read another's rows; a request for someone else's record answers “not found” rather than confirming it exists. Sign-in and credential storage are handled by Clerk, not by us — we hold no passwords. Outbound website fetches run through a guarded fetcher that refuses private and internal network addresses.

No system is perfectly secure. If a data breach is likely to result in serious harm we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires; where the GDPR applies we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify you directly when the risk to you is high.

Children

LeadSwarm is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, email us and we will delete it.

Changes to this policy

If we change something that materially affects you — a new processor, a new purpose, a shorter or longer retention period — we will update the date at the top and email account holders before it takes effect.

Contact

Questions, corrections, removal requests and complaints: support@leadswarm.io.