LEGAL · PRIVACY POLICY

Your privacy, in plain words.

What we collect when you visit Mitte, join the waitlist, apply as a partner or developer, or use the partner portal, and the choices you have.

Last updated Swfte Limited

The short version.

  • Mitte is operated by Swfte Limited, which is responsible for your personal data.
  • We collect only what you give us (for example your name and email when you join the waitlist or apply as a partner) and what we need to run the partner portal securely.
  • The website uses no analytics, advertising or tracking. It loads no third-party scripts or fonts.
  • Waitlist and application details are recorded in a Google Sheet that Swfte manages. Partner accounts live on our servers in AWS Ireland (eu-west-1).
  • We never sell your data. We share it only with the service providers listed below, and only so they can provide their service to us.
  • You can ask to see, correct or delete your data, or withdraw your consent, at any time by writing to privacy@swfte.com.

This summary is here to help. The full text below is what applies.

On this page

1.Who we are#

Mitte is a personal AI assistant, currently in an invite-only beta. Mitte, the website at mitte.si and the partner portal at partners.mitte.si are operated by Swfte Limited (“Swfte”, “we”, “us”), 6th Floor, 2 Grand Canal Square, Dublin 2, D02 A342, Ireland.

For the purposes of the EU General Data Protection Regulation (“GDPR”) and the UK GDPR, Swfte is the controller of the personal data described in this policy, except where we explain that we act on behalf of a partner business (see section 3.7).

Contact us about privacy

Email privacy@swfte.com. You can also reach our data protection contact at dpo@swfte.com, or write to us at the address above.

2.What this policy covers#

This policy explains how we handle personal data when you:

  • visit mitte.si or partners.mitte.si;
  • join the Mitte waitlist or request an invitation, or are invited by someone else;
  • apply to become a Mitte partner or developer;
  • create and use a partner portal account;
  • receive an email from us, or pay a partner business through Mitte-managed checkout.

Processing inside the Mitte app itself (for example, your conversations with your assistant) is described in the privacy information provided with the app. Where the two differ for something that happens in the app, the app’s information applies.

Our Cookie Policy lists every cookie and browser-storage item we use. Use of Mitte is also governed by our Terms of Service.

3.The information we collect#

3.1 When you visit the website

Like every website, our servers receive the technical information your browser sends with each request: your IP address, the page requested, the time, and your browser’s user-agent string. We use it only to deliver the page and keep the service secure. Our reverse proxy does not record request bodies, so the contents of forms are never written to access logs.

The /download link (used by the QR code) reads your user-agent once to send your phone to the right app store. It is not stored. The QR code itself is generated inside your browser.

We do not use analytics, advertising, social-media pixels, session recording or fingerprinting. Our fonts and videos are served from our own servers, so no third party learns that you visited.

3.2 When you join the waitlist or request an invitation

The invitation form asks for your name and email address, plus anything you choose to add in the optional fields, and your agreement to be contacted about Mitte early access. We add a reference number (for example MI-…), the form type and the time of submission.

3.3 When you apply as a partner or developer

Partner applications ask for your name, work email, business or project name, partner category, and optionally your website and a message. Developer applications ask for your name, email, project or team name, the surface you want to build for (for example SMS & WhatsApp, Voice, Wearables, AR & VR or Apps & web), your intended use case and optionally your website. Please don’t include sensitive personal information in the free-text fields.

3.4 Information used to protect the forms

To stop abuse, the forms check that a submission comes from our website, include a hidden field that only automated bots fill in, and limit each connection to ten attempts per hour. The rate limit uses your IP address in the server’s memory only: it is never written to disk or added to your submission, and it is forgotten within an hour.

3.5 When you have a partner portal account

  • Account details: your name, email address, company name, whether your email is verified, and when the account was created. Your password is never stored, only a salted one-way hash of it (see section 9).
  • Sign-in sessions and one-time links: a random session token (stored only as a hash) and the email verification and password-reset tokens we send you (also stored as hashes, valid for 24 hours and 1 hour respectively, and usable once).
  • Your sites and catalog: the sites you connect (name, web address, platform, branding and settings), the domain verification challenge and its result, the product catalog you import or edit (titles, descriptions, prices, availability, product and image links) and your published app.
  • API keys: site keys are shown to you once and stored only as a hash plus a short prefix so you can recognise them.
  • Activity history: a record of the most recent 200 actions on your account (for example “Site settings updated”) with the time. It does not include your IP address.
  • Abuse protection: request counters that limit sign-in, registration, recovery and API attempts. They are keyed by a SHA-256 hash of your IP address, email address or account ID, and are deleted when their time window (at most one hour) ends.

To verify that you control a domain, our servers look up a public DNS TXT record (_mitte-challenge.your-domain). We never fetch arbitrary pages from your website.

3.6 Emails we send

We send partner account emails (to confirm your address or reset your password) through Amazon Simple Email Service in the EU (Ireland) from partners@mitte.si. They contain a one-time link and no tracking pixels. Our mail relay does not log recipients or links. If you joined the waitlist, we use your email address to send your invitation when you are selected, and occasional updates about your place on the waitlist.

3.7 Partner analytics and managed payments

Partner businesses can send us events about activity that started in Mitte (for example “product viewed” or “order completed”) so they can see reports. Customer, session, product and order identifiers are hashed per site when they arrive, conversation transcripts are never ingested, and groups smaller than five are withheld from reports. For this data we act as a processor on behalf of the partner, who is the controller.

If a partner uses Mitte-managed payments, you pay on a page hosted by Stripe. Card details go only to Stripe; we never see them. After payment, Stripe tells us the result and, so the partner can deliver your order, your name, email address and, where collected, shipping details, together with the items, amounts and currency. We share these order details with the partner that is fulfilling it.

3.8 When someone invites you

Mitte members can invite friends, family or their audience. If someone invites you, they give us the contact details needed to deliver the invitation. We use them only to send that invitation and to connect your access to it. Members should only invite people who would expect to hear from them.

4.How we use it, and our legal bases#

Data protection law requires a legal basis for each use of personal data. Here is ours:

Purposes and legal bases
PurposeDataLegal basis
Managing the waitlist, running invitation rounds and contacting you about early accessName, email, optional details, referenceConsent (GDPR art. 6(1)(a)), given with the checkbox. You can withdraw it at any time.
Reviewing partner and developer applications and replying to youApplication detailsSteps you asked for before a contract (art. 6(1)(b)), and your consent to be contacted.
Creating and running your partner account, sites, catalog, keys and published apps; sending verification and password-reset emailsAccount, site and catalog dataPerformance of our contract with you (art. 6(1)(b)).
Keeping the service secure: origin checks, bot traps, rate limits, session protection, activity historyIP address (in memory or hashed), account ID, activity historyLegitimate interests (art. 6(1)(f)) in preventing fraud and abuse.
Processing managed payments, refunds, disputes and transfersOrder, payment and fulfilment recordsContract (art. 6(1)(b)) and legal obligations such as accounting and tax (art. 6(1)(c)).
Partner analytics reportsHashed identifiers and eventsProcessed on the partner’s instructions; the partner determines the legal basis.
Delivering an invitation from another memberThe contact details they provideLegitimate interests (art. 6(1)(f)) of the member and of Swfte in letting people invite those they know.
Complying with the law and defending legal claimsAny relevant dataLegal obligation (art. 6(1)(c)) and legitimate interests (art. 6(1)(f)).

We do not use your data for advertising, we do not sell it, and we do not share it for cross-context behavioural advertising.

5.The waitlist, invitation rounds and random draws#

Because demand for the beta is high, Mitte grows by invitation. Early members received access first and can invite others; partners and creators can invite their audiences. Everyone else can join the waitlist. Invitations from the waitlist are released in rounds, and places in a round are allocated partly by random draw and partly by operational factors, such as available capacity in a region or on a device platform.

The random draw does not use your personal characteristics, and we do not profile you to decide whether you are invited. Being selected, or not yet selected, for a beta invitation has no legal effect on you and does not similarly significantly affect you, so it is not automated decision-making within the meaning of article 22 GDPR. You can still ask us how a round was run, or ask a person to look at your request.

Joining the waitlist is free and involves no purchase. See section 5 of our Terms of Service for how invitations work.

6.Who we share it with#

We use a small number of service providers. They process personal data only on our instructions and under data processing agreements, except where noted.

Service providers and recipients
RecipientWhat they doWhere
Google (Google Workspace: Sheets and Apps Script)Receives and stores waitlist requests and partner and developer applications in a Google Sheet that Swfte manages.Google’s global infrastructure, which may include the United States.
Amazon Web Services (AWS)Hosts the website and partner portal, stores the partner database, its continuous backups and daily disk snapshots (all encrypted), may store an encrypted copy of form submissions, and sends partner emails through Amazon SES.EU, Ireland (eu-west-1).
StripeOnly if a partner enables managed payments: onboarding of the partner’s connected account, hosted checkout, payments, refunds and transfers. Stripe is an independent controller for its own identity verification and fraud prevention.EU (Stripe Payments Europe, Ireland) and the United States.
Partner businessesReceive the order and contact details needed to fulfil a purchase you make through Mitte-managed checkout.Wherever the partner operates.
Advisers and authoritiesLawyers, auditors and insurers under confidentiality; authorities where the law requires it.Mainly the EU.

Let’s Encrypt issues our TLS (HTTPS) certificates. It receives only our domain names, never information about you. Apple’s App Store and Google Play are linked from our site; we share nothing with them, but their own privacy policies apply once you visit them.

A partner’s published business information (business name, website, catalog and app) is public by design and may appear in Mitte for users who are looking for it. If Swfte is involved in a merger, acquisition or sale of assets, personal data may transfer to the new owner under this policy, and we will tell you before that happens.

7.International transfers#

We keep the partner portal and its backups in the EU (AWS Ireland). Some providers, or their parent companies, are based in the United States or process data there, notably Google for the waitlist and application sheet, and Stripe.

When personal data leaves the EEA or UK, we rely on:

  • the EU-US Data Privacy Framework (and its UK Extension and the Swiss-US framework) for recipients that are certified under it, such as Google LLC, Amazon.com, Inc. and Stripe, Inc.; and
  • the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), which are part of these providers’ data processing terms, together with supplementary measures such as encryption in transit and at rest.

You can ask for more information about these safeguards, or a copy of them, by writing to privacy@swfte.com.

8.How long we keep it#

We keep personal data only for as long as we need it for the purpose we collected it for:

Retention periods
InformationHow long
Waitlist and invitation requestsUntil you are invited and your access is set up, you ask us to remove you, or 24 months after your most recent request, whichever comes first.
Partner and developer applications24 months after your most recent application, unless the application leads to a partnership, in which case it is kept for the life of that relationship.
Form rate-limit data (IP address)In memory only; forgotten within an hour or when the server restarts.
Partner account, sites, catalog and keysWhile your account exists. Deleting your account deletes them immediately, except payment records (below).
Sign-in sessions7 days, or until you sign out (sign-out everywhere ends all of them).
Verification and password-reset links24 hours and 1 hour respectively; removed once used or replaced.
Activity historyThe most recent 200 entries, while your account exists.
Portal rate-limit countersUntil their window ends, at most one hour.
Partner analytics events90 days; order summaries 90 days after their last update.
Managed payment and order recordsFor as long as needed for refunds, disputes and reconciliation, and then as accounting and tax law requires (7 years). A connected payment account blocks deletion of the account until this is settled.
Backups of the partner databaseContinuous encrypted backups and daily disk snapshots are kept for 7 days on a rolling basis, so deleted data disappears from backups within about 7 days.
Technical server logsUp to 30 days. They never contain form contents or passwords.

9.How we protect it#

  • Encryption in transit: every page and API is served over HTTPS (TLS); plain HTTP is redirected.
  • Encryption at rest: server disks, snapshots and backup storage are encrypted (AES-256), and stored form copies use server-side encryption.
  • Passwords are hashed with scrypt and a unique random salt. Session tokens, one-time email links and API keys are stored only as SHA-256 hashes.
  • Session cookies are host-only, Secure, HttpOnly and SameSite=Lax, and changes require a matching origin.
  • Least privilege: each component has only the access it needs (for example, the mail relay can only send our two account email templates to links on our own portal). Secrets are kept in AWS Systems Manager Parameter Store, and servers have no SSH access.
  • Minimal logging: request bodies, passwords, form contents, email addresses and email links are not written to logs.
  • Abuse controls: origin checks, request size limits, bot traps and rate limits on every form and sign-in route.

No system is perfectly secure. If you believe you have found a vulnerability, please tell us at security@swfte.com. If a breach is likely to put your rights at risk, we will tell you and the supervisory authority as the law requires.

10.Your rights#

If you are in the EEA, the UK or Switzerland, you have the right to:

  • access your personal data and receive a copy;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict how we use it;
  • receive data you gave us in a portable format (portability);
  • object to processing based on legitimate interests;
  • withdraw consent at any time, for example to leave the waitlist, without affecting what we did before; and
  • not be subject to decisions based solely on automated processing that significantly affect you.

How to exercise them

Email privacy@swfte.com from the address your request relates to, and include your reference number if you have one. Partner account holders can also update their profile, sign out everywhere, and permanently delete their account from Account settings in the portal.

We reply within one month. For complex requests we may extend this by up to two further months, and we will tell you if we do. It is free, unless a request is clearly unfounded or excessive. We may ask you to confirm your identity first. Wherever you live, we will consider any privacy request you make.

11.Cookies and browser storage#

mitte.si stores only two optional preferences in your browser (light or dark theme, and whether background motion is paused), and only when you use those controls. The partner portal uses one strictly necessary sign-in cookie. There are no analytics or advertising cookies. The details are in our Cookie Policy.

12.Children#

Mitte is not directed at children under 16, and you must be 18 or over to join the beta or apply as a partner (see our Terms). We do not knowingly collect personal data from children under 16. If you think a child has given us their details, contact privacy@swfte.com and we will delete them.

13.Changes to this policy#

We will update this policy when our services or the law change. The date at the top shows the latest version. If a change is significant, for example a new purpose or a new kind of recipient, we will tell you by email or in the product before it takes effect, and ask for your consent again where the law requires it.

14.Contact and complaints#

Questions, requests or concerns: privacy@swfte.com, or write to Swfte Limited, 6th Floor, 2 Grand Canal Square, Dublin 2, D02 A342, Ireland.

You also have the right to complain to a data protection supervisory authority, in particular where you live or work or where you think an infringement happened. We would appreciate the chance to resolve your concern first.