Zway.ai

Trust and ethics

The limits are the product.

Zway operators post from accounts the client owns and authorises, or from the founder's own account with their sign-off. We do not create fake personas, fake reviews, or sockpuppet accounts, and we do not astroturf communities. Every piece of work is reviewable before it ships and logged after it ships.

Last reviewed 27 August 2026

The rules

What we do, and what we refuse to do.

These are commitments rather than disclaimers. The whole product depends on accounts that communities take seriously, and there is no version of this business that survives getting caught faking it.

  • Operators post from accounts you own

    Every account we post from is either owned and authorised by you, or is your own account posting with your sign-off. Access is granted through the platform's own delegation tools where they exist. When an engagement ends, access is revoked and the accounts stay entirely yours, because they were never ours.

  • We do not create fake personas

    No invented characters, no fabricated backstories, no accounts built to look like an unaffiliated enthusiast. When an operator participates in a community using their own established account, they are a real person with a real history, and they disclose their relationship to your company when the platform's rules or the context of the conversation calls for it.

  • We do not write fake reviews or testimonials

    Not on review sites, not in app stores, not in comment sections, and not on your own website. This includes reviews written by real people who were incentivised to write them without disclosure. If you want reviews, we will help you ask real customers properly.

  • We do not astroturf

    We do not manufacture the appearance of independent grassroots enthusiasm. No coordinated upvoting, no seeded threads pretending to be organic questions, no networks of accounts amplifying each other. Communities detect this eventually, and when they do, the account is worth less than nothing.

  • Everything is reviewable before it ships

    You can approve every asset, a sample of assets, or none, and you can change that setting per channel at any time. Whatever mode you choose, you see every published asset afterwards with the operator's name and a link to the live post.

  • We correct mistakes in public

    If an operator gets a fact wrong, the correction is public, fast, and made on the same account that made the error. You are told the same day. We do not quietly delete and repost, because in most communities that is more damaging than the original mistake.

The honest version

Why a human layer is the ethical answer, not the shortcut.

The uncomfortable question about this category is obvious: if an AI writes the post and a person clicks publish, who is really speaking?

The answer we hold ourselves to is that the account has to be what it claims to be. A founder's account carrying a founder's view, drafted by someone else and approved by them, is the same arrangement as every executive column ever published. An invented community member with a fabricated three-year history is fraud. The technology in the middle does not change which of those you are doing.

This is also why the human layer exists at all. A fully automated system has no one to hold accountable when it misreads a room, and no standing to lose when it gets caught. An operator has both, which is precisely what makes them trustworthy in a community.

Read the longer argument

Data and security

How your data and access are handled.

What we collect
Your company information, the credentials or delegated access needed to post, and the content produced for you. From the site, form submissions and privacy-preserving analytics.
Where it lives
Lead and account data in Supabase. Content and the five source documents in our internal systems, scoped per client.
Who can see it
The operators assigned to your account and the people supervising them. Not other clients, and not shared across accounts.
Credential handling
We prefer delegated access, such as LinkedIn page admin roles or CMS editor accounts, over shared passwords. Where a password is unavoidable it is held in a managed secrets store, never in a document or a chat message.
On exit
Access is revoked, the accounts remain yours, and the five source documents are handed over. You can request deletion of your data at any point.

Full detail is in the privacy policy. Questions about any of this go to hello@zway.ai.

The questions people actually ask

Is ghostwriting for a founder dishonest?
Not by itself. Executives have had speechwriters for a century and nobody considers that fraud. The line is whether the ideas and the judgement are genuinely the founder's, and whether the account is what it claims to be. A founder's account posting a founder's views, drafted by someone else and approved by them, is honest. An invented person is not.
Do operators disclose that they work with the company?
Yes, wherever the platform's rules or the context calls for it. On Reddit and in most communities, that means saying plainly that they work with the company when recommending it. Operators are trained to disclose early rather than to be caught later, because being caught costs the account permanently.
What happens if a platform changes its rules?
We stop doing the thing. Channel tactics are reviewed against platform policy regularly, and if a technique becomes non-compliant we drop it rather than looking for a workaround. If that materially changes what a channel can deliver for you, we tell you and re-plan rather than quietly under-delivering.
Will you say no to work?
Regularly. We decline channels where the only way to win is to break the rules, claims we cannot substantiate, and engagements where the founder wants volume without judgement. We would rather lose the engagement than run something that damages an account permanently.
Who is liable for what an operator posts?
Operators work under our supervision and to your approved documents, and we take responsibility for our mistakes, including correcting them publicly. Specific contractual liability is set out in the engagement agreement, and we are happy to walk through it before you sign anything.
Can I audit what has been posted on my behalf?
Yes. Every asset is logged with the operator who shipped it, the time it went live, and a link to the live post. That log is available to you continuously, not just in a monthly report, and it is exportable if you need it for your own records.

Ask us the hard version on the call.

Bring the objection you have not seen answered here. We would rather argue it out in thirty minutes than have it sit unresolved.

Book a demo

30 minutes. You leave with the plan either way.