Privacy Policy
Last updated: 22 July 2026
This Privacy Policy explains what information Zwerm collects, how we use it, and the choices you have. Zwerm is an early-stage product; we keep this document plain-language on purpose. If anything here is unclear, email us (see Contact).
1. Who we are
Zwerm is operated by Xander Steenbrugge, a sole operator based in Ghent, Belgium. For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the information described below.
- Service: Zwerm — a collective-memory AI agent for place-rooted communities ("worlds"), reachable at https://zwerm.app.
- Contact: xandersteenbruggex@gmail.com
2. What Zwerm does
Zwerm lets you talk — by voice or chat — to an AI agent that gets to know you and your community so it can surface useful connections, suggestions, and collaborations. Some communities also connect tools (such as Google Calendar or Gmail) so the agent can help with scheduling and coordination on their behalf.
3. Information we collect
Account information. When you sign in, our authentication provider (Clerk) collects your name, email address, and — if you sign in with Google — your profile photo. We use this to identify you, secure your account, and let matches reach you (only when you opt in).
Conversation content. Everything you say to the agent is recorded and stored in our databases: your chat messages, voice transcripts, and a profile/"memory" the agent builds from your conversations over time. This is core to how the service works — the agent cannot remember you or connect you with others without it.
Community ("world") membership. Which community you belong to, your role in it, and onboarding status.
Connected-service data. If you or your community admin connect a third-party account (e.g. Google), we access data from that account as described in §6. We only do this after an explicit authorization step.
Technical and usage data. Basic logs and privacy-respecting product analytics (via Vercel Analytics) — e.g. pages visited and broad usage patterns — to keep the service running and improve it.
4. How we use your information
We use the information above to:
- run, secure, and improve the service;
- let the AI agent remember you and hold a useful conversation;
- build a shared "community brain" that can connect you with relevant people, events, and collaborations;
- surface matches and suggestions to you and to other members of your community;
- communicate with you about the service.
We do not sell your personal information.
5. Sharing within your community
Parts of what you share may be summarised and made available to your wider community through the agent — that is the point of a collective brain. This is governed by your personal privacy prompt, which you can read and edit in the app's settings, and by per-community filters that strip identifying details (names, contact details, addresses) before anything is surfaced collectively.
Because shared input may be seen by others, please don't tell the agent anything you wouldn't want stored or surfaced — passwords, financial or government IDs, health or other sensitive data, or private information about other people without their consent.
Direct messages between members
Some communities enable member-to-member direct messages (including introductions posted by the agent). These conversations are private between their participants: they are excluded from community-admin views and cannot be turned into public share links, and they are not used for the collective community memory today. If and when conversation learning launches, it will be consent-controlled per member — a conversation is only ever learned from with the standing consent of the people in it, and the conversation screen will always tell you whether the agent learns from it.
Direct messages are stored in plaintext on our infrastructure (they are not end-to-end encrypted — the platform must store what it delivers) and can in principle be read by the platform operators, for example when required for abuse investigation or by law. Treat them as private, not secret.
6. Google user data
If you or your community administrator choose to connect a Google account, Zwerm requests access to specific Google services so the agent can act on your community's behalf. We request the narrowest scopes needed for the features a community actually turns on, which may include:
- Google Calendar — to read upcoming events and create, update, or cancel events when asked. This is limited to events; Zwerm cannot manage, share, or delete entire calendars.
- Gmail — to compose and send messages on your community's behalf. We request send-only access; Zwerm does not read your inbox.
How we use Google data. Google data is used only to provide the features you or your community explicitly request (e.g. "what's on the calendar next week?", "schedule that as an event on Thursday", "draft and send this email to the venue"). We access it at the moment it's needed to fulfil a request. We store Google account authorization tokens (encrypted) so the connection persists, and we may keep a record of the actions taken (such as an event created or a message sent); we do not build a standing copy of your calendar or mailbox.
We do not:
- use Google user data for advertising;
- sell or rent Google user data, or transfer it to others except as needed to provide or improve user-facing features, with your consent, or as required by law;
- use Google user data to develop, improve, or train generalized or non-personalized AI/ML models;
- allow humans to read your Google data, except (a) with your explicit consent, (b) for security or abuse investigations, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized.
Limited Use disclosure. Zwerm's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access. You can disconnect Google from within the app at any time, and you can revoke Zwerm's access directly at https://myaccount.google.com/permissions. Revoking access stops future use and deletes the stored authorization tokens.
7. AI processing and model providers
To generate the agent's responses, your conversation content (and, when relevant to your request, connected-service data) is sent to third-party large language model and voice providers that process it on our behalf to produce a reply. We work with providers under terms that do not permit them to use this data to train their own models. Google data accessed via the Google APIs is never used to train generalized AI models, per §6.
8. Service providers (subprocessors)
We rely on a small number of vendors who process data on our behalf, under contract, only to operate the service:
- Clerk — authentication and account management.
- Vercel — web hosting and product analytics.
- Modal — application compute (the per-user agent workers).
- Neon — managed PostgreSQL database.
- OpenRouter and the underlying model providers it routes to — AI text generation.
- ElevenLabs — real-time voice.
- Google — when you connect a Google account (see §6).
- EmailJS — delivery of the "request access" contact form.
9. Data retention
We keep your account and conversation data only for as long as necessary for the purposes described above — while your account is active or as needed to provide the service — not indefinitely. If you ask us to delete your data, we will remove it within a reasonable period, except where we must retain something to comply with the law or resolve disputes. Encrypted Google tokens are deleted when you disconnect or revoke access.
10. Your rights
If you are in the EU/EEA (or a comparable jurisdiction), you have the right to access, correct, delete, restrict, or object to our processing of your personal data, and to data portability. Where processing is based on consent, you can withdraw it at any time. To exercise any of these, email xandersteenbruggex@gmail.com and we'll respond. You also have the right to lodge a complaint with your local data protection authority — in Belgium, the Gegevensbeschermingsautoriteit (GBA/APD).
11. Security
We use encryption in transit, encrypt sensitive stored credentials (such as Google tokens) at rest, and limit access to data. No system is perfectly secure, but we take reasonable measures to protect your information. Because Zwerm is an early beta, please don't share anything you couldn't bear to have exposed.
12. International transfers
Some of our providers are based in the United States, so your data may be processed outside the EEA. Where that happens, we rely on appropriate safeguards (such as the EU Standard Contractual Clauses) offered by those providers.
13. Children
Zwerm is not directed to children under 16, and we do not knowingly collect their personal data. Where a community operates a public, in-person booth that members of the public (including minors) may speak to, that community is responsible for appropriate on-site notice and consent, and such input is anonymized before it is stored collectively.
14. Changes to this policy
We may update this policy as the product evolves. We'll change the "Last updated" date above, and significant changes will be communicated through the service.
15. Contact
Questions about this policy or your data? Email xandersteenbruggex@gmail.com, or reach out to the community organiser who invited you.