SeenByAI — Privacy Policy
Version 1.0 · effective 24 August 2026 · ← seenbyai.uk
1. Controller and contact
The controller of your personal data is Rafał Kawecki, a natural person carrying on unregistered business activity (działalność nierejestrowana) under Polish law, operating the SeenByAI service. Contact on any data protection matter: [email protected]. No data protection officer has been appointed — the law does not require one here; write to the address above.
2. What we process, why, and on what basis
References are to the GDPR (Regulation (EU) 2016/679).
- Email address — sign-in by magic link, delivery of reports, subscription and service notices, and handling complaints. Art. 6(1)(b) — performance of the contract.
- Interface language — so that emails reach you in the language you used. Art. 6(1)(b).
- Brand configuration — brand names, aliases, descriptions, competitors, keywords and any prompts you write yourself. Art. 6(1)(b). Please do not enter personal data in prompts unless it is genuinely needed for the analysis.
- Analysis results — the answers returned by the AI systems, detected mentions, cited sources, metrics and their history. Art. 6(1)(b).
- Subscription data — plan, status, end of the paid period and the Lemon Squeezy subscription identifier. Art. 6(1)(b) and, for settlement records, art. 6(1)(c).
- Free check record — the email address, brand name, language and result. Art. 6(1)(b) to deliver the report, and art. 6(1)(f) to enforce the one-check-per-address limit.
- Sign-in sessions — a server-side session identifier with its creation and last-activity time, which powers the 15-minute idle timeout and lets a logout actually revoke access. Art. 6(1)(f) — security of the service.
- Survey answers — if you fill in the voluntary churn or exit survey, we store your answers together with your email address. Art. 6(1)(f) — improving the service. You may object at any time; ignoring the survey has no consequences.
- Server logs you upload (Agency plan) — on import we keep only the lines matching known AI crawlers, and of those only the timestamp, bot name, path and status code. Everything else in the uploaded file, including your visitors' IP addresses, is discarded and never stored. Art. 6(1)(b).
- Technical request data — the web server and Cloudflare see the IP address of each request while handling it. We do not store IP addresses in our database.
We do not sell data, we do not profile for marketing purposes, and we do not send unsolicited mail. There is no automated decision-making producing legal effects for you.
3. Who we share data with
- Lemon Squeezy, LLC (USA) — merchant of record: payment, invoicing and taxes. It acts as a separate controller of the billing data you give it; we receive the subscription status and the buyer's email address.
- Resend (USA) — technical delivery of our emails.
- OpenAI, Google, Anthropic, xAI, Perplexity (USA) — we send them the text of the questions we run about an industry or brand, and the answers we analyse. They do not receive your account data. One exception, stated plainly: when Claude (Anthropic) writes the internal summary of a completed survey, the prompt includes the respondent's email address alongside the answers.
- Cloudflare, Inc. (USA / EU) — DNS, hosting of the website, the tunnel in front of the API, and the Turnstile anti-bot check.
- Oracle Cloud Infrastructure (Frankfurt, Germany) — the application server and the database.
4. Where data is stored and transfers outside the EEA
The application server and the production database run in the EU (Oracle Cloud, Frankfurt, Germany). Database backups are transferred daily over an encrypted connection to a private server in Poland, where they are kept for 7 days. Transfers to the providers based in the United States listed above take place on the basis of Standard Contractual Clauses or of the EU–US Data Privacy Framework, as applied by each of those providers.
5. How long we keep data
- Account and service data — for as long as the account exists. When a subscription ends the account becomes read-only, and 30 days after paid access ends the operational data (brands, runs, results, history) is deleted automatically. Export your data before then — the export is built into the panel.
- User record and subscription history — kept as the billing trail until you delete the account.
- Free check record — the email address and brand name are kept to enforce the one-check-per-address limit; deleted when you delete your account.
- AI crawler entries from uploaded logs — 90 days.
- Survey answers — kept for product research; deleted on request.
- Sign-in data — a magic-link token is deleted the first time it is used; a session record expires after 15 minutes of inactivity or on logout.
- Backups — overwritten on a 7-day rotation, so a deletion propagates out of the backups within a week.
- Billing data — held by Lemon Squeezy for the period its tax obligations require.
6. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest. Two of these are immediate and self-service in the product: data export (JSON) and permanent account deletion — panel, account section. Deletion removes your brands, results, history, subscriptions and free-check records, and is confirmed by email. For anything else, write to [email protected]. You may also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa).
7. Cookies and local storage
We use one strictly necessary cookie: the sign-in session cookie (geo_session, HttpOnly, SameSite=Lax, sent over HTTPS only). Cloudflare Turnstile, which protects the forms against bots, may set its own technical identifiers. The site also stores your theme and language preference in your browser's local storage — this never leaves your device and is not used to identify you. There are no analytics or marketing cookies and no third-party trackers, which is why the site shows no consent banner.
8. Security
Sign-in is passwordless: there is no password to leak. Sessions live server-side and are revocable, traffic runs over HTTPS through Cloudflare, and access to the production server is restricted to the controller. No service can promise absolute security, but if a breach ever affects your rights we will notify you and the supervisory authority as the GDPR requires.
9. Changes to this policy
- We announce material changes by email before they take effect.
- This is version 1.0, the first published version. Superseded versions will be linked from this page.
Version 1.0 of 24 August 2026. © 2026 SeenByAI · Terms of Service