Privacy Policy
Effective 3 August 2026 · Version 2.0
1. Who We Are
Seido AI Ltd, 17 Meriden Close, Bromley, BR1 2UF, United Kingdom, is the data controller for the personal data described in this policy. You can reach us any time at help@seido.dev.
This policy explains how we process personal data when you use the Seido app (app.seido.dev), subscribe to our newsletter, take part in our user research, or otherwise interact with our website at www.seido.dev.
2. Information We Collect
2.1 Account Information
When you create a Seido account, we collect your name, email address, and the sign-in method you choose (Google, GitHub, Apple, or a magic link). Sign-in is handled by Firebase Authentication. We also collect contact details you voluntarily provide when you subscribe to the newsletter or contact us.
2.2 Your Knowledge Base Content
The heart of Seido is the business knowledge base you build: documents you upload, notes and wiki pages you write, and answers you give our AI agents. This can include information about your business, your plans, and, depending on what you put in, personal data about you or others. It is stored on Google Cloud (Firestore and Cloud Storage). If session replay is on for your account, knowledge base content shown on screen can also appear in replays stored with PostHog (see section 2.6). It is your data: we use it only to run the product for you, never for advertising, and we never sell it.
2.3 Payment Information
If you subscribe to a paid plan, payments are handled by Stripe. Your card details go directly to Stripe and never touch Seido's servers. We receive and keep what we need to run your subscription: your plan, subscription status, billing history, and the last four digits and brand of your card so you can recognise it.
2.4 Usage Information
On the website, we may collect your IP address, browser type, device information, and pages visited. In both the app and this website, we use PostHog (hosted in the EU) to record product usage (which features you use, buttons you click, and pages you visit), linked to your account so we can understand how people actually use Seido and fix what isn't working.
2.5 AI Processing Records
When our AI agents run, we keep technical traces of those runs in Langfuse, an AI observability tool that we host ourselves in our own Google Cloud environment rather than sending traces to a third-party service. Traces can include the content you submitted to the agent and the agent's response. We use them to debug problems, track costs, and improve agent quality, and for nothing else. Traces are deleted when you delete your account, or sooner on request (see section 7).
2.6 Session Replay & Research Recordings
In-app session replay. We record how you interact with the product using PostHog session replay (hosted in the EU). Replays capture what is displayed on your screen while you use Seido, which can include the content of your knowledge base, along with your clicks and navigation. Sensitive inputs like passwords are masked, and this never involves your camera or microphone. We use these replays to find bugs and understand where the product confuses people. If you'd rather not be recorded this way, tell us at help@seido.dev and, once we've verified the request is really from you, we'll switch replay off for your account. You can also ask us to delete existing replays at any time (see section 7).
Website session replay. Session replay can also run on our website at www.seido.dev, recording what is on screen along with your clicks and navigation as you move around the site. The same limits apply: sensitive inputs like passwords are masked, and it never involves your camera or microphone. On the website, replay follows the same controls as the rest of our site analytics: turn analytics off on this device (see section 9) and replay stops with it, or ask us at help@seido.dev.
Research sessions. When you take part in our user research (scheduled sessions where we watch how you work and ask questions), those sessions are recorded (screen and audio) only with your explicit consent, given before the session starts. You can decline recording and still take part, and you can ask us to delete a recording at any time.
3. How AI Processes Your Content
The content you put in your knowledge base, and the messages you send our agents, are processed by large language models to generate answers, build your knowledge map, and produce documents for you. We use models from various suppliers, accessed through OpenRouter.
Your content is used to provide Seido and is not used to train AI models. This applies across the suppliers we use.
4. How We Use Your Information
- Run Seido for you: storing your knowledge base, running agents on it, keeping you signed in. Legal basis: performing our contract with you (UK GDPR Art. 6(1)(b)).
- Take payment and manage your subscription. Legal basis: performing our contract with you (Art. 6(1)(b)); keeping billing records afterwards is a legal obligation (Art. 6(1)(c)), because UK tax law requires it.
- Send you our newsletter and product updates. Legal basis: Consent (Art. 6(1)(a)). You asked for it, and you can stop it any time.
- Understand usage and improve the product (analytics, session replay, AI traces, debugging). Legal basis: Legitimate interests (Art. 6(1)(f)). Watching how the product is actually used is how we make it better and keep it secure. You can opt out of session replay for your account at any time (see section 2.6), and you can turn off analytics on this website at any time (see section 9).
- Measure how our emails perform (aggregated open, click, and bounce rates). Legal basis: Legitimate interests (Art. 6(1)(f)) in improving our communications.
- Record user research sessions. Legal basis: Consent (Art. 6(1)(a)), asked for explicitly before each session, never assumed.
- Keep Seido secure: preventing abuse, investigating incidents, protecting your data. Legal basis: Legitimate interests (Art. 6(1)(f)).
- Maintain compliance records and manage the mailing list (deliverability, abuse prevention, unsubscribes). Legal basis: Legitimate interests (Art. 6(1)(f)).
You can withdraw any consent at any time: click Unsubscribe in any email, or contact us at help@seido.dev.
5. Who Processes Your Data
We use a small number of service providers (processors) to run Seido. We never sell your data, and no provider may use it for their own purposes. Contracts are in place with each of them, including data processing agreements and, where needed, international transfer safeguards (see section 6).
| Provider | What it does for us | Where the data lives |
|---|---|---|
| Google Cloud / Firebase | App hosting, sign-in, databases, and file storage: where your account and knowledge base live | United States (us-central1) |
| OpenRouter / various AI model suppliers | Routes and processes requests using different AI models (see section 3) | Varies by model supplier |
| Stripe | Payment processing and subscription billing | United States / EU |
| PostHog | Product analytics and session replay, across both the app and this website; in-app replays can include knowledge base content shown on screen (see section 2.6) | European Union (Frankfurt) |
| Langfuse (self-hosted) | AI trace logging, running inside our own Google Cloud environment (see section 2.5) | United States (us-central1) |
| Cloudflare | Website hosting and delivery | Global edge network |
| Kit (ConvertKit, LLC) | Email consent, sending, and subscriber management | United States |
Beyond these providers, we disclose personal data only if the law requires it, or to establish, exercise, or defend legal claims. If Seido AI Ltd is ever involved in a merger or acquisition, your data would remain protected by this policy and we would tell you before anything changes.
6. International Transfers
We are a UK company, and the providers listed above store data outside the UK: principally in the United States (Google Cloud and our self-hosted Langfuse, together with Stripe and Kit), in the European Union (PostHog), and, for website delivery, on Cloudflare's global edge network. AI processing locations vary by model supplier. Whenever personal data leaves the UK, we make sure it stays protected to UK standards:
- Transfers to the EU are covered by the UK's adequacy arrangements: EU law protects your data to an equivalent standard.
- For US providers certified under the UK Extension to the EU–US Data Privacy Framework, we rely on that certification.
- In all other cases, we use the ICO-approved International Data Transfer Addendum together with Standard Contractual Clauses in our contracts with the provider.
7. Data Retention
We keep personal data only as long as we need it for the purposes above. These are the windows we work to:
| Data | How long we keep it |
|---|---|
| Account information | While your account is active, then deleted within 30 days of account deletion |
| Knowledge base content | Until you delete it or close your account; removed from live systems within 30 days of deletion, with residual copies in encrypted backups expiring within a further 90 days |
| Payment & billing records | 6 years from the end of the relevant financial year, as UK tax law requires |
| Product analytics events | Up to 12 months |
| Session replay recordings (app and website) | Up to 90 days; deleted sooner if you ask us to or delete your account |
| AI processing traces | Up to 90 days; deleted sooner if you ask us to or delete your account |
| Research session recordings | Until the study they belong to ends, plus 90 days, then deleted |
| Newsletter subscription data | Until you unsubscribe; we then keep a minimal suppression record so we never email you again |
| Support correspondence | 24 months after your request is resolved |
We may keep specific records longer where the law requires it or to establish, exercise, or defend legal claims, never as a blanket exception.
8. Your Rights
Under UK GDPR and applicable EU law, you can request:
- Access to your data
- Rectification of inaccuracies
- Erasure (right to be forgotten)
- Restriction or objection to processing
- Portability of data you provided
- Withdrawal of consent at any time
How to exercise them: email help@seido.dev.
We verify every request before acting on it: we check that it matches the email address on your account, and we send a confirmation message that you need to answer before we release or delete anything. For export and erasure requests, we may also ask you to confirm from inside your signed-in account. Erasure covers everything we hold about you, including session replay recordings and AI processing traces (see section 7).
We respond to every request within one month, and we'll confirm when it's done.
You also have the right to complain to a supervisory authority. In the UK, that is the Information Commissioner's Office (ICO) at ico.org.uk. You don't need our permission to go to the ICO.
10. Security
We use appropriate technical and organisational measures, including TLS encryption in transit, encryption at rest, access controls, least-privilege access, and regular review of processor security commitments.
11. Children's Privacy
Seido is a tool for building businesses and is intended for adults. Our website and product are not directed at anyone under 18, and we do not knowingly collect personal data from children. If you become aware that a child has provided us with personal information, please contact us and we will delete it.
12. Changes to This Policy
When we change this policy, we'll post the new version here with an updated effective date and version number. If a change is material (new categories of data, new purposes, or new providers handling your content), we'll notify account holders by email before it takes effect, not after.
13. Contact
Questions about this policy or how we handle your data? Reach us at help@seido.dev.