Privacy Policy
Last updated: July 16, 2026 · Effective: upon publication
1. Scope & our roles
This policy explains how Seshat ("we", "us", "Seshat") handles personal data on seshatvault.com and in the Seshat application. We act in two roles:
- Controller — for account, billing, and website data, where we decide how and why it's processed.
- Processor — for the email and attachments you vault ("Customer Data"), which we process only on your instructions under our Data Processing Addendum. For that content, you (or your organization) are the controller.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account | Name, email, hashed password, 2FA settings, plan | You |
| Customer Data | Vaulted emails & attachments and their metadata (sender, subject, dates) | Your connected mailboxes |
| Connection tokens | Revocable OAuth/IMAP credentials for connected mailboxes | You / provider |
| Usage & audit | Sign-ins, downloads, deletions, IP, device/browser, timestamps | Automatic |
| Billing | Plan, transaction records (card data held by our processor, not us) | You / processor |
| Support | Messages you send us | You |
We never receive or store your mailbox password — only revocable access tokens.
3. How we use data — and how we don't
We use data to provide, secure, and support the service: to authenticate you, store and organize your email, run searches, display and let you download or delete it, process payments, prevent abuse, and meet legal obligations. Customer Data is decrypted only to perform functions you request (display, search, download).
We do not read your mail for any other purpose, profile you, mine your content for advertising, sell or "share" it, or use it to train AI models. Files you lock with a passphrase are sealed with a key only you hold — not even Seshat can open them.
4. Legal bases (GDPR/UK GDPR)
- Performance of a contract — to deliver the service you sign up for.
- Legitimate interests — to secure, maintain, and improve the service and prevent abuse (balanced against your rights).
- Legal obligation — to comply with applicable law.
- Consent — where required (e.g., certain cookies); you may withdraw it any time.
5. Search
Search runs entirely within Seshat's own infrastructure, over the metadata and message text we index from your vaulted email. We do not send your content to any third-party AI provider for search, and your content is never used to train any model. The providers we do use are listed on our Subprocessors page.
6. Sharing & subprocessors
We share data only with vetted service providers needed to run Seshat — cloud storage, application hosting, our payment processor, and transactional email — each bound by contract to protect it and use it only on our instructions. Current providers are listed on our Subprocessors page, with advance notice of changes. We never sell your data. We may disclose data to comply with law or protect rights, and will notify you where legally permitted. In a merger or acquisition, data may transfer subject to this policy.
7. International transfers
If we transfer personal data outside your region (e.g., the EEA/UK), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, plus supplementary measures including encryption.
8. Data retention
| Data | Retention |
|---|---|
| Vaulted email (Customer Data) | The retention period you/your admin set (default 7 years from the email's date), then deleted — unless under legal hold |
| Account data | For the life of the account; deleted within 30 days of closure |
| Audit logs | 24 months, then aggregated or deleted |
| Backups | Rolling 35 days, then purged (deletions propagate within the backup window) |
| Trial accounts | Deleted 30 days after trial ends if not converted |
When you close your account: you have 30 days to export your vaulted email, after which we permanently delete it — regardless of the default retention period — except where a legal hold or law requires us to keep it. The default retention period governs automatic deletion only while your account is active.
9. Security
We protect data with encryption in transit and at rest, isolated storage, an identity-gated application, least-privilege access, and logging. See our Security page. No method is perfectly secure, but we work to protect your data and to be transparent about how.
10. Your rights (GDPR/UK and others)
Subject to law, you may request to access, correct, delete, restrict, or port your data, and to object to or withdraw consent for certain processing. You can disconnect any mailbox and export your data at any time from the app. To exercise rights, contact [email protected]; we respond within the legally required time. You may also complain to your local data-protection authority. For Customer Data, we will assist your organization (the controller) in fulfilling requests, per the DPA.
11. California privacy (CCPA/CPRA)
California residents have the right to know, delete, and correct personal information, and to limit use of sensitive personal information. We do not sell or "share" (cross-context behavioral advertising) personal information, and have not in the past 12 months. We won't discriminate against you for exercising these rights. To make a request, contact [email protected]; authorized agents may submit requests with proof of authorization. Categories we collect are listed in Section 2; we disclose them only to the subprocessors in Section 6 for the business purposes in Section 3.
12. Breach notification
If a personal-data breach affects data for which we are the controller (your account and website data), we will notify affected users and, where required, regulators without undue delay and within the timeframes the law requires. For Customer Data — the email you vault, where we act as processor — we will notify your organization (the controller) without undue delay so it can meet its own notification duties, as set out in the DPA.
13. Children
Seshat isn't directed to children and isn't intended for anyone under 16, and you must be at least 18 to hold an account (see the Terms). We don't knowingly collect children's data; if we learn we have, we'll delete it.
14. Changes & contact
We'll post changes here and update the date above; material changes get prominent notice. Contact our privacy team at [email protected] or by mail at FTSC Consulting LLC, 1712 Pioneer Ave, Ste 2456, Cheyenne, WY 82001, USA.