What Swarrm handles, in plain language
The answer depends on the surface. The public verifier reads your chosen bundle locally. The hosted gateway handles model traffic in transit. Evidence stores commitments plus bounded operational metadata, which can itself be sensitive.
If you just visit this site
Nothing. No cookies, no trackers, no analytics. The verifier on Verify a bundle runs entirely in your browser — a bundle you drop there is read locally and never uploaded. Choosing it causes no bundle-related request; the page, WASM and optional sample files still load from this site. The site is served by Cloudflare Pages, which handles the connection like any host.
If you create a hosted account
We store the email address and organisation name you give at signup, and your API key in hashed form. Your evidence log stores fingerprints (one-way, salted hashes) and bounded operational metadata of captured actions. Standard capture does not persist prompts, outputs, tool arguments, or business payload bodies in that log, but metadata can still be customer data and must be classified accordingly. Content-fingerprint nonces are kept outside the evidence log and encrypted at rest. With the recorder, they remain in your mounted local volume; with the hosted gateway, they are held in your tenant's encrypted service vault. The operational metadata remains readable.
If you point traffic at the hosted gateway, requests pass through us in transit to reach your model provider; they are relayed, not written down. If that transit is more than you want, run the recorder inside your own network so payloads and nonce custody remain there; you control whether hashes and operational metadata are sent to another service.
Deletion, retention, questions
Email proof@swarrm.ai from your signup address and we delete your account and your tenant's log. We keep data only while your account exists — there is no secondary use, no sale, no sharing, no advertising, full stop. Data is processed in Switzerland on hardware we own.
When enabled, anchoring submits a 32-byte checkpoint hash to Base Sepolia staging and requests a non-qualified RFC 3161 timestamp. The offline verifier treats both as claims rather than independently confirmed time evidence. Neither submission contains prompts, outputs, tool arguments, or customer payloads.