Seige Privacy Policy

DRAFT — not effective or ready to publish. Prepared September 19, 2026. Resolve bracketed fields and the publication checklist before adoption. Statements below describe the reviewed evaluation implementation or explicitly identified proposed commitments; verify deployment before publishing.

Effective date: [EFFECTIVE DATE].

1. Who is responsible

This policy describes how Seige handles personal information. Operator identification is intentionally deferred in this draft; no registered office or jurisdiction is established here. Contact [PRIVACY EMAIL] for privacy questions or requests. [ADD DATA-PROTECTION OFFICER AND REGIONAL REPRESENTATIVE CONTACTS IF REQUIRED.]

This policy covers our website and current account, notes and email evaluation. It also covers people who send messages to Seige users or contact us without an account. It does not claim that planned storage, AI, OAuth or third-party app features are available. We will explain additional processing before introducing such features. Where we process business-customer content solely on their instructions, any required data-processing agreement will separately identify the parties' roles.

2. Information we process

CategoryInformation and sourcePurpose
Account and authenticationYour chosen username, assigned address and account identifier; password-protocol registration data; public keys, encrypted key packages and signatures; optional passkey identifiers, public credential records and encrypted wrappersCreate and authenticate accounts, open supported encrypted data on your device, and prevent unauthorized access
Sessions and browser storageSession identifiers and expiry data; remembered-session token hashes and server wrapping shares; encrypted local account packages and browser-held cryptographic keysMaintain sign-in, restore access and revoke sessions
Stored contentEncrypted notes, drafts, mailbox messages and received originals, including attachments; record identifiers, ownership, sizes, versions, timestamps and mailbox/delivery stateSave, retrieve, synchronize and deliver your information
Email deliverySender and recipient addresses, routing headers, message identifiers, timestamps, delivery results and readable internet-message content at the mail gateway; supplied by senders, recipients and their providersRoute messages, filter spam locally, handle retries and diagnose delivery failures
Connections and operationsIP addresses processed when connecting, connection timing, request and error information, mail-server logs and security signalsServe requests, apply limits, troubleshoot and protect infrastructure
Support and abuse casesContact details, correspondence, reports, supplied evidence and action records from you, reporters or authorized authoritiesAnswer requests, investigate abuse, handle appeals and meet legal duties

The account protocol does not send your raw password or your content private keys to the account API. Passkey verification occurs through your authenticator; Seige does not receive its fingerprint or face templates. Authentication records and encrypted key packages remain security-sensitive information.

The reviewed web configuration does not enable access logs, advertising trackers or third-party analytics. This does not mean all infrastructure is log-free: mail and operating-system services can record operational information, and IP addresses are processed for connections and abuse controls. [CONFIRM ACTUAL LOG FIELDS, PROVIDER TELEMETRY AND RETENTION BEFORE PUBLICATION.]

3. What encryption does and does not protect

Supported notes, drafts and stored mailbox copies are encrypted for your account. For mail between Seige accounts, the sender's browser encrypts separate copies for the sender and recipient. Account servers store those ciphertexts rather than receiving the corresponding content private keys.

Ordinary internet email has a different boundary. Incoming mail is readable by our mail server, spam filter and gateway before encryption into the mailbox. Outgoing internet mail includes a copy encrypted to the gateway, which decrypts it for delivery. Temporary mail queues may contain readable messages. Administrators can observe this delivery plaintext and routing metadata, and the SMTP boundary can be subject to lawful interception. Stored mailbox encryption does not make ordinary internet delivery end-to-end encrypted.

Encrypted backups include gateway key material and may include pending outbound ciphertext, so they must also be protected against access to pending external messages. They do not include the plaintext SMTP retry queue.

Your device decrypts supported content. Compromised devices or browser code can expose it; first-party browser code supplied by Seige is part of the trust boundary. Recipients can keep or share their copies. Lost credentials may prevent recovery. Seige remains an evaluation service without completed independent security qualification; use test data.

4. Uses and legal bases

We use the information above to provide and secure the requested features, communicate about service issues, respond to support and rights requests, investigate misuse and meet legal obligations. We do not sell personal information, use private content for targeted advertising, or train AI models on private content. These are commitments of this proposed policy and must remain consistent with actual practices.

Where a law requires a legal basis, we rely on performing our agreement for account and service delivery; legitimate interests in security, abuse prevention and support, balanced against affected people's rights; and legal obligations for required records, reports and responses. For correspondence involving non-users, the relevant interest is delivering communications requested by our users. Optional processing requiring consent will be explained separately, and consent can be withdrawn without affecting prior lawful processing. We do not treat acceptance of the Terms as blanket privacy consent.

Account information needed for authentication and delivery is necessary to provide those features. Without it, we cannot operate the account or deliver the message. We do not use personal data for advertising profiles. Technical controls may automatically reject requests or mail; contact [APPEALS EMAIL] to request human review of a restriction affecting you.

5. When information is shared

6. Retention, closure and deletion

We keep data for the purposes described here and applicable legal requirements. Current evaluation limits are important:

DataCurrent behavior or required final detail
Account records and encrypted contentPersist in the service database. Self-service account deletion and a complete purge workflow are unfinished. Trash changes mailbox state; it does not erase messages or reclaim quota. Request closure or deletion at [PRIVACY EMAIL]. [DEFINE AND IMPLEMENT ACTIVE-DATA DELETION DEADLINE.]
Remembered sign-inServer grants expire after 60 days without use. Sign-out revokes that browser grant and removes its local remembered cache. Expiry does not necessarily mean immediate removal of every expired database row.
SMTP retry queuesConfigured retries run for up to two days; bounce queues up to one day. These delivery settings are not a deletion guarantee for logs, mailbox copies or backups.
BackupsDocumented daily encrypted server archives rotate after 14 days. Separate operator-held off-server copies exist; their deletion schedule is [OFF-SERVER BACKUP RETENTION]. The 14-day rotation is not a universal erasure deadline.
Logs, support and abuse records[SET PERIODS OR SPECIFIC NECESSITY-BASED CRITERIA FOR EACH CATEGORY, INCLUDING PROVIDER LOGS AND CLOSED CASES.]
Legal holdsRelevant records may be retained for a required preservation period, legal obligation or necessary legal claim, with access restricted and the hold reviewed before release.

We will assess deletion requests individually, explain lawful retention exceptions and meet applicable statutory deadlines. Incomplete self-service tooling does not remove your legal rights. Deletion from Seige cannot remove copies retained by recipients or your devices. Restoring backups must preserve previously actioned deletion requests. [IMPLEMENT AND TEST THIS PROCESS BEFORE ADOPTING THIS POLICY.]

7. Cookies and local storage

The prepared service-domain layout uses `account.seige.ai` for sign-in and the trusted app runtime. Mail and Storage pages embed that runtime from the account origin. Account cookies and encrypted local account storage stay on that origin; service pages exchange only readiness and navigation messages with it. Storage currently shows a coming-soon view. [VERIFY DOMAIN CUTOVER AND BROWSER BEHAVIOR BEFORE PUBLICATION.]

Seige uses cookies for authentication and session security. Remembered sign-in stores an encrypted account package and a browser cryptographic key in IndexedDB; the server supplies a separate wrapping share through an authorized session. These mechanisms support account access, not advertising.

The sign-in screen lets you choose whether to stay signed in. Disabling that choice uses a session cookie, though browsers may restore session cookies when reopening a session. Sign-out clears the remembered grant and local cache for that browser. Blocking essential storage can prevent sign-in or restoration. [VERIFY AND LIST OTHER PREFERENCE STORAGE USED BY THE RELEASE.]

8. Locations and international transfers

The documented service uses Hetzner infrastructure. Actual hosting country, operator access countries, backup destinations and any other processing locations are [CONFIRMED COUNTRIES]. We will identify applicable safeguards for transfers requiring them, such as an adequacy decision or appropriate contractual safeguards, and explain how to obtain a copy at [PRIVACY EMAIL]. [INSERT THE ACTUAL TRANSFER MECHANISM AND RELEVANT RECIPIENTS; DO NOT INFER LAWFUL TRANSFERS FROM A PROVIDER'S BRAND.]

9. Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction or a portable copy of personal information, object to processing based on legitimate interests, and withdraw consent. Send requests to [PRIVACY EMAIL]. We use proportionate verification and do not ask for your password or private keys. We will explain any legally permitted refusal or limitation and applicable appeal route, and respond within the deadline required by your law.

Encryption may limit what we can retrieve in readable form; it does not eliminate rights over metadata or other information we hold. The current interface does not provide complete export or self-service account deletion. Contact us for available assistance.

You may complain to the competent privacy regulator, including the authority where you live or work when applicable. Our lead or local authority, if applicable, is [AUTHORITY AND COMPLAINT LINK]. We will not retaliate against you for exercising privacy rights. [ADD REQUIRED REGIONAL NOTICES, AGENT REQUEST METHODS AND APPEALS AFTER JURISDICTION REVIEW.]

10. Children and updates

Account registration is intended for adults aged 18 and over. If you believe an underage person registered, contact [PRIVACY EMAIL] so we can investigate and take appropriate action. An age restriction does not mean incoming correspondence can never contain information about minors.

We will publish revisions with an effective date and notify users of material changes through the Service or an available account contact. Where required, we will obtain separate consent before introducing new processing. Contact [PRIVACY EMAIL] with questions.