Draft, not legal advice. This page is a standard-form starting point written by the SweepSonar team, not a lawyer. Have it reviewed by qualified counsel in your jurisdiction before relying on it.

Privacy Policy

Last updated August 2, 2026

This Privacy Policy explains what data SweepSonar collects, why, and what rights you have over it. SweepSonar is operated by Webbywolf Innovations ("Webbywolf," "we," "us"), which acts as the data controller for the personal data described below. We expect visitors and customers from the EU/EEA, and this policy is written with GDPR in mind alongside other applicable data protection law.

1. Data we collect

We collect the following categories of data:

  • Account data — the email address and name you sign up with, and your password (handled by our authentication provider; we don't see or store your password in plain text).
  • Your configuration — the search projects and keywords you set up to scan forums, plus in-app settings like digest preferences.
  • Cached forum content — copies of public posts and threads from Reddit, Quora, Hacker News, Stack Exchange, and Indie Hackers that match your configured searches, along with the LLM-generated score and tags we attach to them. This content was already public when we retrieved it; we don't collect private or authenticated forum data.
  • Billing data — if and when paid plans launch, payment details will be collected and processed by a third-party payment processor, not stored on our own servers in full.
  • Technical and log data — IP address, browser/device information, timestamps, and error reports, collected automatically to operate, secure, and debug the Service.

2. How we use it

  • To operate your account and run the scans and scoring you've configured;
  • To deliver lead notifications and digest emails you've opted into;
  • To provide customer support when you contact us;
  • To maintain security, detect abuse, and debug errors (including via error-monitoring tooling that may capture stack traces and request metadata);
  • To bill you, once paid plans are available and you've subscribed to one; and
  • To improve the product — for example, understanding which sources or features get used.

3. Legal basis for processing (GDPR)

Where GDPR applies, we rely on: performance of a contract (running the Service you signed up for); legitimate interests (security, abuse prevention, and improving the product, balanced against your rights); and consent, where we ask for it specifically (for example, optional marketing email). You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

4. Who we share data with

We use a small number of subprocessors to run the Service, each bound by their own data protection obligations to us:

  • Supabase — authentication and database hosting for account and application data.
  • Mailgun — transactional and digest email delivery, hosted in the EU region.
  • Anthropic — the large language model provider used to score and tag forum threads; the content sent for scoring is the public post/thread text, not your account credentials.
  • Sentry — error monitoring, which may capture request metadata and stack traces to help us diagnose bugs.
  • A payment processor, once paid billing is live, for handling card details and charges.

We don't sell personal data, and we don't share it with third parties for their own independent marketing purposes.

5. International transfers

Because our subprocessors operate globally, data may be processed in the European Union, the United States, India, and other jurisdictions depending on each subprocessor's infrastructure. Where personal data from the EU/EEA is transferred outside it, we rely on the relevant subprocessor's Standard Contractual Clauses or equivalent safeguard.

6. Retention

We retain account data for as long as your account is active. Cached forum posts are refreshed and pruned on an ongoing basis rather than retained indefinitely. If you delete your account, we delete or anonymize your account data and configuration within a reasonable period, except where we're required to retain records (for example, billing records) for legal or accounting purposes.

7. Cookies and similar technology

We use strictly necessary cookies to keep you signed in (set by our authentication provider) and, where enabled, a lightweight, privacy-conscious theme preference stored in your browser's local storage. We don't currently use third-party advertising cookies or cross-site tracking.

8. Your rights

Subject to applicable law, and in particular if you're in the EU/EEA, UK, or a jurisdiction with similar protections, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Request erasure of your data ("right to be forgotten");
  • Restrict or object to certain processing;
  • Request a portable copy of data you provided to us; and
  • Lodge a complaint with your local data protection supervisory authority if you believe we've mishandled your data.

To exercise any of these rights, email support@sweepsonar.com. We'll respond within the timeframe required by applicable law.

9. Children

The Service is intended for business use by adults and isn't directed at children. We don't knowingly collect personal data from anyone under 16.

10. Changes to this policy

We may update this Privacy Policy as the Service evolves — for example, if we add a new subprocessor or launch billing. We'll update the "Last updated" date above and, for material changes, notify you by email or in-product notice.

11. Contact

For any privacy question or request, email support@sweepsonar.com. Our legal entity and registered address are listed on the Imprint page.