Privacy Policy

Last updated:

Rather than reviewing long documents, you can log into the platform and ask the AI assistant for precise answers about this Privacy Policy.

Data Collection

We collect:

  • Account details from your sign-in provider (Google display name, email, profile photo, unique account ID)
  • Country (auto-detected from your IP at sign-in, editable on Profile)
  • Preferred language (auto-detected from your browser, editable)
  • Files and notes you upload to your catalogues, including extracted text and document embeddings derived from them
  • Chat queries and AI responses
  • Usage and billing logs for the token-credit system

Data Sharing & AI Processing

We do not sell your personal data. To provide our core functionalities — document extraction, embedding, and AI question answering — we share necessary data with the following enterprise providers, who act strictly as Data Processors under our control:

  • Google's Gemini API: processes your documents, embeddings, and chat queries to generate AI responses
  • Google Vertex AI Discovery Engine (optional): re-ranks search results to improve answer accuracy
  • Firebase (Google Cloud): hosts the database, file storage, and authentication infrastructure
  • Stripe:processes token top-up payments. Stripe receives only the data required to complete the transaction — your card details are entered on Stripe's own hosted page and never reach our servers

We act as the Data Controller. Our processors operate under strict data-protection agreements.

Strict "No Public Training" Guarantee

We understand the sensitivity of your corporate documents. In accordance with enterprise privacy standards and the EU AI Act:

  • The files, text chunks, and queries you upload to Sebtember.app are never used to train, fine-tune, or improve public foundational AI models.
  • All AI processing is conducted within secure, isolated enterprise environments. Once the AI generates the required output, the temporary data used by the AI processor is not permanently retained by the AI provider.

Cookies and Local Storage

We use only essential cookies and local storage required to keep you signed in and run the platform:

  • A secure HTTP-only session cookie set after Google sign-in
  • Your Firebase authentication token in browser local storage

We do not use analytics cookies, advertising pixels, behavioral tracking, or third-party marketing trackers. We do not profile users, build behavioral audiences, or share usage data with any advertiser.

When you complete a payment, Stripe sets its own essential cookies on Stripe's hosted Checkout page (on stripe.com, not on Sebtember.app) to process the transaction.

Performance telemetry

We collect anonymous Core Web Vitals metrics (page load time, interaction responsiveness, layout stability) via Vercel Speed Insights. This data:

  • Uses no cookies and no local storage.
  • Cannot be tied back to your identity or session.
  • Records only the route path (e.g. /blog), the timing measurement, and your browser's general device class (mobile / desktop).
  • Is aggregated by Vercel into a performance dashboard we use to fix slow pages.

We use this telemetry instead of conventional analytics (Google Analytics, Mixpanel, etc.) precisely because it can't identify or profile you. If you'd prefer to opt out entirely, blocking vitals.vercel-insights.com in your browser stops the beacons; nothing on Sebtember breaks.

Your Rights

You have the right to access, correct, or request the deletion of your personal data at any time. You can deactivate your account from your profile settings. Contact hello@sebtember.app for any data-related request.