Privacy Policy
Last updated: September 11, 2026
Your privacy is important to us. This Privacy Policy explains how SeamUI ("we", "us", or "our") collects, uses, and shares information about you when you use our website, products, and services (the "Services").
1. Information We Collect
- Account information such as name, email address, and authentication data.
- Workspace membership, projects, provider API keys, and account preferences.
- Creative content including prompts, saved prompt libraries, generation history and settings, batch inputs, uploaded reference images, videos and audio, and generated images and videos.
- Purchase and plan information, including payment references and AppSumo redemptions, and communications with us, including support messages and attachments.
- Usage information including pages viewed, features used, and interactions.
- Device and log information such as IP address, browser type, and settings.
2. How We Use Information
- Provide your account and workspace, authenticate provider requests, generate and edit content, store your creative work, and let you browse, download, and reuse it.
- Manage purchases, plan entitlements, workspace collaboration, and customer support.
- Communicate with you, including service updates and marketing with your consent.
- Protect the security and integrity of our Services.
Where data protection law requires a legal basis, we process information to perform our contract with you, comply with legal obligations, and pursue legitimate interests in operating, securing, and improving the Services. We rely on consent where required, including for relevant marketing and tracking activities.
3. Provider API Keys
API keys saved in your workspace are encrypted before being stored in our database. They are processed by our backend to authenticate requests to the provider you select. This is encryption at rest, not end-to-end encryption: the generation service must use the key to make authenticated provider requests. Workspace owners and administrators can replace or remove supported provider keys in the API Keys settings.
We retain a saved key while it remains connected to your workspace. Replacing or removing it replaces or removes the stored credential from the active workspace record. Removing a key from SeamUI does not revoke it with the provider; you can revoke it in the provider's own console. Residual backup copies are subject to the backup retention practices described below.
4. Prompts, Reference Media, and Generated Content
In the workspace, prompts, generation settings, and selected reference media are sent to our generation backend and the AI service needed to carry out your request. Reference media can include images, masks, video, and audio, depending on the feature. Existing assets can also be reused as inputs. Content and associated metadata are retained to provide your project gallery, prompt libraries, generation history, and reference reuse features.
We use Supabase for workspace records and content metadata, and Cloudflare R2 for generated image and video files and uploaded generation media. Some other files, such as support attachments and community inspiration submissions, use Supabase Storage. Workspace content is available to workspace members according to their permissions. Submitting content for public inspirations can make that content and its prompt public. Anyone you share a downloadable media link with may be able to access the linked file.
The free browser-based generator uses a different flow: its API keys and generated results are held in browser memory, and generation requests go directly to the selected provider. These keys are not saved as workspace credentials. If you submit your email through that tool, we store the email and the page or tool associated with the submission separately.
5. Cookies and Tracking
We use cookies and similar technologies for authentication, preferences, support, and understanding how the Services are used. Our analytics integrations include Google Analytics, Ahrefs Analytics, and Umami Cloud; our support chat uses Crisp. These services may process page visits, usage events, device or connection information, and information you provide in chat. You can control cookies through your browser settings, although blocking essential cookies may affect sign-in and other features.
6. AI Providers and Other Service Providers
We do not sell your personal information. We may share information with service providers who help us operate the Services, and as required by law or to protect our rights.
- AI processing: depending on the selected model and route, requests are handled by OpenAI, Google (Gemini), Black Forest Labs (Flux), xAI (Grok), BytePlus, or Kie.ai. Kie.ai provides access to multiple model families, including Kling. An intermediary receives the request when you select its route, even if the model carries another vendor's name. Its downstream processing is governed by its own service arrangements.
- Supabase: authentication, database hosting, and storage of account records, encrypted workspace keys, content metadata, prompts, and certain uploaded files.
- Cloudflare: application hosting, generation backend infrastructure, and media storage and delivery.
- Stripe: payment processing and related billing and transaction information.
- Resend: email delivery, including recipient addresses and email content.
- Crisp: customer support conversations and information you submit to support.
- Google Analytics, Ahrefs Analytics, and Umami Cloud: audience measurement and usage analytics.
AI services receive the prompts, selected reference content, and generation parameters needed for the requested operation, rather than every item in your workspace. Their retention, safety review, and model-training practices depend on their terms, the service used, and your provider account settings. Using your own API key does not prevent the selected provider from processing your content. Please review its applicable privacy policy and API terms before submitting sensitive content. Payment, email, support, and analytics services receive information relevant to their respective functions; they do not all receive your generation inputs.
7. Data Retention and Deletion
Projects, saved prompts in your prompt library, and generated images and videos are retained until you delete them or request their deletion. They do not expire merely because they reach the generation-history retention period for your plan.
Background generation records, including prompt logs and generation history, and uploaded reference media follow your plan's retention period, measured from the creation of the record or its recorded use:
- Indie (Individual): 6 months.
- Business: 12 months.
- Scale: 24 months.
AppSumo plans follow the retention period of their equivalent SeamUI plan. A separately agreed custom plan may specify a different period. Shared reference files may remain while they are still needed by retained uses. Expiration of a generation log does not delete the generated image or video from your gallery or a prompt you saved in your library.
Deleting an asset removes it from the active gallery first; permanent file removal takes place through subsequent cleanup and can be delayed where the file is still used as a reference. Deletion is not necessarily immediate across storage, caches, and backups. Contact us to request deletion of your account, workspace, or associated content. Copies already processed by an AI provider are subject to that provider's own retention and deletion practices.
Account, billing, support, and security records are retained for the time needed for their respective purposes, including applicable legal obligations and dispute resolution. Residual copies may remain in backups until those backups expire or are overwritten under the applicable infrastructure retention cycle.
8. Your Rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to the processing of your personal information. Where processing relies on consent, you can withdraw it without affecting the lawfulness of earlier processing. Contact hello@seamui.com to exercise these rights; we may need to verify your identity and authority over a workspace. You may also lodge a complaint with your local data protection authority.
9. International Transfers
We may transfer your information to countries outside your own. When we do, we ensure appropriate safeguards are in place as required by applicable laws.
10. Children’s Privacy
Our Services are not directed to children under 13. We do not knowingly collect personal information from children under 13.
11. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with the "Last updated" date. We will provide additional notice of material changes where required by applicable law.
12. Contact Us
If you have any questions about this Privacy Policy, contact us at hello@seamui.com .