Destructive changes
Wiping data always asks you
Dropping or emptying a table stops for your OK, whatever your settings. That safety net can’t be switched off.
Security
Your account, your apps and your data are protected from the first prompt. Here’s exactly how, in plain English.
Private while you build
Previews need a sign-in and a seat in your workspace. Every table in our database is locked down with row-level security.
Your keys stay secret
Paste a key into chat and Swarmz warns you first. Credentials are encrypted and scrubbed from AI logs.
Nothing drastic without you
Dropping or emptying a table always asks you first. So do connector writes, by default.
Always recoverable
Encrypted nightly backups kept for 30 days, plus one-click version history.
Your account
Your Swarmz account is the key to everything you build, so sign-in is guarded at every step, with Cloudflare Turnstile keeping bots out.
Your team
Give each person the role they need. Roles are enforced in the database itself, not just hidden in the interface.
Data location
Your account and our database are hosted in Ireland. Your projects are built and previewed on our servers in Germany.
Account & database
Ireland
Builds & previews
Nuremberg
Put your app’s data near your customers
When your app gets its own database, you pick where it lives. The nearest region is chosen for you.
Americas
Europe
Asia-Pacific
Some services, such as the AI models and parts of our web app, run in the United States. The full picture is in our Privacy Policy and the provider list below.
Encryption
Everything travels over HTTPS. Our database, file storage and backups are encrypted at rest, and the keys and tokens you connect are encrypted again by us before they’re stored.
That means the accounts you connect, like Slack or Notion, are stored scrambled rather than as readable text.
What’s encrypted, and how
On by defaultEverything you send
Travels over HTTPS, with HSTS preload on our domains
Our database and file storage
Encrypted at rest by Supabase
Connector credentials
Encrypted again by us before they’re saved
Access tokens and sign-in codes
Stored only as a one-way hash, never the real thing
Nightly backups
Encrypted, then kept for 30 days
AI and your data
Swarmz builds with AI models from OpenAI and Anthropic. Here’s what they receive, and what we keep.
Your chats are saved with your project so you can come back to them. What OpenAI and Anthropic do with API data is set by their own policies.
Paste a key into chat and Swarmz stops you, then offers a secure form instead.
Your apps
The AI moves fast. Wiping data always waits for your OK, and anything it sends to your connected apps asks first by default.
Destructive changes
Dropping or emptying a table stops for your OK, whatever your settings. That safety net can’t be switched off.
AI permissions
Let it update your app’s database as it builds, or review every change before it runs.
Connectors
Reading from Slack or Notion just runs. Posting or changing anything asks for your approval by default.
Final checks
Before it says done, Kernel 1 checks code style, types, your preview and runtime errors. If something fails, it tries to fix it, then tells you straight.
Payments & backups
Payments
Checkout is hosted by Stripe, a PCI DSS Level 1 provider. Payments inside your apps run on Stripe Connect.
Backups
Every project is backed up nightly, encrypted, and kept for 30 days. Roll back any change yourself from version history.
Privacy
You own what you build, and you decide what happens to your data. We don’t sell it, and we’re registered with the UK ICO (ZC161704).
Infrastructure
Our database, servers and payments run on providers certified to standards like SOC 2 and ISO 27001. We name every provider, so you know exactly who’s involved.

Supabase
Hosts our database, sign-in and file storage
Hetzner
Runs the servers that build and preview your projects
Stripe
Handles every card payment
Certifications belong to our providers, not to Swarmz. Cloudflare and Vercel also run parts of Swarmz; see the full list below.
A plain-English list of the companies that run parts of Swarmz, taken from how the product is built right now. It’s here so you can see who’s involved. It isn’t a contractual subprocessor list.
Report a problem
A security vulnerability
Found a weakness in Swarmz? Email us privately with the steps to reproduce it, and please don’t share it publicly first.
Abuse, copyright or trademark
Report an app or content made with Swarmz, or appeal a decision. Every report gets its own case reference.
Privacy and your data
Ask for a copy of your data, use any of your UK GDPR rights, or ask how we handle something.