Privacy Policy
Last updated
This policy explains what personal data Ship Systems LLC ("we", "us") collects when you use SeaCat at https://seacat.dev, what we do with it, who else handles it, how long we keep it, and the choices you have. It covers the website, the dashboard and the API. The Terms of Service cover everything else.
The short version
- We keep your email address, your API keys in hashed form, a record of each request's size and cost, and your credit purchases.
- We don't keep what you send to the API. Our servers process it in memory to compute the answers and don't save it, and we never use it to train models.
- We set one cookie, to keep you signed in. There are no analytics, ads or trackers, and our pages load nothing from other sites.
- We don't sell personal data.
- You can download your data, or delete your account, from the dashboard at any time.
- Who is responsible for your data
- What we collect and why
- Cookies
- How we use it, and what we don't do
- Legal bases
- Service providers
- Where your data is processed
- How long we keep it
- Security
- Your rights
- Personal data you send about others
- Children
- Changes to this policy
- Contact
1. Who is responsible for your data
Ship Systems LLC runs SeaCat. We decide how your account, billing and site data is used, so we are its "controller" under data protection laws such as the GDPR.
Content you send to the API can contain personal data about other people. For that data, we act on your instructions, as your "processor" or "service provider". Section 11 explains what that means.
2. What we collect and why
Account data
Your email address, when you created your account, and your credit balance. While there is an access queue, we also record when you joined the waitlist and when you were invited.
Why: to create your account, sign you in, manage access and contact you about your account.
Sign-in data
When anyone asks for a sign-in link, we store the email address it goes to, a hashed copy of the link's secret, and when the link was created, when it expires (15 minutes later) and whether it was used. We delete this record automatically 24 hours after the link is created, whether or not it was used. We limit how many links one address can receive, so the form can't be used to flood someone's inbox.
Why: to sign you in securely and prevent abuse.
API keys
For each key, we store a one-way hash of it, its first 10 characters so you can recognize it on the dashboard, and when it was created, last used and revoked. We never store the key itself: it's shown to you once, when you create it, and we can't recover it.
Why: to check the key on each request.
Usage data
For each successful API request, we record which account and key made it, how many input tokens it had, what it cost and when it happened. Nothing else about the request is recorded.
Why: to charge for requests, show your usage on the dashboard, answer billing questions and understand the load on the service.
Payment data
Stripe collects your card or other payment details and your billing information on its own checkout page. We never see your full card number. We give Stripe your email address and account ID so the payment can be matched to your account. From Stripe we store the checkout session's ID, the amount credited and the time.
Why: to add credits to your account, keep accounting records, and handle refunds and disputes.
Request content
This is what you send to the API, such as the state and your questions, and the answers we return.
- Our servers process it in memory to compute the answers. We don't write it to our database or our logs, and it's gone from our servers once the response is sent.
- On its way to and from the GPU, it passes through the infrastructure of Cloudflare and Modal (see section 6). Modal may hold it briefly in order to deliver it, for example the answer to a request that took longer than about a minute (for example, one that was queued), which waits on Modal until you collect it or it expires.
- We never use it to train or improve any model, we don't read it, and we don't sell or share it.
- An error response, such as one for an invalid request, can repeat parts of your request back to you. It isn't stored either.
Technical data
When you visit the site or call the API, your IP address and ordinary request details, such as the time, the address requested and your browser or client type, pass through Cloudflare and Modal. They route the traffic and may log these details for security and operations, under their own policies. Our application doesn't store IP addresses in its database or logs. To limit abuse of the sign-in form, it keeps the IP address of each sign-in request in memory for up to an hour, then discards it.
Our server logs record errors and operational events, not request content. If an email we send fails, the log can include the recipient's address. Our proxy logs the method and address of any request it fails to deliver.
Why: to deliver the service, keep it secure and fix problems.
Emails and messages
We only send the emails needed to run the service: sign-in links, access invitations, and important notices about your account, the service or our policies. We don't send marketing email. If you write to us, we keep the correspondence for as long as we need it to deal with your message and keep records.
3. Cookies
We set one cookie, called session, and only once you sign in. It holds your account ID, signed so it can't be altered, and keeps you signed in until you sign out, or until 30 days pass without a visit. Browser scripts can't read it, and on HTTPS it is only sent over encrypted connections. It's strictly necessary for the dashboard to work, so it doesn't need your consent.
We use no analytics, advertising or tracking cookies. Our pages load nothing from other sites: every script, style sheet, font and icon, including the viewer for the interactive API reference, comes from our own domain. Links to other sites, such as the model's page, share nothing until you follow them.
Cloudflare may set a strictly necessary security cookie of its own if it has to check traffic that looks suspicious.
4. How we use it, and what we don't do
We use personal data only for the purposes listed in section 2: to provide, secure and bill for the service, to communicate with you, and to meet our legal obligations.
We don't:
- sell or rent personal data, or share it for advertising;
- use request content to train or improve models;
- make automated decisions about you that have legal or similarly significant effects.
We may disclose personal data if the law requires it, to protect the rights and safety of our users or others, or as part of a transfer of the service to a new operator, who would have to honor this policy.
5. Legal bases
If you are in the European Economic Area, the UK or Switzerland, the law requires a legal basis for each use of your personal data. Ours are:
- Contract: to create your account, sign you in, run your requests, bill you and otherwise provide the service you signed up for.
- Legitimate interests: to keep the service secure, prevent abuse and fraud, run the access queue, understand usage so we can keep the service running, and deal with legal claims. We rely on them only where your rights don't outweigh them, and you can object (see section 10).
- Legal obligation: to keep payment and tax records and respond to lawful requests from authorities.
6. Service providers
We rely on these companies to run SeaCat. Each handles personal data for us under its own terms and data protection commitments. We'll update this list when it changes.
| Provider | What it does | Data it handles | Location |
|---|---|---|---|
| Modal | Runs our web server and the GPUs that run the model, and holds our server logs | All requests, including request content while it's being processed; IP addresses; server logs | United States |
| Cloudflare | Serves our domain, encrypts connections and forwards all traffic to Modal | All traffic in transit, including IP addresses and request content; the proxy's error logs | Global network: traffic is handled at a data center near the visitor |
| Neon | Hosts our database | Account, sign-in, API key (hashed), usage and payment records | United States |
| Stripe | Processes payments | Payment details, billing information, email address, account ID and purchase amounts | United States |
| Resend | Sends our emails | Email addresses, and the emails we send, such as sign-in links | United States |
7. Where your data is processed
The service runs in the United States, and our service providers process your data there. If you use the service from outside the US, your data is transferred to the US, where data protection law may differ from yours. Cloudflare may also handle your traffic at a data center outside the US on its way to us.
Where the law requires safeguards for these transfers, for example from the EEA, the UK or Switzerland, we rely on the ones our providers offer, such as the European Commission's Standard Contractual Clauses and the UK's addendum to them.
8. How long we keep it
| Data | How long |
|---|---|
| Request content | Not kept. It's discarded once the answers are returned. |
| Account data | Until you delete your account, which you can do on the dashboard at any time. Deletion is immediate: we delete your email address, API keys, usage records and sign-in records. All that's left is a record of the account without your email address: its ID, when it was created and deleted, and its final credit balance, kept with the payment records below. |
| API keys | Until you delete your account, including revoked keys, which can no longer be used. |
| Usage records | Until you delete your account, so you can see your history and we can answer billing questions. |
| Payment records | As long as tax and accounting law requires, usually up to 7 years, even after you delete your account. Once it's deleted, they're linked only to the account's ID, not to your email address. Stripe keeps its own records of your payments, including your email address, under its own policy. |
| Sign-in records | 24 hours, then deleted automatically, whether or not the link was used. The link itself stops working after 15 minutes or once it's used. Deleting your account deletes these records straight away. |
| Database backups | Neon, our database host, keeps a rolling history of recent changes so the database can be restored after a failure. Data we delete stays in that history for up to 6 hours, until it rolls over. |
| Server and proxy logs | For a limited period, under Modal's and Cloudflare's log retention. |
| Sent emails | Resend keeps a record of each email it sends for a limited period, under its own retention. |
| Session cookie | In your browser until you sign out, or for 30 days after your last visit. |
9. Security
- Connections to the site and the API are encrypted with TLS (HTTPS). Cloudflare forwards traffic to Modal over HTTPS, and our servers reach the database, Stripe and Resend over encrypted connections too.
- We store API keys and sign-in link secrets only as SHA-256 hashes, so a copy of our database wouldn't reveal them.
- Sign-in links expire after 15 minutes and work once. The session cookie is signed and hidden from scripts.
- Card details go straight to Stripe and never reach our servers.
- Only the people who run the service can access production systems and the database.
No system is perfectly secure. If a breach affects your personal data, we'll tell you, and the authorities, as the law requires.
10. Your rights
Wherever you live, you can ask us to:
- access your data: tell you what personal data we hold about you and give you a copy;
- correct it, for example to change your account's email address;
- delete it: close your account and erase your data, except records the law requires us to keep;
- export it: give you your data in a machine-readable format;
- object to, or restrict, some of the ways we use it.
On the dashboard, at any time: download a copy of your data as a JSON file, which covers access and export, and delete your account, which takes effect straight away (see section 8 for what we keep). You can also see your usage and revoke API keys there.
For anything else, such as correcting your email address or objecting to a use of your data, email chris@shipsystems.ai from your account's email address and tell us what you'd like. We may need to confirm the request is yours, usually by replying to that address. We'll respond within 30 days, free of charge.
EEA, UK and Switzerland: the GDPR, the UK GDPR and Swiss law give you the rights above. You can also complain to your local data protection authority, though we'd like the chance to fix the problem first.
California and other US states: laws such as the CCPA give you the right to know what personal information we collect and how we use it, and to delete and correct it. In those laws' terms, we collect identifiers (such as your email and IP address), commercial information (your purchases and usage) and internet activity information (request details), from you and from your use of the service, for the purposes in section 2, and we disclose them only to the service providers in section 6. We don't sell personal information or share it for cross-context behavioral advertising, and we don't use sensitive personal information to infer things about you. We won't treat you differently for using your rights. You can make a request through an authorized agent; we may ask them to show that they act for you.
11. Personal data you send about others
Customers often send content about other people, such as support tickets, emails, applications or listings. For that data:
- You decide what to send and why, so you are its controller (or "business"), and we are your processor (or "service provider"). We process it only to return answers to you.
- You are responsible for having a legal basis to send it, for giving people any notices and getting any consents the law requires, and for handling their requests about their data. Send only what your questions need, and leave out sensitive data, such as health information, unless you have a legal basis and a real need for it.
- We don't use it for our own purposes, sell it, or train models on it.
- Because we don't store request content, we normally hold nothing about these people once a request is finished. If one of them contacts us, we'll refer them to you where we can.
- Data processing agreement: if you need one, for example under the GDPR, email chris@shipsystems.ai and we'll provide it.
12. Children
The service isn't for anyone under 18, and we don't knowingly collect personal data from children. If you think a child has given us personal data, email chris@shipsystems.ai and we'll delete it.
13. Changes to this policy
We may update this policy. The date at the top shows when it last changed. If we make a material change, we'll tell you by email or with a notice on the site before it takes effect.
14. Contact
SeaCat is operated by Ship Systems LLC. Send privacy questions and requests to chris@shipsystems.ai.