Privacy Policy
Translations are provided for convenience. Where permitted by applicable law, the English version controls if there is a conflict. Nothing in this notice limits rights that cannot be waived under applicable law.
Usage analytics
You can allow SEED to collect usage analytics to help improve the service. This is optional and does not affect access to features.
1. Scope
This policy applies to SEED on withseed.app, its localized public pages, the authenticated app, and the free SEED Starter theme operated by Mint Labs.
2. Data We Collect
| Context | Data | Purpose |
|---|---|---|
| Account | Name, email address, profile image, verification status, linked sign-in provider ID, session IP address, and browser user agent | Authentication, account access, session security, notices, and support |
| Blog analysis | Email address, public blog URL, public content snippets, analysis results, selected search market, and language settings | Blog analysis, reports, recommendations, and usage limits |
| App usage | Drafts, titles, prompts, AI outputs, generated images, Context video projects, Wikimedia search and import records, video media and render results, publishing records, usage counters, request metadata, and error logs | Writing and publishing features, storage, security, quota accounting, and troubleshooting |
| Payments | Email, order/subscription identifiers, purchase status | Subscription access, billing support, tax records, and fraud prevention |
| Connected publishing integrations | Google account identifier, Blogger blog IDs, blog names and URLs, selected blog, granted scopes, encrypted refresh token, Facebook Page, Threads, Bluesky, and LinkedIn account identifiers, user-selected Mastodon account identifiers and server origins, names/usernames, URLs, granted scopes, encrypted access tokens, selected destinations, and publication records | Google sign-in and, when separately authorized, Blogger discovery, publishing, updates, and connection management; Facebook Page, Threads, Bluesky, LinkedIn, and user-selected Mastodon connection and destination discovery, plus user-requested publishing from SEED |
| CC0 image finder | Draft title and keyword sent to Openverse for search, selected indexed-media records, accessibility text, and the imported image copy | Find, preview, and store user-selected CC0 images in the editor |
When you request publishing, SEED sends the approved post text and, when selected, the image or image URL supported by the connected provider and, where supported, its alt text, to the connected Facebook Page, Threads, Bluesky, LinkedIn, or user-selected Mastodon destination using the provider access token. The provider may also receive the destination identifier needed to publish the post. SEED does not send a draft to a social provider unless you request publishing.
3. How We Use Data
- Provide blog analysis, keyword ideas, market signals, and SEO review.
- Authenticate users and manage account sessions.
- Apply plan limits, rate limits, and abuse prevention.
- Process payments and grant subscription access.
- Send magic links, reports, product notices, and support replies.
- Improve product quality through aggregate analytics.
- Connect Facebook Pages, Threads, Bluesky, LinkedIn, and user-selected Mastodon destinations and publish user-approved promotion content when separately authorized.
4. Processors and External Services
SEED uses third-party services to operate the product. Sensitive payment-card data is handled by the payment processor and is not stored by SEED.
| Provider | Purpose | Retention |
|---|---|---|
| Cloudflare, Inc.; Vercel Inc. | Cloudflare Workers hosting, D1 data, R2 storage, and queued jobs; Vercel frontend hosting and delivery | According to SEED account-deletion, backup, security, and legal-retention requirements |
| OpenAI | User-requested writing, SEO review, translation, image generation, rendered-video frame review, and text-to-speech using submitted draft, prompt, frame, or narration content | For applicable Responses API requests, SEED asks OpenAI to disable response storage. By default, OpenAI may retain abuse-monitoring logs for up to 30 days; longer retention may apply when required by law or reasonably necessary to protect OpenAI, its services, or a third party from harm. This storage setting is not the same as Zero Data Retention. |
| Openverse (editor images); Wikimedia Commons (Shorts media) | User-requested Openverse searches using draft titles and keywords and CC0 catalog metadata for editor images; Wikimedia Commons searches and imports approved Shorts media under CC0, CC BY 3.0, or CC BY 4.0; selected media is fetched into SEED R2 | Openverse and Wikimedia Commons handle their respective search requests and source metadata under their policies. SEED may retain provenance and imported copies for selected editor images or Shorts media after a draft is deleted until the applicable image, account, storage, backup, security, or legal-retention process is complete. |
| Merchant of Record / payment processor | Subscription billing, taxes, receipts, refunds, and fraud prevention | According to the processor's policy |
| Google LLC | Google sign-in, keyword services, and separately authorized Blogger access | Blogger authorization is retained until disconnection, account deletion, token invalidation, or operational expiry |
| Meta Platforms, Inc. (Facebook and Threads); Bluesky; LinkedIn; and user-selected Mastodon servers | OAuth authorization, destination discovery, and user-requested publishing for connected Facebook Pages, Threads, Bluesky, LinkedIn, and user-selected Mastodon servers | SEED stops using a connection after disconnection, but disconnection does not by itself delete its identifiers, token records, destinations, or publication records. SEED handles related records through the applicable verified deletion and retention process, which may include account deletion, token invalidation, operational expiry, or required security, dispute, backup, or legal retention. |
| Resend, Inc. | Email delivery for magic links, reports, and support | Delivery logs according to provider policy |
| Google Analytics | Page visits, device and browser information, approximate location, and product-usage statistics when analytics is enabled | According to the retention setting configured for the SEED Google Analytics property |
| Market data providers | Keyword volumes, competition signals, and related searches | API calls are processed as needed |
5. Cookies
SEED uses required cookies for sign-in, security and preferences such as display language. Optional analytics stays off until you allow it. You can withdraw permission in Privacy or Settings to stop future tracking and clear analytics cookies. When editing a draft, SEED also keeps recovery copies in this browser. After the server confirms a save, the matching copy from the current editor window is removed. Other copies, including those kept before replacing your text, have no automatic expiry and may remain after sign-out. You can remove them by clearing this site's browser data. Blocking required cookies may prevent signed-in features from working.
6. Retention
- Account and profile data are retained while the account is active and then deleted or de-identified, except where security, dispute, or legal obligations require a longer period.
- Drafts, generated content including Context video media and render results, and publication records are retained for the active draft or account and handled through the applicable deletion process, subject to limited backup and legal-retention requirements.
- Subscription and transaction identifiers are retained for the periods required by tax, accounting, fraud-prevention, and dispute-resolution obligations.
- Security and request logs are retained only as long as reasonably needed for abuse prevention, incident investigation, reliability, and applicable legal obligations.
- Facebook Page, Threads, Bluesky, LinkedIn, and user-selected Mastodon connection identifiers, server origins where applicable, granted scopes, encrypted access tokens, destinations, and provider publication records are retained while the connection is active. After disconnection, SEED stops using the connection; disconnection alone does not delete these records. A verified deletion request or account deletion triggers the applicable removal or de-identification process, subject to security, dispute, backup, and legal-retention requirements.
7. Legal Bases and International Processing
Depending on location and context, SEED processes data to perform the user agreement, comply with legal obligations, protect legitimate security and operational interests, or act on consent where required. Providers may process data outside the user's country. Where required, SEED relies on applicable contractual or legal safeguards for those transfers.
8. User Rights
Users may request access, correction, deletion, or restriction of personal data by contacting hello@withseed.app. Users in the EU or EEA may also request portability or object to certain processing where applicable under GDPR.
For Meta-linked deletion requests, follow the Meta data deletion instructions.
9. Children's Privacy
SEED is not directed to children under 13 or a higher minimum age required by local law. If personal data from a child was submitted without valid permission, contact hello@withseed.app so it can be reviewed and deleted.
10. Security
SEED uses HTTPS, Google sign-in or email magic links, access controls, and encryption for sensitive Blogger authorization tokens. No online service can guarantee perfect security, but SEED limits access to what is operationally necessary.
11. Contact
Privacy questions or data requests can be sent to Mint Labs at hello@withseed.app.