LEGAL STATEMENT

// Privacy Policy

arrow_back Return to Login
VERSION: 2026-07-05-v1
CLASSIFICATION: PUBLIC

This Privacy Policy explains how SEAI Solutions, Inc., a Delaware corporation doing business as SE.ai, with its principal place of business in South Carolina ("SE.ai," "we," "us," or "our"), collects, uses, discloses, retains, and protects information when you access or use SE.ai Workbench, our websites, applications, AI-powered regulatory tools, knowledge systems, Koins, reports, outputs, APIs, and related services (collectively, the "Service").

This Privacy Policy applies to Individual Users, Consumer Users, Organizations, Organization Accounts, Authorized Users, website visitors, and other users of the Service.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. Where consent is required by applicable law, we will request consent separately.


// 01. Definitions

"Authorized User" means an individual who accesses or uses the Service on behalf of, under, or through an Organization Account.

"Consumer User" means an Individual User who is entitled to non-waivable consumer protection, privacy, or data protection rights under applicable law.

"Customer Content" means content, data, prompts, queries, device descriptions, regulatory information, text, feedback, notes, messages, or other materials that you submit, enter, transmit, create, or otherwise provide to the Service, as well as outputs generated specifically for you based on your inputs.

"Individual User" means a user who accesses or uses the Service for personal, independent, non-organizational, or non-enterprise purposes.

"Koins" means platform credits that may be used within the Service to access eligible workflows, features, reports, analyses, or other paid functions.

"Organization" means a company, startup, institution, consultancy, laboratory, research organization, regulatory affairs firm, CRO, testing organization, or other legal entity.

"Organization Account" means an account, workspace, or other Service environment created, paid for, administered, or controlled by an Organization.

"Personal Data" or "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual, as defined by applicable law.


// 02. Information We Collect

We collect information depending on how you interact with the Service.

2.1 Account and Profile Information

When you create an account or use the Service, we may collect:

  • first and last name;
  • email address;
  • company name, affiliation, or Organization name;
  • role, title, or professional category;
  • account credentials and authentication information;
  • optional profile image;
  • account settings and preferences;
  • workspace or Organization Account membership;
  • administrator or billing contact information.

We do not store plaintext passwords. Passwords are protected using salted, adaptive password hashing or equivalent credential protection mechanisms.

2.2 Organization Account Information

If you use the Service through an Organization Account, we may collect and process information relating to:

  • Organization name and account details;
  • Authorized Users;
  • workspace settings;
  • administrator actions;
  • permissions and access controls;
  • Koin usage;
  • usage history;
  • reports, workflows, and outputs associated with the Organization Account;
  • billing, invoicing, or payment-related records.

Organization administrators may be able to access, manage, export, restrict, delete, or otherwise control Customer Content and usage information associated with the Organization Account.

2.3 Payment and Koin Information

When you purchase Koins or paid features, we may collect information necessary to process the transaction, including:

  • purchase history;
  • Koin balance and usage;
  • transaction identifiers;
  • billing contact information;
  • payment status;
  • refund or support history.

Payments may be processed by third-party payment processors. We generally do not store full payment card numbers.

2.4 Usage, Device, and Log Information

We automatically collect information about how you interact with the Service, including:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • approximate location inferred from IP address;
  • access times;
  • pages viewed;
  • features used;
  • workflow events;
  • error logs;
  • diagnostic data;
  • performance data;
  • security logs;
  • authentication events;
  • session activity;
  • cookie and similar technology data.

2.5 AI Interaction Data and Customer Content

When you use AI-powered features, we may process:

  • prompts;
  • queries;
  • chats;
  • device descriptions;
  • regulatory questions;
  • workflow inputs;
  • analysis requests;
  • generated outputs;
  • reports;
  • comparison tables;
  • structured results;
  • feedback;
  • related metadata.

We use this information to provide, secure, maintain, support, troubleshoot, and improve the Service as described in this Privacy Policy.

2.6 Support, Communications, and Feedback

If you contact us, participate in surveys, provide feedback, or request support, we may collect:

  • name and email address;
  • message content;
  • support history;
  • troubleshooting information;
  • feedback and suggestions;
  • communication preferences.

2.7 Cookies and Similar Technologies

We may use cookies, local storage, pixels, SDKs, and similar technologies to:

  • maintain login sessions;
  • remember preferences;
  • secure accounts;
  • understand Service usage;
  • measure performance;
  • improve user experience;
  • detect fraud or abuse.

You can control cookies through your browser settings and, where available, through our consent banner or cookie preference tools. Disabling certain cookies may affect Service functionality.


// 03. Information We Do Not Intend to Collect

3.1 No PHI or ePHI

The Service is not designed for, and must not be used to create, receive, maintain, transmit, or process, protected health information ("PHI") or electronic protected health information ("ePHI") as those terms are used under HIPAA.

SE.ai is not intended to be used as a HIPAA-compliant service. SEAI Solutions, Inc. does not act as a Business Associate under HIPAA through the standard Service.

You must not upload, submit, enter, transmit, or otherwise provide PHI, ePHI, patient-identifiable information, medical records, DICOM files containing patient identifiers, clinical records containing identifiable patient information, or other regulated health information to the Service. This restriction applies to prompts, queries, chats, device descriptions, forms, notes, messages, documents, and other inputs.

If we determine or reasonably suspect that information submitted to the Service contains PHI, ePHI, patient-identifiable information, or other prohibited regulated health information, we may suspend processing, restrict access, delete the information, require removal or replacement, suspend the affected account or workspace, and take other steps reasonably necessary to protect the Service and comply with applicable law.

3.2 Sensitive Personal Information

We do not intentionally request sensitive Personal Information unless it is necessary to provide the Service or comply with law. You should not submit government identification numbers, financial account numbers, precise geolocation, biometric information, health information, patient information, or other sensitive Personal Information unless the Service specifically requests it and you are legally permitted to provide it.


// 04. Sources of Information

We collect information from:

  • you directly;
  • your Organization or Organization administrator;
  • Authorized Users;
  • Service usage and device interactions;
  • payment processors;
  • authentication, security, analytics, hosting, AI, and infrastructure providers;
  • customer support tools;
  • public regulatory sources;
  • third parties you authorize or integrate with the Service.

// 05. How We Use Information

We use information for the following purposes.

5.1 Provide and Operate the Service

We use information to:

  • create and manage accounts;
  • authenticate users;
  • provide AI-powered regulatory workflows;
  • process prompts, queries, and Customer Content;
  • generate outputs, reports, summaries, comparisons, and analyses;
  • manage Koins and usage;
  • provide Organization Account functionality;
  • deliver customer support;
  • maintain user preferences;
  • provide requested features.

5.2 AI Processing and Regulatory Workflows

We may process Customer Content using artificial intelligence, machine learning, retrieval systems, search indexes, embeddings, structured reasoning workflows, and third-party AI service providers to generate outputs and provide the Service.

We may create account-specific or workspace-specific indexes, embeddings, metadata, summaries, intermediate files, logs, or derived artifacts to provide, secure, maintain, support, and troubleshoot the Service.

5.3 Security, Fraud Prevention, and Abuse Detection

We use information to:

  • protect accounts;
  • detect unauthorized access;
  • prevent fraud;
  • investigate abuse;
  • enforce our Terms of Use;
  • monitor system integrity;
  • maintain audit logs;
  • protect SE.ai, users, Organizations, and third parties.

5.4 Product Improvement and Analytics

We may use usage data, telemetry data, diagnostic data, aggregated data, and de-identified data to:

  • understand how the Service is used;
  • improve reliability;
  • enhance features;
  • debug issues;
  • monitor performance;
  • develop new functionality;
  • improve user experience.

5.5 Communications

We may use information to:

  • send administrative notices;
  • respond to support requests;
  • provide security alerts;
  • send product updates;
  • send billing or Koin-related notices;
  • communicate changes to our Terms or Privacy Policy;
  • send marketing communications where permitted by law.

You may opt out of marketing communications, but you may still receive administrative, transactional, security, or account-related messages.

5.6 Legal Compliance and Enforcement

We may use information to:

  • comply with applicable laws;
  • respond to legal process;
  • protect legal rights;
  • resolve disputes;
  • enforce agreements;
  • cooperate with law enforcement or regulators where legally required or appropriate.

// 06. No Training on Customer Content

SE.ai does not use Customer Content to train third-party foundation models.

SE.ai does not use Customer Content to train SE.ai foundation models or proprietary regulatory models unless you expressly authorize such use or enter into a separate written agreement with SE.ai.

Where SE.ai uses third-party AI service providers to provide inference or related processing, SE.ai requires such providers to process Customer Content only to provide services to SE.ai and not to use Customer Content to train their foundation models.

Third-party AI service providers may retain Customer Content or related processing data for abuse monitoring, security, debugging, reliability, or legal compliance purposes for no longer than thirty (30) days, unless a shorter period is agreed in writing or longer retention is required by law.

We may use aggregated, de-identified, or telemetry data to monitor performance, detect abuse, improve reliability, develop features, and improve the Service, provided that such data does not identify you or disclose your Customer Content.


// 07. How We Disclose Information

We may disclose information in the following circumstances.

7.1 Service Providers and Processors

We may disclose information to service providers, contractors, and processors that help us operate the Service, including providers of:

  • cloud infrastructure;
  • database hosting;
  • search and indexing;
  • AI inference and related processing;
  • payment processing;
  • authentication;
  • email delivery;
  • customer support;
  • analytics;
  • security monitoring;
  • logging and diagnostics;
  • error tracking;
  • fraud prevention;
  • legal, accounting, and professional services.

These providers are authorized to process information only as necessary to provide services to us or as otherwise permitted by applicable law and contract.

7.2 Organizations and Administrators

If you use the Service through an Organization Account, we may disclose account, usage, Customer Content, Koin, and administrative information to the Organization and its administrators.

Organization administrators may be able to access, manage, export, delete, or restrict information associated with the Organization Account.

7.3 Legal Requirements and Protection

We may disclose information where we believe disclosure is reasonably necessary to:

  • comply with law;
  • respond to subpoenas, court orders, legal process, or government requests;
  • enforce our Terms of Use;
  • protect the rights, property, or safety of SE.ai, users, Organizations, or third parties;
  • prevent fraud, abuse, or security incidents;
  • investigate violations of our policies.

7.4 Business Transfers

We may disclose or transfer information in connection with a merger, acquisition, financing, corporate reorganization, sale of assets, bankruptcy, or similar transaction.

7.5 With Your Direction or Consent

We may disclose information where you direct us to do so, authorize an integration, request support involving a third party, or otherwise provide consent.


// 08. Google Analytics, Cookies, and Similar Technologies

We use Google Analytics and similar analytics tools to understand website traffic, usage patterns, performance, and Service interactions.

These tools may collect information such as pages visited, referring pages, browser type, device type, approximate location, interaction events, and other usage information.

We use a consent banner or similar consent mechanism for non-essential cookies and similar technologies where required by applicable law. You may manage cookie preferences through the consent banner where available or through your browser settings.

We do not use Google Analytics to sell Personal Information. We do not currently use Google Analytics to share Personal Information for cross-context behavioral advertising as those terms are used under California privacy law.

If we enable advertising features, remarketing, Google signals, ads personalization, or similar advertising-related features in the future, we will update this Privacy Policy and provide any notices, consent mechanisms, or opt-out choices required by applicable law.


// 09. Sale, Sharing, and Advertising

SE.ai does not sell Personal Information.

SE.ai does not share Personal Information for cross-context behavioral advertising as those terms are used under California privacy law.

If our practices change in the future, we will update this Privacy Policy and provide any notices, consent mechanisms, or opt-out choices required by applicable law.


// 10. Data Retention

We retain information for as long as reasonably necessary to provide the Service, maintain accounts, comply with law, resolve disputes, enforce agreements, prevent fraud, protect security, and fulfill the purposes described in this Privacy Policy.

Retention periods vary depending on the type of information, the purpose of processing, legal requirements, account settings, Organization instructions, backup cycles, and legitimate business needs.

General retention practices include:

Category General Retention Approach
Account information Retained while the account is active and for a reasonable period after closure as needed for legal, security, tax, accounting, or dispute purposes
Customer Content Retained while needed to provide the Service, unless deleted earlier by you or your Organization, subject to backups, logs, legal holds, and retention obligations
AI interaction data Retained as needed to provide, secure, troubleshoot, and improve the Service, subject to account settings and applicable law
Third-party AI provider processing data Third-party AI providers may retain Customer Content or related processing data for no longer than thirty (30) days, unless a shorter period is agreed in writing or longer retention is required by law
Koin and transaction records Retained as needed for billing, tax, accounting, fraud prevention, dispute resolution, and legal compliance
Security logs Retained as reasonably necessary for security, fraud prevention, abuse detection, investigation, and legal compliance
Support communications Retained as needed to provide support, maintain records, improve service quality, and resolve disputes
Marketing preferences Retained as needed to honor opt-outs and communication preferences
Backups Retained for limited backup and disaster recovery periods before deletion or overwriting according to backup schedules

Following account deletion, we will delete or anonymize Personal Information and Customer Content according to our deletion processes, backup cycles, legal obligations, security needs, and applicable agreements.

We may retain limited records where reasonably necessary for legal compliance, security, fraud prevention, dispute resolution, enforcement of our Terms, or protection of the Service.


// 11. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure.

These safeguards may include encryption in transit, encryption at rest where appropriate, access controls, authentication, password hashing, logging, monitoring, vulnerability management, backup controls, and personnel access restrictions.

No method of transmission or storage is completely secure. We cannot guarantee absolute security.

If you believe your account or information may have been compromised, contact us at [email protected].


// 12. International Data Transfers

SE.ai is based in the United States. Your information may be processed in the United States and other countries where we or our service providers operate.

If we transfer Personal Information from the European Economic Area, the United Kingdom, Switzerland, or other jurisdictions that require transfer safeguards, we will rely on appropriate legal mechanisms where required, such as adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, Data Privacy Framework certification where applicable, or other lawful transfer mechanisms.


// 13. Your Rights and Choices

Depending on your location and applicable law, you may have rights regarding your Personal Information, including the right to:

  • access Personal Information;
  • request correction of inaccurate Personal Information;
  • request deletion of Personal Information;
  • request portability or export of Personal Information;
  • object to certain processing;
  • restrict certain processing;
  • opt out of marketing communications;
  • withdraw consent where processing is based on consent;
  • appeal or challenge certain decisions where applicable;
  • lodge a complaint with a data protection authority where applicable.

To exercise privacy rights, contact us at [email protected].

We may need to verify your identity before processing your request. If you are an Authorized User of an Organization Account, we may direct certain requests to the applicable Organization administrator or respond in accordance with the Organization's instructions and applicable law.

We will respond to requests within the timeframe required by applicable law.


// 14. California Privacy Notice

This Section applies to California residents to the extent California privacy law applies to SE.ai.

14.1 Categories of Personal Information We Collect

In the preceding 12 months, we may have collected the following categories of Personal Information:

Category Examples
Identifiers Name, email address, account identifiers, IP address
Customer records information Billing contact information, transaction information
Commercial information Koin purchases, usage history, payment status, transaction records
Internet or network activity Log data, device data, browser data, feature usage, session activity
Geolocation information Approximate location inferred from IP address
Professional or employment-related information Company, affiliation, role, title, Organization information
Inferences Preferences, usage patterns, workflow activity, product interaction patterns
Sensitive Personal Information Account login credentials; we do not intentionally collect PHI/ePHI or patient-identifiable information

14.2 Sources of Personal Information

We collect Personal Information from:

  • you;
  • your Organization or administrators;
  • your device and browser;
  • your use of the Service;
  • payment processors;
  • service providers;
  • third parties you authorize;
  • public regulatory sources where applicable.

14.3 Purposes for Collection, Use, and Disclosure

We collect, use, and disclose Personal Information for the business and commercial purposes described in Sections 5, 7, and 8 of this Privacy Policy, including providing the Service, processing transactions, securing accounts, supporting users, improving the Service, detecting abuse, analytics, and complying with law.

14.4 Categories of Third Parties to Whom We Disclose Personal Information

We may disclose Personal Information to:

  • cloud and infrastructure providers;
  • AI service providers;
  • payment processors;
  • analytics providers, including Google Analytics;
  • security and fraud prevention providers;
  • customer support tools;
  • professional advisors;
  • Organizations and administrators;
  • government authorities or legal recipients where required or appropriate;
  • parties involved in business transfers.

14.5 Sale or Sharing

We do not sell Personal Information.

We do not share Personal Information for cross-context behavioral advertising.

14.6 Sensitive Personal Information

We do not use or disclose Sensitive Personal Information for purposes that would require a right to limit under California privacy law, unless we provide the required notice and choice.

You must not submit PHI/ePHI or patient-identifiable information to the Service.

14.7 California Privacy Rights

California residents may have the right to:

  • know what Personal Information we collect, use, disclose, sell, or share;
  • access Personal Information;
  • delete Personal Information;
  • correct inaccurate Personal Information;
  • opt out of sale or sharing;
  • limit certain uses or disclosures of Sensitive Personal Information;
  • not be discriminated against for exercising privacy rights.

To exercise California privacy rights, contact us at [email protected].

You may use an authorized agent where permitted by law. We may require verification of your identity and the agent's authority.


// 15. EEA, UK, and Swiss Privacy Rights

If you are located in the European Economic Area, the United Kingdom, or Switzerland, this Section applies to the extent applicable law applies to SE.ai.

15.1 Controller and Processor Roles

For account registration, website operation, payment records, security, service administration, marketing, and legal compliance, SE.ai generally acts as a controller.

Where SE.ai processes Personal Information contained in Customer Content on behalf of an Organization under an applicable Data Processing Addendum or other written agreement, SE.ai may act as a processor or service provider, and the Organization may act as the controller.

15.2 Legal Bases

We may process Personal Information under the following legal bases:

Processing Activity Legal Basis
Account creation and Service delivery Performance of a contract
AI workflows requested by you Performance of a contract
Organization Account administration Performance of a contract; legitimate interests
Payment and Koin processing Performance of a contract; legal obligations
Security, fraud prevention, and abuse detection Legitimate interests; legal obligations
Customer support Performance of a contract; legitimate interests
Product analytics and improvement Legitimate interests; consent where required
Google Analytics and non-essential cookies Consent where required
Marketing communications Consent or legitimate interests, depending on jurisdiction and context
Legal compliance Legal obligations
Protection of legal rights Legitimate interests; legal claims

15.3 Your Rights

Subject to applicable law, you may have the right to:

  • access your Personal Information;
  • rectify inaccurate or incomplete Personal Information;
  • erase Personal Information;
  • restrict processing;
  • object to processing;
  • receive Personal Information in a portable format;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a supervisory authority.

To exercise these rights, contact us at [email protected].


// 16. Cookies and Similar Technologies

We use cookies and similar technologies for authentication, security, preferences, analytics, performance, and Service operation.

Where required by law, we will request consent before using non-essential cookies or similar technologies.

You can manage cookies through browser settings. If we provide a cookie banner or preference center, you may use it to manage applicable choices.


// 17. Marketing Communications

You may unsubscribe from marketing emails by following the instructions in those emails or contacting us at [email protected].

Even if you opt out of marketing communications, we may still send administrative, transactional, security, billing, legal, or Service-related messages.


// 18. Children's Privacy

The Service is not intended for children under 18.

We do not knowingly collect Personal Information from children under 18. If we learn that we have collected Personal Information from a child under 18, we will take steps to delete it.


// 19. Third-Party Links and Services

The Service may contain links to third-party websites, services, tools, or resources. We are not responsible for the privacy practices of third parties.

Your use of third-party services may be governed by their own terms and privacy policies.


// 20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or Service features.

If we make material changes, we will provide reasonable notice, such as by posting the updated Privacy Policy, sending an email, providing in-product notice, or requesting renewed consent where required by law.

We will not materially expand our use of previously collected Customer Content for AI model training or unrelated purposes without appropriate notice and, where required by law or contract, your consent.

The "Last Updated" date indicates when this Privacy Policy was last revised.


// 21. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:

SEAI Solutions, Inc.
A Delaware corporation doing business as SE.ai
Principal place of business: South Carolina
Email: [email protected]
Website: https://seai.chat