Privacy Policy

Effective date: November 1, 2024 (prior edition)

Last updated: November 1, 2025

This Privacy Policy (this “Policy”) explains how Multi-AI Brainstorming SEIGETSU (“we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data about individuals (“you,” “your”) when you use our website, application, and related services (collectively, the “Services”).

Controller (Data Controller): Daisuke Yamaguchi (“SEIGETSU”)

Contact: See the contact form at the end of this Policy.

Our Terms of Service are provided separately and form part of the contract with you. This Policy is incorporated by reference into the Terms of Service.


1. Personal Data We Collect

1.1 Data You Provide

1.2 Data We Receive Automatically (Technical Information)

1.3 Data from Other Sources

We may receive information from trusted partners (e.g., security vendors to help protect against unauthorized access, abuse, and threats; marketing providers regarding potential B2B leads), only to the extent lawful and necessary. We may also consult publicly available information for service quality control and security enhancement.

We use services from Anthropic, Google, xAI, OpenAI, and DeepSeek. The processing of personal data by those providers is governed by their respective terms and privacy policies.

Model training: We do not develop or offer our own large language model and do not use your Content to train our models. Whether third-party providers use data for their training is governed by their respective terms and privacy policies.


2. Purposes of Processing

We process personal data to:

Email and unsubscribe: We primarily send transactional notices (e.g., account, security, billing). As such, general unsubscribe does not apply to essential transactional emails.

We may aggregate and/or de-identify data so it can no longer reasonably identify you and use such information for the purposes above. We keep de-identified data as de-identified, will not attempt re-identification unless required by law, and apply supplementary measures (e.g., access controls, minimum aggregation thresholds, encryption).


3. Disclosures of Personal Data (Third-Party Sharing)

3.1 Processors and Service Providers

We may disclose personal data to processors (service providers) that process data on our behalf (e.g., hosting, cloud, CDN, customer support, email delivery, web analytics, payment processing, security monitoring, and IT services). These processors are bound by contracts imposing confidentiality, security, and purpose limitation and process data only per our instructions.

Payments (PayPal): We use PayPal. Sensitive payment card data (e.g., card numbers) are collected and stored directly by PayPal; we do not store such data. Please consult PayPal’s privacy policy for details.

We do not share raw authentication tokens with processors. Where token identifiers must be processed for security, we use hashed identifiers and limit use strictly to security purposes.

3.2 Corporate Transactions

In connection with a merger, acquisition, reorganization, asset transfer, bankruptcy, or similar transaction (collectively, “Transaction”), we may disclose data to counterparties and advisors for due diligence and transfer data to an acquirer/affiliate as part of the Transaction.

3.3 Legal Compliance and Protection

We may disclose personal data to government authorities, regulators, courts, or parties to a legal proceeding when required by law, or where reasonably necessary to: (i) comply with legal obligations; (ii) protect our rights or property; (iii) address violations of our Terms, policies, or law; (iv) detect/prevent fraud, abuse, or illegal acts; (v) protect the safety, security, and integrity of our products, personnel, users, or the public; or (vi) protect against legal liability.

3.4 Affiliates & Business Accounts

We may disclose personal data to our affiliates (limited to uses consistent with this Policy). If you use a business account, the account administrator may access and manage your account and certain Content. If you register with an employer/organization email, we may disclose the fact of account ownership and certain account details (e.g., email address) to that organization.


4. Legal Bases (including EEA/UK)

Purpose Personal Data (main categories) Legal Basis
Provide, analyze, and maintain the Services Account, User Content, Communications, Logs, Usage, Device, Location, Cookies Contract performance (e.g., processing user inputs to respond)
Improvements, new features, research As needed from the above Legitimate interests (service enhancement, quality control, UX)
Communications (service changes, events) Account, Communications, as needed Contract performance (important service notices) or Consent (certain marketing)
Fraud/abuse prevention & security As needed from the above, Cookies Legal obligations and/or Legitimate interests (safety, abuse prevention)
Legal compliance & rights protection Transactions/records, logs, necessary minimum Legal obligations and/or Legitimate interests

You may object at any time to processing for direct marketing purposes. Where we rely on legitimate interests, you may also object on grounds relating to your particular situation.

Additionally, we rely on legitimate interests (GDPR Art. 6(1)(f)) for security and fraud prevention, including short-term retention of token identifiers to prevent token replay and abuse. We document the balancing test and record the retention period in our records of processing activities (ROPA).


5. Retention

We retain personal data only for as long as necessary for: (a) providing the Services; (b) dispute resolution; (c) security; and (d) legal compliance and other legitimate business purposes. Duration varies by purpose, amount/nature/sensitivity of data, risk of harm from misuse/disclosure, and legal requirements. Even if you request erasure, we may retain data for the minimum necessary period to comply with legal obligations or protect our rights.

After account deletion (erasure):

Authentication token identifiers (e.g., refresh token blacklist entries; not raw tokens) are retained only as long as necessary for security: typically up to 8 days (refresh token lifetime of 7 days plus a 24-hour buffer) and deleted via a daily purge job. In higher-risk contexts, we may retain up to 14 days. A 30-day retention applies only where legally or contractually required and documented. CSRF tokens are not stored in our database.

We may retain a minimal suppression list (email addresses and required metadata) solely to honor unsubscribe/opt-out requests and prevent further emails. We do not use suppression data for other purposes, and we delete it when no longer necessary to comply with legal obligations and prevent re-contact.


6. Cookies

We primarily use strictly necessary cookies (essential for core site functions). Where appropriate, we use analytics cookies with your consent (e.g., Google Analytics). You can withdraw consent at any time via the cookie banner or the “Cookie Settings” link. See Cookie Policy for details.

CSRF tokens are issued as cookies to protect requests and are not persisted in our database. We do not store raw CSRF tokens in logs.

For our Canva extension, we do not use our own cookies or WebStorage; any cookies are controlled by Canva.


7. Your Rights

Subject to applicable law (and its conditions/exceptions), you may have the right to:

On accuracy of AI outputs: We use third-party generative AI to produce responses. Due to probabilistic behavior, outputs may not always be factually accurate. If any output contains inaccurate personal data about you, please contact us; we will assess and act consistent with technical constraints to the third-party provider.


8. Children

The Services are not directed to children under 13 and we do not knowingly collect personal data from them. If you believe a child under 13 has provided personal data to us, contact us and we will investigate and, where appropriate, delete such data. Users under 18 must have parental/guardian permission to use the Services.


9. Security

We implement commercially reasonable technical, organizational, and operational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, and destruction. However, no Internet or email transmission is ever fully secure. We are not responsible for circumvention of privacy/security settings or measures on the Services or third-party sites.

We do not store raw authentication tokens. Where token identifiers are recorded (e.g., JWT JTI for blacklist), we use hashed identifiers and apply access controls, encryption in transit/at rest, and least-privilege permissions. Daily purge jobs remove expired identifiers according to our retention policy.


10. International Data Transfers

We may process and store personal data on servers outside the EEA, Switzerland, and the UK (e.g., in Japan). Laws differ by country, but we apply the protections described in this Policy regardless of location. For transfers from the EEA/Switzerland/UK to third countries, we rely on lawful transfer mechanisms, including:

We also apply supplementary measures (e.g., encryption in transit/at rest, access controls, purpose limitation, data minimization). You may request a copy or summary of the SCCs and details of safeguards via the contact form below.


11. Automated Decision-Making

We do not engage in automated individual decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of GDPR Article 22.


12. Roles for B2B Use

Where you use the Services as an organization/administrator, we may act as a processor for certain processing under an applicable data processing agreement (DPA). For consumer use, we act as the controller.


13. Changes to this Policy

We may update this Policy from time to time. Unless another form of notice is required by law, we will post the updated Policy and its effective date on this page.


14. Contact

For questions about this Policy, our processing of personal data, to exercise your rights (access, deletion, rectification, objection, portability, withdrawal of consent), please contact us via:

Email: info@seigetsu.ai

Contact Form: https://docs.google.com/forms/d/e/1FAIpQLScDI_3mO1tO3oM1lKVD0YIeIhXcgCy8v0nxQU2Jqm-FeEmf5Q/viewform?usp=header