This Privacy Policy explains how Seafly (“Seafly,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use seafly.app and related apps and services (the “Service”).
Our product philosophy is simple: We will never waste your attention. We will never trade trust for speed. That means we aim to collect only what we need to provide a reliable “signal layer” — not an attention machine.
1) Information we collect
1.1 Information you provide
- Account info: name (optional), email address, authentication tokens, and preferences.
- Voice presets / settings: tone, audience, style guidance, banned phrases, calls-to-action preferences.
- Inputs you submit: URLs, transcripts, text, prompts, and content you paste or upload.
- Feedback: quality ratings, “time saved,” edits/regeneration actions, support messages.
1.2 Information from connected accounts (Google OAuth)
If you choose to connect a Google account, we may access information you explicitly authorize via OAuth scopes. Depending on what you enable, this may include:
- basic Google profile (e.g., email address)
- Gmail metadata and/or message content
- Google Drive files and/or file content
You control what you connect and can disconnect at any time.
Google API Services User Data policy (Limited Use): If we access Google user data, we will use it only to provide or improve the user-facing features you request, and not for advertising, data resale, or unrelated profiling. We do not allow humans to read Google user content except (a) with your explicit consent, (b) for security/fraud prevention, or (c) to comply with law.
1.3 Automatically collected information
- Usage and diagnostics: pages visited, features used, generation success/failure, latency, crash logs.
- Device and browser info: IP address, device type, operating system, browser type, approximate location (city/region).
- Cookies / local storage: session management and basic analytics.
2) How we use information
We use information to:
- provide the Service (ingestion, transcription/extraction, summarization, generation, editing, exports)
- apply your voice preset and formatting preferences
- improve reliability and trust features (e.g., source mapping, “faithfulness” checks)
- measure performance (latency, error rates) and product success (retention, activation)
- prevent spam, abuse, and fraud; secure accounts and infrastructure
- communicate with you (account notices, security alerts, support)
We do not sell your personal information.
3) AI processing and “do not train” stance
Seafly processes your Inputs to generate Outputs. Depending on your setup, processing may involve third-party providers for:
- transcription (automatic speech recognition)
- large language model text generation
- infrastructure and logging
We do not use your private Inputs (including connected inbox/Drive content) to train public foundation models. If a vendor processes data on our behalf, we require contractual protections appropriate for the Service (confidentiality, security, and limited processing).
(If you want to be extra strict: add “We use API modes where providers do not train on API data, where available.”)
4) How we share information
We share information only as needed:
4.1 Service providers (processors)
We may share data with vendors that help us operate the Service, such as:
- hosting and databases
- analytics and error tracking
- transcription providers
- large language model providers
- email delivery providers
They are permitted to process information only to provide services to Seafly.
4.2 Legal, safety, and enforcement
We may disclose information if we believe in good faith it’s necessary to:
- comply with law or legal process
- protect rights, safety, and security of Seafly, users, or the public
- prevent fraud or abuse
4.3 Business transfers
If Seafly is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
5) Data retention
We retain personal information only as long as necessary for the purposes described above, including to provide the Service and meet legal/security obligations.
Default retention (suggested for MVP — adjust to match your actual behavior):
- Projects, Inputs, and Outputs: retained up to 90 days by default, unless you delete earlier or choose extended retention.
- Account records: retained while your account is active.
- Logs and diagnostics: typically retained for {{30–180}} days for reliability and security.
You can request deletion as described below.
6) Your choices and rights
6.1 Access, export, and deletion
You can:
- delete projects and drafts within the app (if available), and/or
- request account deletion by emailing sup
Upon deletion request, we delete or de-identify your data unless we must retain limited information for security, fraud prevention, or legal compliance.
6.2 Disconnect Google
You can disconnect Google access anytime:
- inside the app (if available), and/or
- via your Google Account settings (“Third-party access”)
Disconnecting stops new data access. Previously stored data remains until deleted, per retention settings.
6.3 Email preferences
You can opt out of non-essential product emails at any time using unsubscribe links.
6.4 Region-specific rights
Depending on where you live, you may have rights to:
- know what personal data we collect and how we use it
- request access, correction, or deletion
- object to certain processing
- appeal a denied request (where applicable)
California notice: We do not sell personal information and do not share it for cross-context behavioral advertising as defined by California law.
To exercise rights, contact: support@seafly.app.
7) Security
We use reasonable administrative, technical, and physical safeguards designed to protect information, such as:
- encryption in transit (Transport Layer Security) and at rest where supported
- access controls and least-privilege permissions
- monitoring and rate-limiting to prevent abuse
No system is 100% secure. You are responsible for keeping your account secure.
8) Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
9) International data transfers
If you access the Service from outside the United States, your information may be processed in countries where our vendors operate. We take steps to ensure appropriate safeguards for international transfers where required by law.
10) Third-party links and services
The Service may link to or integrate with third-party sites and services (including Google). Their privacy practices are governed by their own policies. We are not responsible for third-party practices.
11) Changes to this Privacy Policy
We may update this Policy from time to time. We will update the “Last updated” date and provide additional notice for material changes (for example, in-app).
12) Contact
Privacy questions or requests: **Email: support@seafly.app