Privacy Policy
Last updated 26 September 2026
Who is responsible for your data
Seylo is operated by Jakub Radziejewski, Rytro 163, 33-343 Rytro, Poland, contact support@seylo.co. Under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) that person is the controller of the personal data described here.
What we collect, and why
Your account. Your email address and a password, which is stored only as a cryptographic hash and is never readable by us. If you sign in with Google or Apple we receive your email address and name from them instead (from Apple, a relay address if you chose to hide your own). We use this to create your account, sign you in, and contact you about the service. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
The waitlist. If you ask for an invitation before you have an account, we keep the email address you gave us, the line about what you are making if you wrote one, and which site sent you to the form. We use it to invite you and to tell you when Seylo opens to everyone, and for nothing else. To stop the form being flooded we also keep a one-way fingerprint of the network address the request came from; it is erased after a day. Write to us and we will take you off the list. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
What you put into Seylo. Your projects, assets, project context, uploaded files, and the version history of edits you make. We store this so the product works. We do not read it, and we do not use it to train any model. Legal basis: performance of our contract with you.
Messages you send us. If you write to us from Help inside Seylo, we keep what you wrote, your account’s email address, and which screen you were on, so that the message can be understood, acted on and answered. It is read by the people who build Seylo and shared with nobody else. Legal basis: our legitimate interest in fixing and improving the service (Art. 6(1)(f) GDPR).
Access tokens. If you connect Claude or another tool over MCP, we store the token’s name, the date it was created and last used, and a SHA-256 hash of the token. The token itself is shown once and never stored, so it cannot be recovered from our database.
Paired phones. If you pair the Seylo app with your account, we keep the name your phone gives itself and when it was paired, so that you can tell your phones apart and disconnect one from Settings. The app holds a session for your account in the phone’s keychain; it does not track you and contains no advertising or analytics software.
Collaborators. If you share a project, we store which account it was shared with and what level of access it has.
Visits to the website. When you arrive at seylo.co from somewhere else, we count the visit: the day, the site or link it came from, and the country your connection is in. To count people rather than page loads, your network address and browser are combined with a random value that is created for that day and turned into a one-way code; the random value and the codes are deleted when the day ends, so a visit cannot be traced back to you or linked to another day. We keep only the daily totals. No cookie is set and nothing is stored in your browser. Our legitimate interest (Art. 6(1)(f) GDPR) is knowing whether people find Seylo and where from. Visits while you are signed in are not counted.
What we do not collect. Seylo has no third-party analytics, no advertising trackers, and no tracking cookies. We do not profile you and we take no automated decisions that produce legal effects for you.
Tools you connect yourself
If you connect Claude, ChatGPT or another tool over MCP, or install the browser extension, content moves between Seylo and that tool because you asked it to. Whatever reaches the other side is then handled by that provider under their own terms and privacy policy, not ours. We have no control over what they do with it and cannot delete it on your behalf.
Nothing leaves Seylo this way unless you connect a tool and ask it to act. Revoking the access token in Settings ends that access immediately.
Cookies
Seylo sets one kind of cookie: the session cookie that keeps you signed in. It is strictly necessary for the service to function, so under Art. 5(3) of the ePrivacy Directive it does not require consent. Clearing it signs you out. We use no analytics or marketing cookies, which is why Seylo shows no cookie banner.
Who else processes your data
Supabase hosts our database and authentication, acting as our processor under a data processing agreement. Data is stored in Ireland (EU West), so it does not leave the European Economic Area.
Cloudflare serves the application, stores the files you upload in a bucket restricted to the European Union, and runs Turnstile, the check on the sign-in page that tells people from bots. Resend delivers account emails such as confirmation and password-reset links. Stripe processes payments. Card details go to Stripe directly and never reach our servers; we store only the customer reference Stripe gives us. Zoho Mail, in its EU data centre, holds the inboxes you reach when you email us.
OpenAI powers searching by meaning, which is part of the paid plans. On those accounts, the text of what you save, and what you type into search, is sent to OpenAI’s API to be turned into embeddings (lists of numbers that let two pieces of text be compared), which we store with your project. Your uploaded files and pictures are not sent, and nothing from an account on the free plan is. OpenAI does not use data sent through its API to train its models, and keeps it for no more than 30 days to detect abuse. This is the one processor that sees the contents of your work, and it sees only text.
Where a provider processes data outside the European Economic Area, that transfer relies on the European Commission’s Standard Contractual Clauses or an adequacy decision.
How long we keep it
Your account and its contents are kept until you delete them. Deleting your account removes your projects, assets, version history, uploaded files and access tokens; deletion cascades through our database, so nothing of yours is left behind. Backups are overwritten on our provider’s ordinary cycle.
Once paid plans exist, invoicing records will be kept for as long as tax law requires, which is longer than the account itself.
Your rights
Under the GDPR you may request access to your data, correction of it, erasure, restriction of processing, and portability, and you may object to processing. You can exercise most of these directly in the app: Settings holds your profile, an export of your workspace, and project deletion. For anything else, write to support@seylo.co and we will respond within one month.
If you believe we handle your data unlawfully you may complain to your local supervisory authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa.
Security
Every row in our database is bound to the account that owns it and protected by row-level security, so one account cannot read another’s data. Uploaded files are held in a private bucket and served only through short-lived signed links. Passwords are hashed, and access tokens are stored only as hashes.
No system is perfectly secure. If a breach is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform you where the law requires it.
Changes
If this policy changes materially we will tell you by email before the change takes effect. The date at the top always reflects the current version.