Draft, pending review. This text has not been approved yet and may change before it takes effect. Bracketed items are placeholders.

Privacy notice

This notice explains what Seal collects, why, and what we do with it. Seal is run by [Operator legal name] (“we”). Questions and requests: [contact email].

What we collect

Account holders. Email address, name and workspace name; passkey public keys (the private key never leaves your device); sign-in times, IP addresses and browser details, for security; workspace settings; and a record of what you and your connected agents did.

Recipients (signers, approvers and viewers). The name and email address the sender entered. When you use a signing page: your consent to electronic records, one-time code checks, the values and signatures you enter, attachments, comments, decline reasons, your IP address, browser details and the times of each step. These become part of the envelope’s audit trail and certificate of completion.

Documents. The files senders upload, and the sealed results.

Email delivery. Bounces and complaints reported by our email provider.

Seal uses no advertising or analytics trackers. Signing in sets two cookies: a session cookie and an anti-forgery cookie. Signing pages set none.

Why we use it

  • To run Seal: deliver envelopes, run signing pages, seal documents and show you your data.
  • To keep evidence: the audit trail and the certificate are what make a signature provable, for the sender and for the recipients.
  • To keep Seal safe: rate limits, bot checks, and abuse review (for example hidden text in documents, or bounce and complaint rates).

We don’t sell personal data, and we don’t use your documents or data to train AI models.

AI features

Agents you connect read and change data in your workspace through the tools you allow. The in-browser assistant sends document text from your browser directly to the AI provider whose key you entered (Anthropic, OpenAI or OpenRouter), under that provider’s terms. Seal’s server never receives your key or the assistant’s requests.

Who processes it for us

  • Cloudflare: network, bot checks (Turnstile), and storage of documents, evidence and encrypted backups (R2).
  • Resend: sending email.
  • The service itself runs on a machine we operate in [location].

How long we keep it

  • Evidence of a sent envelope (documents, audit trail, sealed results and the recipient details in them): 1 year on Free, 7 years on Workspace, in write-once storage, then deleted within 30 days.
  • Drafts, templates and contacts: until you delete them.
  • Logs of agent calls: 90 days. Encrypted backups: 35 days.
  • Account data: while the account exists, then until backups expire.

Your rights

You can ask for a copy of your data, to correct it, or to delete it. Envelope evidence can’t be deleted during its retention term, because the sender and the other recipients rely on it; we use it for nothing else. If you are a recipient, the sender controls the envelope, so contact them first, or us. You can also complain to your data protection authority.

Security

Passkeys for signing in, hashed session tokens and API keys, encrypted backups, write-once evidence storage, and a signed, timestamped seal on every completed document so that changes can be detected.

Changes

We post changes here and tell account holders about material ones by email.