Legal
Privacy Policy
1. What Swiftly collects
When you sign in with Google, Firebase Authentication provides us with your Firebase UID (a pseudonymous identifier) and your Google account email address. We use these to maintain your account and credit balance.
During an interview session, we collect:
- Session metadata — session start time, duration in seconds, credit consumed. No interview content.
- Credit ledger entries — an immutable record of credits granted and debited, keyed to your UID.
- Coaching output — the probe questions and flags generated during your session are held in your browser's local memory for the duration of the tab session. They are not sent to or stored on our servers unless you explicitly opt into report persistence at session start.
2. What Swiftly does not collect
- Audio recordings — audio chunks are transmitted to our server for transcription and discarded immediately after processing. No audio file is stored anywhere.
- Raw transcripts — transcript text is held in memory on your device for the duration of the session and is not persisted to our servers.
- Candidate data — Swiftly does not collect, infer, or store any information about the candidates you interview: no names, no scores, no assessments, no biometric data.
- Emotion or sentiment signals — we do not analyse tone, sentiment, fluency, or any characteristic of the candidate's voice.
3. How audio is processed
Your device microphone captures audio in 250ms chunks. Each chunk is transmitted over an encrypted WebSocket connection to our server (Cloud Run, asia-south1, Mumbai) where it is forwarded to Sarvam AI's speech-to-text API. The resulting text is returned to your browser. The audio chunk is not written to disk at any point in this pipeline and is discarded from memory after the API call completes.
Sarvam AI's own data handling applies to the brief in-flight processing of audio chunks. We do not control Sarvam's server-side handling; please refer to Sarvam AI's Privacy Policy for details.
4. Where data is stored
Account data (UID, email, credit balance, ledger) is stored in Google Cloud Firestore in the asia-south1 (Mumbai) region. Data does not leave this region in normal operation.
5. Data retention
- Account and credit data — retained for as long as your account is active. You may request deletion at any time (see section 7).
- Session metadata — retained for 90 days, then automatically deleted.
- Coaching output (if report persistence is opted in) — retained until you delete it or request account deletion.
6. Cookies and tracking
We use Google Analytics 4 (GA4) on this marketing page to understand aggregate traffic patterns (page views, CTA clicks). GA4 may set cookies in your browser. No cross-site tracking is enabled. You can opt out via your browser's cookie controls or by installing the Google Analytics Opt-out Browser Add-on.
The Swiftly application itself (the interview tool at /app) does not use analytics cookies.
7. Your rights
You may request access to, correction of, or deletion of your personal data at any time by emailing privacy@flowcraft.systems. We will respond within 30 days. Account deletion removes your UID, email, credit balance, and all ledger entries.
8. Security
All data in transit is encrypted with TLS. Cloud Firestore access is controlled by Firebase Security Rules that deny all direct client writes — only our server-side application can write credit-bearing data. API keys are stored in Google Secret Manager and never exposed in the browser bundle.
9. Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated by updating the effective date above and, where feasible, by email. Continued use of Swiftly after a policy update constitutes acceptance of the revised terms.
10. Contact
Questions about privacy: privacy@flowcraft.systems
Flowcraft Systems, India