1. Introduction and Data Controller
Welcome to Seedots ("we", "us", "our"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our AI-powered image generation platform.
Seedots acts as the data controller for the personal data processed through our platform. This means we determine the purposes and means of processing your personal data.
This policy applies to all users of our website and services, including visitors, registered users, and subscribers. By using our services, you acknowledge that you have read and understood this Privacy Policy.
2. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
- Contract Performance (Article 6(1)(b)): Processing necessary to provide our services, manage your account, process payments, and deliver generated content.
- Legitimate Interests (Article 6(1)(f)): Processing for fraud prevention, security, service improvement, and internal analytics, where our interests do not override your rights.
- Consent (Article 6(1)(a)): Processing for marketing communications, non-essential cookies, and analytics tracking. You may withdraw consent at any time.
- Legal Obligation (Article 6(1)(c)): Processing required to comply with tax, accounting, and other legal requirements.
3. Personal Data We Collect
We collect and process the following categories of personal data:
3.1 Account Information
- Email address (required for registration)
- Password (encrypted and hashed)
- Account creation and modification dates
- Subscription status and plan type
- Credit balance and transaction history
3.2 User-Generated Content
- Text prompts submitted for image generation
- Images uploaded for processing (upscaling, modification, background removal)
- Generated images and their metadata
- Moodboards, zones, and workspace configurations
- Audio files generated through speech synthesis
3.3 Technical and Usage Data
- IP address and approximate geolocation
- Browser type, version, and language settings
- Device type, operating system, and screen resolution
- Pages visited, features used, and time spent on site
- Referring website and exit pages
- Error logs and performance metrics
3.4 Payment Information
- Billing name and address (processed by Stripe)
- Payment method details (stored securely by Stripe, not by us)
- Transaction amounts and dates
- Subscription renewal information
4. How We Use Your Data
We use your personal data for the following purposes:
4.1 Service Delivery
- Create and manage your user account
- Process your prompts and generate images using AI models
- Store and organize your generated content
- Manage your credit balance and subscription
- Process payments through our payment processor
4.2 Service Improvement
- Analyze usage patterns to improve our platform
- Debug technical issues and optimize performance
- Develop new features based on user behavior
- Conduct internal research and analytics
4.3 Communication
- Send transactional emails (account confirmation, password reset)
- Notify you of important service changes or outages
- Send marketing communications (with your consent)
- Respond to your support inquiries
4.4 Security and Compliance
- Prevent fraud, abuse, and unauthorized access
- Enforce our Terms of Service
- Comply with legal obligations
- Protect the rights and safety of users
5. AI Processing and Content Generation
Our platform uses artificial intelligence to generate images based on your prompts. You should be aware of the following:
- Prompt Processing: Your text prompts are sent to third-party AI providers for processing. These prompts may be temporarily stored by these providers according to their data retention policies.
- Image Processing: Images you upload for modification, upscaling, or background removal are processed by AI models. These images are transmitted to our processing infrastructure.
- No Training on Your Data: We do not use your personal prompts or uploaded images to train AI models. Your content remains private and is only used to fulfill your specific requests.
- Content Moderation: AI-generated content may be subject to automated content moderation to prevent the generation of prohibited material.
6. Data Sharing and Third Parties
We share your personal data with the following categories of third parties:
6.1 Service Providers
- Supabase: Database hosting, user authentication, and file storage. Data stored in secure cloud infrastructure.
- Stripe: Payment processing. Stripe collects and processes payment information independently as a data controller. See Stripe's Privacy Policy.
- AI Model Providers: Processing of prompts and image generation. Prompts are transmitted securely for processing.
- Email Service Providers: Delivery of transactional and marketing emails.
6.2 Analytics and Advertising
- Meta (Facebook) Pixel: With your consent, we use Meta Pixel to measure advertising effectiveness and create custom audiences. This involves sharing hashed identifiers and browsing behavior with Meta. You can opt out through our cookie settings.
6.3 Legal Requirements
We may disclose your personal data if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
6.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you of such transfer and any changes to this Privacy Policy.
7. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions for countries recognized as providing adequate data protection
- Binding Corporate Rules for transfers within corporate groups
- Your explicit consent for specific transfers
8. Data Retention
We retain your personal data for the following periods:
- Account Data: Retained for the duration of your account and for 30 days after deletion to allow for account recovery.
- Generated Content: Retained until you delete it or your account is terminated. Deleted content is permanently removed within 30 days.
- Payment Records: Retained for 7 years to comply with tax and accounting requirements.
- Technical Logs: Retained for up to 90 days for security and debugging purposes.
- Marketing Preferences: Retained until you withdraw consent or delete your account.
9. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Article 15): Request a copy of your personal data and information about how it is processed.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten").
- Right to Restriction (Article 18): Request limitation of processing of your personal data.
- Right to Data Portability (Article 20): Receive your personal data in a structured, machine-readable format.
- Right to Object (Article 21): Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Right to Lodge a Complaint: File a complaint with your local data protection authority.
To exercise these rights, please contact us at privacy@seedots.app or use the account deletion feature in your Settings.
10. Your Rights (CCPA - California Residents)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request disclosure of personal information collected, used, and shared about you.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out: Opt out of the sale or sharing of your personal information. Note: We do not sell your personal information.
- Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights.
Categories of Personal Information Collected: Identifiers, commercial information, internet activity, and inferences drawn from the above.
We Do Not Sell Your Personal Information. We may share data with service providers and for targeted advertising with your consent.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication with hashed passwords
- Row-level security in our database to isolate user data
- Regular security audits and vulnerability assessments
- Access controls limiting employee access to personal data
- Secure cloud infrastructure with industry certifications
While we strive to protect your personal data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
12. Children's Privacy
Our service is not intended for users under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at privacy@seedots.app, and we will take steps to delete such information.
13. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect information about your browsing activities. For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Notify you by email (for registered users) or through a prominent notice on our website
- Obtain your consent where required by law for material changes
We encourage you to review this Privacy Policy periodically for any changes.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
- Email: privacy@seedots.app
- Contact Form: Contact Page
We will respond to your request within 30 days, or sooner as required by applicable law.