Privacy Policy

Privacy notice

Swain API Integration connector privacy notice

How Swain Technology Ltd processes personal data when you connect an MCP-compatible assistant to Swain.

Effective date: 12 July 2026

Controller: Swain Technology Ltd, company number 16730982

Registered office: 9 Cedar Crescent, Eaglescliffe, Stockton-On-Tees, England, TS16 0BB

Privacy contact: info@swain.technology

Scope

This notice explains how Swain Technology Ltd processes personal data when a user connects an MCP-compatible assistant to Swain. It applies to the hosted MCP endpoint at https://api.swain.technology/mcp.

The AI assistant or MCP client selected by the user is a separate service. Its privacy terms apply to the information the user gives it and to the connector results it receives.

Data processed

Depending on the user’s permissions and request, the connector may process:

  • Swain account and user identifiers;
  • tenant, account, project, connection, and deployed API identifiers;
  • OAuth authorisation grants, token claims, scopes, and token-lifecycle metadata;
  • deployed API schema and OpenAPI metadata;
  • tool inputs needed to select a connection, plan an integration, or validate a request artifact;
  • operational metadata such as tool name, workflow phase, result category, duration, input field names, error category, and recommended next tool; and
  • support, security, and audit records supplied by or associated with the user.

The connector is not designed to collect passwords, database credentials, private keys, API keys, OAuth bearer-token values, full assistant conversations, assistant memory, or unrelated user files. Users should not place secrets in tool arguments.

Purposes and lawful bases

Swain processes account, authorisation, tenant, connection, schema, and tool-request data because it is necessary to provide the connector and perform the contract with the customer or user (UK GDPR Article 6(1)(b)).

Swain processes proportionate operational telemetry, error information, abuse signals, and security/audit records for its legitimate interests in securing, maintaining, troubleshooting, and improving the connector (Article 6(1)(f)). Those interests are balanced against user rights by minimising logged content, excluding credential values and request bodies from MCP journey events, limiting access, and applying the retention periods below. Users may object to processing based on legitimate interests by contacting Swain.

Swain may process or retain limited records where necessary to comply with a legal obligation, respond to lawful requests, exercise data-protection rights, or establish, exercise, or defend legal claims (Article 6(1)(c) or, where applicable, Article 6(1)(f)). Consent is not used as the primary lawful basis for processing required to operate the connector.

Sharing and service providers

Swain shares data only as needed to operate, secure, support, and bill for the service. Current provider categories include network protection, UK compute and database hosting, EU object storage, error tracking, transactional email, and account billing. The current provider list, purpose, and principal processing location are published on the Swain service-provider page.

The MCP client or AI service selected by the user is not appointed by Swain as a subprocessor merely because the user connects it. The user directs the transfer of connector results to that service, and the service’s own privacy terms apply.

Retention

Swain applies the following default retention schedule:

  • OAuth authorisation codes expire after five minutes.
  • MCP access tokens expire after fifteen minutes.
  • MCP refresh tokens and grants expire after thirty days and may be revoked earlier when a user disconnects the connector.
  • Expired OAuth grant and token-lifecycle records may be retained for up to twelve months after expiry for abuse prevention and security investigation, then deleted or irreversibly anonymised.
  • Routine MCP operational telemetry is retained for thirty days. Individual records isolated for an active reliability or security investigation may be retained for up to ninety days.
  • Security and audit records are retained for twelve months. Records required for an active incident, dispute, regulatory request, or legal claim may be retained until that matter is resolved and for any applicable limitation period.
  • Support records are retained for twenty-four months after the support matter is closed, unless a longer period is required for an active dispute or legal obligation.

Production container logs are size-rotated and capped in addition to these time limits. Backups may retain deleted records temporarily until the applicable backup cycle completes; restored data remains subject to this schedule.

Security

Swain uses HTTPS, OAuth 2.0 authorisation code flow with S256 PKCE, short-lived and scoped access tokens, audience and tenant checks, confirmation-gated privileged workflows, credential redaction, restricted operational access, and size-rotated production logs. No system can be guaranteed completely secure.

Security concerns can be reported to info@swain.technology.

International transfers

Swain’s primary production application and database are hosted in London, UK. Some service providers operate internationally and may process limited data outside the UK. Where a restricted transfer occurs, Swain relies on the applicable UK adequacy regulation or the transfer safeguard made available in the provider’s data-processing agreement, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another legally recognised safeguard, together with appropriate technical and organisational measures.

User choices and rights

Users can disconnect the connector and revoke its authorisation. Depending on their circumstances, users may have rights to access, correct, delete, restrict, or object to processing, or receive a portable copy of personal data.

Requests can be sent to info@swain.technology. Swain may need to verify the requester’s identity. UK users may also complain to the Information Commissioner’s Office.

Changes

Material changes will be posted on this page with a revised effective date. Where required, users will receive additional notice.