Privacy Policy
Last updated October 5, 2026
This policy explains how account information, billing information, and desktop data are handled when you use SwarmPane.
Who is responsible
OverMCP LLC in United States is responsible for the SwarmPane account service. Contact support@overmcp.com about privacy questions or requests.
Information used for your account
When you register or sign in, the service stores an account identifier, email address, display name, and account timestamps. Google sign-in may also provide a profile image. Email/password accounts store a salted password hash rather than the password itself, an email-verification timestamp, and the version of terms accepted. Every account also has a session version: signing out or resetting a password changes it, which ends the account’s browser sessions everywhere.
Verification and recovery links use random, expiring tokens; the database stores a hash of the token. Browser sessions use a signed, HttpOnly cookie. Desktop connections use a separate token so the application can check your account and subscription.
Billing and support information
Stripe processes payments and maintains payment details under its own privacy policy. SwarmPane stores the customer and subscription identifiers, plan identifier, subscription status, and billing-period start and end needed to determine access, including during a trial or the grace period after a failed payment. A support request may include your contact details and any information you choose to include.
Project files, conversations and voice
Desktop workspace data, including chat history and workflow configuration, is stored on the computer running the app. The account database does not currently synchronize your project files or conversation history between computers.
The desktop app keeps a log of its own messages, such as errors and status lines, on your computer (on macOS in ~/Library/Logs/SwarmPane, at most about 2 MB). Recognized secrets such as tokens and API keys are removed before a line is written, but a line can include file or project names, or an error message printed by a coding tool. The log is not sent anywhere; Export diagnostics in the app’s settings adds its latest lines to the file you save, which you choose whether to share.
When you run a coding agent or connect a tool, that provider may receive prompts, selected files, or other information needed for your request. Its own settings, terms, and privacy policy apply. Review a tool’s access before enabling it.
With cloud voice, included with SwarmPane Pro, the desktop app sends the recording of each dictation to the SwarmPane service, which has it transcribed by Whisper large v3 turbo, an open speech-recognition model running on Cloudflare Workers AI, and returns the text to the app. The audio and the text exist only while that request is handled: SwarmPane does not store or log them or use them for anything else, and Cloudflare does not use them to train models. To count credits, the service keeps the seconds of audio each account used in each credit period, and each request leaves a log entry with its length, timing and outcome, never its words.
When cloud voice is off or can’t be used, for example offline or out of credits, any transcription happens on your computer and the audio does not leave it. You can turn cloud voice off in the app’s voice settings. Voice is not currently available in Windows or Linux test builds. Review operating-system microphone permissions and provider settings before recording.
Why information is processed
Account information is used to authenticate you, connect the desktop app, manage subscriptions, deliver verification and recovery messages, respond to support requests, and protect the service from abuse.
Where data-protection law requires a lawful basis, account and subscription functions support the requested service, security measures support legitimate interests in protecting it, and records required by law support legal obligations. Optional communications or features that require consent will request it separately.
Service providers and transfers
Depending on the feature used, providers include Turso for account storage, Google for Google sign-in and the website’s fonts (the desktop app’s fonts are bundled with it), Stripe for billing, and Cloudflare for website hosting, account email delivery, and cloud voice (transcription with Workers AI and credit counts in D1). Apple sign-in is not yet implemented.
Providers may process data in countries outside your location. We do not treat connecting a coding provider as permission to upload all files on your computer.
Retention
Browser sessions expire after seven days. A desktop sign-in is extended while the app uses it; it ends after at most thirty days without use, and 180 days after it was approved in any case. Unapproved desktop pairing codes expire after ten minutes. Email verification and password-reset tokens expire after thirty minutes and are consumed when used. Expiration prevents use; stored expired records are removed through maintenance.
Account and subscription records are retained while needed to provide the service and meet legal or accounting obligations. Cloud voice audio and transcripts are not retained after the request; cloud voice credit records (the account identifier, the credit period and the seconds used) are kept like subscription records. Support records are retained while needed to resolve the request.
Cookies and security
The website uses an essential session cookie to keep you signed in. Authentication and desktop-pairing request limits use keyed hashes of request identifiers. The current application does not require marketing cookies to create an account. See Cookie information.
Credentials are kept on the server; they are not included in the website bundle. Desktop account tokens use the operating system’s secure storage when available. No system is completely secure, so keep your devices and coding-provider accounts protected.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability of your personal information. You may also have the right to complain to a data-protection authority. Contact support@overmcp.com; we may need to verify ownership before acting on an account request.
Canceling a subscription, signing out, and deleting an account are separate actions. Deleting a SwarmPane account does not automatically delete data held by your coding providers or files on your computer.
Changes
We will update this page when data practices change and provide further notice where required. Review the date above and contact us if anything is unclear.