Privacy Policy
Effective date: March 11, 2026 · Last updated: September 14, 2026
1. Information We Collect
We collect the following categories of information when you use the Service:
- Account information — business name, email address, plan tier, and account status.
- Business context — information you provide during the AI onboarding interview, including your business description, operational details, and channel preferences. This information is used to configure your AI agent.
- Conversation data — messages sent to and received from your AI agent via connected channels (Telegram, Discord, etc.).
- Usage data — token counts, model usage, and cost data generated by your AI agent's activity, used for billing and quota management.
- Billing information — payment method details are processed and stored by Stripe, Inc. Seaboss stores only a Stripe Customer ID and subscription status; we do not store raw card numbers.
- Technical data — IP addresses, request IDs, timestamps, and access logs generated during normal system operation.
- Secrets and credentials — API keys and other secrets you provide (e.g., for third-party integrations) are stored encrypted at rest and never logged in plaintext.
- Third-party integration data — if you connect a third-party service such as Google Drive, we store the OAuth tokens (access and refresh tokens) needed to maintain the connection. We access only the data and scopes you explicitly authorize.
2. How We Use Your Information
We use the information we collect to:
- Set up, operate, and maintain Seaboss and your pod
- Calculate, bill, and collect subscription fees and credit-pack purchases
- Provide customer support and respond to inquiries
- Monitor platform health, security, and reliability
- Send transactional communications (account creation, billing alerts, service announcements)
- Connect to third-party services you authorize (e.g., Google Drive) so your AI agent can act on your behalf
- Comply with applicable legal obligations
We do not use your data for advertising or sell it to third parties.
3. Third-Party Data Processing
We share limited data with the following third-party processors:
- Third-Party AI Providers — Conversation content and Inputs are transmitted to third-party AI APIs to generate responses. Depending on your configuration, these may include Anthropic, Google, OpenAI, Qwen, OpenRouter, or other model providers. Processing is governed by their respective commercial API terms.
- Stripe, Inc. — Payment card data and billing transactions are processed by Stripe under Stripe's privacy policy. Seaboss does not handle raw payment card data.
- Google LLC — If you connect Google Drive, your AI agent accesses your Google Drive files via the Google Drive API using OAuth tokens you authorize. Seaboss accesses only the scopes you grant (file reading and file management). See Section 3a below for details.
We do not sell, rent, or share your personal information with any other third parties except as required by law or with your explicit consent. A complete, continuously updated list of every vendor that touches customer data — including its purpose, the categories of data involved, and its location — is published on our Subprocessors page.
Where your data is stored. Your dedicated agent environment and our management systems are hosted in the United States, in Chicago, Illinois. Encrypted off-site backups of our management database are also held in the United States.
International transfers. Some AI model providers you can use are operated outside the United States, including providers located in China and Singapore. Sending a message to one of those models sends your conversation content to that provider. Every provider we can route to, and the country it operates in, is listed on our Subprocessors page. If you pick your models yourself, or use a routing preset, you can see exactly which providers apply before you choose. If you turn on Auto, Seaboss picks the model for each request based on price and capability, without any geographic restriction — so the whole Subprocessors list applies, including the non-US providers on it. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses as set out in our Data Processing Addendum.
3a. Google Drive Integration
If you choose to connect your Google account, Seaboss requests access to the following OAuth scopes:
- drive.file — allows your AI agent to create, read, and manage only the specific Google Drive files you open with Seaboss or that the agent creates on your behalf. Your AI agent cannot see or access other files in your Drive.
What we access: Your AI agent accesses Google Drive files only when performing tasks you request (e.g., "save this report to my Drive" or to read a file you've explicitly opened with Seaboss via the Google file picker). Seaboss does not browse, index, or copy your Drive contents for any other purpose, and cannot read files you haven't directly authorized.
How data is stored: OAuth tokens (access and refresh tokens) are stored encrypted at rest using AES-256-GCM. Tokens are used solely to maintain the connection between your AI agent and your Google account. File contents retrieved from Google Drive are processed in your agent's isolated environment and are not stored on Seaboss servers beyond the duration of the task.
Revoking access: You can disconnect Google Drive at any time from the Integrations tab in your dashboard. You can also revoke Seaboss's access directly from your Google Account permissions page. Revoking access immediately stops your AI agent from accessing your Google Drive.
No training: Google Drive data is never used to train AI models unless you have opted in under one of the two exceptions described in Section 4 — a training-tier model, or our routing-improvement program.
4. AI Model Training
Your data is not used to train AI models, except where you specifically opt in. Seaboss uses commercial APIs from our LLM providers (such as Anthropic, Google, and OpenRouter), whose terms prohibit using your data to train their models. That is our default for every model on the platform. There are exactly two exceptions, and each one requires a separate, explicit opt-in from you.
- Training-tier models. Models we label training-tier are opt-in only and clearly marked wherever you would select them. Today that is two models — Muse Spark 1.2 Contributor and Muse Spark 1.3 Contributor, both from Meta — which you can only turn on after confirming that Meta may use your prompts and completions to train future Meta models. You can revoke this choice at any time by switching models.
- Helping Seaboss route better. If you use Auto model selection, you can separately opt in to let us keep the questions and instructions you send — never your agent's replies — to improve the system that decides which model answers each request. This is used only for that purpose, only by Rise and Shine Futures, and is never sold, shared, or used to train a model that writes replies. The exact wording you agree to is shown in your dashboard before you turn it on, and we ask again if that wording ever changes. You can turn it off at any time, and you can ask us to delete what we have kept.
5. Data Retention
- Active accounts: Data is retained for as long as your account is active and as necessary to provide the Service.
- Agent Memory Consolidation: To maintain performance, older conversation data may be automatically summarized and consolidated into your agent's long-term memory. The raw underlying chat logs may be periodically deleted or archived once summarized, while the consolidated memory is retained to allow your agent to recall important context.
- Raw Conversation Logs: Retained for up to 90 days before being automatically summarized or deleted, unless configured otherwise.
- Subscriptions that end: if your trial ends, a payment fails, or you cancel, your agent is paused for 7 days and nothing is deleted. Your files, your agent's memory, and your settings stay exactly as they are, on the same private server. During those 7 days you can restart your subscription and pick up where you left off, download your data, or close your account yourself.
- Closed accounts: once an account is closed — by you, or by us at the end of the 7-day pause — you have 7 days to download your data from your dashboard. After those 7 days your Seaboss environment and everything in it are permanently deleted from our systems, except where retention is required by law or where a specific retention period below applies.
- Our accounting copy of a closed account: when an account is closed we keep one internal archive of it for 12 months, for accounting, tax, and dispute-resolution purposes only. It is not something you can download after the 7-day window, it is not used for anything else, and it is deleted at the end of the 12 months.
- Usage logs: Aggregated usage and billing logs are retained for 12 months for accounting and dispute resolution purposes.
- Routing decision records (Auto only): when Auto is on and routing-evidence collection is enabled, we keep a record of what your agent's request looked like statistically — length, number of messages, whether it had attachments, what kind of task it was, and which model we picked — for 12 months. These records contain no message text. Closing your account does not shorten this period; because these records contain no message text and are not linked back to you once your account is gone, they are kept for the full 12 months.
- Opted-in request records: if you have opted in under Section 4(2), the request side of those conversations is kept encrypted for 30 days. Closing your account deletes them straight away, rather than waiting out the remainder of the 30 days.
6. Data Security
We implement industry-standard security measures to protect your data, including:
- AES-256-GCM encryption for all secrets and API credentials stored at rest
- HTTPS/TLS for all data in transit
- Isolated environments per Customer — your pod cannot access another Customer's environment
- WAL-mode SQLite databases with access controls
- Request ID logging for security audit trails
No security system is infallible. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.
7. Data Isolation
Each Customer account operates in a dedicated, isolated environment (Pod). Your workspace, conversation data, configuration files, and secrets are stored separately and are not accessible to other Customers. Administrative access to your Pod is restricted to authorized Seaboss personnel for support and maintenance purposes only.
8. Cookies & Analytics
The Seaboss web application stores a JSON Web Token (JWT) in your browser's local storage for authentication purposes. We do not use third-party advertising cookies. We may use minimal, privacy-respecting analytics to understand aggregate usage patterns and improve the platform. We do not track individual users across sites.
9. Your Rights
You have the following rights regarding your personal data:
- Access & export: You may export your data at any time through the dashboard or by contacting support.
- Correction: You may update your account information through the dashboard.
- Deletion: You may request deletion of your account and associated data by contacting us. Deletion requests will be processed within 30 days, subject to legal retention requirements.
- Know: You may request confirmation of whether we process personal information about you, and the categories of personal information, sources, purposes, and third parties involved.
- Non-discrimination: We will not deny service, charge a different price, or provide a different quality of service because you exercised any of these rights.
We do not sell or share your personal information as those terms are defined by the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), or by any other US state privacy law, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information beyond the purposes permitted under those laws, so no "limit the use of my sensitive personal information" right arises. We do not use your data to train AI models, except under the two opt-in exceptions described in Section 4.
If the GDPR or UK GDPR applies to you, you additionally have the right to restrict or object to processing, the right to data portability, the right to withdraw consent at any time without affecting processing already carried out, and the right to lodge a complaint with your local supervisory authority. Where we act as a processor on behalf of a business customer, we will refer your request to that customer, who is the controller of the data.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days, or within 45 days where a US state privacy law allows an extension and we notify you of it. We may need to verify your identity before acting on a request. An authorized agent may submit a request on your behalf with proof of authorization. If we decline a request, you may appeal that decision by replying to our response, and we will inform you of the outcome of the appeal.
10. Children's Privacy
The Service is intended for adults operating business entities. We do not knowingly collect personal information from individuals under 18 years of age. If you believe a minor has provided us with personal information, please contact us at [email protected] and we will delete it promptly.
11. Changes & Contact
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before they take effect. Continued use of the Service after the effective date of an update constitutes your acceptance of the revised policy.
For privacy-related questions or requests, contact us at: [email protected]
The Service is operated by Rise and Shine Futures, LLC, an Illinois limited liability company doing business as Seaboss, 1538 Saratoga Ct., Libertyville, IL 60048, United States. Business customers who need contractual data protection terms should see our Data Processing Addendum.