Seshat shield seshatsecure file vault
Features How it works Security Pricing Help Sign in Get started

Privacy Policy

Last updated: July 16, 2026 · Effective: upon publication

1. Scope & roles2. Data we collect3. How we use it4. Legal bases5. Search6. Sharing & subprocessors7. International transfers8. Retention9. Security10. Your rights11. California12. Breach notice13. Children14. Changes & contact

1. Scope & our roles

This policy explains how Seshat ("we", "us", "Seshat") handles personal data on seshatvault.com and in the Seshat application. We act in two roles:

  • Controller — for account, billing, and website data, where we decide how and why it's processed.
  • Processor — for the email and attachments you vault ("Customer Data"), which we process only on your instructions under our Data Processing Addendum. For that content, you (or your organization) are the controller.

2. Data we collect

CategoryExamplesSource
AccountName, email, hashed password, 2FA settings, planYou
Customer DataVaulted emails & attachments and their metadata (sender, subject, dates)Your connected mailboxes
Connection tokensRevocable OAuth/IMAP credentials for connected mailboxesYou / provider
Usage & auditSign-ins, downloads, deletions, IP, device/browser, timestampsAutomatic
BillingPlan, transaction records (card data held by our processor, not us)You / processor
SupportMessages you send usYou

We never receive or store your mailbox password — only revocable access tokens.

3. How we use data — and how we don't

We use data to provide, secure, and support the service: to authenticate you, store and organize your email, run searches, display and let you download or delete it, process payments, prevent abuse, and meet legal obligations. Customer Data is decrypted only to perform functions you request (display, search, download).

We do not read your mail for any other purpose, profile you, mine your content for advertising, sell or "share" it, or use it to train AI models. Files you lock with a passphrase are sealed with a key only you hold — not even Seshat can open them.

4. Legal bases (GDPR/UK GDPR)

  • Performance of a contract — to deliver the service you sign up for.
  • Legitimate interests — to secure, maintain, and improve the service and prevent abuse (balanced against your rights).
  • Legal obligation — to comply with applicable law.
  • Consent — where required (e.g., certain cookies); you may withdraw it any time.

5. Search

Search runs entirely within Seshat's own infrastructure, over the metadata and message text we index from your vaulted email. We do not send your content to any third-party AI provider for search, and your content is never used to train any model. The providers we do use are listed on our Subprocessors page.

6. Sharing & subprocessors

We share data only with vetted service providers needed to run Seshat — cloud storage, application hosting, our payment processor, and transactional email — each bound by contract to protect it and use it only on our instructions. Current providers are listed on our Subprocessors page, with advance notice of changes. We never sell your data. We may disclose data to comply with law or protect rights, and will notify you where legally permitted. In a merger or acquisition, data may transfer subject to this policy.

7. International transfers

If we transfer personal data outside your region (e.g., the EEA/UK), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, plus supplementary measures including encryption.

8. Data retention

DataRetention
Vaulted email (Customer Data)The retention period you/your admin set (default 7 years from the email's date), then deleted — unless under legal hold
Account dataFor the life of the account; deleted within 30 days of closure
Audit logs24 months, then aggregated or deleted
BackupsRolling 35 days, then purged (deletions propagate within the backup window)
Trial accountsDeleted 30 days after trial ends if not converted

When you close your account: you have 30 days to export your vaulted email, after which we permanently delete it — regardless of the default retention period — except where a legal hold or law requires us to keep it. The default retention period governs automatic deletion only while your account is active.

9. Security

We protect data with encryption in transit and at rest, isolated storage, an identity-gated application, least-privilege access, and logging. See our Security page. No method is perfectly secure, but we work to protect your data and to be transparent about how.

10. Your rights (GDPR/UK and others)

Subject to law, you may request to access, correct, delete, restrict, or port your data, and to object to or withdraw consent for certain processing. You can disconnect any mailbox and export your data at any time from the app. To exercise rights, contact [email protected]; we respond within the legally required time. You may also complain to your local data-protection authority. For Customer Data, we will assist your organization (the controller) in fulfilling requests, per the DPA.

11. California privacy (CCPA/CPRA)

California residents have the right to know, delete, and correct personal information, and to limit use of sensitive personal information. We do not sell or "share" (cross-context behavioral advertising) personal information, and have not in the past 12 months. We won't discriminate against you for exercising these rights. To make a request, contact [email protected]; authorized agents may submit requests with proof of authorization. Categories we collect are listed in Section 2; we disclose them only to the subprocessors in Section 6 for the business purposes in Section 3.

12. Breach notification

If a personal-data breach affects data for which we are the controller (your account and website data), we will notify affected users and, where required, regulators without undue delay and within the timeframes the law requires. For Customer Data — the email you vault, where we act as processor — we will notify your organization (the controller) without undue delay so it can meet its own notification duties, as set out in the DPA.

13. Children

Seshat isn't directed to children and isn't intended for anyone under 16, and you must be at least 18 to hold an account (see the Terms). We don't knowingly collect children's data; if we learn we have, we'll delete it.

14. Changes & contact

We'll post changes here and update the date above; material changes get prominent notice. Contact our privacy team at [email protected] or by mail at FTSC Consulting LLC, 1712 Pioneer Ave, Ste 2456, Cheyenne, WY 82001, USA.

seshat · seshatvault.com Help · Security · SLA · Terms · Acceptable Use · Privacy · Cookies · DPA · Subprocessors · Law Enforcement