Effective 8 October 2026. This updates the policy published on 27 September 2026.
Who we are
Sweat AI provides managed onboarding, fraud and due-diligence operations for businesses. Check is no longer offered as a standalone self-service product. Existing workspaces, case records and agreed integrations remain subject to their access arrangements and applicable agreements.
What we collect
Accounts and workspaces. We store sign-in email addresses, workspace membership and access information. Google sign-in supplies an email address, name and profile picture; we do not receive your Google password.
Case and document data. We process the subjects, questions, context, uploaded documents and connected workflow data supplied for a review. Documents can contain personal data, including identifiers, when a customer submits them. Submit only information you are authorized to provide and that is needed for the agreed work.
Evidence and review records. We retain captured source material, capture times and hashes, findings, document-check results and workflow or decision records so the work can be traced to its evidence. Public-source evidence can contain personal information published by the source.
Website and scheduling data. Lead forms collect contact and business details, the review scope you describe and optional referral information. Website analytics can include page visits, interaction events, referral and campaign parameters, an opaque analytics identifier, browser/device information and approximate location derived from an IP address. Campaign attribution is stored in browser storage. Calendly handles meeting scheduling and booking details; its privacy terms also apply.
Product analytics. Application routes for real casework, document intake and authentication are excluded from session replay and automatic interaction capture. These controls also apply to demonstration workspaces, which can hold mutable records. Do not enter real case data in demonstrations. Explicit operational events and error logs can still be processed to operate and diagnose the service. Earlier product recordings may contain unmasked case content; the new controls do not retroactively erase those recordings. Privacy requests can include those historical recordings.
We do not receive payment card details through the application. If a payment processor is used under an existing arrangement, it handles payment credentials under its own terms.
How we use data
We use data to deliver the agreed review, retain inspectable evidence, manage account access and capacity, respond to enquiries, schedule meetings and find service failures. We do not sell customer data or use case contents to train third-party models.
Access and service providers
Access depends on workspace roles, case privacy and explicit sharing permissions. A workspace membership does not by itself mean every member can see every case. An authorized document-request or collection link grants only the scope of that link and remains subject to its validity and expiry.
Providers used by the service include Supabase for database and storage; Amazon Web Services for application hosting; Cloudflare for website delivery; Anthropic, OpenAI and Google for AI inference; Browserbase for hosted public-source lookups; PostHog for analytics; and Calendly for scheduling. Information shared depends on the function being used: a registry lookup may require a subject name, inference may require case material, and scheduling requires booking details. Connected messaging or social platforms apply their own terms to data exchanged through those integrations.
We disclose information when required by a binding legal obligation. Specific contractual processing, location, access and retention requirements should be agreed before customer work begins.
Retention and deletion
The existing shared-service Check case policy is 30 days from case creation unless an order form sets a different period. Managed-service retention follows the applicable agreement. Other account data is retained while the account is active; the existing account-deletion policy provides for removal within 30 days, except records that must be retained by law.
Deletion covers applicable case records, captured sources, documents and storage objects. Cleanup is tracked separately from hiding or denying access to a case. Backups, provider-held data and legally required records require their own disposition; a successful interface action does not by itself certify that every copy has been removed. We confirm the scope and any exceptions when responding to a request.
Connected messaging and our social accounts
A workspace that connects its own messaging account supplies messages, sender identities, conversation context and workflow records for that workspace's review and response. A short technical copy used to diagnose delivery problems has a 30-day retention policy. See the data-deletion instructions for connected Instagram accounts.
We also store tokens for our own social accounts to publish content and read post performance. Comments or messages sent to those accounts remain subject to the platform's own privacy terms.
Requests and contact
Request access, correction or deletion by emailing privacy@getsweat.ai. We verify the requester's authority and the affected account, workspace or case scope before acting. Removing one member does not automatically delete another customer's records or a shared workspace. See data deletion for the request procedure.
Sweat AI · privacy@getsweat.ai