Privacy Policy
Effective date: November 1, 2024 (prior edition)
Last updated: November 1, 2025
This Privacy Policy (this “Policy”) explains how Multi-AI Brainstorming SEIGETSU (“we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data about individuals (“you,” “your”) when you use our website, application, and related services (collectively, the “Services”).
Controller (Data Controller): Daisuke Yamaguchi (“SEIGETSU”)
Contact: See the contact form at the end of this Policy.
Our Terms of Service are provided separately and form part of the contract with you. This Policy is incorporated by reference into the Terms of Service.
1. Personal Data We Collect
1.1 Data You Provide
- Account Information: Name (a handle/pseudonym is acceptable), contact details (e.g., email address), authentication credentials, payment information, and transaction history.
- User Content Information: Content you enter or upload to the Services (e.g., text, files, images) according to feature prompts.
- Communications: Your name, contact details, and message content when you interact with us (e.g., via email or contact form).
- Social Media Information (if applicable): Your username, public profile information, and messages sent via our official social channels.
- Other Information You Provide: Information you submit for events or surveys, or voluntarily to verify age/identity.
1.2 Data We Receive Automatically (Technical Information)
- Log Data: IP address, browser type/settings, request date/time, and your interactions within the Services.
- Usage Data: Types of content viewed or engaged with, features used and actions taken, time zone, country, access timestamps, user agent/version, device type, and connection details.
- Device Information: Operating system, browser name, device identifiers (details vary by device/settings).
- Location Information: Approximate region based on IP (e.g., for suspicious login detection or response optimization). If you permit via device settings, we may receive more precise location (e.g., GPS).
- Cookies & Similar Technologies: Used to operate/administer the Services and improve your experience. Analytics cookies are used with your consent. See our Cookie Policy for details. You can manage or withdraw consent at any time via the cookie banner or the “Cookie Settings” link in the site.
1.3 Data from Other Sources
We may receive information from trusted partners (e.g., security vendors to help protect against unauthorized access, abuse, and threats; marketing providers regarding potential B2B leads), only to the extent lawful and necessary. We may also consult publicly available information for service quality control and security enhancement.
We use services from Anthropic, Google, xAI, OpenAI, and DeepSeek. The processing of personal data by those providers is governed by their respective terms and privacy policies.
Model training: We do not develop or offer our own large language model and do not use your Content to train our models. Whether third-party providers use data for their training is governed by their respective terms and privacy policies.
2. Purposes of Processing
We process personal data to:
-
Provide, analyze, and maintain the Services;
-
Improve the Services, develop new features, and conduct research;
-
Communicate with you (including notices of changes/improvements and information about events);
-
Prevent and detect fraud, illegal activity, or abuse and protect the security and integrity of our systems and Services;
-
Comply with legal obligations and protect the rights, privacy, safety, or property of users, us, or others.
-
For security and abuse prevention, maintain minimal authentication token identifiers (e.g., refresh token blacklist entries) for a short period solely to prevent token reuse and fraud.
Email and unsubscribe: We primarily send transactional notices (e.g., account, security, billing). As such, general unsubscribe does not apply to essential transactional emails.
We may aggregate and/or de-identify data so it can no longer reasonably identify you and use such information for the purposes above. We keep de-identified data as de-identified, will not attempt re-identification unless required by law, and apply supplementary measures (e.g., access controls, minimum aggregation thresholds, encryption).
3. Disclosures of Personal Data (Third-Party Sharing)
3.1 Processors and Service Providers
We may disclose personal data to processors (service providers) that process data on our behalf (e.g., hosting, cloud, CDN, customer support, email delivery, web analytics, payment processing, security monitoring, and IT services). These processors are bound by contracts imposing confidentiality, security, and purpose limitation and process data only per our instructions.
Payments (PayPal): We use PayPal. Sensitive payment card data (e.g., card numbers) are collected and stored directly by PayPal; we do not store such data. Please consult PayPal’s privacy policy for details.
We do not share raw authentication tokens with processors. Where token identifiers must be processed for security, we use hashed identifiers and limit use strictly to security purposes.
3.2 Corporate Transactions
In connection with a merger, acquisition, reorganization, asset transfer, bankruptcy, or similar transaction (collectively, “Transaction”), we may disclose data to counterparties and advisors for due diligence and transfer data to an acquirer/affiliate as part of the Transaction.
3.3 Legal Compliance and Protection
We may disclose personal data to government authorities, regulators, courts, or parties to a legal proceeding when required by law, or where reasonably necessary to: (i) comply with legal obligations; (ii) protect our rights or property; (iii) address violations of our Terms, policies, or law; (iv) detect/prevent fraud, abuse, or illegal acts; (v) protect the safety, security, and integrity of our products, personnel, users, or the public; or (vi) protect against legal liability.
3.4 Affiliates & Business Accounts
We may disclose personal data to our affiliates (limited to uses consistent with this Policy). If you use a business account, the account administrator may access and manage your account and certain Content. If you register with an employer/organization email, we may disclose the fact of account ownership and certain account details (e.g., email address) to that organization.
4. Legal Bases (including EEA/UK)
| Purpose | Personal Data (main categories) | Legal Basis |
|---|---|---|
| Provide, analyze, and maintain the Services | Account, User Content, Communications, Logs, Usage, Device, Location, Cookies | Contract performance (e.g., processing user inputs to respond) |
| Improvements, new features, research | As needed from the above | Legitimate interests (service enhancement, quality control, UX) |
| Communications (service changes, events) | Account, Communications, as needed | Contract performance (important service notices) or Consent (certain marketing) |
| Fraud/abuse prevention & security | As needed from the above, Cookies | Legal obligations and/or Legitimate interests (safety, abuse prevention) |
| Legal compliance & rights protection | Transactions/records, logs, necessary minimum | Legal obligations and/or Legitimate interests |
You may object at any time to processing for direct marketing purposes. Where we rely on legitimate interests, you may also object on grounds relating to your particular situation.
Additionally, we rely on legitimate interests (GDPR Art. 6(1)(f)) for security and fraud prevention, including short-term retention of token identifiers to prevent token replay and abuse. We document the balancing test and record the retention period in our records of processing activities (ROPA).
5. Retention
We retain personal data only for as long as necessary for: (a) providing the Services; (b) dispute resolution; (c) security; and (d) legal compliance and other legitimate business purposes. Duration varies by purpose, amount/nature/sensitivity of data, risk of harm from misuse/disclosure, and legal requirements. Even if you request erasure, we may retain data for the minimum necessary period to comply with legal obligations or protect our rights.
After account deletion (erasure):
- We may retain the minimum necessary data for legal obligations, defense of claims, and fraud/security purposes.
- Examples:
- Payments/accounting records (invoices, payments, refunds): up to 7 years (may vary by jurisdiction).
- Security/audit logs: about 90–180 days.
- Consent logs (cookies/marketing): around 1 year from last relevant processing.
- Where feasible, we anonymize/pseudonymize retained data and delete or irreversibly de-identify it once the purpose is fulfilled.
Authentication token identifiers (e.g., refresh token blacklist entries; not raw tokens) are retained only as long as necessary for security: typically up to 8 days (refresh token lifetime of 7 days plus a 24-hour buffer) and deleted via a daily purge job. In higher-risk contexts, we may retain up to 14 days. A 30-day retention applies only where legally or contractually required and documented. CSRF tokens are not stored in our database.
We may retain a minimal suppression list (email addresses and required metadata) solely to honor unsubscribe/opt-out requests and prevent further emails. We do not use suppression data for other purposes, and we delete it when no longer necessary to comply with legal obligations and prevent re-contact.
6. Cookies
We primarily use strictly necessary cookies (essential for core site functions). Where appropriate, we use analytics cookies with your consent (e.g., Google Analytics). You can withdraw consent at any time via the cookie banner or the “Cookie Settings” link. See Cookie Policy for details.
CSRF tokens are issued as cookies to protect requests and are not persisted in our database. We do not store raw CSRF tokens in logs.
For our Canva extension, we do not use our own cookies or WebStorage; any cookies are controlled by Canva.
7. Your Rights
Subject to applicable law (and its conditions/exceptions), you may have the right to:
- Access your personal data and information about our processing;
- Erase your personal data;
- Rectify/Update your personal data;
- Port your data (data portability);
- Restrict processing;
- Withdraw consent where processing relies on consent;
- Complain to your supervisory/data protection authority;
- Object to processing for direct marketing at any time, and to processing based on legitimate interests.
On accuracy of AI outputs: We use third-party generative AI to produce responses. Due to probabilistic behavior, outputs may not always be factually accurate. If any output contains inaccurate personal data about you, please contact us; we will assess and act consistent with technical constraints to the third-party provider.
8. Children
The Services are not directed to children under 13 and we do not knowingly collect personal data from them. If you believe a child under 13 has provided personal data to us, contact us and we will investigate and, where appropriate, delete such data. Users under 18 must have parental/guardian permission to use the Services.
9. Security
We implement commercially reasonable technical, organizational, and operational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, and destruction. However, no Internet or email transmission is ever fully secure. We are not responsible for circumvention of privacy/security settings or measures on the Services or third-party sites.
We do not store raw authentication tokens. Where token identifiers are recorded (e.g., JWT JTI for blacklist), we use hashed identifiers and apply access controls, encryption in transit/at rest, and least-privilege permissions. Daily purge jobs remove expired identifiers according to our retention policy.
10. International Data Transfers
We may process and store personal data on servers outside the EEA, Switzerland, and the UK (e.g., in Japan). Laws differ by country, but we apply the protections described in this Policy regardless of location. For transfers from the EEA/Switzerland/UK to third countries, we rely on lawful transfer mechanisms, including:
- Adequacy decisions under GDPR Article 45(1), where applicable;
- Standard Contractual Clauses (SCCs) under GDPR Article 46(2)(c) and, as needed, the UK Data Transfer Addendum.
We also apply supplementary measures (e.g., encryption in transit/at rest, access controls, purpose limitation, data minimization). You may request a copy or summary of the SCCs and details of safeguards via the contact form below.
11. Automated Decision-Making
We do not engage in automated individual decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of GDPR Article 22.
12. Roles for B2B Use
Where you use the Services as an organization/administrator, we may act as a processor for certain processing under an applicable data processing agreement (DPA). For consumer use, we act as the controller.
13. Changes to this Policy
We may update this Policy from time to time. Unless another form of notice is required by law, we will post the updated Policy and its effective date on this page.
14. Contact
For questions about this Policy, our processing of personal data, to exercise your rights (access, deletion, rectification, objection, portability, withdrawal of consent), please contact us via:
Email: info@seigetsu.ai
Contact Form: https://docs.google.com/forms/d/e/1FAIpQLScDI_3mO1tO3oM1lKVD0YIeIhXcgCy8v0nxQU2Jqm-FeEmf5Q/viewform?usp=header