This Privacy Policy explains how SEAI Solutions, Inc., a Delaware corporation doing business as SE.ai, with its principal place of business in South Carolina ("SE.ai," "we," "us," or "our"), collects, uses, discloses, retains, and protects information when you access or use SE.ai Workbench, our websites, applications, AI-powered regulatory tools, knowledge systems, Koins, reports, outputs, APIs, and related services (collectively, the "Service").
This Privacy Policy applies to Individual Users, Consumer Users, Organizations, Organization Accounts, Authorized Users, website visitors, and other users of the Service.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. Where consent is required by applicable law, we will request consent separately.
"Authorized User" means an individual who accesses or uses the Service on behalf of, under, or through an Organization Account.
"Consumer User" means an Individual User who is entitled to non-waivable consumer protection, privacy, or data protection rights under applicable law.
"Customer Content" means content, data, prompts, queries, device descriptions, regulatory information, text, feedback, notes, messages, or other materials that you submit, enter, transmit, create, or otherwise provide to the Service, as well as outputs generated specifically for you based on your inputs.
"Individual User" means a user who accesses or uses the Service for personal, independent, non-organizational, or non-enterprise purposes.
"Koins" means platform credits that may be used within the Service to access eligible workflows, features, reports, analyses, or other paid functions.
"Organization" means a company, startup, institution, consultancy, laboratory, research organization, regulatory affairs firm, CRO, testing organization, or other legal entity.
"Organization Account" means an account, workspace, or other Service environment created, paid for, administered, or controlled by an Organization.
"Personal Data" or "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual, as defined by applicable law.
We collect information depending on how you interact with the Service.
When you create an account or use the Service, we may collect:
We do not store plaintext passwords. Passwords are protected using salted, adaptive password hashing or equivalent credential protection mechanisms.
If you use the Service through an Organization Account, we may collect and process information relating to:
Organization administrators may be able to access, manage, export, restrict, delete, or otherwise control Customer Content and usage information associated with the Organization Account.
When you purchase Koins or paid features, we may collect information necessary to process the transaction, including:
Payments may be processed by third-party payment processors. We generally do not store full payment card numbers.
We automatically collect information about how you interact with the Service, including:
When you use AI-powered features, we may process:
We use this information to provide, secure, maintain, support, troubleshoot, and improve the Service as described in this Privacy Policy.
If you contact us, participate in surveys, provide feedback, or request support, we may collect:
We may use cookies, local storage, pixels, SDKs, and similar technologies to:
You can control cookies through your browser settings and, where available, through our consent banner or cookie preference tools. Disabling certain cookies may affect Service functionality.
The Service is not designed for, and must not be used to create, receive, maintain, transmit, or process, protected health information ("PHI") or electronic protected health information ("ePHI") as those terms are used under HIPAA.
SE.ai is not intended to be used as a HIPAA-compliant service. SEAI Solutions, Inc. does not act as a Business Associate under HIPAA through the standard Service.
You must not upload, submit, enter, transmit, or otherwise provide PHI, ePHI, patient-identifiable information, medical records, DICOM files containing patient identifiers, clinical records containing identifiable patient information, or other regulated health information to the Service. This restriction applies to prompts, queries, chats, device descriptions, forms, notes, messages, documents, and other inputs.
If we determine or reasonably suspect that information submitted to the Service contains PHI, ePHI, patient-identifiable information, or other prohibited regulated health information, we may suspend processing, restrict access, delete the information, require removal or replacement, suspend the affected account or workspace, and take other steps reasonably necessary to protect the Service and comply with applicable law.
We do not intentionally request sensitive Personal Information unless it is necessary to provide the Service or comply with law. You should not submit government identification numbers, financial account numbers, precise geolocation, biometric information, health information, patient information, or other sensitive Personal Information unless the Service specifically requests it and you are legally permitted to provide it.
We collect information from:
We use information for the following purposes.
We use information to:
We may process Customer Content using artificial intelligence, machine learning, retrieval systems, search indexes, embeddings, structured reasoning workflows, and third-party AI service providers to generate outputs and provide the Service.
We may create account-specific or workspace-specific indexes, embeddings, metadata, summaries, intermediate files, logs, or derived artifacts to provide, secure, maintain, support, and troubleshoot the Service.
We use information to:
We may use usage data, telemetry data, diagnostic data, aggregated data, and de-identified data to:
We may use information to:
You may opt out of marketing communications, but you may still receive administrative, transactional, security, or account-related messages.
We may use information to:
SE.ai does not use Customer Content to train third-party foundation models.
SE.ai does not use Customer Content to train SE.ai foundation models or proprietary regulatory models unless you expressly authorize such use or enter into a separate written agreement with SE.ai.
Where SE.ai uses third-party AI service providers to provide inference or related processing, SE.ai requires such providers to process Customer Content only to provide services to SE.ai and not to use Customer Content to train their foundation models.
Third-party AI service providers may retain Customer Content or related processing data for abuse monitoring, security, debugging, reliability, or legal compliance purposes for no longer than thirty (30) days, unless a shorter period is agreed in writing or longer retention is required by law.
We may use aggregated, de-identified, or telemetry data to monitor performance, detect abuse, improve reliability, develop features, and improve the Service, provided that such data does not identify you or disclose your Customer Content.
We may disclose information in the following circumstances.
We may disclose information to service providers, contractors, and processors that help us operate the Service, including providers of:
These providers are authorized to process information only as necessary to provide services to us or as otherwise permitted by applicable law and contract.
If you use the Service through an Organization Account, we may disclose account, usage, Customer Content, Koin, and administrative information to the Organization and its administrators.
Organization administrators may be able to access, manage, export, delete, or restrict information associated with the Organization Account.
We may disclose information where we believe disclosure is reasonably necessary to:
We may disclose or transfer information in connection with a merger, acquisition, financing, corporate reorganization, sale of assets, bankruptcy, or similar transaction.
We may disclose information where you direct us to do so, authorize an integration, request support involving a third party, or otherwise provide consent.
We use Google Analytics and similar analytics tools to understand website traffic, usage patterns, performance, and Service interactions.
These tools may collect information such as pages visited, referring pages, browser type, device type, approximate location, interaction events, and other usage information.
We use a consent banner or similar consent mechanism for non-essential cookies and similar technologies where required by applicable law. You may manage cookie preferences through the consent banner where available or through your browser settings.
We do not use Google Analytics to sell Personal Information. We do not currently use Google Analytics to share Personal Information for cross-context behavioral advertising as those terms are used under California privacy law.
If we enable advertising features, remarketing, Google signals, ads personalization, or similar advertising-related features in the future, we will update this Privacy Policy and provide any notices, consent mechanisms, or opt-out choices required by applicable law.
SE.ai does not sell Personal Information.
SE.ai does not share Personal Information for cross-context behavioral advertising as those terms are used under California privacy law.
If our practices change in the future, we will update this Privacy Policy and provide any notices, consent mechanisms, or opt-out choices required by applicable law.
We retain information for as long as reasonably necessary to provide the Service, maintain accounts, comply with law, resolve disputes, enforce agreements, prevent fraud, protect security, and fulfill the purposes described in this Privacy Policy.
Retention periods vary depending on the type of information, the purpose of processing, legal requirements, account settings, Organization instructions, backup cycles, and legitimate business needs.
General retention practices include:
| Category | General Retention Approach |
|---|---|
| Account information | Retained while the account is active and for a reasonable period after closure as needed for legal, security, tax, accounting, or dispute purposes |
| Customer Content | Retained while needed to provide the Service, unless deleted earlier by you or your Organization, subject to backups, logs, legal holds, and retention obligations |
| AI interaction data | Retained as needed to provide, secure, troubleshoot, and improve the Service, subject to account settings and applicable law |
| Third-party AI provider processing data | Third-party AI providers may retain Customer Content or related processing data for no longer than thirty (30) days, unless a shorter period is agreed in writing or longer retention is required by law |
| Koin and transaction records | Retained as needed for billing, tax, accounting, fraud prevention, dispute resolution, and legal compliance |
| Security logs | Retained as reasonably necessary for security, fraud prevention, abuse detection, investigation, and legal compliance |
| Support communications | Retained as needed to provide support, maintain records, improve service quality, and resolve disputes |
| Marketing preferences | Retained as needed to honor opt-outs and communication preferences |
| Backups | Retained for limited backup and disaster recovery periods before deletion or overwriting according to backup schedules |
Following account deletion, we will delete or anonymize Personal Information and Customer Content according to our deletion processes, backup cycles, legal obligations, security needs, and applicable agreements.
We may retain limited records where reasonably necessary for legal compliance, security, fraud prevention, dispute resolution, enforcement of our Terms, or protection of the Service.
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure.
These safeguards may include encryption in transit, encryption at rest where appropriate, access controls, authentication, password hashing, logging, monitoring, vulnerability management, backup controls, and personnel access restrictions.
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
If you believe your account or information may have been compromised, contact us at [email protected].
SE.ai is based in the United States. Your information may be processed in the United States and other countries where we or our service providers operate.
If we transfer Personal Information from the European Economic Area, the United Kingdom, Switzerland, or other jurisdictions that require transfer safeguards, we will rely on appropriate legal mechanisms where required, such as adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, Data Privacy Framework certification where applicable, or other lawful transfer mechanisms.
Depending on your location and applicable law, you may have rights regarding your Personal Information, including the right to:
To exercise privacy rights, contact us at [email protected].
We may need to verify your identity before processing your request. If you are an Authorized User of an Organization Account, we may direct certain requests to the applicable Organization administrator or respond in accordance with the Organization's instructions and applicable law.
We will respond to requests within the timeframe required by applicable law.
This Section applies to California residents to the extent California privacy law applies to SE.ai.
In the preceding 12 months, we may have collected the following categories of Personal Information:
| Category | Examples |
|---|---|
| Identifiers | Name, email address, account identifiers, IP address |
| Customer records information | Billing contact information, transaction information |
| Commercial information | Koin purchases, usage history, payment status, transaction records |
| Internet or network activity | Log data, device data, browser data, feature usage, session activity |
| Geolocation information | Approximate location inferred from IP address |
| Professional or employment-related information | Company, affiliation, role, title, Organization information |
| Inferences | Preferences, usage patterns, workflow activity, product interaction patterns |
| Sensitive Personal Information | Account login credentials; we do not intentionally collect PHI/ePHI or patient-identifiable information |
We collect Personal Information from:
We collect, use, and disclose Personal Information for the business and commercial purposes described in Sections 5, 7, and 8 of this Privacy Policy, including providing the Service, processing transactions, securing accounts, supporting users, improving the Service, detecting abuse, analytics, and complying with law.
We may disclose Personal Information to:
We do not sell Personal Information.
We do not share Personal Information for cross-context behavioral advertising.
We do not use or disclose Sensitive Personal Information for purposes that would require a right to limit under California privacy law, unless we provide the required notice and choice.
You must not submit PHI/ePHI or patient-identifiable information to the Service.
California residents may have the right to:
To exercise California privacy rights, contact us at [email protected].
You may use an authorized agent where permitted by law. We may require verification of your identity and the agent's authority.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, this Section applies to the extent applicable law applies to SE.ai.
For account registration, website operation, payment records, security, service administration, marketing, and legal compliance, SE.ai generally acts as a controller.
Where SE.ai processes Personal Information contained in Customer Content on behalf of an Organization under an applicable Data Processing Addendum or other written agreement, SE.ai may act as a processor or service provider, and the Organization may act as the controller.
We may process Personal Information under the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and Service delivery | Performance of a contract |
| AI workflows requested by you | Performance of a contract |
| Organization Account administration | Performance of a contract; legitimate interests |
| Payment and Koin processing | Performance of a contract; legal obligations |
| Security, fraud prevention, and abuse detection | Legitimate interests; legal obligations |
| Customer support | Performance of a contract; legitimate interests |
| Product analytics and improvement | Legitimate interests; consent where required |
| Google Analytics and non-essential cookies | Consent where required |
| Marketing communications | Consent or legitimate interests, depending on jurisdiction and context |
| Legal compliance | Legal obligations |
| Protection of legal rights | Legitimate interests; legal claims |
Subject to applicable law, you may have the right to:
To exercise these rights, contact us at [email protected].
We use cookies and similar technologies for authentication, security, preferences, analytics, performance, and Service operation.
Where required by law, we will request consent before using non-essential cookies or similar technologies.
You can manage cookies through browser settings. If we provide a cookie banner or preference center, you may use it to manage applicable choices.
You may unsubscribe from marketing emails by following the instructions in those emails or contacting us at [email protected].
Even if you opt out of marketing communications, we may still send administrative, transactional, security, billing, legal, or Service-related messages.
The Service is not intended for children under 18.
We do not knowingly collect Personal Information from children under 18. If we learn that we have collected Personal Information from a child under 18, we will take steps to delete it.
The Service may contain links to third-party websites, services, tools, or resources. We are not responsible for the privacy practices of third parties.
Your use of third-party services may be governed by their own terms and privacy policies.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or Service features.
If we make material changes, we will provide reasonable notice, such as by posting the updated Privacy Policy, sending an email, providing in-product notice, or requesting renewed consent where required by law.
We will not materially expand our use of previously collected Customer Content for AI model training or unrelated purposes without appropriate notice and, where required by law or contract, your consent.
The "Last Updated" date indicates when this Privacy Policy was last revised.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:
SEAI Solutions, Inc.
A Delaware corporation doing business as SE.ai
Principal place of business: South Carolina
Email: [email protected]
Website: https://seai.chat