Privacy Policy
Last updated: August 16, 2026. Effective immediately for all users of Swavon.
Swavon ("Swavon", "we", "us") provides a follow-up and deal-monitoring assistant for real estate agents. Swavon is the data controller for the information described here. This policy explains what data Swavon collects, how it is stored, when AI is used, and how you can disconnect or delete it. It covers both the beta application form at /beta and the Gmail and Google Calendar integrations used inside the product. Our terms are available at /terms.
Contact
Privacy questions, access requests, and deletion requests: support@swavon.com. Legal notices: legal@swavon.com. We respond within 30 days.
Google API Services User Data Policy
Swavon's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Google user data is used only to provide and improve the user-facing features described on this page.
- Google user data is never used for advertising and is never sold or transferred for advertising purposes.
- Google user data is not used to develop, improve or train generalized AI or machine-learning models.
- Humans do not read your Google data except with your explicit permission, to resolve a support issue you have reported, for security purposes, or where required by law.
- Google user data is not transferred to third parties except to the sub-processors listed below, strictly to operate the service.
Sub-processors that can touch Google data
- Lovable Cloud / Supabase — application hosting, managed Postgres database, serverless functions, secrets vault.
- Lovable AI Gateway and the model providers it routes to — AI processing of qualified real-estate conversations only.
- Sentry — error monitoring; configured to report technical diagnostics, not message content.
Deleting your Google data in one step
Go to Settings → Integrations, disconnect Gmail (or Google Calendar) and choose "delete data" — that revokes the token and wipes the content Swavon synchronized from your Google account. You can also revoke access directly in your Google Account under Security → Third-party access.
Beta application — what we collect
Your name, work email, brokerage or team name, role, current CRM, approximate active lead volume, and a short free-text description of your follow-up problem. We also record the time you submitted, a hashed representation of your IP address (never the raw IP), and any UTM parameters present in the referring link.
Beta application — how we use it
We use this information only to review your application and reply to you about the Swavon private beta. We do not sell it, share it with third parties, or use it for advertising. Marketing updates are only sent if you separately opt in with the checkbox on the application form.
Gmail data
Swavon connects to Gmail through Google's OAuth flow. We never see or store your Google password. You can revoke access at any time from your Google Account (Security → Third-party access) or from Settings → Integrations inside Swavon.
Scopes we request
gmail.readonly— read message metadata and content so Swavon can identify real-estate conversations that need a follow-up.gmail.compose— create and update drafts in your own Gmail drafts folder for the replies Swavon prepares. This scope cannot send mail: Swavon deliberately does not requestgmail.send, so no message leaves your account unless you send it yourself in Gmail.userinfo.email/userinfo.profile/openid— identify which Google account is connected.
Swavon does not request permission to delete email, and it never permanently deletes your client email.
What Swavon accesses and stores
- Message metadata: sender, recipients, subject, timestamps, thread and message IDs, Gmail labels.
- Message bodies: text and HTML content of synced conversations, stored inside your private workspace in our database so Swavon can display threads, match them to leads, and generate follow-ups.
- Attachments themselves are not downloaded or stored by Swavon during the private beta — only attachment names and sizes may be recorded.
- Sync state: your last sync history ID, watch subscription, and integration health so we can keep your inbox current and recover from failures.
Encryption
All Gmail data is transmitted over TLS and stored encrypted at rest in Swavon's managed cloud database. OAuth refresh tokens are stored in a hardware-backed secrets vault, referenced only by opaque UUID pointers — never in application tables.
Google Calendar data
Connecting Google Calendar is optional and separate from Gmail. It uses the same Google OAuth flow, and can be disconnected at any time in Settings → Integrations or from your Google Account.
Scopes we request
calendar.readonly— read your existing events so the follow-ups and showings Swavon proposes do not collide with commitments you already have, and so travel time between showings can be estimated.calendar.events— create and update the showing or follow-up appointments you confirm inside Swavon, and keep reschedules in sync. Swavon only modifies events it created on your behalf.userinfo.email/userinfo.profile/openid— identify which Google account is connected.
What Swavon accesses and stores
- Event data: title, start and end times, timezone, location, attendee email addresses, event and calendar IDs, and busy/free status.
- Your primary calendar ID and timezone, plus sync state (sync tokens, channel subscriptions, integration health) so the planner stays current.
- Events Swavon creates for you are linked to the corresponding Swavon appointment so status changes stay in sync.
Calendar data is transmitted over TLS and stored encrypted at rest in your private workspace. Calendar refresh tokens are stored in the same secrets vault as Gmail tokens, referenced only by opaque UUID pointers. Calendar content is used for scheduling and conflict detection; it is not sent to AI models.
AI processing
To generate lead prioritization, deal insights, and drafted replies, Swavon sends relevant email content to large language models through the Lovable AI Gateway, which routes requests to underlying providers on our behalf. When this happens:
- Only conversations classified as real-estate related (buyer/seller/client/showing/contract/closing/inspection) are sent to the model. A privacy gate on our servers refuses to forward personal, marketing, or excluded threads.
- Content sent to the model may include: sender/recipient names and emails, subject, message body text, prior thread history, matched lead context, and past summaries.
- We do not permit our AI providers to use your email content to train their models. Requests are transactional only.
- You can turn this off at any time in Settings → Gmail sync settings. Gmail sync continues; new insights and drafts stop.
Model outputs (summary, priority, suggested actions, draft replies) are stored inside your workspace so you can review them without reprocessing. They are not shared across workspaces.
Disconnect and deletion
When you disconnect Gmail in Settings → Integrations, Swavon offers two explicit options:
- Disconnect only. We revoke your Google refresh token, stop the Gmail push subscription, and remove the OAuth secret from our vault. Previously synchronized emails and insights remain in your workspace so you keep your history.
- Disconnect and permanently delete synchronized Gmail data. We do everything above, and additionally delete every email, conversation, draft, and enrichment record that was synchronized from your Gmail account in Swavon. This action is confirmed with a second step and cannot be undone.
Both disconnect flows write an entry to Swavon's tamper-evident audit log, including who performed the action, when, and whether data was deleted. Duplicate deletion requests against an already-disconnected integration are treated as no-ops.
Retention
- Pending beta applications: kept for up to 12 months from submission.
- Rejected or withdrawn applications: deleted within 90 days after the decision.
- Accepted applications: retained for the duration of your Swavon account and deleted 12 months after account closure.
- Gmail messages, conversations, and enrichments: retained inside your workspace for as long as Gmail remains connected, or until you request deletion or perform a "disconnect and delete".
- Google Calendar events and sync state: retained while Calendar remains connected, or until you disconnect and request deletion.
- OAuth refresh tokens: revoked and destroyed immediately on disconnect.
- Audit logs: retained for at least 12 months for security review.
Your rights
You can request a copy of the information we hold about you, or ask us to correct or delete it, by emailing support@swavon.com. We respond within 30 days. While Swavon is in private beta, deletion is honored even for accepted accounts on request.
Children
Swavon is a professional tool for licensed real estate agents and is not directed to anyone under 18. We do not knowingly collect data from children.
Changes to this policy
If we change how we handle your data, we will update this page and revise the "last updated" date above. Material changes affecting Google user data will be communicated by email to connected accounts.