Privacy Policy

Effective 3 August 2026 · Version 2.0

1. Who We Are

Seido AI Ltd, 17 Meriden Close, Bromley, BR1 2UF, United Kingdom, is the data controller for the personal data described in this policy. You can reach us any time at help@seido.dev.

This policy explains how we process personal data when you use the Seido app (app.seido.dev), subscribe to our newsletter, take part in our user research, or otherwise interact with our website at www.seido.dev.

2. Information We Collect

2.1 Account Information

When you create a Seido account, we collect your name, email address, and the sign-in method you choose (Google, GitHub, Apple, or a magic link). Sign-in is handled by Firebase Authentication. We also collect contact details you voluntarily provide when you subscribe to the newsletter or contact us.

2.2 Your Knowledge Base Content

The heart of Seido is the business knowledge base you build: documents you upload, notes and wiki pages you write, and answers you give our AI agents. This can include information about your business, your plans, and, depending on what you put in, personal data about you or others. It is stored on Google Cloud (Firestore and Cloud Storage). If session replay is on for your account, knowledge base content shown on screen can also appear in replays stored with PostHog (see section 2.6). It is your data: we use it only to run the product for you, never for advertising, and we never sell it.

2.3 Payment Information

If you subscribe to a paid plan, payments are handled by Stripe. Your card details go directly to Stripe and never touch Seido's servers. We receive and keep what we need to run your subscription: your plan, subscription status, billing history, and the last four digits and brand of your card so you can recognise it.

2.4 Usage Information

On the website, we may collect your IP address, browser type, device information, and pages visited. In both the app and this website, we use PostHog (hosted in the EU) to record product usage (which features you use, buttons you click, and pages you visit), linked to your account so we can understand how people actually use Seido and fix what isn't working.

2.5 AI Processing Records

When our AI agents run, we keep technical traces of those runs in Langfuse, an AI observability tool that we host ourselves in our own Google Cloud environment rather than sending traces to a third-party service. Traces can include the content you submitted to the agent and the agent's response. We use them to debug problems, track costs, and improve agent quality, and for nothing else. Traces are deleted when you delete your account, or sooner on request (see section 7).

2.6 Session Replay & Research Recordings

In-app session replay. We record how you interact with the product using PostHog session replay (hosted in the EU). Replays capture what is displayed on your screen while you use Seido, which can include the content of your knowledge base, along with your clicks and navigation. Sensitive inputs like passwords are masked, and this never involves your camera or microphone. We use these replays to find bugs and understand where the product confuses people. If you'd rather not be recorded this way, tell us at help@seido.dev and, once we've verified the request is really from you, we'll switch replay off for your account. You can also ask us to delete existing replays at any time (see section 7).

Website session replay. Session replay can also run on our website at www.seido.dev, recording what is on screen along with your clicks and navigation as you move around the site. The same limits apply: sensitive inputs like passwords are masked, and it never involves your camera or microphone. On the website, replay follows the same controls as the rest of our site analytics: turn analytics off on this device (see section 9) and replay stops with it, or ask us at help@seido.dev.

Research sessions. When you take part in our user research (scheduled sessions where we watch how you work and ask questions), those sessions are recorded (screen and audio) only with your explicit consent, given before the session starts. You can decline recording and still take part, and you can ask us to delete a recording at any time.

2.7 Newsletter & Email Information

We may collect information about your subscription including your time of signup, form URL, page URL, consent text shown, confirmation status, and unsubscribe events. We may collect information about emails sent to your email including delivery status, opens, clicks, bounces, and unsubscribes (used to measure performance and maintain list hygiene). We do not intentionally collect special categories of data via the newsletter form.

3. How AI Processes Your Content

The content you put in your knowledge base, and the messages you send our agents, are processed by large language models to generate answers, build your knowledge map, and produce documents for you. We use models from various suppliers, accessed through OpenRouter.

Your content is used to provide Seido and is not used to train AI models. This applies across the suppliers we use.

4. How We Use Your Information

  • Run Seido for you: storing your knowledge base, running agents on it, keeping you signed in. Legal basis: performing our contract with you (UK GDPR Art. 6(1)(b)).
  • Take payment and manage your subscription. Legal basis: performing our contract with you (Art. 6(1)(b)); keeping billing records afterwards is a legal obligation (Art. 6(1)(c)), because UK tax law requires it.
  • Send you our newsletter and product updates. Legal basis: Consent (Art. 6(1)(a)). You asked for it, and you can stop it any time.
  • Understand usage and improve the product (analytics, session replay, AI traces, debugging). Legal basis: Legitimate interests (Art. 6(1)(f)). Watching how the product is actually used is how we make it better and keep it secure. You can opt out of session replay for your account at any time (see section 2.6), and you can turn off analytics on this website at any time (see section 9).
  • Measure how our emails perform (aggregated open, click, and bounce rates). Legal basis: Legitimate interests (Art. 6(1)(f)) in improving our communications.
  • Record user research sessions. Legal basis: Consent (Art. 6(1)(a)), asked for explicitly before each session, never assumed.
  • Keep Seido secure: preventing abuse, investigating incidents, protecting your data. Legal basis: Legitimate interests (Art. 6(1)(f)).
  • Maintain compliance records and manage the mailing list (deliverability, abuse prevention, unsubscribes). Legal basis: Legitimate interests (Art. 6(1)(f)).

You can withdraw any consent at any time: click Unsubscribe in any email, or contact us at help@seido.dev.

5. Who Processes Your Data

We use a small number of service providers (processors) to run Seido. We never sell your data, and no provider may use it for their own purposes. Contracts are in place with each of them, including data processing agreements and, where needed, international transfer safeguards (see section 6).

Provider What it does for us Where the data lives
Google Cloud / Firebase App hosting, sign-in, databases, and file storage: where your account and knowledge base live United States (us-central1)
OpenRouter / various AI model suppliers Routes and processes requests using different AI models (see section 3) Varies by model supplier
Stripe Payment processing and subscription billing United States / EU
PostHog Product analytics and session replay, across both the app and this website; in-app replays can include knowledge base content shown on screen (see section 2.6) European Union (Frankfurt)
Langfuse (self-hosted) AI trace logging, running inside our own Google Cloud environment (see section 2.5) United States (us-central1)
Cloudflare Website hosting and delivery Global edge network
Kit (ConvertKit, LLC) Email consent, sending, and subscriber management United States

Beyond these providers, we disclose personal data only if the law requires it, or to establish, exercise, or defend legal claims. If Seido AI Ltd is ever involved in a merger or acquisition, your data would remain protected by this policy and we would tell you before anything changes.

6. International Transfers

We are a UK company, and the providers listed above store data outside the UK: principally in the United States (Google Cloud and our self-hosted Langfuse, together with Stripe and Kit), in the European Union (PostHog), and, for website delivery, on Cloudflare's global edge network. AI processing locations vary by model supplier. Whenever personal data leaves the UK, we make sure it stays protected to UK standards:

  • Transfers to the EU are covered by the UK's adequacy arrangements: EU law protects your data to an equivalent standard.
  • For US providers certified under the UK Extension to the EU–US Data Privacy Framework, we rely on that certification.
  • In all other cases, we use the ICO-approved International Data Transfer Addendum together with Standard Contractual Clauses in our contracts with the provider.

7. Data Retention

We keep personal data only as long as we need it for the purposes above. These are the windows we work to:

Data How long we keep it
Account information While your account is active, then deleted within 30 days of account deletion
Knowledge base content Until you delete it or close your account; removed from live systems within 30 days of deletion, with residual copies in encrypted backups expiring within a further 90 days
Payment & billing records 6 years from the end of the relevant financial year, as UK tax law requires
Product analytics events Up to 12 months
Session replay recordings (app and website) Up to 90 days; deleted sooner if you ask us to or delete your account
AI processing traces Up to 90 days; deleted sooner if you ask us to or delete your account
Research session recordings Until the study they belong to ends, plus 90 days, then deleted
Newsletter subscription data Until you unsubscribe; we then keep a minimal suppression record so we never email you again
Support correspondence 24 months after your request is resolved

We may keep specific records longer where the law requires it or to establish, exercise, or defend legal claims, never as a blanket exception.

8. Your Rights

Under UK GDPR and applicable EU law, you can request:

  • Access to your data
  • Rectification of inaccuracies
  • Erasure (right to be forgotten)
  • Restriction or objection to processing
  • Portability of data you provided
  • Withdrawal of consent at any time

How to exercise them: email help@seido.dev.

We verify every request before acting on it: we check that it matches the email address on your account, and we send a confirmation message that you need to answer before we release or delete anything. For export and erasure requests, we may also ask you to confirm from inside your signed-in account. Erasure covers everything we hold about you, including session replay recordings and AI processing traces (see section 7).

We respond to every request within one month, and we'll confirm when it's done.

You also have the right to complain to a supervisory authority. In the UK, that is the Information Commissioner's Office (ICO) at ico.org.uk. You don't need our permission to go to the ICO.

9. Cookies & Analytics

You can control cookies through your browser settings, but disabling them may affect certain features of the site.

Analytics: We use PostHog (hosted in the EU) to understand how the site is used. It automatically records usage events, including page views, clicks, and form interactions across the site, together with technical details such as your device, browser, and approximate location. This is limited to product-usage analytics; we do not use it for advertising or cross-site ad tracking. We honour your browser's Do Not Track signal: if it is switched on, analytics is turned off for your visit. We do not act on Global Privacy Control, because that signal covers the selling or sharing of personal data for cross-context advertising, and we do neither: this is first-party product analytics only.

Consent: If you visit from the EU, EEA, UK, or Switzerland, we ask for your consent before any analytics cookie is set. Until you choose, nothing is stored on your device. If you decline, we still count your visit anonymously using a privacy-preserving hash, with no cookies and nothing stored on your device. Visitors from other regions are counted with cookies by default.

Across our sites: PostHog sets a cookie scoped to the seido.dev domain so your activity is recognised consistently across this marketing site and the Seido app (app.seido.dev). If you later sign in, earlier anonymous browsing on this site may be linked to your account.

Your choice: You can turn analytics off on this device at any time using the button below. You can also reach us at help@seido.dev.

10. Security

We use appropriate technical and organisational measures, including TLS encryption in transit, encryption at rest, access controls, least-privilege access, and regular review of processor security commitments.

11. Children's Privacy

Seido is a tool for building businesses and is intended for adults. Our website and product are not directed at anyone under 18, and we do not knowingly collect personal data from children. If you become aware that a child has provided us with personal information, please contact us and we will delete it.

12. Changes to This Policy

When we change this policy, we'll post the new version here with an updated effective date and version number. If a change is material (new categories of data, new purposes, or new providers handling your content), we'll notify account holders by email before it takes effect, not after.

13. Contact

Questions about this policy or how we handle your data? Reach us at help@seido.dev.