Legal

Privacy Policy

What Seal collects, why, who processes it, and the choices you have.

Last updated July 21, 2026. This describes how Seal handles data during its beta. We collect what the service needs to work, and nothing we sell.

Controller and roles

Seal is operated from Brazil. For account and billing data, Seal is the controller. For the approval payloads, context, and audit events your organization submits, your organization is the controller and Seal acts as a processor on your behalf — the terms for that role are in our Data Processing Agreement.

What we collect

  • Account data — your identity from GitHub sign-in (name, email, avatar) and the organization you create.
  • Approval data — the actions, payloads, and context your agents submit, plus the decisions and audit events they generate. This is the core of the service.
  • Billing data — handled by Stripe; we store customer and subscription identifiers, not card numbers.
  • Usage analytics — aggregate, cookieless page metrics via Plausible. No cross-site tracking and no advertising profiles.

How we use it

To run the approval flow, deliver notifications, keep the audit trail verifiable, bill paid plans, secure the platform, and support you. We do not sell personal data or use approval content to train models.

Legal bases

Where data-protection law such as the LGPD or GDPR applies, we process personal data to perform our contract with you (running the service and billing), on the basis of our legitimate interest in securing and improving the platform, to comply with legal obligations, and — for cookieless analytics — because it is necessary for those legitimate interests without tracking you across sites.

Subprocessors

We rely on a small set of providers to operate the service — hosting, database, billing, email, and approval delivery. The current list, with each provider’s purpose and location, is on the subprocessors page (7 in total).

International transfers

Seal is operated from Brazil and several subprocessors are in the United States and the European Union, so your data may be processed outside your country. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

Retention

Audit events are retained per your plan (see pricing). The audit log is append-only by design, so entries are not edited in place. Deleting your organization removes your data, subject to anything we are legally required to keep.

Security

Every request, key, and audit event is org-scoped; evaluation of untrusted input is fail-closed; and the audit log is hash-chained and tamper-evident. The full model is on the security page.

Your rights

Subject to applicable law such as the LGPD and GDPR, you can request access to your personal data and its correction, deletion, portability, or restriction, and you can object to or withdraw consent for processing based on it. You can self-serve most of this: access and export your organization’s data through the API and dashboard, and delete your organization to remove it. For anything you cannot self-serve, contact us and we will respond within the timeframes the law requires. You also have the right to complain to your local data-protection authority.

Data breaches

If a breach affects your personal data, we will notify you and, where required, the relevant authority without undue delay, with the information you need to meet your own obligations.

Cookies

We use only essential cookies needed to keep you signed in. Analytics is cookieless, so there is no advertising or tracking cookie to consent to.

Data processing agreement

Our Data Processing Agreement covers the terms under which we process personal data on your behalf. If your organization needs a countersigned copy, request one at hello@useseal.dev.

Contact

Privacy questions: hello@useseal.dev.