Privacy Policy
What we collect, what we deliberately do not, and how long we hold it.
Last updated 31 August 2026
01What this covers
This describes what seams collects when you use the gateway, the console and the hosted portal, what we do with it, and how long we hold it. It applies to you as our customer, and to the end users you provision keys for.
seams is operated by Kosi Asuzu as a sole trader. For data you give us about your own staff and account we are the controller, and you can reach us at asuzukosiie@gmail.com. For your end users’ data you are the controller and we are your processor: what you tell your customers about their data is your responsibility, and what we do with it is described here.
02What we do not store
We do not store prompt or completion content. Not in logs, not in the usage record, not in a debug buffer. The record a request produces has no messages field, no prompt field, no completion field and no body field, and there is no configuration that adds one.
This is a property of the data model rather than a setting. Request and response bodies pass through the gateway to the provider and are not written down on the way.
We make no claim about what a model provider stores once a request reaches them. That is governed by their terms, not ours, and we have no contract with them that would let us promise otherwise.
03What we do collect
Enough to bill correctly and to show your customers what they used.
- Account data: your organisation name, the email addresses of your staff, and authentication material for the console.
- End-user identifiers you supply when minting a key, typically an email address or an internal id, stored as the actor label so usage can be attributed.
- Request metadata: timestamp, model alias, resolved provider model, token counts, latency, status and computed cost. No content.
- Ledger entries: credits granted, holds taken, charges settled, all as integer micro-dollar amounts.
- Sign-in records for the console and portal, including IP address and user agent, used for security and abuse prevention.
04Why we are allowed to process it
For your account data we rely on three grounds, and nothing else.
- To perform our contract with you: running the gateway, metering usage, and billing for it.
- Our legitimate interests: keeping the service secure, preventing abuse, and understanding whether it works. We do not profile anyone or make automated decisions about people.
- Legal obligations: keeping the billing records that tax and accounting rules require.
- For your end users’ data we act on your instructions as your processor. Choosing the lawful basis for that processing is yours, not ours.
05Provider credentials
If you bring your own provider key, it is stored with envelope encryption: a per-request data key encrypts the secret, and a master key wraps the data key, bound to a per-customer encryption context. The master key is held by the deployment. Ciphertext is never stored in plaintext.
Plaintext exists only inside the request that needs it, in memory, for the length of that request. Resolved credentials are never written to a cache that persists to disk or replicates over a network, never logged, and never included in an error message. The object holding one throws if something tries to serialise it.
06Who else sees it
Your requests reach the model provider you have selected, because that is what the product does. Under bring-your-own-key those calls are made on your provider account with your key, so that relationship is yours and their terms govern it.
Beyond that we use a small number of companies to run the service: Cloudflare for the websites, DNS and certificates, Fly.io to run the gateway, API, portal and console, Stripe to collect our tier fee, and GitHub for our source code, our build pipeline and console sign-in. We do not sell data, and we do not use your traffic or your customers’ traffic to train anything.
Those companies operate globally, including in the United States, so if you or your end users are in the UK or the EEA your data is transferred outside it. We have not yet put standard contractual clauses in place, because we are not yet a company that can sign them. If you need a data processing agreement before you can use seams, say so and we will tell you honestly where we are.
07How long we keep it
Usage records and ledger entries are retained while your account is open and for as long afterwards as tax and accounting rules require, because they are the evidence behind invoices.
The ledger is append-only by design and enforced by a database trigger: entries cannot be edited or deleted in place, even by us. A correction is a new entry, which is what makes an audit trail worth having.
There is no self-serve account deletion. Ask us and we will delete your account data by hand and confirm when it is done, keeping only the ledger and billing records we are required to hold.
08Your rights
If the UK or EU GDPR applies to you, you have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable form. Ask us and we will act within thirty days.
Your usage and ledger data can be read from the console and the command line at any time. For anything else, or for a request on behalf of one of your end users, contact us.
Because we do not hold prompt or completion content, a content deletion request has nothing for us to delete, which is the point of not collecting it.
If you think we have handled your data badly, tell us first and we will try to fix it. You can also complain to the data protection regulator where you live; in the UK that is the Information Commissioner’s Office.
09Changes
If this document changes in a way that materially affects you, we will tell you before it takes effect. The date at the top always reflects the current version.
Questions about this document go to asuzukosiie@gmail.com.