Seal Privacy Policy
Effective date: September 2, 2026 Last updated: September 2, 2026
Seal is operated by New Eden Research, Inc. ("New Eden Research," "we," "us," "our"), a Delaware corporation located at 2810 North Church Street, STE 90398, Wilmington, DE 19802.
This policy explains what we collect when you use the Seal mobile application and the website at heyseal.ai (together, the "Service"), why we collect it, who we share it with, and the choices you have.
The short version
| What Seal does with your content | Your content passes through our own gateway and is sent to third-party AI providers to generate responses. It is not used to train anyone's AI models. |
| Do we sell your data? | No. We do not sell or share your personal information for cross-context behavioral advertising. |
| Do we show ads? | No. |
| How you pay | Per request, in USDC, from a non-custodial wallet you control. We never hold your private keys. |
| Can you delete everything? | Everything on our systems, yes. Email privacy@heyseal.ai and we'll do it. Blockchain transactions cannot be deleted by anyone. See Section 5. |
| Who to contact | privacy@heyseal.ai |
This summary is for orientation. The sections below control.
1. Information we collect
1.1 Information you give us
Account information. To create an account you provide an email address. You sign in either with a passkey or with a one-time sign-in link sent to that address. Authentication is handled for us by Privy, Inc.
We do not use passwords at all. There is no password to create, store, leak, or reset. If you use a passkey, we hold only the public key; the private key stays on your device and never reaches us. We never receive or store your biometrics. Face ID and Touch ID are handled entirely by your device.
Your content. Anything you put into Seal: text you write, images or photos you submit, questions you ask, and the conversation history that results. We call this "Your Content" throughout this policy.
Communications. If you email us for support or feedback, we keep that correspondence.
Wallet and transaction information. Seal operates on a pay-per-request model settled in USDC. We record your public wallet address and the requests charged against it. We never receive payment card details.
Your wallet is created and secured through Privy's embedded wallet infrastructure. Privy splits your private key into two encrypted shares using Shamir's secret sharing: one held inside a trusted execution environment, and one held by Privy and released only against your valid authentication. Neither share alone gives access to the wallet, and the key is reassembled only inside that environment, only for an operation you authorize. New Eden Research never holds either share, never holds your private key, and cannot move, freeze, or recover your funds.
1.2 Information collected automatically
- Device and app information: device model, operating system version, app version, language, and time zone
- Usage information: features used, actions taken, session length, and timestamps
- Log and diagnostic data: crash reports, error traces, and performance data
- Approximate location: inferred from IP address at city level. We do not collect precise GPS location.
We do not use third-party advertising SDKs, and we do not track you across other companies' apps or websites. Seal does not present an App Tracking Transparency prompt because we do not engage in tracking as Apple defines it.
1.3 Information from third parties
Privy, Inc. handles authentication on our behalf. Through Privy we receive your email address and a unique account identifier confirming that you signed in successfully. Privy's own handling of that information is governed by its privacy policy.
2. How we use information
We use information to:
- Provide the Service: process Your Content, generate responses, and maintain your history across sessions
- Authenticate you and keep your account secure
- Diagnose crashes, fix bugs, and improve reliability and performance
- Understand which features are used so we can decide what to build
- Respond to your support requests
- Detect, prevent, and investigate abuse, fraud, and violations of our Terms of Use
- Comply with legal obligations
We do not use Your Content to train AI models, not ours and not our providers'. See Section 3.
3. AI processing and third-party model providers
This is the section that matters most, so we've kept it plain.
How a request travels. When you ask Seal something, Your Content goes first to a gateway we operate ourselves, and from there to the model provider you selected. You choose which model handles your request. Today the available providers are:
- Anthropic, PBC: Claude models
- X.AI Corp: Grok models
Your Content is sent only to the provider behind the model you chose. There is no way to use Seal's core features without this transmission. We may add or change available providers; when we do, we will update this list.
What happens to it there. We use both providers under commercial API terms which state that they do not train on API inputs or outputs. Each retains request data for up to 30 days for abuse monitoring, after which it is deleted from their systems.
What we don't do. We do not use Your Content to train models. We do not sell Your Content. We do not permit our providers to train on it. We do not review Your Content except in the narrow cases described in Section 4.
What this means for you. Do not put information into Seal that you could not tolerate being processed by a third-party service: for example, government identification numbers, private keys or seed phrases, financial account credentials, or health information you consider sensitive. Seal is not designed for, and should not be used with, protected health information under HIPAA.
4. How we share information
We share personal information only in these circumstances:
Service providers. Companies that operate infrastructure on our behalf, under contracts that restrict them to processing data for us and nothing else:
| Provider | Purpose | Data involved |
|---|---|---|
| Anthropic, PBC | Generating responses (Claude models) | Your Content |
| X.AI Corp | Generating responses (Grok models) | Your Content |
| Privy, Inc. | Authentication, sign-in, and wallet infrastructure | Email address, account identifiers, wallet address |
| Railway Corp. | Application hosting and database | All stored data |
| PostHog, Inc. | Product usage analytics | Usage and device data |
| Apple Inc. | App distribution | Account and device identifiers |
Legal requirements. We may disclose information if we believe in good faith that it is required by law, subpoena, or other legal process, or is necessary to protect the rights, property, or safety of New Eden Research, our users, or the public.
Safety and abuse. A small number of authorized personnel may access Your Content when investigating a specific report of abuse or a violation of our Terms of Use, or when you ask us to look at something to resolve a support issue.
Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. If ownership changes materially, we will notify you before your information becomes subject to a different privacy policy.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5. How long we keep information, and what we cannot delete
| Category | Retention |
|---|---|
| Your Content | Until you delete it, or until you delete your account |
| Account information | Life of the account, then deleted within 30 days |
| Database backups | 7 days, on a rolling basis |
| Server logs and diagnostics | 30 days |
| Product analytics events | 12 months |
| Records we must keep by law | As long as the applicable law requires |
When you delete your account, we delete Your Content and account information from our production systems within 30 days. Content already transmitted to an AI provider is deleted per that provider's 30-day window described in Section 3.
Deleted data may persist briefly in encrypted database backups until those backups age out, currently up to 7 days. We do not restore deleted data from backups, and we do not use backups to reconstruct deleted accounts.
Blockchain data is permanent
Please read this carefully, because it is an exception to every deletion right described in this policy.
Payments in Seal settle on a public blockchain. Transactions involving your wallet (the address, the amounts, the timing, and the counterparties) are recorded on a public ledger that anyone can read. That record is permanent and outside anyone's control, including ours. We cannot edit it, delete it, or make it private, and neither can you.
If you delete your account, we delete our records. The blockchain record remains. Anyone who learns your wallet address can view its full transaction history, including activity unrelated to Seal. If that matters to you, use a wallet address you have not linked to your identity elsewhere.
6. Security
We protect information using encryption in transit (TLS) and at rest, access controls limiting employee access to what their role requires, and regular review of our infrastructure configuration.
No system is perfectly secure. We cannot guarantee that unauthorized parties will never defeat our safeguards. Protect your account by using a passkey where available, keeping your device locked, and telling us promptly at security@heyseal.ai if you believe your account has been compromised.
7. Your choices and rights
Delete your account. Email privacy@heyseal.ai from the address on your account and ask us to delete it. We will confirm and complete the deletion within 30 days. This is permanent and removes Your Content along with the account.
Export your data. Email privacy@heyseal.ai and we will provide a copy of your account information and Your Content in a portable format.
Marketing email. Unsubscribe from any marketing message, or email us. We will still send necessary transactional messages about your account.
Push notifications. Turn off in your device settings.
8. Your California privacy rights
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the rights described below.
Categories of personal information we collect
| CCPA category | Do we collect it? | Examples |
|---|---|---|
| Identifiers | Yes | Email address, account ID, device identifiers, IP address, public wallet address |
| Customer records (Cal. Civ. Code § 1798.80) | Yes | Email address |
| Protected classifications | No | N/A |
| Commercial information | Yes | Per-request transaction records and usage history |
| Biometric information | No | N/A |
| Internet or network activity | Yes | Feature usage, session data, crash logs |
| Geolocation data | Yes (coarse) | City-level location inferred from IP |
| Audio, visual, or similar | Yes | Images and photos you submit |
| Employment or education information | No | N/A |
| Inferences | Yes | Product preferences drawn from usage |
| Sensitive personal information | Yes (limited) | Account login credentials; the contents of Your Content, which you control |
Sources: directly from you, automatically from your device, and from your sign-in provider.
Purposes: the purposes listed in Section 2.
Disclosure: we disclose these categories to the service providers listed in Section 4 for the purposes stated there. We have not sold or shared personal information in the preceding twelve months.
Your rights
- Know: request the categories and specific pieces of personal information we have collected about you
- Delete: request deletion of personal information we hold about you
- Correct: request correction of inaccurate personal information
- Opt out of sale or sharing: we do not sell or share personal information, so there is nothing to opt out of
- Limit use of sensitive personal information: we use sensitive personal information only to provide the Service, which is a use the CCPA exempts from the right to limit
- Non-discrimination: we will not deny service, charge different prices, or provide a different quality of service because you exercised a right
How to exercise them. Email privacy@heyseal.ai. We will verify your identity by confirming control of the email address on the account, then respond within 45 days. If we need more time, we will tell you and may take up to 90 days total. You may use an authorized agent; we will ask for proof of their authority.
9. Children's privacy
Seal is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn we have collected such information, we will delete it. If you believe a child under 13 has provided us information, contact privacy@heyseal.ai.
Our App Store age rating reflects this. We do not sell or share the personal information of anyone under 16.
10. Users outside the United States
Seal is operated from the United States and is currently intended for users in the United States. If you use the Service from elsewhere, your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your country. By using the Service you understand that this transfer occurs.
11. Changes to this policy
We may update this policy. If we make a material change, we will notify you by email or through an in-app notice at least 30 days before it takes effect. Minor clarifications take effect when posted. The "Last updated" date at the top always reflects the current version.
12. Contact us
New Eden Research, Inc. 2810 North Church Street, STE 90398 Wilmington, DE 19802 United States
Privacy questions and requests: privacy@heyseal.ai Security reports: security@heyseal.ai General support: support@heyseal.ai