Privacy Policy

Last updated: July 13, 2026

Last updated: July 13, 2026

1. Introduction & Scope

Perks Express, Inc. ("Perks Express," "we," "us," or "our") operates Blog Swiftly ("the Service"), a platform for AI-assisted blog content creation, SEO analysis, publishing, and client billing tools. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use the Service, regardless of where in the world you are located.

This policy applies to all users of the Service, including trial users, subscribers, and individuals who interact with public pages (such as approver review links, estimate review links, and our marketing site).

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, you should not use the Service.

2. Personal Data We Collect

Account data: Your name, email address, and authentication details when you register. If you sign in with Google OAuth, we receive your name and email as provided by Google.

Content data: Blog posts, personas, platform connections, voice recordings (transcribed text and audio files), estimates, invoices, and any other content you create, upload, or generate using the Service.

Billing data: Subscription status, plan type, and billing history. Payment details are processed exclusively by Stripe — we never store your full card numbers, CVV, or complete bank account details.

Usage data: Aggregate and session-level analytics about feature usage, device type, browser, IP address, and interaction logs to improve the Service and detect abuse.

Communication data: Records of emails sent to or from the Service (trial reminders, welcome emails, newsletter deliveries, document deliveries, and support communications).

Approver & client data: When you submit a blog post for approval or send an estimate/invoice, the recipient's name and email are collected to deliver the review link and record their response. These individuals are data subjects under this policy even if they are not registered users.

3. Lawful Basis for Processing (GDPR)

For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, we process your personal data only where we have a lawful basis under Article 6 of the UK GDPR / EU GDPR. The lawful bases we rely on are:

  • Performance of a contract (Art. 6(1)(b)): Processing your account data, content data, and billing data to provide the Service you signed up for.
  • Legitimate interests (Art. 6(1)(f)): Usage analytics, fraud prevention, security monitoring, and service improvement — balanced against your privacy rights.
  • Legal obligation (Art. 6(1)(c)): Retaining billing records and complying with tax or legal requirements.
  • Consent (Art. 6(1)(a)): For optional activities such as marketing communications and AI voice processing — you may withdraw consent at any time.

4. How We Use Your Personal Data

We use your personal data for the following purposes:

  • To provide, maintain, and improve the Service and its features
  • To process subscriptions, manage billing, and deliver receipts
  • To send trial reminders, welcome emails, and important service notices
  • To generate AI-assisted content based on your personas, voice recordings, and inputs
  • To publish content to third-party platforms you have connected
  • To send estimates and invoices to your clients and track their responses
  • To detect, prevent, and address fraud, abuse, or security issues
  • To comply with legal obligations

We do not sell your personal data to third parties. We do not use your blog content or voice recordings to train AI models.

5. AI Processing & Voice Data

When you use AI Assist features, your blog content, persona details, prompts, and transcribed voice text are sent to our AI providers (which may include Google, OpenAI, and Anthropic) to generate responses. These providers process your data solely to return AI-generated results to you.

Voice recordings you upload are transcribed using speech recognition. The audio file and transcript are stored with your account so you can review and manage your voice ideas. You can delete voice recordings at any time.

Important: You are responsible for not entering sensitive personal data (such as health information, government ID numbers, or financial account credentials) into AI prompts or voice recordings. Perks Express is not liable for sensitive data you voluntarily submit to AI processing.

6. Third-Party Services & Subprocessors

We use the following third-party services to operate the Service:

  • Stripe — payment processing (PCI-DSS compliant; processes card data, never shared with us)
  • Google — OAuth login authentication and AI model services
  • OpenAI / Anthropic — AI content generation models
  • Resend — transactional email delivery
  • WordPress (your site) — publishing, when you connect your own WordPress credentials
  • Zapier / Make.com — optional webhook integrations you configure for non-WordPress platforms

Each provider has its own privacy policy governing data they process. We only share the minimum data necessary to provide the specific feature you are using. We do not grant these providers the right to use your content for their own purposes beyond providing the service to us.

When you publish to a Third-Party Platform (WordPress, Medium, LinkedIn, etc.), your published content is subject to that platform's privacy policy and terms. Perks Express is not responsible for how third-party platforms handle your data after publication.

7. International Data Transfers

The Service is available worldwide. Your personal data may be processed in the United States and in other countries where our subprocessors operate. If you are located in the EEA, UK, or Switzerland, your data may be transferred to countries that the European Commission has not deemed to provide an "adequate" level of data protection.

For such transfers, we rely on appropriate safeguards, which may include Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Agreement, or other valid transfer mechanisms. Where we rely on SCCs, a copy is available upon request.

If you are located in a country outside the United States, you acknowledge that your personal data will be transferred to and processed in the United States, which may have data protection laws that differ from those in your jurisdiction.

8. Data Retention

We retain your personal data only as long as necessary to fulfill the purposes outlined in this policy:

  • Account data: Retained for as long as your account is active
  • Content data: Retained for as long as your account is active; after cancellation, retained for 30 days then permanently deleted, unless legally required otherwise
  • Voice recordings & transcripts: Retained until you delete them or your account is terminated
  • Billing records: Retained for the period required by tax and financial regulations (typically 7 years)
  • Usage data: Retained in aggregate, de-identified form indefinitely; raw usage logs retained for up to 12 months
  • Approver/client email records: Retained for as long as the associated blog post or estimate/invoice exists in your account
  • Communication data (emails sent): Retained for up to 12 months for delivery confirmation and abuse prevention

You may request early deletion of your data at any time, subject to legal retention obligations.

9. Data Security

We use industry-standard security measures to protect your personal data, including TLS encryption for data in transit and encryption at rest. Access to personal data is restricted to authorized personnel who require it to operate the Service. Platform credentials (e.g., WordPress application passwords) are stored encrypted and only used to publish your content.

No method of transmission or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify affected users and the relevant supervisory authority without undue delay, in accordance with applicable law.

Workspace isolation & admin access: Your accounts, blog posts, personas, channels, estimates, invoices, and client data are private to your workspace. Blog Swiftly platform administrators can only access the account data necessary to provide login, billing, and core Service operation (such as your name and email address). The platform admin cannot view a blogger's accounts, published or draft content, connected channel credentials, or any other private workspace data unless that admin has been explicitly added as a team member to that specific account. Editors and approvers you invite see only the account they were invited to — never any other blogger's or admin's work. This keeps every creator's content confidential and private by default.

Magic-link review access: When you submit a post for approval, send an estimate or invoice, share a wireframe layout for review, or deliver a post to a client, the recipient receives a magic link — a short-lived, single-use, tokenized access key — rather than a shared password. Each review round (for example, each new wireframe review request) is issued its own unique token, so every link ever sent remains valid and resolvable to its own review context, and a stale or reused token cannot be used to edit content, publish a post, or alter an invoice. Tokens are scoped to a single document and action, and recipients review via a public, read-only page — they never receive full app access unless you explicitly invite them as a team member. You can learn more on our Security overview.

10. Your Rights — GDPR (EEA, UK, Switzerland)

If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure ("right to be forgotten"): Request deletion of your personal data, subject to legal retention obligations
  • Right to data portability: Receive your personal data in a structured, machine-readable format and transmit it to another controller
  • Right to object: Object to processing based on legitimate interests or for direct marketing
  • Right to restrict processing: Request that we limit processing of your data under certain conditions
  • Right to withdraw consent: Withdraw consent for processing based on consent (e.g., marketing emails) at any time without affecting processing already carried out
  • Right to lodge a complaint: You have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK, the CNIL in France, or the relevant authority in your country)

To exercise any of these rights, contact us through our About Us page. We will respond within one month, as required by the GDPR. If we need more time, we will inform you of the extension and the reason.

11. Your Rights — CCPA/CPRA (California Residents)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  • Right to know: Request the categories and specific pieces of personal data we collect, how we use it, and who we share it with
  • Right to delete: Request deletion of your personal data, subject to exceptions under California law
  • Right to correct: Request correction of inaccurate personal data
  • Right to opt out of sale or sharing: We do not sell your personal data. We do not share your personal data for cross-context behavioral advertising.
  • Right to non-discrimination: We will not discriminate against you for exercising your privacy rights
  • Right to limit use of sensitive personal data: You may request that we limit use of sensitive personal data to what is necessary to provide the Service

To submit a request under the CCPA/CPRA, contact us through our About Us page. We will verify your identity before processing your request and respond within 45 days, as required by California law.

12. Your Rights — Other Jurisdictions

If you are located outside the EEA, UK, Switzerland, or California, you still have the right to access, correct, or delete your personal data, and to object to certain processing. Contact us through our About Us page to exercise any of these rights.

13. Cookies & Tracking

We use the following categories of cookies and similar technologies:

  • Essential cookies: Required to maintain your login session, remember language and theme preferences, and provide core functionality. These cannot be disabled.
  • Functional cookies: Remember your settings (e.g., sidebar width, selected account) to improve your experience.
  • Analytics cookies: Help us understand how users interact with the Service so we can improve it. These are deactivated by default and only activated with your consent.

We do not use third-party advertising cookies, cross-site tracking pixels, or fingerprinting for advertising purposes. We do not sell cookie data to third parties.

For EEA and UK users, non-essential cookies are only set after you have given consent. You can manage or withdraw your cookie consent at any time through your browser settings. Most browsers allow you to refuse cookies or alert you when cookies are being sent.

14. Children's Privacy

The Service is not intended for or directed to children under the age of 13 (under 16 in the EEA, UK, and other jurisdictions where the age of digital consent is 16). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us immediately through our About Us page, and we will take steps to delete such data without undue delay.

15. Data Controller & Contact

Perks Express, Inc. is the data controller responsible for your personal data. For any questions about this Privacy Policy or to exercise your data subject rights, visit our About Us page for contact information.

For privacy-specific inquiries, you may contact us with the subject line "Privacy Request" through the contact information on our About Us page. We will respond to verified requests within the timeframes required by applicable law.

16. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated via email or in-app notice at least 30 days before taking effect, where required by law. Continued use of the Service after changes constitutes acceptance of the updated policy.

We use cookies to keep you signed in, remember your preferences, and understand how the product is used. See our Privacy Policy for details.