Privacy Policy
Effective June 19, 2026
This Privacy Policy explains how sealmd (“Seal,” “we”) collects, uses, and protects information in connection with the Seal service at sealmd.net (the “Service”). It is part of our Terms of Service.
1. A note on local rendering
The open-source Seal rendering skill runs entirely on your own machine and makes zero network calls. Your document does not reach our servers — and this policy does not apply to that local processing — until you choose to publish, share, or sync a document to the hosted Service.
2. Information we collect
Information you provide
| Category | Examples |
|---|---|
| Account | Email address, display name, and — for SSO sign-in — a stable identity subject from your identity provider. |
| Workspace content | Documents and their Markdown, immutable version snapshots, comments, approvals, provenance metadata, and document summaries. |
| Collaboration | Workspace and membership details, roles, invitations, and assignment data. |
| Connectors | GitHub repository references and installation metadata you connect. |
| Feedback | Product feedback you submit, including an optional email and the page it was sent from. |
| Billing | Plan and subscription status, and Stripe customer/subscription identifiers. Card details go directly to Stripe; we do not store them. |
Information collected automatically
- Authentication: short-lived single-use login tokens and session records (creation, expiry, last-seen, revocation).
- Product analytics (clickstream): event name, the surface/path, a visitor id (browser local storage) and per-tab session id, referrer, and user-agent. We store a salted SHA-256 hash of your IP address — never the raw IP.
We do not sell your data, and we do not use third-party advertising trackers.
3. How we use information
- To provide the Service: render documents, capture identity-verified approvals, bind approvals to content hashes, and enable collaboration.
- To authenticate you and keep your sessions and workspaces secure.
- To generate document summaries via our AI provider (see Section 5).
- To send transactional email (magic links, invitations, notifications) via Resend.
- To operate connectors you enable, such as writing back to GitHub.
- To process payments via Stripe.
- To understand product usage, debug, prevent abuse, and improve the Service.
- To comply with legal obligations and enforce our Terms.
4. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on the bases of: performance of our contract with you (providing the Service), our legitimate interests (security, abuse prevention, product improvement), consent where required (certain analytics), and compliance with legal obligations.
5. AI processing
When you publish a document, its content is sent to a third-party AI provider (currently Cloudflare Workers AI; Anthropic in some configurations) solely to generate a summary and related outputs. These providers are contractually bound not to train their models on submitted content. AI processing happens only in our background worker, never on the approval-integrity path.
6. Sub-processors
We share data with the following service providers, only as needed to run the Service:
| Provider | Purpose |
|---|---|
| Supabase | Managed Postgres database / primary data hosting |
| Vercel | Web application hosting |
| Railway | Background worker hosting |
| Cloudflare | Workers AI (summary generation); edge/network |
| Anthropic | AI model provider (certain configurations) |
| Resend | Transactional email delivery |
| Stripe | Payment processing |
| GitHub | Repository connector (only when you enable it) |
We require sub-processors to protect data consistent with this policy.
7. Data location and international transfers
Workspace data is hosted in the United States (default region us-east-1). If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where our sub-processors operate. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
8. Security
- Encryption: data is encrypted in transit; sensitive content is encrypted at rest with per-subject data-encryption keys that support crypto-shredding on deletion.
- Tenant isolation: row-level security separates each workspace’s data at the database layer.
- Identity gating: no approval can be recorded for an unverified email address.
- Tamper-evidence: approvals are pinned to a document’s content hash; any change breaks the seal.
- Least privilege: distinct database roles for the app, worker, and migrations.
No system is perfectly secure, but we design for these guarantees from the start.
9. Data retention
We keep your information for as long as your account or workspace is active, or as needed to provide the Service. Each workspace has a configurable retention policy. Version snapshots and approvals are retained as immutable records of the review history unless you delete the workspace or document. Login tokens expire within 15 minutes; sessions expire on their set lifetime. We may retain limited information longer where required by law or to resolve disputes.
10. Your rights and choices
- Access, correction, deletion, portability: depending on your jurisdiction (e.g., GDPR, UK GDPR, CCPA/CPRA), you may request access to, correction of, deletion of, or a copy of your personal data.
- Crypto-shredding: deletion requests can be honored by destroying the relevant encryption keys, rendering encrypted content unrecoverable.
- Objection/restriction: you may object to or ask us to restrict certain processing.
- Withdraw consent: where processing relies on consent, you may withdraw it.
- Do not sell/share: we do not sell or share personal data for cross-context behavioral advertising.
To exercise any right, contact privacy@sealmd.net. We will respond as required by applicable law. If your data sits within an organization’s workspace, we may direct your request to that organization as the controller.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email or in-product, and the “Effective” date above will be updated.
13. Contact
Privacy questions or requests: privacy@sealmd.net.