Skip to main content
Swan processes data on your behalf in order to research accounts, enrich contacts, draft and send outreach, and identify who’s visiting your website. This page describes what that data is, who else touches it, and how long it sticks around. It summarizes the concepts — the binding documents are the Terms of Service, the Privacy Policy, and the Data Processing Agreement, and where a detail here differs from those, they win.

What Swan processes

  • CRM data — the companies, contacts, deals, and activity you’ve connected from your CRM (see Swan vs your CRM).
  • Company and contact records Swan builds itself — enrichment results, research notes, and prospecting output.
  • Outreach content — the emails and LinkedIn messages Swan drafts and sends, and the replies it reads to manage a sequence.
  • Website visitor identities — if you’ve installed the tracking script, the companies and (where a provider supports it) individuals Swan identifies from your site traffic. See visitor identification.
  • Conversation and execution history — your chats with Swan and the record of what triggers and sequences did.

Who else processes it

Swan is an orchestration layer over several categories of third-party providers, each handling a specific slice of the work:
  • AI model providers — the language models Swan’s agent reasons with. Requests relevant to your task (research briefs, message drafts, CRM field values) are sent to these providers to generate a response.
  • Enrichment and prospecting data providers — services Swan queries to find and enrich companies and contacts, and to read buying-intent signals (for example Explorium and Bombora, among others).
  • Website visitor identification providers — services that turn anonymous site traffic into identified companies or people when you have the tracking script installed.
  • Outreach sending infrastructure — Unipile, which holds the actual connection to your email and LinkedIn accounts and performs the send/receive on Swan’s instruction (see security for how those credentials are handled).
  • Quality and observability tooling — internal tooling Swan’s team uses to monitor agent behavior, debug issues, and evaluate output quality. This doesn’t include your outreach recipients or CRM records being shared outside the categories above; it’s operational telemetry about how Swan itself is performing.
The authoritative, current list of named subprocessors lives in the Data Processing Agreement, which is linked from Swan’s Terms of Service — it’s deliberately not duplicated here, so there’s one place to keep current.

Your data is not used to train AI

Swan’s Terms of Service commit that your data, Swan’s outputs for you, and statistics derived from them are not used to train any AI model. Swan may use de-identified, aggregated statistics about how the service operates to improve it — but never your content as training data, and never data identifiable to your org. Under Swan’s data processing agreement, your organization is the data controller and Swan is the processor: Swan processes personal data solely to provide the service, on your documented instructions, and your organization is responsible for the lawfulness of the data it discloses to Swan and the outreach it directs. In practice: Swan sends messages using the instructions, targeting, and content you configure — compliance with email and messaging regulations in your market (consent or legitimate-interest requirements) is your organization’s responsibility, the same as if you sent the message yourself.

Retention and deletion

While your account is active, conversation history, sequence records, and execution logs are kept as your organization’s operating history rather than being automatically purged after a set period. Deleting a record in the product (for example archiving a sequence) removes it from your active views but doesn’t necessarily erase the underlying data immediately. If you end your agreement with Swan, your data is made available to you for retrieval for a window after termination and then deleted, on the timeline set out in the Terms of Service and your DPA. Swan also corrects or erases specific data on your organization’s instruction, per the DPA. There’s currently no self-serve “export everything” or “delete everything” button in the product. If you need a full data export, targeted correction or erasure, or the permanent deletion of your organization’s data, contact Swan support directly.

Common questions

Does Swan share my contact data with AI providers? Relevant context is sent to the AI model providers Swan uses to power its reasoning — for example, when drafting a message or answering a question about a contact. It isn’t sold or shared beyond what’s needed to do the work you’ve asked for, and it’s never used to train AI models. Can I get a copy of all my org’s data, or delete it entirely? Not through a self-serve tool today. Contact Swan support to request an export or full deletion. Does Swan keep outreach history forever? While your account is active, yes — sequence history isn’t automatically expired; it stays as part of your organization’s record unless you request deletion. After termination, your data is deleted on the timeline in the Terms of Service and DPA. Does website visitor tracking require cookie consent? Visitor identification is based on IP and cookie data, so in jurisdictions with cookie-consent requirements you should include the Swan tracking script in your site’s consent flow. See tracking script for how the script itself works. Is Swan GDPR or CCPA compliant? Swan operates as a data processor under GDPR Article 28: a data processing agreement is in place, data-subject requests are supported (Swan refers them to your organization as the controller and assists with fulfilling them), transfers outside the EU/EEA rely on standard contractual clauses, and Swan carries contractual breach-notification obligations. Swan is currently in its SOC 2 observation period, with certification expected by the end of Q3 2026.