Legal
Privacy Policy
This Privacy Policy explains what personal data we collect when you use the SwayByte website and platform (the “Services”), why we collect it, who we share it with, how long we keep it and what rights you have over it.
SwayByte is owned and operated by OmniRogue.com (OmniRogue Inc.). OmniRogue Inc. is the data controller for personal data processed through the Services, and the seller and merchant of record for purchases made through this site unless expressly stated otherwise at checkout.
1. Company Information and Merchant of Record
SwayByte is owned and operated by OmniRogue.com (OmniRogue Inc.), a corporation registered in the State of Florida, United States. OmniRogue Inc. is the controller responsible for personal data processed through the Services.
OmniRogue Inc.400 N Tampa St Ste 1550 #767523
Tampa, FL 33602-4719
United States
Privacy and data requests: support@swaybyte.com
2. Information We Collect
A. Information you provide directly
- Account data: name, email address, password (stored hashed), and account preferences.
- Billing data: billing name, billing address, country, tax identifiers where applicable, and the plan or credit pack purchased.
- User Content: prompts, scripts, uploaded images, audio, video, reference material, brand assets and knowledge-base material you submit for processing.
- Support data: the contents of emails and support requests you send us.
B. Information collected automatically
- Device and connection data: IP address, browser type and version, operating system, device identifiers, language and referring URL.
- Usage data: pages viewed, features and studios used, jobs submitted, credits consumed, timestamps, error and diagnostic logs.
- Cookies and similar technologies, as described in the Cookies section below.
C. Payment information
Payments are processed by PCI-DSS compliant third-party processors, including Stripe. We do not receive or store full payment card numbers. We receive limited transaction metadata — last four digits, card brand, expiry, billing country, transaction status and processor identifiers — for account management, fraud prevention, tax compliance, refunds and dispute handling.
3. AI Models and Data Processing
To generate output, the content of your request — prompts and any reference material you attach — is transmitted to the AI model provider that serves the model you have selected, and is processed by that provider in order to return a result.
We select providers that offer business or enterprise processing terms which, as a default, do not use customer content submitted through their API to train their general-purpose models. Provider terms are set by those providers and may change; the current provider for a given model is identifiable in the Services.
We do not sell your User Content, and we do not use your User Content to train our own general-purpose models without your explicit, separately obtained consent.
We may process content through automated safety and moderation systems, and may retain limited records of blocked or flagged requests for abuse prevention.
4. How We Use Your Information
We process personal data to:
- provide, operate and maintain the Services and generate the output you request;
- create and administer your account and authenticate you;
- take payment, meter credits, issue receipts, handle renewals, cancellations, refunds and disputes, and meet tax and accounting obligations;
- provide customer support and respond to your enquiries;
- monitor, investigate and prevent fraud, abuse, security incidents and breaches of our Acceptable Use Policy;
- analyse aggregate usage in order to fix defects, improve reliability and develop the Services;
- send service and transactional communications, and — where you have not opted out — occasional product updates;
- comply with legal obligations and enforce our Terms.
Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract (account, billing and delivery of the Services); legitimate interests (security, fraud prevention, service improvement, and direct marketing to existing customers); legal obligation (tax, accounting, responding to lawful requests); and consent (optional marketing and any non-essential cookies), which you may withdraw at any time.
5. Data Sharing and Disclosure
We do not sell personal data and do not share it for cross-context behavioural advertising. We share personal data only with:
- Service providers and subprocessors acting on our instructions — cloud hosting and storage, AI model providers, payment processors, email delivery, analytics, customer support tooling and security services — each bound by contract to protect it and to use it only to provide their service to us;
- OmniRogue Inc. group operations, as SwayByte is a brand operated by OmniRogue Inc. and shares that company's account, billing, support and security infrastructure;
- Professional advisers such as auditors, accountants and lawyers, under duties of confidentiality;
- Authorities and third parties where required to comply with law, legal process or an enforceable governmental request, or where necessary to establish, exercise or defend legal claims, prevent fraud, or protect the rights, safety or property of any person;
- An acquirer, in connection with a merger, acquisition, financing or sale of assets, subject to this Policy continuing to apply to the transferred data.
6. Data Retention and Your Rights
We retain personal data for as long as your account is active and thereafter only as long as necessary for the purposes described in this Policy. Indicatively:
- Account data: for the life of the account, then deleted or anonymised within 90 days of account closure.
- User Content and generated output: until you delete it or close your account. Deleted items are removed from active systems promptly and purged from encrypted backups within 35 days.
- Billing and transaction records: retained for the period required by tax and accounting law, typically seven years.
- Security, abuse and moderation logs: typically 12–24 months.
Subject to applicable law, you have the right to access the personal data we hold about you; to have inaccurate data corrected; to have your data deleted; to restrict or object to processing, including direct marketing; to receive your data in a portable format; and to withdraw consent where processing relies on it.
California residents additionally have the rights to know, delete, correct, and opt out of sale or sharing (we do neither), and not to be discriminated against for exercising those rights.
To exercise any right, email support@swaybyte.com or see Data Deletion Requests. We verify requests against the account email and respond within 30 days (or 45 days for CCPA requests where an extension is required). If you are in the EEA or UK you may also complain to your local supervisory authority.
7. International Transfers
We are based in the United States, and our providers operate globally. Personal data is therefore transferred to and processed in the United States and other countries whose data protection laws may differ from those of your country.
Where personal data is transferred out of the EEA, the UK or Switzerland, we rely on an adequacy decision where one applies, or on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), together with appropriate technical and organisational safeguards.
8. Security
We use encryption in transit (TLS) and at rest, access controls and least-privilege permissions, credential hashing, network isolation, logging and monitoring, and regular review of our providers' security posture.
No system is perfectly secure. If a breach affecting your personal data occurs, we will notify you and the relevant supervisory authorities as required by applicable law.
9. Cookies and Similar Technologies
We use strictly necessary cookies for authentication, session management, security and load balancing. These are required for the Services to function and cannot be switched off in our systems.
Where we use analytics or preference cookies that are not strictly necessary, they are set only with your consent where consent is required in your jurisdiction, and you can change that choice at any time. Most browsers also allow you to block or delete cookies, though doing so may prevent parts of the Services from working.
10. Children's Privacy
The Services are not directed to children. We do not knowingly collect personal data from anyone under 18 years of age. If you believe a child has provided us with personal data, contact support@swaybyte.com and we will delete it.
11. Service Providers and Subprocessors
We engage subprocessors in the following categories: cloud infrastructure and storage; AI model inference providers; payment processing; transactional email delivery; error monitoring and analytics; and customer support tooling.
Each subprocessor is engaged under a written agreement requiring confidentiality, appropriate security measures, and processing limited to our instructions. A current list of subprocessors is available on request from support@swaybyte.com.
12. Service Improvement and Safety
We analyse aggregated and de-identified usage data — such as which features are used, job success and failure rates, latency and error patterns — to fix defects and improve the Services. This analysis does not identify individual users.
We may retain limited records of content flagged by our safety systems, and of accounts associated with abuse, for the purpose of preventing recurrence and enforcing our Acceptable Use Policy.
13. Changes to This Policy
We may update this Policy. The effective date at the top of this page shows when it was last revised. Where a change materially affects how we use your personal data, we will notify you by email or by prominent notice in the Services before it takes effect.
14. Contact Information
For any privacy question, or to exercise a data right, contact support@swaybyte.com. We aim to respond within 1–3 business days and in all cases within the timeframes required by applicable law.
OmniRogue Inc.400 N Tampa St Ste 1550 #767523
Tampa, FL 33602-4719
United States