Last updated: September 2026
This policy covers the Swan voice screening service, including its use through a connector inside a third-party assistant such as Muse. It sets out what a screening receives, what is kept, and what the service does not do.
Swan is operated by Humsana. This policy applies to recordings submitted to Swan and to the metadata records kept about screenings. It does not cover the assistant that calls Swan. When Swan is used inside Muse, Meta's own privacy policy governs Muse, the Muse account, and the conversation. This policy governs what reaches Humsana and what Humsana does with it.
Each screening produces a metadata record: the screening identifier, the date and time, the length of the recording, the detector version, the outcome, the evidence grade, the recommended action, the detector's score, the audio quality measurements behind that grade, the context the caller supplied, meaning what they stated about where the message came from and what it asked for, and whether the request used a reviewer credential. A caller may also state whether the person on the recording was a person or an automated agent. That statement is compared with the audio and reported in the response. It is not written to the record.
The record exists so that a result can be traced and explained, which matters when a screening is used to support a decision. It contains no audio. It contains no hash or fingerprint of the audio either, so it cannot be used to recognise a recording later, or to tell whether two recordings are the same. The digest of a recording is returned to the caller in that screening's response, so they can confirm the result belongs to the file they sent, and is not stored here.
The record is kept for 30 days, after which it is no longer served or used.
The web server writes standard access logs, which contain the requesting IP address, the method and path requested, the response status, and the timing. These logs exist to keep the service running and to detect abuse, such as a key used beyond its limits. They rotate at 20 MB and the five most recent files are kept; older files are deleted as new ones replace them.
Request bodies are not written to these logs, so submitted audio and the text of a request do not appear in them.
Muse runs each person's assistant inside a dedicated virtual machine, and a separate component decides which outbound requests are allowed and holds the credentials. In that arrangement:
Because the audio is not kept and no name, email address, or other identifier for the person in a recording is held, a screening usually cannot be located on request. With a screening identifier, the metadata record that matches it can be acted on.
To ask what is held about you, and for deletion where the law provides for it, contact us. Personal data is not sold and is not processed for advertising.
Swan is not intended for use by children. It is designed for adults assessing recordings that they have the right to assess.
If this policy changes, the date at the top of the page changes with it. Material changes are described on this page.
Email: contact@humsana.com