Trust and ethics
The limits are the product.
Zway operators post from accounts the client owns and authorises, or from the founder's own account with their sign-off. We do not create fake personas, fake reviews, or sockpuppet accounts, and we do not astroturf communities. Every piece of work is reviewable before it ships and logged after it ships.
Last reviewed 27 August 2026
The rules
What we do, and what we refuse to do.
These are commitments rather than disclaimers. The whole product depends on accounts that communities take seriously, and there is no version of this business that survives getting caught faking it.
Operators post from accounts you own
Every account we post from is either owned and authorised by you, or is your own account posting with your sign-off. Access is granted through the platform's own delegation tools where they exist. When an engagement ends, access is revoked and the accounts stay entirely yours, because they were never ours.
We do not create fake personas
No invented characters, no fabricated backstories, no accounts built to look like an unaffiliated enthusiast. When an operator participates in a community using their own established account, they are a real person with a real history, and they disclose their relationship to your company when the platform's rules or the context of the conversation calls for it.
We do not write fake reviews or testimonials
Not on review sites, not in app stores, not in comment sections, and not on your own website. This includes reviews written by real people who were incentivised to write them without disclosure. If you want reviews, we will help you ask real customers properly.
We do not astroturf
We do not manufacture the appearance of independent grassroots enthusiasm. No coordinated upvoting, no seeded threads pretending to be organic questions, no networks of accounts amplifying each other. Communities detect this eventually, and when they do, the account is worth less than nothing.
Everything is reviewable before it ships
You can approve every asset, a sample of assets, or none, and you can change that setting per channel at any time. Whatever mode you choose, you see every published asset afterwards with the operator's name and a link to the live post.
We correct mistakes in public
If an operator gets a fact wrong, the correction is public, fast, and made on the same account that made the error. You are told the same day. We do not quietly delete and repost, because in most communities that is more damaging than the original mistake.
The honest version
Why a human layer is the ethical answer, not the shortcut.
The uncomfortable question about this category is obvious: if an AI writes the post and a person clicks publish, who is really speaking?
The answer we hold ourselves to is that the account has to be what it claims to be. A founder's account carrying a founder's view, drafted by someone else and approved by them, is the same arrangement as every executive column ever published. An invented community member with a fabricated three-year history is fraud. The technology in the middle does not change which of those you are doing.
This is also why the human layer exists at all. A fully automated system has no one to hold accountable when it misreads a room, and no standing to lose when it gets caught. An operator has both, which is precisely what makes them trustworthy in a community.
Data and security
How your data and access are handled.
- What we collect
- Your company information, the credentials or delegated access needed to post, and the content produced for you. From the site, form submissions and privacy-preserving analytics.
- Where it lives
- Lead and account data in Supabase. Content and the five source documents in our internal systems, scoped per client.
- Who can see it
- The operators assigned to your account and the people supervising them. Not other clients, and not shared across accounts.
- Credential handling
- We prefer delegated access, such as LinkedIn page admin roles or CMS editor accounts, over shared passwords. Where a password is unavoidable it is held in a managed secrets store, never in a document or a chat message.
- On exit
- Access is revoked, the accounts remain yours, and the five source documents are handed over. You can request deletion of your data at any point.
Full detail is in the privacy policy. Questions about any of this go to hello@zway.ai.
The questions people actually ask
Is ghostwriting for a founder dishonest?
Do operators disclose that they work with the company?
What happens if a platform changes its rules?
Will you say no to work?
Who is liable for what an operator posts?
Can I audit what has been posted on my behalf?
Ask us the hard version on the call.
Bring the objection you have not seen answered here. We would rather argue it out in thirty minutes than have it sit unresolved.
30 minutes. You leave with the plan either way.