SwanPrivacy

Swan Privacy Policy

Last updated: September 2026

This policy covers the Swan voice screening service, including its use through a connector inside a third-party assistant such as Muse. It sets out what a screening receives, what is kept, and what the service does not do.

Scope

Swan is operated by Humsana. This policy applies to recordings submitted to Swan and to the metadata records kept about screenings. It does not cover the assistant that calls Swan. When Swan is used inside Muse, Meta's own privacy policy governs Muse, the Muse account, and the conversation. This policy governs what reaches Humsana and what Humsana does with it.

What a screening receives

  • The recording being asked about, either as a file or as a link
  • Nothing else that identifies a person. There is no Swan account, no sign up, and no requirement to send a name, an email address, or a phone number in order to screen a recording
  • The API key of the integration, which identifies the application making the request rather than the person using it

What happens to the audio

  • The recording is decoded in memory and measured to produce a result
  • When the file format requires a seekable copy to decode, most commonly an m4a voice memo from a phone, that copy is held in a memory backed temporary file that is deleted as soon as decoding finishes. It is never written to the disk of the server
  • It is then discarded. The audio is not written to disk, not cached, and not queued for later work
  • It is not used to train or improve any model
  • It is not shared, licensed, sold, or disclosed to anyone, including advertisers
  • No decision about a person is made or stored on the basis of their voice

What is kept

Each screening produces a metadata record: the screening identifier, the date and time, the length of the recording, the detector version, the outcome, the evidence grade, the recommended action, the detector's score, the audio quality measurements behind that grade, the context the caller supplied, meaning what they stated about where the message came from and what it asked for, and whether the request used a reviewer credential. A caller may also state whether the person on the recording was a person or an automated agent. That statement is compared with the audio and reported in the response. It is not written to the record.

The record exists so that a result can be traced and explained, which matters when a screening is used to support a decision. It contains no audio. It contains no hash or fingerprint of the audio either, so it cannot be used to recognise a recording later, or to tell whether two recordings are the same. The digest of a recording is returned to the caller in that screening's response, so they can confirm the result belongs to the file they sent, and is not stored here.

The record is kept for 30 days, after which it is no longer served or used.

Server logs

The web server writes standard access logs, which contain the requesting IP address, the method and path requested, the response status, and the timing. These logs exist to keep the service running and to detect abuse, such as a key used beyond its limits. They rotate at 20 MB and the five most recent files are kept; older files are deleted as new ones replace them.

Request bodies are not written to these logs, so submitted audio and the text of a request do not appear in them.

What the service does not do

  • It does not identify who is speaking
  • It does not create or store a voiceprint, and it does not compare a recording against any other recording
  • It does not build a profile of any person, and it does not link screenings to each other by voice
  • It does not use recordings for advertising, for research, or for model training
  • It does not send a recording to a third party for analysis. The detector runs on infrastructure operated by Humsana

When Swan is used through Muse

Muse runs each person's assistant inside a dedicated virtual machine, and a separate component decides which outbound requests are allowed and holds the credentials. In that arrangement:

  • Swan receives only the recording being asked about, and only because the request was approved
  • Swan never receives Muse credentials, a password, or payment details
  • Swan returns a screening result to the assistant. What Muse retains about the conversation is governed by Meta's policy for Muse

Security

  • All traffic is encrypted with HTTPS
  • Each integration uses its own API key, and a key can be rotated or withdrawn
  • Requests are rate limited per key
  • Uploads are capped at 25 MB, and anything above the limit is rejected before it is processed

Choices and rights

Because the audio is not kept and no name, email address, or other identifier for the person in a recording is held, a screening usually cannot be located on request. With a screening identifier, the metadata record that matches it can be acted on.

To ask what is held about you, and for deletion where the law provides for it, contact us. Personal data is not sold and is not processed for advertising.

Children

Swan is not intended for use by children. It is designed for adults assessing recordings that they have the right to assess.

Changes

If this policy changes, the date at the top of the page changes with it. Material changes are described on this page.

Contact

Email: contact@humsana.com